 | OTL logfile created on: 12/30/2011 6:41:35 PM - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\slayerman1\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.49 Mb Total Physical Memory | 632.98 Mb Available Physical Memory | 61.85% Memory free 2.40 Gb Paging File | 2.14 Gb Available in Paging File | 89.15% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 24.41 Gb Total Space | 15.29 Gb Free Space | 62.61% Space Free | Partition Type: NTFS Drive E: | 50.11 Gb Total Space | 47.07 Gb Free Space | 93.93% Space Free | Partition Type: NTFS Drive Z: | 74.47 Gb Total Space | 54.35 Gb Free Space | 72.98% Space Free | Partition Type: NTFS
Computer Name: MASTER | User Name: slayerman1 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011/12/30 18:21:09 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\slayerman1\Desktop\OTL.exe PRC - [2011/06/15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe PRC - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2005/03/14 11:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [Disabled | Stopped] -- -- (HidServ) SRV - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc) SRV - [2005/03/14 11:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2011/12/30 09:38:22 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87F2E821-3C9A-4A5A-9AA4-6BAD520F1CC8}\MpKslf85264e4.sys -- (MpKslf85264e4) DRV - [2011/12/30 09:02:18 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87F2E821-3C9A-4A5A-9AA4-6BAD520F1CC8}\MpKsl69d6621d.sys -- (MpKsl69d6621d) DRV - [2008/04/13 23:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum) DRV - [2002/08/28 17:59:12 | 000,036,224 | ---- | M] (ADMtek Incorporated.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\an983.sys -- (AN983) DRV - [2002/07/24 12:52:26 | 000,998,004 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha10kx2k.sys -- (ha10kx2k) DRV - [2002/07/19 09:48:32 | 000,156,604 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia) DRV - [2002/07/19 09:48:22 | 000,213,860 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k) DRV - [2002/07/19 09:48:08 | 000,011,068 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k) DRV - [2002/07/19 09:48:04 | 000,195,432 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv) DRV - [2002/07/19 09:47:52 | 000,837,548 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM) DRV - [2002/07/19 09:46:28 | 000,127,948 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k) DRV - [2001/08/31 08:37:58 | 000,036,992 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sfman.sys -- (sfman) Creative SoundFont Manager Driver (WDM) DRV - [2001/08/17 07:19:20 | 000,003,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctljystk.sys -- (ctljystk) DRV - [2001/08/14 10:17:52 | 000,775,296 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emu10k1f.sys -- (emu10k) Creative SB Live! series(WDM) DRV - [2001/07/11 06:34:52 | 000,006,912 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctlface.sys -- (emu10k1) Creative Interface Manager Driver (WDM) DRV - [1999/12/17 00:00:00 | 000,006,752 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\PFMODNT.SYS -- (PfModNT)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »www.google.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=#E56717]========== FireFox ==========[/color]
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: E:\Mozilla Thunderbird\components [2011/11/20 14:41:28 | 000,000,000 | ---D | M]
[2011/09/24 11:22:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\slayerman1\Application Data\Mozilla\Extensions
O1 HOSTS File: ([2003/03/31 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: = O8 - Extra context menu item: E&xport to Microsoft Excel - E:\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] http in Trusted sites) O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} »quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} »windowsupdate.microsoft.com/wind···35599176 (WUWebControl Class) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} »download.eset.com/special/eos/On···nner.cab (OnlineScanner Control) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} »fpdownload2.macromedia.com/get/s···lash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.233.217.3 64.233.217.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F117E8C2-F617-4367-9019-6084DFB1035C}: DhcpNameServer = 64.233.217.3 64.233.217.5 O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011/09/22 16:28:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011/12/30 18:21:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\slayerman1\Application Data\QuickScan [2011/12/30 18:20:46 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\slayerman1\Desktop\OTL.exe [2011/12/30 16:49:48 | 000,472,064 | ---- | C] ( ) -- C:\Documents and Settings\slayerman1\Desktop\RootRepeal.exe [2011/12/30 09:37:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\slayerman1\Recent [2011/12/29 19:02:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2011/12/29 16:48:06 | 001,578,288 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\slayerman1\Desktop\TDSSKiller.exe [2011/12/29 16:48:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\slayerman1\Local Settings\Application Data\jZip [2011/12/03 09:45:48 | 003,552,208 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\slayerman1\My Documents\ccsetup313.exe [2011/09/23 18:09:25 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011/12/30 18:21:10 | 000,879,683 | ---- | M] () -- C:\Documents and Settings\slayerman1\Desktop\SecurityCheck.exe [2011/12/30 18:21:09 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\slayerman1\Desktop\OTL.exe [2011/12/30 16:49:10 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011/12/30 09:38:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011/12/30 09:38:03 | 000,150,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011/12/30 09:37:29 | 000,029,808 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000F-00001102-00000002-80641102}.rfx [2011/12/30 09:37:29 | 000,029,808 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000F-00001102-00000002-80641102}.rfx [2011/12/30 09:37:29 | 000,017,500 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000F-00001102-00000002-80641102}.rfx [2011/12/30 09:37:29 | 000,017,500 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000F-00001102-00000002-80641102}.rfx [2011/12/30 09:37:29 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm [2011/12/30 09:37:29 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm [2011/12/30 09:37:29 | 000,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000F-00001102-00000002-80641102}.dat [2011/12/30 09:37:29 | 000,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000F-00001102-00000002-80641102}.dat [2011/12/29 15:55:50 | 001,558,406 | ---- | M] () -- C:\Documents and Settings\slayerman1\Desktop\tdsskiller.zip [2011/12/29 15:49:57 | 000,000,544 | ---- | M] () -- C:\Documents and Settings\slayerman1\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk [2011/12/27 14:09:16 | 000,000,211 | RHS- | M] () -- C:\boot.ini [2011/12/23 14:52:26 | 001,578,288 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\slayerman1\Desktop\TDSSKiller.exe [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2011/12/03 09:46:08 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\slayerman1\My Documents\ccsetup313.exe
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011/12/30 18:20:52 | 000,879,683 | ---- | C] () -- C:\Documents and Settings\slayerman1\Desktop\SecurityCheck.exe [2011/12/30 16:50:03 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\slayerman1\Desktop\gmer.exe [2011/12/30 09:38:03 | 000,150,792 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011/12/29 15:55:37 | 001,558,406 | ---- | C] () -- C:\Documents and Settings\slayerman1\Desktop\tdsskiller.zip [2011/12/29 15:49:57 | 000,000,544 | ---- | C] () -- C:\Documents and Settings\slayerman1\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk [2011/10/08 10:15:59 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\slayerman1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/09/24 11:18:24 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2011/09/23 18:56:36 | 000,000,024 | ---- | C] () -- C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000F-00001102-00000002-80641102}.dat [2011/09/23 18:56:36 | 000,000,024 | ---- | C] () -- C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000F-00001102-00000002-80641102}.dat [2011/09/23 18:09:28 | 000,037,727 | ---- | C] () -- C:\WINDOWS\System32\Emu10kx.ini [2011/09/23 18:09:28 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini [2011/09/23 18:09:25 | 000,184,320 | ---- | C] () -- C:\WINDOWS\PSCONV.EXE [2011/09/23 18:09:25 | 000,179,669 | ---- | C] () -- C:\WINDOWS\System32\ctstatic.dat [2011/09/23 18:09:25 | 000,164,044 | ---- | C] () -- C:\WINDOWS\System32\ctdlang.dat [2011/09/23 18:09:25 | 000,113,373 | ---- | C] () -- C:\WINDOWS\System32\ctbasicw.dat [2011/09/23 18:09:25 | 000,113,273 | ---- | C] () -- C:\WINDOWS\System32\CTBAS2W.DAT [2011/09/23 18:09:25 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\KILLAPPS.EXE [2011/09/23 18:09:25 | 000,044,055 | ---- | C] () -- C:\WINDOWS\System32\ctdaught.dat [2011/09/23 18:09:25 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\REGPLIB.EXE [2011/09/23 18:09:25 | 000,000,180 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI [2011/09/22 17:36:10 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll [2011/09/22 17:32:29 | 000,105,074 | ---- | C] () -- C:\WINDOWS\HPFins09.dat [2011/09/22 17:32:29 | 000,003,732 | ---- | C] () -- C:\WINDOWS\hpfmdl09.dat [2011/09/22 17:26:15 | 000,000,036 | ---- | C] () -- C:\WINDOWS\plugSpk.INI [2011/09/22 17:22:59 | 001,048,576 | ---- | C] () -- C:\WINDOWS\System32\sfman.dat [2011/09/22 17:22:59 | 000,000,231 | ---- | C] () -- C:\WINDOWS\ac3api.ini [2011/09/22 17:22:23 | 000,000,129 | ---- | C] () -- C:\WINDOWS\SBWIN.INI [2011/09/22 16:31:02 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2011/09/22 16:25:32 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2011/09/22 12:17:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2004/08/02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2003/03/31 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2003/03/31 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2003/03/31 07:00:00 | 000,405,342 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2003/03/31 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2003/03/31 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2003/03/31 07:00:00 | 000,054,560 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2003/03/31 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2003/03/31 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2003/03/31 07:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2003/03/31 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [2003/03/31 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2001/07/06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[color=#E56717]========== LOP Check ==========[/color]
[2011/09/24 11:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2011/09/24 09:28:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\slayerman1\Application Data\Auslogics [2011/12/30 18:22:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\slayerman1\Application Data\QuickScan [2011/09/24 11:22:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\slayerman1\Application Data\Thunderbird
[color=#E56717]========== Purity Check ==========[/color] |