OTL scan:
OTL logfile created on: 6/26/2012 6:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Cain\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 55.73% Memory free
2.98 Gb Paging File | 2.11 Gb Available in Paging File | 70.76% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 148.95 Gb Total Space | 126.80 Gb Free Space | 85.13% Space Free | Partition Type: NTFS
Drive D: | 145.84 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: CAIN-PC | User Name: Cain | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Cain\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
========== Win32 Services (SafeList) ==========
SRV:[b]64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://iat.ninemsn.com.au/tickler/default.aspx
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E4 F3 8E D0 93 48 CD 01 [binary data]
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\..\SearchScopes\{012B4696-57B8-4C16-9915-5BD69971A95F}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10401&src=crm&q={searchTerms}&locale=&apn_ptnrs=^ABZ&apn_dtid=^YYYYYY^YY^AU&apn_uid=a2abc1d7-7cfb-4199-9e35-12f9d645d978&apn_sauid=28081A30-A1E8-470C-B581-2A2B039DCAA2
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1907864757-3584112839-898014372-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10401&locale=en_AU&apn_uid=a2abc1d7-7cfb-4199-9e35-12f9d645d978&apn_ptnrs=^ABZ&apn_sauid=28081A30-A1E8-470C-B581-2A2B039DCAA2&apn_dtid=^YYYYYY^YY^AU&&q="
FF - user.js - File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/12 22:36:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/06/12 22:36:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Cain\AppData\Roaming\Mozilla\Extensions
[2012/06/25 12:27:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Cain\AppData\Roaming\Mozilla\Firefox\Profiles\lzp9ylmb.default\extensions
[2012/06/25 19:57:46 | 000,000,000 | ---D | M] ("Avira SearchFree Toolbar plus Web Protection") -- C:\Users\Cain\AppData\Roaming\Mozilla\Firefox\Profiles\lzp9ylmb.default\extensions\toolbar@ask.com
[2012/06/25 19:57:50 | 000,002,413 | ---- | M] () -- C:\Users\Cain\AppData\Roaming\Mozilla\Firefox\Profiles\lzp9ylmb.default\searchplugins\askcom.xml
[2012/06/12 22:36:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/02 01:40:25 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/02 01:39:16 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/02 01:39:16 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 211.31.138.11 211.29.132.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{722AFB9E-660A-40D8-A243-6E5DB630BA11}: DhcpNameServer = 208.67.222.222 208.67.220.220 211.31.138.11 211.29.132.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{722AFB9E-660A-40D8-A243-6E5DB630BA11}: NameServer = 10.0.0.10
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/06/26 18:21:38 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\Cain\Desktop\OTL.exe
[2012/06/26 18:17:24 | 002,128,984 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Cain\Desktop\tdsskiller.exe
[2012/06/26 18:10:24 | 000,000,000 | ---D | C] -- C:\Users\Cain\Desktop\RK_Quarantine
[2012/06/25 20:02:32 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Cain\Desktop\dds.scr
[2012/06/25 17:01:15 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Roaming\Avira
[2012/06/25 12:28:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012/06/25 12:27:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2012/06/25 12:27:21 | 000,132,832 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012/06/25 12:27:21 | 000,098,848 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012/06/25 12:27:21 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2012/06/25 12:27:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012/06/25 12:27:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012/06/25 12:26:27 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012/06/20 03:15:00 | 000,000,000 | ---D | C] -- C:\Users\Cain\Desktop\100MEDIA
[2012/06/12 22:36:32 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Roaming\Mozilla
[2012/06/12 22:36:32 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Local\Mozilla
[2012/06/12 22:36:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012/06/12 22:36:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/06/12 22:36:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/06/12 22:34:37 | 000,132,072 | ---- | C] (PortableApps.com) -- C:\Users\Cain\Desktop\7-ZipPortable.exe
[2012/06/12 22:31:16 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2012/06/12 22:18:13 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Local\ElevatedDiagnostics
[2012/06/12 22:17:45 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Local\Diagnostics
[2012/06/12 22:16:22 | 000,037,600 | ---- | C] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012/06/12 22:16:20 | 000,000,000 | -H-D | C] -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Disabled Startup Items
[2012/06/12 22:16:20 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disabled Startup Items
[2012/06/12 22:15:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Greatis
[2012/06/12 22:13:29 | 000,000,000 | ---D | C] -- C:\Users\Cain\Documents\RegRun2
[2012/06/12 22:13:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2012/06/12 22:13:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UnHackMe
[2012/06/10 13:17:15 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012/06/10 12:26:43 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012/06/10 12:23:58 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012/06/10 12:23:01 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/06/10 08:05:13 | 000,000,000 | ---D | C] -- C:\Users\Cain\Desktop\New folder
[2012/06/09 19:47:09 | 000,000,000 | R--D | C] -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/06/09 19:47:09 | 000,000,000 | R--D | C] -- C:\Users\Cain\Searches
[2012/06/09 19:47:09 | 000,000,000 | R--D | C] -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/06/09 19:47:09 | 000,000,000 | -H-D | C] -- C:\Users\Cain\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/06/09 19:46:58 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Roaming\Identities
[2012/06/09 19:46:53 | 000,000,000 | R--D | C] -- C:\Users\Cain\Contacts
[2012/06/09 19:46:50 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Local\VirtualStore
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\AppData\Local\Temporary Internet Files
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Templates
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Start Menu
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\SendTo
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Recent
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\PrintHood
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\NetHood
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Documents\My Videos
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Documents\My Pictures
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Documents\My Music
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\My Documents
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Local Settings
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\AppData\Local\History
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Cookies
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\Application Data
[2012/06/09 19:46:26 | 000,000,000 | -HSD | C] -- C:\Users\Cain\AppData\Local\Application Data
[2012/06/09 19:46:24 | 000,000,000 | --SD | C] -- C:\Users\Cain\AppData\Roaming\Microsoft
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Videos
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Saved Games
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Pictures
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Music
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Links
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Favorites
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Downloads
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Documents
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\Desktop
[2012/06/09 19:46:24 | 000,000,000 | R--D | C] -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/06/09 19:46:24 | 000,000,000 | -H-D | C] -- C:\Users\Cain\AppData
[2012/06/09 19:46:24 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Local\Temp
[2012/06/09 19:46:24 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Local\Microsoft
[2012/06/09 19:46:24 | 000,000,000 | ---D | C] -- C:\Users\Cain\AppData\Roaming\Media Center Programs
[2012/06/09 19:46:14 | 000,000,000 | -HSD | C] -- C:\Recovery
========== Files - Modified Within 30 Days ==========
[2012/06/26 18:21:39 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Cain\Desktop\OTL.exe
[2012/06/26 18:17:44 | 002,128,984 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Cain\Desktop\tdsskiller.exe
[2012/06/26 18:09:09 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/26 18:09:09 | 000,615,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/26 18:09:09 | 000,103,702 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/26 18:09:05 | 001,521,152 | ---- | M] () -- C:\Users\Cain\Desktop\RogueKiller.exe
[2012/06/26 18:04:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/26 18:04:18 | 1200,087,040 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/26 18:00:02 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/26 18:00:01 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 20:11:38 | 000,001,816 | ---- | M] () -- C:\Users\Cain\Desktop\Attach.zip
[2012/06/25 20:02:38 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Cain\Desktop\dds.scr
[2012/06/25 12:28:13 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/06/15 08:35:57 | 000,001,304 | ---- | M] () -- C:\Users\Cain\Desktop\Notepad.lnk
[2012/06/12 22:36:28 | 000,001,130 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/06/12 22:26:44 | 000,000,532 | -H-- | M] () -- C:\regrun.war
[2012/06/12 22:17:11 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2012/06/12 22:17:11 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\CONFIG.NT
[2012/06/12 22:17:11 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012/06/12 22:16:22 | 000,037,600 | ---- | M] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012/06/12 22:06:27 | 000,001,437 | ---- | M] () -- C:\Users\Cain\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/06/10 12:31:05 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/10 12:27:12 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012/06/10 12:27:12 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012/06/10 09:35:11 | 001,647,252 | ---- | M] () -- C:\Users\Cain\Desktop\.Spotlight-V100.zip
[2012/06/10 07:58:38 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
========== Files Created - No Company Name ==========
[2012/06/26 18:09:04 | 001,521,152 | ---- | C] () -- C:\Users\Cain\Desktop\RogueKiller.exe
[2012/06/25 20:11:38 | 000,001,816 | ---- | C] () -- C:\Users\Cain\Desktop\Attach.zip
[2012/06/25 12:28:13 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/06/15 08:35:57 | 000,001,304 | ---- | C] () -- C:\Users\Cain\Desktop\Notepad.lnk
[2012/06/12 22:36:28 | 000,001,142 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/06/12 22:36:28 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/06/12 22:21:20 | 000,000,532 | -H-- | C] () -- C:\regrun.war
[2012/06/12 22:16:06 | 000,057,556 | ---- | C] () -- C:\Windows\guard.bmp
[2012/06/12 22:14:15 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2012/06/12 22:14:15 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\CONFIG.NT
[2012/06/12 22:14:15 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012/06/12 22:06:27 | 000,001,437 | ---- | C] () -- C:\Users\Cain\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/06/10 12:26:59 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012/06/10 12:26:45 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012/06/10 12:23:01 | 1200,087,040 | -HS- | C] () -- C:\hiberfil.sys
[2012/06/10 09:34:29 | 001,647,252 | ---- | C] () -- C:\Users\Cain\Desktop\.Spotlight-V100.zip
[2012/06/10 07:58:38 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/06/09 19:47:18 | 000,001,409 | ---- | C] () -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/06/09 19:47:11 | 000,001,443 | ---- | C] () -- C:\Users\Cain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/06/09 19:46:24 | 000,000,290 | ---- | C] () -- C:\Users\Cain\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/06/09 19:46:24 | 000,000,272 | ---- | C] () -- C:\Users\Cain\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
< End of report >