I tried aswMBR.exe
Malewarebyte and cure doctor but nothing is working
Below is the log to aswMBR.exe
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-14 15:47:49
-----------------------------
15:47:49.194 OS Version: Windows 6.0.6002 Service Pack 2
15:47:49.194 Number of processors: 2 586 0x6801
15:47:49.196 ComputerName: ROBINS-LT UserName: Chosen072
15:47:53.611 Initialize success
15:48:01.813 AVAST engine defs: 12051400
15:48:05.295 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
15:48:05.316 Disk 0 Vendor: ST9120822AS 3.BHE Size: 114473MB BusType: 3
15:48:05.323 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-6
15:48:05.328 Disk 1 Vendor: ST9120822AS 3.BHE Size: 114473MB BusType: 3
15:48:05.390 Disk 0 MBR read successfully
15:48:05.396 Disk 0 MBR scan
15:48:05.469 Disk 0 unknown MBR code
15:48:05.501 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 105857 MB offset 63
15:48:05.538 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 8612 MB offset 216797175
15:48:05.579 Disk 0 scanning sectors +234436545
15:48:05.715 Disk 0 scanning C:\Windows\system32\drivers
15:48:31.614 File: C:\Windows\system32\drivers\netbt.sys **INFECTED** Win32:Rootkit-gen [Rtk]
15:48:56.652 AVAST engine scan C:\Windows
15:49:27.986 AVAST engine scan C:\Windows\system32
16:00:21.724 AVAST engine scan C:\Windows\system32\drivers
16:00:46.262 File: C:\Windows\system32\drivers\netbt.sys **INFECTED** Win32:Rootkit-gen [Rtk]
16:01:25.811 AVAST engine scan C:\Users\Chosen072
16:08:56.702 Disk 0 MBR has been saved successfully to "C:\Users\Chosen072\Desktop\MBR.dat"
16:08:56.717 The log file has been saved successfully to "C:\Users\Chosen072\Desktop\chozens mbrI.txt"
=========================================================================================================================
OTL Log
OTL logfile created on: 5/14/2012 6:35:49 PM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\Chosen072\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 44.49% Memory free
4.11 Gb Paging File | 2.88 Gb Available in Paging File | 70.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 103.38 Gb Total Space | 34.30 Gb Free Space | 33.18% Space Free | Partition Type: NTFS
Drive D: | 111.79 Gb Total Space | 12.21 Gb Free Space | 10.92% Space Free | Partition Type: NTFS
Drive E: | 8.41 Gb Total Space | 1.35 Gb Free Space | 16.03% Space Free | Partition Type: NTFS
Computer Name: ROBINS-LT | User Name: Chosen072 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/05/14 18:35:21 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Chosen072\Desktop\OTL.exe
PRC - [2012/05/14 15:14:59 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Chosen072\Desktop\aswMBR.exe
PRC - [2012/05/14 14:42:44 | 000,351,904 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2012/05/14 14:40:00 | 000,019,392 | ---- | M] () -- C:\Users\Chosen072\qgl6wo88sw.exe
PRC - [2012/05/04 14:41:36 | 027,087,944 | ---- | M] (Dropbox, Inc.) -- C:\Users\Chosen072\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/02/01 15:18:14 | 002,918,224 | ---- | M] (TechSmith Corporation) -- C:\Program Files\TechSmith\Jing\Jing.exe
PRC - [2010/12/15 13:31:20 | 000,460,144 | ---- | M] () -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
PRC - [2010/12/15 13:22:42 | 001,085,440 | ---- | M] () -- C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
PRC - [2010/10/18 09:37:35 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\consent.exe
PRC - [2010/09/17 11:14:50 | 000,098,304 | ---- | M] (Firebird Project) -- C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
PRC - [2010/09/17 11:14:42 | 003,735,552 | ---- | M] (Firebird Project) -- C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
PRC - [2009/07/24 16:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2009/06/26 17:21:00 | 000,757,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\vVX1000.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2012/05/14 14:40:00 | 000,019,392 | ---- | M] () -- C:\Users\Chosen072\qgl6wo88sw.exe
MOD - [2012/05/11 05:38:13 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/11 05:36:39 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/11 05:36:19 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4d54640bacd18e047a4573cb4611bd3\System.Windows.Forms.ni.dll
MOD - [2012/05/11 05:36:06 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5d8696f15e49aedf883dd945806a7049\System.Drawing.ni.dll
MOD - [2012/05/11 05:35:37 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012/05/11 05:35:30 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/11 05:35:29 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c466fbf8e50c7c11b2fa994707124290\PresentationFramework.ni.dll
MOD - [2012/05/11 05:35:08 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b4ade6954a61a7626858c123dc951ba6\PresentationCore.ni.dll
MOD - [2012/05/11 05:34:52 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/11 05:34:47 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/11 05:34:38 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012/02/01 15:18:20 | 001,144,656 | ---- | M] () -- C:\Program Files\TechSmith\Jing\Recorder.dll
MOD - [2012/01/08 09:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2009/11/03 20:14:04 | 000,054,272 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_01.dll
MOD - [2008/06/20 00:42:56 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/12/19 20:27:04 | 000,066,856 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/02/29 09:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2010/12/15 13:31:20 | 000,460,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
SRV - [2010/12/15 13:22:42 | 001,085,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe -- (FlipShareServer)
SRV - [2010/09/17 11:14:50 | 000,098,304 | ---- | M] (Firebird Project) [Auto | Running] -- C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance)
SRV - [2010/09/17 11:14:42 | 003,735,552 | ---- | M] (Firebird Project) [On_Demand | Running] -- C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe -- (FirebirdServerDefaultInstance)
SRV - [2010/06/01 09:07:50 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/07/24 16:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled | Stopped] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/19 03:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/01/09 17:55:34 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\Drivers\vdm2mjyx.sys -- (vdm2mjyx)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | Auto | Stopped] -- -- (MCSTRM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\CHOSEN~1\AppData\Local\Temp\aswMBR.sys -- (aswMBR)
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\6d4db.sys -- (6d4db)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2010/01/25 16:49:36 | 000,032,408 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PCTINDIS5.sys -- (PCTINDIS5)
DRV - [2009/12/16 17:48:51 | 000,019,944 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\tsk_atapi.sys -- (atapi)
DRV - [2009/12/16 16:11:04 | 000,011,264 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\uzm2mjyx.sys -- (uzm2mjyx)
DRV - [2009/11/24 19:49:48 | 000,053,328 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2009/07/16 08:53:18 | 000,107,776 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\gtuhs51.sys -- (GTUHSNDISIPXP)
DRV - [2009/07/16 08:51:50 | 000,067,840 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\gtuhsbus.sys -- (GTUHSBUS)
DRV - [2009/07/16 08:49:56 | 000,008,064 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\gtuhsser.sys -- (GTUHSSER)
DRV - [2009/06/26 17:21:02 | 001,956,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VX1000.sys -- (VX1000)
DRV - [2009/06/10 16:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2008/12/04 03:42:00 | 007,606,688 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/08/22 10:05:42 | 000,026,760 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\swmsflt.sys -- (swmsflt)
DRV - [2008/08/01 19:51:14 | 001,052,704 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008/03/03 11:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/07/10 06:27:56 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/07/03 18:59:10 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG Mobile Modem Diagnostic Serial Port (WDM)
DRV - [2007/07/03 18:58:20 | 000,106,792 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2007/07/03 18:57:24 | 000,011,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2007/07/03 18:54:24 | 000,080,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2007/04/11 22:30:52 | 000,160,768 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007/02/24 10:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/02/16 19:50:32 | 000,012,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2007/01/23 13:03:28 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/01/23 12:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/30 13:24:58 | 000,008,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2006/06/28 12:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CPQBttn.sys -- (HBtnKey)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {40439b93-f815-4122-8073-d03bed94c303}
IE - HKLM\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect...hromesbox-en-us
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{9AE845A0-B8DE-4C87-A54E-55B6FFA38502}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpd
IE - HKLM\..\SearchScopes\{C710C720-B588-4676-A61E-B8C9C166D712}: "URL" = http://search.live.c...#38;FORM=HVDUS7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {13BA74AE-E197-454E-B8DB-18B78838913A}
IE - HKCU\..\SearchScopes\{13BA74AE-E197-454E-B8DB-18B78838913A}: "URL" = http://search.yahoo....ing}&fr=hp-pvdt
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask...s}&locale=en_US
IE - HKCU\..\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}: "URL" = http://www.fastbrows...B-9E5E79F3A0D0}
IE - HKCU\..\SearchScopes\{3BB94474-A314-4576-8AA2-2EC058F35DF5}: "URL" = http://www.flickr.co...q={searchTerms}
IE - HKCU\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect...hromesbox-en-us
IE - HKCU\..\SearchScopes\{5065E8C3-F3BD-4103-80B4-2AA72165195D}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKCU\..\SearchScopes\{5F4764C9-A953-44D8-BA81-4C334ADB8090}: "URL" = http://rover.ebay.co...36017972&type=3
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...&rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{6CD9BBE3-DD01-49C6-BE7D-9AC27CA79035}: "URL" = http://www.amazon.co...de=ur2&ie=UTF-8
IE - HKCU\..\SearchScopes\{9AE845A0-B8DE-4C87-A54E-55B6FFA38502}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpd
IE - HKCU\..\SearchScopes\{C710C720-B588-4676-A61E-B8C9C166D712}: "URL" = http://search.live.c...#38;FORM=HVDUS7
IE - HKCU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://dl.ask.com/to...m=1&toolbar=GV2
IE - HKCU\..\SearchScopes\{FAB2F0FF-089C-49EA-BFBF-2EAAA16E7367}: "URL" = http://delicious.com...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\Chosen072\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Chosen072\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Chosen072\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Chosen072\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Chosen072\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Chosen072\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/03/22 12:43:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/01/02 22:10:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/03/22 12:43:01 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\Chosen072\Program Files\DNA [2010/01/05 16:06:52 | 000,000,000 | ---D | M]
[2009/09/29 07:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chosen072\AppData\Roaming\Mozilla\Extensions
[2009/03/28 08:23:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chosen072\AppData\Roaming\Mozilla\Extensions\[email protected]
Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [hcpaui] rundll32.exe "C:\Users\CHOSEN~1\AppData\Local\Temp\hcpaui.dll",CheckTextureRequirements File not found
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Regedit32] C:\Windows\system32\regedit.exe File not found
O4 - HKLM..\Run: [stfxfg] rundll32.exe "C:\Users\CHOSEN~1\AppData\Local\Temp\stfxfg.dll",SteamGameServerStats File not found
O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [qgl6wo88sw] C:\Users\Chosen072\qgl6wo88sw.exe ()
O4 - HKCU..\Run: [Spotify] "C:\Users\Chosen072\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart File not found
O4 - HKLM..\RunOnce: [Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
O4 - Startup: C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Chosen072\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Chosen072\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Chosen072\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\system32\wshbth.dll File not found
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8C77DCEE-1FB5-4633-8DEF-A02C55F1F52B}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A84C4504-3EDA-44AC-886B-C316CF2D95A3}: DhcpNameServer = 209.183.33.23 209.183.35.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B0717666-99DE-4E14-B322-505B7C9031E4}: DhcpNameServer = 68.87.75.198 68.87.64.150
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (wuruteli.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/04 22:57:23 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - E:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{4e690e46-3703-11e0-967d-001b24910987}\Shell - "" = AutoRun
O33 - MountPoints2\{4e690e46-3703-11e0-967d-001b24910987}\Shell\AutoRun\command - "" = F:\HPLauncher.exe
O33 - MountPoints2\{6d93134e-7e0c-11de-bf03-001b24910987}\Shell - "" = AutoRun
O33 - MountPoints2\{6d93134e-7e0c-11de-bf03-001b24910987}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{eb794350-b445-11df-bf05-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{eb794350-b445-11df-bf05-806e6f6e6963}\Shell\AutoRun\command - "" = F:\ATTPreCopy.exe -d:OPETNAEXPCI -7
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/05/14 18:34:07 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Users\Chosen072\Desktop\OTL.exe
[2012/05/14 17:43:48 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/05/14 17:42:22 | 002,075,184 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Chosen072\Desktop\TDSSKiller.exe
[2012/05/14 17:40:32 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/05/14 17:40:17 | 004,492,858 | R--- | C] (Swearware) -- C:\Users\Chosen072\Desktop\ComboFix.exe
[2012/05/14 16:53:25 | 000,000,000 | ---D | C] -- C:\ProgramData\F4D562B6006C2C790023F9D02830AD02
[2012/05/14 15:14:52 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Chosen072\Desktop\aswMBR.exe
[2012/05/14 14:55:12 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012/05/14 14:46:17 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Fortress 2012
[2012/05/14 14:42:13 | 000,000,000 | ---D | C] -- C:\ProgramData\F4D562B6006C2C790023F9D0570F1C8B
[2012/05/13 19:24:42 | 000,000,000 | R--D | C] -- C:\Users\Chosen072\Dropbox
[2012/05/13 19:20:30 | 000,000,000 | R--D | C] -- C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/05/13 19:20:17 | 000,000,000 | ---D | C] -- C:\Program Files\Dropbox
[2012/05/13 19:19:48 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/05/13 19:16:41 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\Dropbox
[2012/05/13 09:12:13 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\Flip Video
[2012/05/13 09:10:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Flip Video
[2012/05/13 09:10:31 | 000,000,000 | ---D | C] -- C:\Program Files\Flip Video
[2012/05/10 18:39:01 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2012/05/10 18:39:01 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012/05/10 18:39:01 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012/05/10 18:39:01 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2012/05/10 18:39:00 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012/05/10 18:38:46 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012/05/10 18:38:46 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012/05/10 18:38:45 | 002,044,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/05/10 05:43:40 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\Yahoo!
[2012/05/04 08:11:46 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\Desktop\Templates
[2012/04/18 15:34:04 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\Downloaded Installations
[2012/04/15 13:02:40 | 000,000,000 | ---D | C] -- C:\Users\Chosen072\AppData\Roaming\SecondLife
========== Files - Modified Within 30 Days ==========
[2012/05/14 18:35:21 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Chosen072\Desktop\OTL.exe
[2012/05/14 18:27:01 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-984307550-3928441585-2128114710-1000UA.job
[2012/05/14 18:16:53 | 000,056,875 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012/05/14 18:14:32 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/14 18:14:32 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/14 18:14:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/14 17:44:50 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/05/14 17:42:22 | 002,075,184 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Chosen072\Desktop\TDSSKiller.exe
[2012/05/14 17:40:25 | 004,492,858 | R--- | M] (Swearware) -- C:\Users\Chosen072\Desktop\ComboFix.exe
[2012/05/14 17:26:36 | 000,081,112 | ---- | M] () -- C:\Windows\System32\drivers\7eebc29cd94c9851.sys
[2012/05/14 16:58:29 | 000,609,506 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/05/14 16:58:29 | 000,106,014 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/05/14 16:57:00 | 000,001,038 | ---- | M] () -- C:\Users\Chosen072\Desktop\Smart Fortress 2012.lnk
[2012/05/14 16:08:56 | 000,000,512 | ---- | M] () -- C:\Users\Chosen072\Desktop\MBR.dat
[2012/05/14 15:14:59 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Chosen072\Desktop\aswMBR.exe
[2012/05/14 14:42:44 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/05/14 14:42:44 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/14 14:40:00 | 000,019,392 | ---- | M] () -- C:\Users\Chosen072\qgl6wo88sw.exe
[2012/05/14 14:00:14 | 000,056,875 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012/05/14 13:37:25 | 000,096,360 | ---- | M] () -- C:\Users\Chosen072\Desktop\A Simple Conversation Part I.pdf
[2012/05/14 11:27:03 | 000,000,872 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-984307550-3928441585-2128114710-1000Core.job
[2012/05/14 08:17:35 | 000,446,017 | ---- | M] () -- C:\Users\Chosen072\Desktop\photo.jpg
[2012/05/13 19:24:42 | 000,000,947 | ---- | M] () -- C:\Users\Chosen072\Desktop\Dropbox.lnk
[2012/05/13 19:20:30 | 000,000,957 | ---- | M] () -- C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/05/13 13:54:38 | 000,092,160 | ---- | M] () -- C:\Users\Chosen072\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/13 09:11:03 | 000,000,921 | ---- | M] () -- C:\Users\Public\Desktop\FlipShare.lnk
[2012/05/13 08:58:56 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForChosen072.job
[2012/05/11 15:22:13 | 000,016,245 | ---- | M] () -- C:\Users\Chosen072\Desktop\GCCSA-HEADSTART_TEACHER.pdf
[2012/05/11 15:20:40 | 000,047,081 | ---- | M] () -- C:\Users\Chosen072\Desktop\CentralTXOpp_Lead_Teacher_Supv.pdf
[2012/05/11 05:31:53 | 001,811,336 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/05/09 10:28:33 | 000,000,680 | ---- | M] () -- C:\Users\Chosen072\AppData\Local\d3d9caps.dat
[2012/05/03 08:11:47 | 000,096,193 | ---- | M] () -- C:\Users\Chosen072\Desktop\A Simple Conversation.pdf
[2012/04/26 03:02:47 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/04/24 12:28:14 | 000,027,439 | ---- | M] () -- C:\Users\Chosen072\Desktop\bluetooth.jpg
[2012/04/19 12:25:01 | 000,063,883 | ---- | M] () -- C:\Users\Chosen072\Desktop\Business_Plan_Template.PDF
========== Files Created - No Company Name ==========
[2012/05/14 17:26:36 | 000,081,112 | ---- | C] () -- C:\Windows\System32\drivers\7eebc29cd94c9851.sys
[2012/05/14 15:26:16 | 000,000,512 | ---- | C] () -- C:\Users\Chosen072\Desktop\MBR.dat
[2012/05/14 14:46:16 | 000,001,038 | ---- | C] () -- C:\Users\Chosen072\Desktop\Smart Fortress 2012.lnk
[2012/05/14 14:41:48 | 000,019,392 | ---- | C] () -- C:\Users\Chosen072\qgl6wo88sw.exe
[2012/05/14 13:37:23 | 000,096,360 | ---- | C] () -- C:\Users\Chosen072\Desktop\A Simple Conversation Part I.pdf
[2012/05/13 19:24:42 | 000,000,947 | ---- | C] () -- C:\Users\Chosen072\Desktop\Dropbox.lnk
[2012/05/13 19:20:30 | 000,000,957 | ---- | C] () -- C:\Users\Chosen072\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/05/13 10:51:04 | 000,446,017 | ---- | C] () -- C:\Users\Chosen072\Desktop\photo.jpg
[2012/05/13 09:11:03 | 000,000,933 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlipShare.lnk
[2012/05/13 09:11:03 | 000,000,921 | ---- | C] () -- C:\Users\Public\Desktop\FlipShare.lnk
[2012/05/11 15:22:13 | 000,016,245 | ---- | C] () -- C:\Users\Chosen072\Desktop\GCCSA-HEADSTART_TEACHER.pdf
[2012/05/11 15:20:40 | 000,047,081 | ---- | C] () -- C:\Users\Chosen072\Desktop\CentralTXOpp_Lead_Teacher_Supv.pdf
[2012/05/03 08:11:44 | 000,096,193 | ---- | C] () -- C:\Users\Chosen072\Desktop\A Simple Conversation.pdf
[2012/04/26 03:02:44 | 000,001,788 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/24 12:29:59 | 000,027,439 | ---- | C] () -- C:\Users\Chosen072\Desktop\bluetooth.jpg
[2012/04/19 12:20:06 | 000,063,883 | ---- | C] () -- C:\Users\Chosen072\Desktop\Business_Plan_Template.PDF
[2012/03/29 18:48:46 | 000,180,624 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll
[2010/08/31 15:06:49 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 173 bytes -> C:\ProgramData\TEMP:A6CD15C3
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
I hope someone can help me
Thanks
Edited by chosen072, 14 May 2012 - 04:52 PM.