Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

metropolitan police ukash trojan [Solved]


  • This topic is locked This topic is locked

#1
th0mh

th0mh

    Member

  • Member
  • PipPip
  • 32 posts
Hello there,

I'm having a big issue right now somehow i got an trojan on my pc. Ive done some research about it and it is called metropolitan police ukash trojan. Ive read an older topic that has been closed about this problem aswell.

@essexboy
This was the guide you posted at that time. Ive come till step 11 but then i have to select an folder and i dont know in what folder it is located i have and idea. I cant acces i think it was appdata located in user folder.

1.Download OTLPENet.exe to your desktop
2.Download the attacherd scan.txt to a USB drive
3.Attached File scan.txt (520bytes)
4.Number of downloads: 70
5.Ensure that you have a blank CD in the drive
6.Double click OTLPENet.exe and this will then open imgburn to burn the file to CD
7.Reboot your system using the boot CD you just created.Note : If you do not know how to set your computer to boot from CD follow the steps here
8.As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads :)
9.Your system should now display a Reatogo desktop.Note : as you are running from CD it is not exactly speedy
10.Double-click on the OTLPE icon.
11.Select the Windows folder of the infected drive if it asks for a location
12.When asked "Do you wish to load the remote registry", select Yes
13.When asked "Do you wish to load remote user profile(s) for scanning", select Yes
14.Ensure the box "Automatically Load All Remaining Users" is checked and press OK
15.OTL should now start
16.Drag and drop the scan.txt into the Custom scans and fixes box, or double click the scan box
17.Press Run Scan to start the scan.
18.When finished, the file will be saved in drive C:\OTL.txt
19.Copy this file to your USB drive if you do not have internet connection on this system
20.Right click the file and select send to : select the USB drive.
21.Confirm that it has copied to the USB drive by selecting it
22.You can backup any files that you wish from this OS
23.Please post the contents of the C:\OTL.txt file in your reply.

I really have no idea what i can do about this im not stupid with computers but i never had a virus this big. I would ask your help in this case.

Thanks Th0mh
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Select the windows folder - what happens when you try to boot to normal mode ?
  • 0

#3
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
I will always get stuck on a white screen saying: Please wait for the connection to restablish. Btw ive pulled my internet cable out of the pc so when even i boot it doesnt allow them to watch my pc or anything. Should i leave the cable out?
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Initially yes, just until we can remove the main culprit

Does OTL now run ? If not do you have a USB drive ? Also what is your operating system
  • 0

#5
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
I'm running on windows 7. Yes i have an usb currently i got the .txt file on it. And when i select system map in the windows map it says target is not windows 2000 or later. Am i using the wrong map?
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Ok I will use a different tool in conjunction with the OTLPE disc

  • On your USB download the following programme
  • Download Farbar Recovery Scan Tool and save it to a flash drive.
  • Using the CD go to the Reatogo desktop.
  • Insert the flash drive with FRST on it
  • Locate the flash drive and run FSRT
  • The tool will start to run.
    Posted Image
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.


[/list]
  • 0

#7
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 16-04-2012
Ran by SYSTEM at 17-04-2012 22:46:51
Running from I:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe [2077536 2012-01-26] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-03-18] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [141624 2010-06-15] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2011-01-31] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-05] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [Logitech G35] C:\Program Files\Logitech\G35\G35.exe [1811800 2010-10-05] (Logitech©)
HKU\Thom\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\Thom\...\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent [1242448 2011-08-02] (Valve Corporation)
HKU\Thom\...\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2741616 2011-03-04] (Hewlett-Packard Company)
HKU\Thom\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [3481408 2012-02-13] (DT Soft Ltd)
HKU\Thom\...\Run: [] C:\Users\Thom\AppData\Roaming\.exe [x]
HKU\Thom\...\Run: [SystemSecurityGuardAutoStart] "C:\Program Files\System Security Guard\SystemSecurityGuardTray.exe" /TRAY [1102336 2012-03-28] (SystemSecurityGuard.com)
HKU\Thom\...\Run: [5kS43ADO0bzprWo] C:\Users\Thom\AppData\Roaming\soundblaster_fx648.exe [238080 2012-04-17] (QRPU)
HKU\Thom\...\Policies\system: [DisableTaskMgr] 1
HKU\Thom\...\Policies\system: [DisableRegistryTools] 1
HKU\Thom\...\Winlogon: [Userinit] C:\Users\Thom\AppData\Roaming\soundblaster_fx648.exe,C:\WINDOWS\System32\userinit.exe, [26624 2010-11-20] (Microsoft Corporation)
HKU\Thom\...\Winlogon: [Shell] C:\Users\Thom\AppData\Roaming\soundblaster_fx648.exe [238080 2012-04-17] (QRPU)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
AppInit_DLLs: avgrsstx.dll

================================ Services (Whitelisted) ==================

3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [253600 2012-04-05] (Adobe Systems Incorporated)
2 avg9emc; "C:\Program Files\AVG\AVG9\avgemc.exe" [921952 2010-07-21] (AVG Technologies CZ, s.r.o.)
2 avg9wd; "C:\Program Files\AVG\AVG9\avgwdsvc.exe" [308136 2010-07-16] (AVG Technologies CZ, s.r.o.)
2 NAUpdate; "C:\Program Files\Nero\Update\NASvc.exe" [584488 2011-03-04] (Nero AG)
4 NetMsmqActivator; "C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [124240 2010-03-18] (Microsoft Corporation)
4 NetPipeActivator; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
4 NetTcpActivator; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2214504 2011-05-21] (NVIDIA Corporation)
2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2011-10-04] ()
2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [189248 2011-10-04] ()
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-02-29] (Skype Technologies)
3 SSGHelpService; C:\Program Files\System Security Guard\SSGService.exe [558728 2012-03-09] (systemsecurityguard.com)
3 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)
3 rpcapd; "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini" [x]
2 wlidsvc; "c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" [x]

========================== Drivers (Whitelisted) =============

1 AvgLdx86; C:\Windows\System32\Drivers\avgldx86.sys [216400 2010-07-16] (AVG Technologies CZ, s.r.o.)
1 AvgMfx86; C:\Windows\System32\Drivers\avgmfx86.sys [29712 2011-09-13] (AVG Technologies CZ, s.r.o.)
1 AvgTdiX; C:\Windows\System32\Drivers\avgtdix.sys [243152 2011-05-06] (AVG Technologies CZ, s.r.o.)
3 cpuz134; \??\C:\Program Files\CPUID\PC Wizard 2010\pcwiz_x32.sys [20328 2010-07-09] (Windows ® Win 7 DDK provider)
3 CV2K1; C:\Windows\System32\DRIVERS\cv2k1.sys [9906 2012-02-25] (TamoSoft, Inc.)
1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-03-29] (DT Soft Ltd)
3 LADF_DHP2; C:\Windows\System32\DRIVERS\ladfDHP2i386.sys [53976 2010-09-29] (Logitech)
3 LADF_SBVM; C:\Windows\System32\DRIVERS\ladfSBVMi386.sys [335064 2010-09-29] (Logitech)
2 NPF; C:\Windows\System32\drivers\npf.sys [35088 2010-06-25] (CACE Technologies, Inc.)
3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2012-04-17 22:46 - 2011-11-18 09:19 - 0000000 ____D C:\FRST
2012-04-17 12:01 - 2009-07-13 21:14 - 0062674 ____A C:\Windows\ntbtlog.txt
2012-04-17 11:05 - 2011-11-20 14:52 - 0238080 ____A (QRPU) C:\Users\Thom\AppData\Roaming\soundblaster_fx648.exe
2012-04-13 09:13 - 2009-07-13 22:37 - 0000000 ____D C:\Program Files\Common Files\Skype
2012-04-12 18:45 - 2012-02-27 21:52 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-04-12 18:45 - 2012-02-27 21:18 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-04-12 18:45 - 2012-02-27 21:09 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-04-12 18:45 - 2012-02-27 21:06 - 1799168 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-04-12 18:45 - 2012-02-27 21:03 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-04-12 18:45 - 2012-02-14 19:02 - 9705984 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-04-12 18:45 - 2012-02-14 19:02 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-04-12 18:45 - 2012-02-14 19:02 - 12281856 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-04-12 18:45 - 2012-02-14 19:02 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-04-12 18:45 - 2011-05-03 00:30 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-04-12 18:45 - 2010-11-20 08:21 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-04-12 18:45 - 2009-07-13 21:16 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-04-12 18:45 - 2009-07-13 21:14 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-04-12 18:41 - 2009-07-13 21:20 - 0019824 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys
2012-04-12 18:41 - 2009-07-13 21:16 - 0172544 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-04-12 18:41 - 2009-07-13 21:14 - 0159232 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll
2012-04-12 18:41 - 2009-07-13 21:11 - 0005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll
2012-04-12 18:41 - 2009-06-10 17:42 - 0000000 ____D C:\dd948e71af1aa86fab95b1d57304
2012-04-12 16:45 - - 0000000 ____D C:\Users\Thom\.Dharoks_v4
2012-04-10 12:53 - 2011-11-08 08:18 - 0000000 ____D C:\Users\Thom\Desktop\Cd
2012-04-07 19:24 - 2010-11-19 07:09 - 0024389 ____A C:\Users\Thom\Desktop\hs_err_pid10108.log
2012-04-07 15:58 - 2011-11-28 16:58 - 0000000 ____D C:\.soulsplit
2012-04-06 10:31 - 2012-04-17 12:51 - 0000000 ____D C:\Program Files\System Security Guard
2012-04-06 10:31 - 2012-04-11 11:58 - 0000000 ____D C:\Users\Thom\AppData\Roaming\SystemSecurityGuard
2012-04-06 10:31 - 2010-04-28 13:29 - 0001111 ____A C:\Users\Public\Desktop\System Security Guard.lnk
2012-04-06 10:30 - 2011-12-21 14:07 - 4453512 ____A (SystemSecurityGuard.com) C:\Users\Thom\Downloads\SystemSecurityGuardInstaller.exe
2012-04-06 10:30 - 2010-05-08 05:50 - 0000000 ____D C:\ProgramData\SystemSecurityGuard
2012-04-05 12:53 - 2012-04-07 19:24 - 0013254 ____A C:\Users\Thom\Desktop\hs_err_pid6116.log
2012-04-05 04:15 - 2009-07-13 21:14 - 0418464 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-04-05 04:15 - - 0000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-04-02 11:40 - 2012-01-26 12:59 - 0144251 ____A C:\Users\Thom\Downloads\watch(2).htm
2012-03-30 18:09 - 2011-05-18 14:27 - 0000000 ____D C:\Users\Thom\Documents\Games for Windows - LIVE Demos
2012-03-30 10:49 - 2012-04-13 16:41 - 0000000 ____D C:\Users\Thom\Documents\WB Games
2012-03-30 10:47 - 2009-07-14 03:50 - 0000000 ____D C:\Program Files\Microsoft Games for Windows - LIVE
2012-03-30 10:47 - 2009-07-13 21:16 - 0000000 ____D C:\Windows\System32\xlive
2012-03-30 04:27 - 2009-07-14 00:52 - 0007206 ____A C:\Windows\PFRO.log
2012-03-29 15:02 - 2012-02-17 01:34 - 0129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-03-29 15:02 - 2010-11-20 06:24 - 0058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-03-29 14:45 - 2012-03-29 07:31 - 0292184 ____A (Microsoft Corporation) C:\Users\Thom\Downloads\dxwebsetup.exe
2012-03-29 14:44 - 2009-07-13 21:16 - 0000000 ____D C:\Windows\System32\SPReview
2012-03-29 14:43 - 2009-07-13 21:14 - 0000000 ____D C:\Windows\System32\EventProviders
2012-03-29 14:39 - 2012-04-17 12:51 - 0000000 ____D C:\users\UpdatusUser
2012-03-29 14:39 - 2012-04-03 17:21 - 0000020 __ASH C:\Users\UpdatusUser\ntuser.ini
2012-03-29 14:39 - 2012-03-29 14:41 - 0000000 __SHD C:\Users\UpdatusUser\AppData\Local\Temporary Internet Files
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Templates
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Start Menu
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\NetHood
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Documents\My Videos
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Documents\My Pictures
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\AppData\Local\History
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 ____D C:\Users\UpdatusUser\AppData\LocalLow
2012-03-29 14:39 - 2011-06-23 08:35 - 0000000 ____D C:\ProgramData\NVIDIA
2012-03-29 14:39 - 2011-05-21 00:01 - 3693672 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-03-29 14:39 - 2011-05-21 00:01 - 2560616 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-03-29 14:39 - 2011-05-21 00:01 - 2557544 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc.dll
2012-03-29 14:39 - 2011-05-21 00:01 - 0615528 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-03-29 14:39 - 2011-05-21 00:01 - 0111208 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-03-29 14:39 - 2011-05-21 00:01 - 0066664 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-03-29 14:39 - 2011-02-20 14:26 - 0000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Media Center Programs
2012-03-29 14:39 - 2009-07-13 22:04 - 0000000 __SHD C:\Users\UpdatusUser\PrintHood
2012-03-29 14:39 - 2009-07-13 22:04 - 0000000 __SHD C:\Users\UpdatusUser\My Documents
2012-03-29 14:39 - 2009-07-13 21:15 - 0543336 ____A (NVIDIA Corporation) C:\Windows\System32\easyupdatusapiu.dll
2012-03-29 14:39 - - 0000000 __SHD C:\Users\UpdatusUser\Documents\My Music
2012-03-29 14:39 - - 0000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia
2012-03-29 14:37 - 2012-03-29 14:40 - 0000000 ____D C:\ProgramData\NVIDIA Corporation
2012-03-29 14:37 - 2012-02-15 10:35 - 0000000 ____D C:\Program Files\NVIDIA Corporation
2012-03-29 14:33 - 2010-05-15 19:10 - 0000000 ____D C:\Users\Thom\Documents\Battlefield 3
2012-03-29 14:30 - 2011-09-15 12:24 - 0000539 ____A C:\Windows\KB893803v2.log
2012-03-29 14:06 - 2011-09-16 16:49 - 0000000 ____D C:\Users\Thom\Desktop\BF3
2012-03-29 08:43 - 2011-10-04 08:00 - 0000000 ____D C:\Users\Thom\AppData\Local\WB Games
2012-03-29 08:38 - 2011-09-22 13:25 - 0001331 ____A C:\Users\Public\Desktop\Lord of the Rings - War in the North.lnk
2012-03-29 08:26 - 2012-04-13 09:13 - 0000000 ____D C:\Program Files\Snowblind Studios
2012-03-29 07:34 - 2011-06-10 14:14 - 0001896 ____A C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2012-03-29 07:32 - 2011-09-15 12:23 - 0000000 ____D C:\Program Files\DAEMON Tools Lite
2012-03-29 07:32 - 2011-05-05 13:51 - 0000000 ____D C:\Users\Thom\AppData\Roaming\DAEMON Tools Lite
2012-03-29 07:32 - 2011-03-15 09:27 - 0000000 ____D C:\ProgramData\DAEMON Tools Lite
2012-03-29 07:32 - 2009-07-13 19:50 - 0242240 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
2012-03-29 07:31 - 2012-02-15 19:10 - 14109664 ____A (DT Soft Ltd.) C:\Users\Thom\Downloads\DTLite4453-0297.exe
2012-03-27 12:15 - 2012-04-17 22:46 - 0000000 ____D C:\Games
2012-03-27 12:15 - 2012-04-17 12:51 - 0000000 ____D C:\Users\Thom\AppData\Roaming\wargaming.net
2012-03-27 12:15 - 2011-02-21 11:50 - 0000769 ____A C:\Users\Public\Desktop\World of Tanks.lnk
2012-03-27 12:15 - 2009-07-13 21:15 - 0000000 ____D C:\Windows\System32\directx
2012-03-27 12:15 - 2009-06-10 17:19 - 0000000 ___HD C:\Windows\msdownld.tmp
2012-03-27 12:14 - 2012-01-06 21:46 - 7516152 ____A (Wargaming.net ) C:\Users\Thom\Downloads\WoT_internet_install_eu.exe
2012-03-25 09:01 - - 0000000 ____D C:\Program Files\7-Zip
2012-03-25 08:58 - - 1110476 ____A C:\Users\Thom\Downloads\7z920.exe
2012-03-23 15:39 - 2012-02-14 09:49 - 0019020 ___SH C:\Users\Thom\Downloads\Folder.jpg
2012-03-23 15:39 - 2011-10-31 18:13 - 0005606 ___SH C:\Users\Thom\Downloads\AlbumArtSmall.jpg
2012-03-19 13:07 - 2011-11-28 16:56 - 6950552 ____A (Microsoft Corporation) C:\Users\Thom\Downloads\Silverlight.exe
2012-03-18 05:28 - 2010-06-08 15:27 - 0002612 ____A C:\Users\Thom\Documents\Mijn film.wlmp


============ 3 Months Modified Files and Folders ===============

2012-04-17 22:46 - 2012-04-17 22:46 - 0000000 ____D C:\FRST
2012-04-17 14:16 - 2009-07-14 00:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-04-17 14:15 - 2012-01-07 06:01 - 0008724 ____A C:\Windows\setupact.log
2012-04-17 14:15 - 2010-04-28 20:35 - 2415357952 __ASH C:\hiberfil.sys
2012-04-17 12:51 - 2012-04-06 10:31 - 0000000 ____D C:\Users\Thom\AppData\Roaming\SystemSecurityGuard
2012-04-17 12:51 - 2012-03-29 14:39 - 0000000 ____D C:\users\UpdatusUser
2012-04-17 12:51 - 2011-05-24 16:37 - 0000000 ____D C:\Users\Thom\AppData\Roaming\TS3Client
2012-04-17 12:51 - 2010-12-16 14:32 - 0000000 ____D C:\Users\Thom\AppData\Roaming\vlc
2012-04-17 12:51 - 2010-12-13 20:13 - 0000000 ____D C:\Users\Thom\AppData\Roaming\Azureus
2012-04-17 12:51 - 2010-04-29 06:08 - 0000000 ____D C:\Windows\System32\Drivers\Avg
2012-04-17 12:51 - 2010-04-28 20:46 - 0000000 ____D C:\Users\Thom\AppData\Roaming\Skype
2012-04-17 12:51 - 2010-04-28 20:45 - 0000000 ____D C:\Program Files\SwiftKit
2012-04-17 12:51 - 2010-04-28 20:43 - 0000000 ____D C:\Windows\System32\Macromed
2012-04-17 12:51 - 2010-04-28 20:41 - 0000000 ____D C:\users\Thom
2012-04-17 12:51 - 2010-04-28 04:26 - 0000000 ____D C:\Program Files\Steam
2012-04-17 12:51 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\System32\wfp
2012-04-17 12:51 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\System32\DriverStore
2012-04-17 12:51 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\registration
2012-04-17 12:51 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\AppCompat
2012-04-17 12:02 - 2012-04-17 12:01 - 0062674 ____A C:\Windows\ntbtlog.txt
2012-04-17 11:52 - 2012-04-05 04:15 - 0000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-04-17 11:52 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\System32\config\TxR
2012-04-17 11:05 - 2012-04-17 11:05 - 0238080 ____A (QRPU) C:\Users\Thom\AppData\Roaming\soundblaster_fx648.exe
2012-04-17 11:02 - 2010-04-28 20:50 - 0000046 ____A C:\Users\Thom\jagex_runescape_preferences.dat
2012-04-17 10:54 - 2010-04-28 20:51 - 0000129 ____A C:\Users\Thom\jagex_runescape_preferences2.dat
2012-04-17 03:04 - 2010-04-28 22:19 - 0000000 ____D C:\Users\Thom\Tracing
2012-04-16 15:40 - 2011-10-25 10:25 - 0000032 ____A C:\Users\Thom\jagex_cl_runescape_LIVE.dat
2012-04-14 03:06 - 2009-11-11 01:43 - 0778150 ____A C:\Windows\System32\PerfStringBackup.INI
2012-04-14 03:05 - 2010-04-28 20:43 - 1409850 ____A C:\Windows\WindowsUpdate.log
2012-04-13 19:05 - 2009-07-14 00:34 - 0014224 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-04-13 19:05 - 2009-07-14 00:34 - 0014224 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-04-13 16:41 - 2010-12-13 20:16 - 0000000 ____D C:\Users\Thom\Documents\Vuze Downloads
2012-04-13 09:13 - 2012-04-13 09:13 - 0000000 ____D C:\Program Files\Common Files\Skype
2012-04-13 09:13 - 2011-08-10 09:09 - 0002503 ____A C:\Users\Public\Desktop\Skype.lnk
2012-04-13 09:13 - 2010-04-28 20:46 - 0000000 ___RD C:\Program Files\Skype
2012-04-13 09:13 - 2010-04-28 20:46 - 0000000 ____D C:\ProgramData\Skype
2012-04-13 04:36 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\Microsoft.NET
2012-04-13 03:04 - 2012-03-30 04:27 - 0007206 ____A C:\Windows\PFRO.log
2012-04-12 18:43 - 2012-04-12 18:41 - 0000000 ____D C:\dd948e71af1aa86fab95b1d57304
2012-04-12 18:41 - 2009-10-14 05:57 - 55154568 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-04-12 16:47 - 2012-04-12 16:45 - 0000000 ____D C:\Users\Thom\.Dharoks_v4
2012-04-11 11:58 - 2011-12-21 14:08 - 0000000 ____D C:\Users\Thom\AppData\Local\Spotify
2012-04-11 11:58 - 2011-12-21 14:07 - 0000000 ____D C:\Users\Thom\AppData\Roaming\Spotify
2012-04-11 10:46 - 2012-03-29 14:06 - 0000000 ____D C:\Users\Thom\Desktop\BF3
2012-04-11 06:09 - 2012-03-15 12:57 - 0000000 ____D C:\Users\Thom\.fatality_cache_32
2012-04-10 13:00 - 2012-04-10 12:53 - 0000000 ____D C:\Users\Thom\Desktop\Cd
2012-04-09 15:21 - 2010-05-01 14:25 - 0000000 ____D C:\Users\Thom\Desktop\muziek
2012-04-07 19:24 - 2012-04-07 19:24 - 0024389 ____A C:\Users\Thom\Desktop\hs_err_pid10108.log
2012-04-07 15:58 - 2012-04-07 15:58 - 0000000 ____D C:\.soulsplit
2012-04-06 12:35 - 2010-08-29 09:57 - 0000000 ____D C:\Users\Thom\Desktop\troep
2012-04-06 10:31 - 2012-04-06 10:31 - 0001111 ____A C:\Users\Public\Desktop\System Security Guard.lnk
2012-04-06 10:31 - 2012-04-06 10:31 - 0000000 ____D C:\Program Files\System Security Guard
2012-04-06 10:30 - 2012-04-06 10:30 - 4453512 ____A (SystemSecurityGuard.com) C:\Users\Thom\Downloads\SystemSecurityGuardInstaller.exe
2012-04-06 10:30 - 2012-04-06 10:30 - 0000000 ____D C:\ProgramData\SystemSecurityGuard
2012-04-05 12:53 - 2012-04-05 12:53 - 0013254 ____A C:\Users\Thom\Desktop\hs_err_pid6116.log
2012-04-05 05:06 - 2012-04-05 04:15 - 0418464 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-04-05 05:06 - 2011-05-18 01:05 - 0070304 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-04-02 13:16 - 2011-05-02 18:13 - 0000000 ____D C:\Users\Thom\Desktop\songs
2012-04-02 11:40 - 2012-04-02 11:40 - 0144251 ____A C:\Users\Thom\Downloads\watch(2).htm
2012-03-31 08:15 - 2012-01-23 11:48 - 0000000 ___AD C:\Users\Thom\Desktop\2011
2012-03-30 18:09 - 2012-03-30 18:09 - 0000000 ____D C:\Users\Thom\Documents\Games for Windows - LIVE Demos
2012-03-30 10:49 - 2012-03-30 10:49 - 0000000 ____D C:\Users\Thom\Documents\WB Games
2012-03-30 10:47 - 2012-03-30 10:47 - 0000000 ____D C:\Windows\System32\xlive
2012-03-30 10:47 - 2012-03-30 10:47 - 0000000 ____D C:\Program Files\Microsoft Games for Windows - LIVE
2012-03-30 10:47 - 2009-07-13 22:37 - 0000000 ____D C:\Program Files\Common Files\microsoft shared
2012-03-30 06:56 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\rescache
2012-03-30 04:30 - 2010-04-28 20:41 - 0000174 ___SH C:\Users\Thom\Start Menu\Programs\Startup\desktop.ini
2012-03-30 04:30 - 2010-04-28 20:41 - 0000174 ___SH C:\Users\Thom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2012-03-30 04:28 - 2009-07-14 00:33 - 3622752 ____A C:\Windows\System32\FNTCACHE.DAT
2012-03-29 17:07 - 2009-07-14 03:50 - 0000000 ____D C:\Program Files\Windows Journal
2012-03-29 17:07 - 2009-07-14 03:49 - 0000000 __SHD C:\Windows\BitLockerDiscoveryVolumeContents
2012-03-29 17:07 - 2009-07-14 00:52 - 0000000 ____D C:\Program Files\Windows Sidebar
2012-03-29 17:07 - 2009-07-14 00:52 - 0000000 ____D C:\Program Files\Windows Portable Devices
2012-03-29 17:07 - 2009-07-14 00:52 - 0000000 ____D C:\Program Files\Windows Photo Viewer
2012-03-29 17:07 - 2009-07-14 00:52 - 0000000 ____D C:\Program Files\Windows Defender
2012-03-29 17:07 - 2009-07-14 00:52 - 0000000 ____D C:\Program Files\DVD Maker
2012-03-29 17:07 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\System32\AdvancedInstallers
2012-03-29 17:07 - 2009-07-13 22:37 - 0000000 ____D C:\Program Files\Common Files\System
2012-03-29 14:55 - 2012-03-29 14:33 - 0000000 ____D C:\Users\Thom\Documents\Battlefield 3
2012-03-29 14:50 - 2009-07-13 22:05 - 0152576 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-03-29 14:46 - 2012-03-27 12:15 - 0000000 ___HD C:\Windows\msdownld.tmp
2012-03-29 14:46 - 2012-03-27 12:15 - 0000000 ____D C:\Windows\System32\directx
2012-03-29 14:45 - 2012-03-29 14:45 - 0292184 ____A (Microsoft Corporation) C:\Users\Thom\Downloads\dxwebsetup.exe
2012-03-29 14:44 - 2012-03-29 14:44 - 0000000 ____D C:\Windows\System32\SPReview
2012-03-29 14:43 - 2012-03-29 14:43 - 0000000 ____D C:\Windows\System32\EventProviders
2012-03-29 14:40 - 2012-03-29 14:39 - 0000000 ____D C:\ProgramData\NVIDIA
2012-03-29 14:39 - 2012-03-29 14:39 - 0000020 __ASH C:\Users\UpdatusUser\ntuser.ini
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Templates
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Start Menu
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\PrintHood
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\NetHood
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\My Documents
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Documents\My Videos
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Documents\My Pictures
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\Documents\My Music
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\AppData\Local\Temporary Internet Files
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 __SHD C:\Users\UpdatusUser\AppData\Local\History
2012-03-29 14:39 - 2012-03-29 14:39 - 0000000 ____D C:\Users\UpdatusUser\AppData\LocalLow
2012-03-29 14:39 - 2012-03-29 14:37 - 0000000 ____D C:\Program Files\NVIDIA Corporation
2012-03-29 14:39 - 2009-07-13 22:37 - 0000000 ____D C:\Windows\Help
2012-03-29 14:37 - 2012-03-29 14:37 - 0000000 ____D C:\ProgramData\NVIDIA Corporation
2012-03-29 14:31 - 2011-10-04 06:34 - 0000000 ____D C:\Users\Thom\AppData\Roaming\Origin
2012-03-29 14:31 - 2011-10-04 06:34 - 0000000 ____D C:\Program Files\Origin
2012-03-29 14:30 - 2012-03-29 14:30 - 0000539 ____A C:\Windows\KB893803v2.log
2012-03-29 08:43 - 2012-03-29 08:43 - 0000000 ____D C:\Users\Thom\AppData\Local\WB Games
2012-03-29 08:38 - 2012-03-29 08:38 - 0001331 ____A C:\Users\Public\Desktop\Lord of the Rings - War in the North.lnk
2012-03-29 08:26 - 2012-03-29 08:26 - 0000000 ____D C:\Program Files\Snowblind Studios
2012-03-29 07:35 - 2012-03-29 07:32 - 0000000 ____D C:\Users\Thom\AppData\Roaming\DAEMON Tools Lite
2012-03-29 07:34 - 2012-03-29 07:34 - 0001896 ____A C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2012-03-29 07:32 - 2012-03-29 07:32 - 0242240 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
2012-03-29 07:32 - 2012-03-29 07:32 - 0000000 ____D C:\ProgramData\DAEMON Tools Lite
2012-03-29 07:32 - 2012-03-29 07:32 - 0000000 ____D C:\Program Files\DAEMON Tools Lite
2012-03-29 07:31 - 2012-03-29 07:31 - 14109664 ____A (DT Soft Ltd.) C:\Users\Thom\Downloads\DTLite4453-0297.exe
2012-03-27 13:41 - 2012-03-27 12:15 - 0000000 ____D C:\Users\Thom\AppData\Roaming\wargaming.net
2012-03-27 12:15 - 2012-03-27 12:15 - 0000769 ____A C:\Users\Public\Desktop\World of Tanks.lnk
2012-03-27 12:15 - 2012-03-27 12:15 - 0000000 ____D C:\Games
2012-03-27 12:14 - 2012-03-27 12:14 - 7516152 ____A (Wargaming.net ) C:\Users\Thom\Downloads\WoT_internet_install_eu.exe
2012-03-25 09:01 - 2012-03-25 09:01 - 0000000 ____D C:\Program Files\7-Zip
2012-03-25 08:58 - 2012-03-25 08:58 - 1110476 ____A C:\Users\Thom\Downloads\7z920.exe
2012-03-23 15:39 - 2012-03-23 15:39 - 0019020 ___SH C:\Users\Thom\Downloads\Folder.jpg
2012-03-23 15:39 - 2012-03-23 15:39 - 0005606 ___SH C:\Users\Thom\Downloads\AlbumArtSmall.jpg
2012-03-23 03:42 - 2010-04-28 04:26 - 0000000 ____D C:\Program Files\Common Files\Steam
2012-03-20 13:08 - 2011-11-19 12:38 - 0000044 ____A C:\Users\Thom\jagex_cl_runescape_LIVE1.dat
2012-03-20 04:29 - 2010-06-04 06:47 - 0000000 ____D C:\Program Files\Microsoft Silverlight
2012-03-19 13:07 - 2012-03-19 13:07 - 6950552 ____A (Microsoft Corporation) C:\Users\Thom\Downloads\Silverlight.exe
2012-03-18 07:41 - 2012-03-18 05:28 - 0002612 ____A C:\Users\Thom\Documents\Mijn film.wlmp
2012-03-18 05:11 - 2011-10-27 12:15 - 0000000 ____D C:\Program Files\Mozilla Firefox
2012-03-15 10:33 - 2010-12-18 16:31 - 0000000 ____D C:\Users\Thom\AppData\Roaming\dvdcss
2012-03-14 09:01 - 2010-12-13 20:14 - 0000000 ____D C:\Users\Thom\AppData\Roaming\TuneUpMedia
2012-03-11 12:53 - 2012-03-11 12:50 - 0000000 ____D C:\Users\Thom\runecore
2012-03-05 12:13 - 2012-03-05 12:13 - 0000044 ____A C:\Users\Thom\jagex_cl_runescape_LIVE2.dat
2012-03-05 12:13 - 2012-03-05 12:13 - 0000000 ____D C:\Users\Thom\jagexcache2
2012-03-05 06:39 - 2012-03-05 06:38 - 0152248 ____A C:\Windows\Minidump\030512-21528-01.dmp
2012-03-05 06:38 - 2012-03-05 06:38 - 211559680 ____A C:\Windows\MEMORY.DMP
2012-03-05 06:38 - 2011-06-22 12:37 - 0000000 ____D C:\Windows\Minidump
2012-03-04 18:41 - 2012-03-04 18:41 - 0000000 ____D C:\Users\Thom\AppData\Local\Gearbox Software
2012-03-04 09:34 - 2012-03-04 09:34 - 0209959 ____A C:\Users\Thom\Downloads\photo.php
2012-03-01 01:46 - 2012-04-12 18:41 - 0019824 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys
2012-03-01 01:37 - 2012-04-12 18:41 - 0172544 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-03-01 01:33 - 2012-04-12 18:41 - 0159232 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll
2012-03-01 01:29 - 2012-04-12 18:41 - 0005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll
2012-02-27 21:52 - 2012-04-12 18:45 - 12281856 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-02-27 21:27 - 2012-04-12 18:45 - 9705984 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-02-27 21:18 - 2012-04-12 18:45 - 1799168 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-02-27 21:12 - 2012-04-12 18:45 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-02-27 21:11 - 2012-04-12 18:45 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-02-27 21:11 - 2012-04-12 18:45 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-02-27 21:09 - 2012-04-12 18:45 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-02-27 21:08 - 2012-04-12 18:45 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-02-27 21:06 - 2012-04-12 18:45 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-02-27 21:04 - 2012-04-12 18:45 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-02-27 21:03 - 2012-04-12 18:45 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-02-27 21:03 - 2012-04-12 18:45 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-02-27 20:59 - 2012-04-12 18:45 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-02-26 14:52 - 2012-02-26 14:12 - 343448523 ____A C:\Users\Thom\Downloads\BTCPKgnLKrtr.rar
2012-02-25 08:58 - 2012-02-25 08:14 - 0000000 ____D C:\Program Files\CommView
2012-02-25 08:18 - 2012-02-25 08:14 - 0009906 ____A (TamoSoft, Inc.) C:\Windows\System32\Drivers\cv2k1.sys
2012-02-25 08:14 - 2012-02-25 08:14 - 0000967 ____A C:\Users\Public\Desktop\CommView.lnk
2012-02-25 08:10 - 2012-02-25 08:10 - 0111024 ____A C:\Users\Thom\Downloads\Commview.exe
2012-02-25 08:08 - 2011-11-19 08:14 - 0000000 ____D C:\ProgramData\TamoSoft
2012-02-25 05:53 - 2012-02-25 05:50 - 0000000 ____D C:\Users\Thom\Desktop\Jersey shore
2012-02-17 17:37 - 2012-02-17 17:37 - 0173363 ____A C:\Users\Thom\Downloads\YouTube-startpagina(3).htm
2012-02-17 01:34 - 2012-03-14 02:29 - 0919040 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-02-17 01:34 - 2012-03-14 02:29 - 0826880 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll
2012-02-17 00:14 - 2012-03-14 02:29 - 0183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-02-17 00:13 - 2012-03-14 02:29 - 0024576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys
2012-02-15 19:23 - 2012-02-15 10:35 - 0000000 ____D C:\Users\Thom\AppData\Roaming\Notepad++
2012-02-15 19:11 - 2012-02-15 19:11 - 0000000 ____D C:\Program Files\Microsoft.NET
2012-02-15 19:10 - 2012-02-15 19:10 - 0889416 ____A (Microsoft Corporation) C:\Users\Thom\Downloads\dotNetFx40_Full_setup.exe
2012-02-15 19:09 - 2012-02-15 19:09 - 0102975 ____A C:\Users\Thom\Downloads\LOIC-1.0.7.42-binary.zip
2012-02-15 10:54 - 2012-02-15 10:34 - 0000000 ____D C:\Users\Thom\Desktop\site
2012-02-15 10:35 - 2012-02-15 10:35 - 0001021 ____A C:\Users\Thom\Desktop\Notepad++.lnk
2012-02-15 10:35 - 2012-02-15 10:35 - 0000000 ____D C:\Program Files\Notepad++
2012-02-15 10:34 - 2012-02-15 10:34 - 5650428 ____A C:\Users\Thom\Downloads\npp.5.9.8.Installer.exe
2012-02-15 10:26 - 2012-02-15 10:25 - 0000000 ____D C:\Users\Thom\Desktop\Xamp
2012-02-15 10:25 - 2012-02-15 10:24 - 72538227 ____A C:\Users\Thom\Downloads\xampp-win32-1.7.7-VC9.7z
2012-02-15 04:04 - 2009-10-14 06:50 - 0000000 ____D C:\Windows\Panther
2012-02-14 19:02 - 2012-02-14 19:02 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-02-14 19:02 - 2012-02-14 19:02 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-02-14 19:02 - 2012-02-14 19:02 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0072822 ____A C:\Windows\System32\ieuinit.inf
2012-02-14 19:02 - 2012-02-14 19:02 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-02-14 19:02 - 2012-02-14 19:02 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-02-14 19:02 - 2012-02-14 19:02 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-02-14 19:02 - 2012-02-14 19:02 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-02-14 19:02 - 2012-02-14 19:00 - 0003797 ____A C:\Windows\IE9_main.log
2012-02-14 10:07 - 2011-03-02 11:41 - 0000000 ____D C:\Users\Thom\AppData\Roaming\EpicBot
2012-02-14 09:50 - 2012-02-14 09:50 - 0001815 ____A C:\Users\Public\Desktop\EpicBot.lnk
2012-02-14 09:50 - 2012-02-14 09:50 - 0000000 ____D C:\Program Files\Driver-Soft
2012-02-14 09:50 - 2010-08-13 10:01 - 0000000 ____D C:\Program Files\Free Offers from Freeze.com
2012-02-14 09:49 - 2012-02-14 09:49 - 1653952 ____A (W3i, LLC) C:\Users\Thom\Downloads\epicbot_520.exe
2012-02-14 09:49 - 2010-04-28 20:41 - 0000000 ____D C:\Users\Thom\AppData\LocalLow
2012-02-10 01:38 - 2012-03-14 02:30 - 1077248 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-02-04 20:54 - 2012-02-04 20:54 - 0000000 ____D C:\Users\Thom\.RS2006
2012-02-03 07:35 - 2009-07-14 00:53 - 0032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-02-02 23:54 - 2012-03-14 02:30 - 2343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-01-27 05:52 - 2010-04-28 13:22 - 0000000 ____D C:\Users\Thom\Documents\Mijn ontvangen bestanden
2012-01-26 17:33 - 2012-01-26 17:33 - 0001024 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-01-26 17:33 - 2012-01-26 17:33 - 0000000 ____D C:\Program Files\VideoLAN
2012-01-26 17:31 - 2012-01-26 17:31 - 21073936 ____A C:\Users\Thom\Downloads\vlc-1.1.11-win32(1).exe
2012-01-26 13:02 - 2010-06-23 18:06 - 0000000 ____D C:\Users\Thom\AppData\Local\Apple Computer
2012-01-26 12:59 - 2012-01-26 12:58 - 21073936 ____A C:\Users\Thom\Downloads\vlc-1.1.11-win32.exe
2012-01-26 12:57 - 2012-01-26 12:57 - 0000000 ____A C:\Users\Thom\Documents\vlc-1.1.11-win32.exe
2012-01-25 01:32 - 2012-03-29 15:02 - 0129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-01-25 01:32 - 2012-03-29 15:02 - 0058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-01-25 01:27 - 2012-03-14 13:25 - 0008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points (XP) =====================


========================= Memory info ======================

Percentage of memory in use: 8%
Total physical RAM: 3071.22 MB
Available physical RAM: 2797.46 MB
Total Pagefile: 2895.95 MB
Available Pagefile: 2837.09 MB
Total Virtual: 2047.88 MB
Available Virtual: 2002.03 MB

======================= Partitions =========================

1 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
2 Drive c: () (Fixed) (Total:585.88 GB) (Free:103.68 GB) NTFS
7 Drive h: () (Fixed) (Total:10.29 GB) (Free:10.2 GB) NTFS
8 Drive i: () (Removable) (Total:3.76 GB) (Free:3.46 GB) FAT32
9 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS

Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 4 Online 596 GB 0 B

Partitions of Disk 4:
===============

The disk management services could not complete the operation.

======================================================================================================

==========================================================

Last Boot: 2012-04-09 05:56

======================= End Of Log ==========================
  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Download the attached fixlist.txt to the same USB as FSRT

Insert the USB into the sick computer
From the reatogo desktop run FSRT and select fix

Once it has completed it will save a log to the USB
Reboot to normal windows and post that log plus the following OTL scan


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    %Temp%\smtmp\1\*.*
    %Temp%\smtmp\2\*.*
    %Temp%\smtmp\3\*.*
    %Temp%\smtmp\4\*.*
    >C:\commands.txt echo list vol /raw /hide /c
    /wait
    >C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
    /wait
    type c:\diskreport.txt /c
    /wait
    erase c:\commands.txt /hide /c
    /wait
    erase c:\diskreport.txt /hide /c
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#9
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
What maybe useful aswell i just saw: HKU\Thom\...\Winlogon: [Shell] C:\Users\Thom\AppData\Roaming\soundblaster_fx648.exe [238080 2012-04-17] (QRPU) in fixlist and i remember the first time the virus appeared it was running on my task manager maybe useful information? Im going to do your steps now.
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yep that will be history after the FSRT run
  • 0

Advertisements


#11
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
And correct meif im wrong but do i have to reboot my pc and just do a normal windows boot?
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yes reboot to normal windows
  • 0

#13
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
But i dont got the install for just OTLPE where do i get it cause that comes with the burned didc right. Normal windows boots again btw
  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Once you are in normal windows then download a fresh copy of OTL

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    %Temp%\smtmp\1\*.*
    %Temp%\smtmp\2\*.*
    %Temp%\smtmp\3\*.*
    %Temp%\smtmp\4\*.*
    >C:\commands.txt echo list vol /raw /hide /c
    /wait
    >C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
    /wait
    type c:\diskreport.txt /c
    /wait
    erase c:\commands.txt /hide /c
    /wait
    erase c:\diskreport.txt /hide /c
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#15
th0mh

th0mh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
My bad i didnt see that it was a download link
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP