Ok,this one has me stumped. I ate a trojan redirect virus some weeks ago (pretty sure it was one of the Puma ones, it all started when I clicked on a link while searching something on google and puma-something was on the url) and tried to get rid of it by backing up my files and then system restoring to factory default. The thing was forcing BSoD's on my laptop not even 10 seconds after starting up a user profile, so I figured a drastic fix was in order. I could not even get online to update my copy of MBAM when it kept crashing on me.
It worked? That's what I thought. No more BSODs, so looking to start over I go on IE to start downloading all my necessities; MBAM, Chrome/Firefox, Open Office, GIMP etc... but soon as I turn it on I start getting redirected to an obviously shady search engine, and trying to go to a few websites rerouted me to places with "ninjaa.info.de" in the url or other such.
I tried to get rid of it on my own. Pulled up a flash drive, VIPRERESCUE, rkill... nothing. Eventually I decide I'll load up MBAM on that Flash Drive, and I let it scan overnight.
When I woke up this morning, I tried to unhibernate my computer and that BSOD was back with a vengeance. Good thing the log still saved; I pulled it up and took a look, but once again the computer couldn't find anything wrong... and then I ate another BSOD.
I put the computer in safe mode, got OTL on that flash drive, and full scanned my laptop. This is what I got.
OTL logfile created on: 2/24/2012 8:42:15 AM - Run 2
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Users\T.K Balanga\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.95 Mb Total Physical Memory | 737.09 Mb Available Physical Memory | 72.70% Memory free
1.99 Gb Paging File | 1.73 Gb Available in Paging File | 87.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.95 Gb Total Space | 117.44 Gb Free Space | 85.76% Space Free | Partition Type: NTFS
Computer Name: PSYBLASTER | User Name: T.K Balanga | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/23 16:10:07 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Users\T.K Balanga\Desktop\OTL.exe
PRC - [2009/07/23 15:51:26 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/23 15:51:26 | 000,645,328 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/07/13 20:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/08/18 02:46:33 | 000,332,272 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\ProgramData\Partner\Partner.exe -- (Partner Service)
SRV - [2009/08/06 12:18:54 | 000,311,592 | ---- | M] () [Auto | Stopped] -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009/08/05 23:31:06 | 000,727,584 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009/07/23 15:51:26 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/07/22 15:16:30 | 000,894,136 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/07/13 20:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/10 04:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2009/07/03 20:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2009/06/18 12:14:46 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Stopped] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2009/06/16 22:29:18 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2009/06/16 21:00:46 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2009/06/04 08:04:50 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009/05/22 13:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/04/09 19:04:30 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009/04/09 13:46:14 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/04/09 10:18:50 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
========== Driver Services (SafeList) ==========
DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/11/09 13:56:12 | 000,098,392 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2009/07/27 02:06:44 | 000,051,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV - [2009/07/16 06:31:38 | 001,176,064 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/06/23 21:59:10 | 000,167,424 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/06/18 12:15:22 | 000,214,024 | ---- | M] (McAfee, Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/06/18 12:15:22 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2009/06/18 12:15:22 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/06/18 12:15:22 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/06/18 12:14:52 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/06/02 06:15:40 | 000,060,976 | ---- | M] (Egis Technology Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV - [2009/06/02 06:15:38 | 000,016,432 | ---- | M] (Egis Technology Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2009/06/02 06:15:34 | 000,018,992 | ---- | M] (Egis Technology Inc.) [File_System | System | Stopped] -- C:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV - [2009/04/09 16:23:02 | 000,130,424 | ---- | M] (McAfee, Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\Mpfp.sys -- (MPFP)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...44ww15w4822372s
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...44ww15w4822372s
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...44ww15w4822372s
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2012/02/22 17:37:32 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2009/06/10 16:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B4115C0A-3964-41FD-A7A4-D3DCF0C2C2CD}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/24 01:30:02 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Malwarebytes
[2012/02/24 01:18:16 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\Desktop\Google
[2012/02/24 01:17:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/24 01:17:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/02/24 01:17:24 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/02/24 01:17:23 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/23 19:21:44 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2012/02/23 19:21:44 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\sbbd.exe
[2012/02/23 19:21:05 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2012/02/23 18:04:40 | 000,583,680 | ---- | C] (OldTimer Tools) -- C:\Users\T.K Balanga\Desktop\OTL.exe
[2012/02/23 12:39:06 | 000,197,632 | ---- | C] (Intel® Corporation) -- C:\Windows\System32\ir32_32.dll
[2012/02/23 12:39:06 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2012/02/20 23:58:39 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Google
[2012/02/20 23:58:38 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Local\Google
[2012/02/20 13:08:30 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Adobe
[2012/02/20 07:08:18 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2012/02/20 07:08:18 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2012/02/20 07:08:18 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2012/02/20 07:08:17 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2012/02/20 07:08:17 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2012/02/20 07:08:17 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2012/02/20 07:08:16 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2012/02/20 07:08:16 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2012/02/20 07:07:18 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2012/02/20 07:00:47 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/02/20 06:57:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/02/20 06:46:36 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys
[2012/02/20 02:35:52 | 000,000,000 | ---D | C] -- C:\Windows\System32\Lang
[2012/02/20 02:35:50 | 001,002,008 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igxpun.exe
[2012/02/20 02:34:06 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/02/20 00:47:54 | 003,957,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012/02/20 00:47:53 | 003,901,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012/02/20 00:35:56 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Macromedia
[2012/02/20 00:35:54 | 000,000,000 | ---D | C] -- C:\Windows\Screensavers
[2012/02/20 00:29:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
[2012/02/20 00:21:45 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2012/02/20 00:20:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2012/02/20 00:18:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2012/02/20 00:18:02 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2012/02/20 00:17:43 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2012/02/20 00:17:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2012/02/20 00:16:56 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2012/02/20 00:10:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2012/02/20 00:05:37 | 001,654,784 | ---- | C] (SuYin) -- C:\Windows\Acer Crystal Eye webcam.EXE
[2012/02/20 00:05:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam
[2012/02/20 00:03:56 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2012/02/20 00:03:16 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\InstallShield
[2012/02/20 00:02:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
[2012/02/20 00:02:12 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Acer
[2012/02/20 00:02:10 | 000,000,000 | ---D | C] -- C:\book
[2012/02/20 00:01:57 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Leadertech
[2012/02/20 00:01:52 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Local\EgisTec
[2012/02/20 00:00:47 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/02/20 00:00:47 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/02/20 00:00:46 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Searches
[2012/02/20 00:00:46 | 000,000,000 | -H-D | C] -- C:\Users\T.K Balanga\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/02/20 00:00:24 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Identities
[2012/02/20 00:00:12 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Contacts
[2012/02/19 23:58:05 | 000,000,000 | ---D | C] -- C:\ProgramData\OEM_E471269A730D
[2012/02/19 23:58:00 | 000,000,000 | ---D | C] -- C:\Program Files\OEM
[2012/02/19 23:57:41 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Acer
[2012/02/19 23:56:03 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Local\VirtualStore
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\AppData\Local\Temporary Internet Files
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Templates
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Start Menu
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\SendTo
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Recent
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\PrintHood
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\NetHood
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Documents\My Videos
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Documents\My Pictures
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Documents\My Music
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\My Documents
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Local Settings
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\AppData\Local\History
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Cookies
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\Application Data
[2012/02/19 23:55:50 | 000,000,000 | -HSD | C] -- C:\Users\T.K Balanga\AppData\Local\Application Data
[2012/02/19 23:55:49 | 000,000,000 | --SD | C] -- C:\Users\T.K Balanga\AppData\Roaming\Microsoft
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Videos
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Saved Games
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Pictures
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Music
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Links
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Favorites
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Downloads
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Documents
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\Desktop
[2012/02/19 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\T.K Balanga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/02/19 23:55:49 | 000,000,000 | -H-D | C] -- C:\Users\T.K Balanga\AppData
[2012/02/19 23:55:49 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Local\Temp
[2012/02/19 23:55:49 | 000,000,000 | ---D | C] -- C:\Users\T.K Balanga\AppData\Local\Microsoft
[2012/02/19 23:55:03 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012/02/19 23:53:35 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
========== Files - Modified Within 30 Days ==========
[2012/02/24 08:21:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/24 08:21:30 | 797,396,992 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/24 08:21:29 | 165,858,467 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/24 01:17:36 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/24 00:07:29 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/24 00:07:29 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/23 23:57:56 | 000,475,185 | ---- | M] () -- C:\Users\T.K Balanga\Desktop\Convention.rtf
[2012/02/23 18:19:18 | 112,033,792 | ---- | M] () -- C:\Users\T.K Balanga\Desktop\VIPRERescue11581.exe
[2012/02/23 17:54:38 | 000,004,931 | ---- | M] () -- C:\Windows\System32\Config.MPF
[2012/02/23 16:10:07 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Users\T.K Balanga\Desktop\OTL.exe
[2012/02/22 18:03:48 | 000,001,097 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Works.lnk
[2012/02/20 23:57:59 | 000,001,411 | ---- | M] () -- C:\Users\T.K Balanga\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/20 12:48:38 | 000,615,360 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/20 12:48:38 | 000,103,702 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/20 02:52:20 | 000,035,789 | ---- | M] () -- C:\Windows\System32\license.rtf
[2012/02/20 02:36:42 | 000,000,006 | ---- | M] () -- C:\Windows\System32\PLD_Framework.cmd
[2012/02/20 00:52:12 | 000,332,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/02/20 00:52:09 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job
[2012/02/20 00:52:09 | 000,000,320 | ---- | M] () -- C:\Windows\tasks\McQcTask.job
[2012/02/20 00:20:28 | 000,000,020 | ---- | M] () -- C:\Windows\Èù
[2012/02/20 00:04:27 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/02/19 23:57:12 | 000,013,866 | ---- | M] () -- C:\Windows\System32\results.xml
========== Files Created - No Company Name ==========
[2012/02/24 01:17:36 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/23 19:20:26 | 112,033,792 | ---- | C] () -- C:\Users\T.K Balanga\Desktop\VIPRERescue11581.exe
[2012/02/22 18:03:48 | 000,001,097 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Works.lnk
[2012/02/20 23:57:59 | 000,001,411 | ---- | C] () -- C:\Users\T.K Balanga\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/20 12:50:10 | 000,475,185 | ---- | C] () -- C:\Users\T.K Balanga\Desktop\Convention.rtf
[2012/02/20 07:00:22 | 165,858,467 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/02/20 02:34:06 | 797,396,992 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/20 00:30:17 | 000,002,557 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2012/02/20 00:29:05 | 000,001,109 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2012/02/20 00:20:26 | 000,000,020 | ---- | C] () -- C:\Windows\Èù
[2012/02/20 00:05:39 | 000,020,480 | ---- | C] () -- C:\Windows\USB_VIDEO_REG.exe
[2012/02/20 00:05:39 | 000,008,312 | ---- | C] () -- C:\Windows\Suyin.reg
[2012/02/20 00:05:38 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2012/02/20 00:05:38 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2012/02/20 00:05:38 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2012/02/20 00:04:27 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/02/20 00:00:52 | 000,001,417 | ---- | C] () -- C:\Users\T.K Balanga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/02/19 23:58:26 | 000,002,021 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Assist.lnk
[2012/02/19 23:57:12 | 000,013,866 | ---- | C] () -- C:\Windows\System32\results.xml
[2012/02/19 23:56:28 | 000,000,342 | ---- | C] () -- C:\Windows\tasks\McDefragTask.job
[2012/02/19 23:56:25 | 000,000,320 | ---- | C] () -- C:\Windows\tasks\McQcTask.job
[2012/02/19 23:55:49 | 000,000,290 | ---- | C] () -- C:\Users\T.K Balanga\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/02/19 23:55:49 | 000,000,272 | ---- | C] () -- C:\Users\T.K Balanga\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
========== LOP Check ==========
[2012/02/20 00:02:12 | 000,000,000 | ---D | M] -- C:\Users\T.K Balanga\AppData\Roaming\Acer
[2012/02/20 00:01:57 | 000,000,000 | ---D | M] -- C:\Users\T.K Balanga\AppData\Roaming\Leadertech
[2012/02/20 00:52:09 | 000,000,342 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2012/02/20 00:52:09 | 000,000,320 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2009/07/13 23:53:46 | 000,004,890 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >