OTS logfile created on: 5/23/2011 9:40:12 AM - Run 3
OTS by OldTimer - Version 3.1.43.0 Folder = D:\VIRUS-Malware help
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.88 Gb Total Space | 172.38 Gb Free Space | 77.34% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 107.53 Gb Free Space | 11.54% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GATEWAY-PC
Current User Name: Gateway
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> D:\VIRUS-Malware help\OTS.exe -> [2011/05/22 18:35:06 | 000,645,632 | ---- | M] (OldTimer Tools)
avastui.exe -> C:\Program Files\AVAST Software\Avast\AvastUI.exe -> [2011/05/10 07:10:58 | 003,459,712 | ---- | M] (AVAST Software)
avastsvc.exe -> C:\Program Files\AVAST Software\Avast\AvastSvc.exe -> [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software)
flashutil10p_activex.exe -> C:\Windows\System32\Macromed\Flash\FlashUtil10p_ActiveX.exe -> [2011/04/23 15:54:37 | 000,235,168 | ---- | M] (Adobe Systems, Inc.)
epowersvc.exe -> C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe -> [2009/06/18 20:00:24 | 000,723,488 | ---- | M] (Acer Incorporated)
epowertray.exe -> C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe -> [2009/06/18 20:00:24 | 000,703,008 | ---- | M] (Acer Incorporated)
epowerevent.exe -> C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe -> [2009/06/18 20:00:22 | 000,453,152 | ---- | M] (Acer Incorporated)
lmanager.exe -> C:\Program Files\Launch Manager\LManager.exe -> [2009/05/11 00:14:54 | 000,805,384 | ---- | M] (Dritek System Inc.)
amicosinglun.exe -> C:\Program Files\Selective Suspend Driver\AmIcoSinglun.exe -> [2009/04/29 17:09:14 | 000,237,568 | ---- | M] (AlcorMicro Co., Ltd.)
iaantmon.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -> [2009/02/11 19:38:40 | 000,354,840 | ---- | M] (Intel Corporation)
iaanotif.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe -> [2009/02/11 19:38:38 | 000,186,904 | ---- | M] (Intel Corporation)
explorer.exe -> C:\Windows\explorer.exe -> [2008/10/29 01:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation)
audiodg.exe -> C:\Windows\System32\audiodg.exe -> [2008/01/20 21:24:54 | 000,088,064 | ---- | M] (Microsoft Corporation)
msascui.exe -> C:\Program Files\Windows Defender\MSASCui.exe -> [2008/01/20 21:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation)
[Modules - Safe List]
ots.exe -> D:\VIRUS-Malware help\OTS.exe -> [2011/05/22 18:35:06 | 000,645,632 | ---- | M] (OldTimer Tools)
snxhk.dll -> C:\Program Files\AVAST Software\Avast\snxhk.dll -> [2011/05/10 07:10:55 | 000,199,792 | ---- | M] (AVAST Software)
comctl32.dll -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll -> [2010/08/31 10:39:57 | 001,684,480 | ---- | M] (Microsoft Corporation)
syshook.dll -> C:\Program Files\Gateway\Gateway Power Management\SysHook.dll -> [2009/06/18 20:00:42 | 000,215,584 | ---- | M] (Acer Incorporated)
[Win32 Services - Safe List]
(Norton Internet Security) Norton Internet Security [Auto | Stopped] -> -> File not found
(avast! Antivirus) avast! Antivirus [Auto | Running] -> C:\Program Files\AVAST Software\Avast\AvastSvc.exe -> [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software)
(ePowerSvc) Acer ePower Service [Auto | Running] -> C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe -> [2009/06/18 20:00:24 | 000,723,488 | ---- | M] (Acer Incorporated)
(IAANTMON) Intel(R) Matrix Storage Event Monitor [Auto | Running] -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -> [2009/02/11 19:38:40 | 000,354,840 | ---- | M] (Intel Corporation)
(GameConsoleService) GameConsoleService [On_Demand | Stopped] -> C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe -> [2008/05/05 17:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.)
(WinDefend) Windows Defender [Auto | Running] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(aswSnx) aswSnx [File_System | System | Running] -> C:\Windows\System32\drivers\aswSnx.sys -> [2011/05/10 07:03:54 | 000,441,176 | ---- | M] (AVAST Software)
(aswSP) aswSP [Kernel | System | Running] -> C:\Windows\System32\drivers\aswSP.sys -> [2011/05/10 07:03:44 | 000,307,928 | ---- | M] (AVAST Software)
(aswTdi) avast! Network Shield Support [Kernel | System | Running] -> C:\Windows\System32\drivers\aswTdi.sys -> [2011/05/10 07:02:37 | 000,049,240 | ---- | M] (AVAST Software)
(aswRdr) aswRdr [Kernel | System | Running] -> C:\Windows\System32\drivers\aswRdr.sys -> [2011/05/10 06:59:56 | 000,025,432 | ---- | M] (AVAST Software)
(aswMonFlt) aswMonFlt [File_System | Auto | Running] -> C:\Windows\System32\drivers\aswMonFlt.sys -> [2011/05/10 06:59:44 | 000,053,592 | ---- | M] (AVAST Software)
(aswFsBlk) aswFsBlk [File_System | Auto | Running] -> C:\Windows\System32\drivers\aswFsBlk.sys -> [2011/05/10 06:59:35 | 000,019,544 | ---- | M] (AVAST Software)
(L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\L1C60x86.sys -> [2009/04/27 03:16:04 | 000,050,176 | ---- | M] (Atheros Communications, Inc.)
(NETw5v32) Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\NETw5v32.sys -> [2009/03/03 21:49:22 | 004,232,704 | ---- | M] (Intel Corporation)
(IntcHdmiAddService) Intel(R) High Definition Audio HDMI [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\IntcHdmi.sys -> [2008/12/04 13:25:38 | 000,112,640 | ---- | M] (Intel(R) Corporation)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp32&d=1109&m=ec18 ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp32&d=1109&m=ec18 ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3149059129-435206734-2226088797-1000\] > -> ->
HKEY_USERS\S-1-5-21-3149059129-435206734-2226088797-1000\: Main\\"Default_Page_URL" -> http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp32&d=1109&m=ec18 ->
HKEY_USERS\S-1-5-21-3149059129-435206734-2226088797-1000\: Main\\"SearchDefaultBranded" -> 1 ->
HKEY_USERS\S-1-5-21-3149059129-435206734-2226088797-1000\: Main\\"Start Page" -> http://www.google.com/ ->
HKEY_USERS\S-1-5-21-3149059129-435206734-2226088797-1000\: Main\\"StartPageCache" -> 1 ->
HKEY_USERS\S-1-5-21-3149059129-435206734-2226088797-1000\: "ProxyEnable" -> 0 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
< FireFox Extensions [User Folders] > ->
< HOSTS File > ([2008/01/20 21:24:21 | 000,007,369 | ---- | M] - 348 lines) -> C:\Windows\System32\drivers\etc\hosts ->
First 25 entries...