Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

!Malware , Trojan horse. I cant get rid of them.Please Heelp!


  • This topic is locked This topic is locked

#1
Havocc

Havocc

    Member

  • Member
  • PipPip
  • 23 posts
Hi.I keep getting a pop up every 3-5 minutes from Avast that saying 'avast! File system shield has blocked a threat. no further action is required'.I got infected when I tried to install a game that i downloaded from a torrent site.I uninstalled it and did a full system scan with avast.i moved all 3 malware-gen and 1 trojan horse sh*t to chest.Then avast still showed me these threats, so I ran a boot time scan which took about four hours to finish. I did the correct actions, but it still showed me these annoying pop ups.So I then searched on the internet and found essexboys information topic on avast site and I followed it step by step.I scanned my computer using Malwarebytes' Anti-Malware and deleted what it found.malwarebytes then prompted me to restart my computer, so I did.I did a scan after restart and found it again.I was thinking about doing a system restore or using ComboFix,but i rather not run ComboFix without someone who has been properly trained.

English is not my first language and I am an ordinary notebook user with a Windows 7 (64 Bit) system. I need help




OTL logfile created on: 7/24/2012 4:21:11 PM - Run 2
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy

7.95 Gb Total Physical Memory | 3.62 Gb Available Physical Memory | 45.53% Memory free
7.95 Gb Paging File | 2.46 Gb Available in Paging File | 30.90% Paging File free
Paging file location(s): [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.41 Gb Total Space | 283.52 Gb Free Space | 62.81% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 99.32 Gb Free Space | 21.32% Space Free | Partition Type: NTFS
Drive E: | 14.06 Gb Total Space | 1.57 Gb Free Space | 11.15% Space Free | Partition Type: NTFS

Computer Name: USER-HP | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
PRC - D:\PRRRRROOOOGGG\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (HP)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - D:\PRRRRROOOOGGG\VLC\vlc.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\libglesv2.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\libegl.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\avutil-51.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\avformat-54.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\avcodec-54.dll ()
MOD - C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\0018dd52b56988a833ee41699cf49325\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e7cd67fc34ad0fc611c1e1244cfc6584\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libvorbis_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libxml_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libtheora_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libzip_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libvout_directx_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libvcd_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libwaveout_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libtrivial_channel_mixer_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libugly_resampler_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libtrivial_resampler_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libqt4_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libskins2_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libschroedinger_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libspeex_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libscaletempo_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libstream_filter_rar_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libsimple_channel_mixer_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libstream_filter_record_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libpng_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libmp4_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libmpgatofixed32_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libplaylist_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libmpeg_audio_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libmemcpymmxext_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liblpcm_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liblibass_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libfaad_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libflac_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libdvdnav_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libdshow_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libdtstofloat32_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liblibmpeg2_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libhotkeys_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libconverter_float_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libequalizer_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libdts_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libfake_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libcdg_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liblinear_resampler_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libglobalhotkeys_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libdtstospdif_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libconverter_fixed_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libfloat32_mixer_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libdolby_surround_decoder_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libavcodec_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libbandlimited_resampler_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaraw_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaout_directx_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaes3_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\libvlccore.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\libvlc.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaccess_bd_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liba52tofloat32_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaccess_directory_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liba52_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaccess_file_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\libaccess_fake_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\plugins\liba52tospdif_plugin.dll ()
MOD - D:\PRRRRROOOOGGG\VLC\vlc.exe ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) -- C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (AESTFilters) -- C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (FPLService) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (HP)
SRV - (hpCMSrv) -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (Bluetooth OBEX Service) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
SRV - (Bluetooth Media Service) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation)
SRV - (Bluetooth Device Monitor) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (HPWMISVC) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (atksgt) -- C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (intelkmd) -- C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (NETwNs64) -- C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (wdkmd) -- C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (btmaux) -- C:\Windows\SysNative\drivers\btmaux.sys (Intel Corporation)
DRV:64bit: - (iBtFltCoex) -- C:\Windows\SysNative\drivers\iBtFltCoex.sys (Intel Corporation)
DRV:64bit: - (btmhsf) -- C:\Windows\SysNative\drivers\btmhsf.sys (Intel Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (clwvd) -- C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (Revoflt) -- C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (RivaTuner64) -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ie.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-IE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC B6 B0 C4 4F 4B CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.ie/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.ie/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Simple Pass 2011 (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\npwebsitelogon.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: Website Logon = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\
CHR - Extension: Turn Off the Lights = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.0.0.106_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Battlefield Play4Free = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.80.2_0\
CHR - Extension: Timer = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd\1.7.6_0\
CHR - Extension: avast! WebRep = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: Adblock for Pirate Bay = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\imkpamgpfalmdaikobnkefcmmkpgljjd\1.27_0\
CHR - Extension: Zombie Pandemic = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkicdgidnfmdfnhhllffoplpaldkljl\1_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RivaTunerStartupDaemon] C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\PRRRRROOOOGGG\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.101.160.4 89.101.160.5
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BB097F33-436F-45FE-A61F-30C1C21499A1}: DhcpNameServer = 89.101.160.4 89.101.160.5
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{ec6a526d-8e45-11e1-9cd1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{ec6a526d-8e45-11e1-9cd1-806e6f6e6963}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/24 00:44:18 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2012/07/23 20:08:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2012/07/23 20:08:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/23 20:08:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/23 20:08:00 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/23 20:08:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/23 02:06:35 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Bulletstorm insall info
[2012/07/21 16:01:11 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2012/07/21 02:19:16 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Audacity
[2012/07/19 16:17:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\InstallShield Installation Information
[2012/07/19 16:13:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Team17
[2012/07/19 02:21:29 | 000,000,000 | ---D | C] -- C:\ProgramData\MumboJumbo
[2012/07/19 02:20:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glowfish
[2012/07/19 00:39:12 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\JustAdventure
[2012/07/18 16:04:33 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Battlefield Play4Free
[2012/07/18 16:03:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
[2012/07/14 21:39:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2012/07/14 21:36:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\PunkBuster
[2012/07/14 20:26:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\THQ
[2012/07/13 23:33:24 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Monolith Productions
[2012/07/13 23:33:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Trymedia
[2012/07/13 22:08:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F.E.A.R. Platinum
[2012/07/13 18:56:41 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\PAYDAY
[2012/07/13 15:40:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Elephant Games
[2012/07/13 15:40:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Elephant Games
[2012/07/12 16:30:25 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grim Tales 3 - The Wishes CE
[2012/07/10 01:07:26 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\WB Games
[2012/07/10 01:00:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snowblind Studios
[2012/07/08 18:15:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1953 - KGB Unleashed
[2012/07/07 16:39:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\My Games
[2012/07/06 21:15:10 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Endless Space
[2012/07/06 21:08:40 | 000,000,000 | ---D | C] -- C:\ProgramData\REVOLT
[2012/07/05 19:38:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
[2012/07/05 18:28:26 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\WB Games
[2012/07/04 14:59:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Thomas Was Alone
[2012/07/02 21:05:24 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cubemen
[2012/06/29 18:41:47 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\2012
[2012/06/29 16:03:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\BlamGames
[2012/06/28 23:49:24 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\DeadIsland
[2012/06/28 15:52:02 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\ElevatedDiagnostics
[2012/06/27 15:27:43 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Salvation Prophecy
[2012/06/27 15:27:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Salvation Prophecy
[2012/06/27 02:54:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Rainbow
[2012/06/27 02:33:52 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Containment The Zombie Puzzler
[2012/06/27 01:51:55 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Activision
[2012/06/26 15:15:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
[2012/06/25 18:34:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages
[2012/06/24 23:17:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Warner Bros. Interactive Entertainment
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/24 15:48:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-782919554-1672995099-123328311-1000UA.job
[2012/07/24 14:06:26 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/24 14:06:26 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/24 13:59:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/24 13:59:02 | 2106,478,591 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/24 00:43:55 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2012/07/23 20:08:04 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/22 16:48:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-782919554-1672995099-123328311-1000Core.job
[2012/07/22 15:04:42 | 000,332,749 | ---- | M] () -- C:\Users\User\Desktop\song5.wma
[2012/07/22 14:47:41 | 000,355,199 | ---- | M] () -- C:\Users\User\Documents\song 4.wma
[2012/07/22 03:24:28 | 000,015,978 | ---- | M] () -- C:\Users\User\Desktop\ez jonak tunik.JPG
[2012/07/22 00:02:44 | 000,001,670 | ---- | M] () -- C:\Users\User\Desktop\MOHA - Shortcut.lnk
[2012/07/21 02:19:07 | 000,000,686 | ---- | M] () -- C:\Users\User\Desktop\Audacity.lnk
[2012/07/21 01:25:39 | 000,628,460 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/21 01:25:39 | 000,110,612 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/21 01:25:38 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/19 17:05:07 | 000,111,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/07/19 17:05:07 | 000,111,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012/07/19 16:13:14 | 000,001,060 | ---- | M] () -- C:\Users\Public\Desktop\Alien Breed 2 Assault.lnk
[2012/07/19 14:38:09 | 000,282,104 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012/07/19 14:02:43 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForUser.job
[2012/07/19 02:20:20 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\Glowfish.lnk
[2012/07/18 17:19:39 | 000,000,738 | ---- | M] () -- C:\Users\User\Desktop\BFP4f - Shortcut.lnk
[2012/07/18 16:13:03 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/07/17 17:24:40 | 000,000,717 | ---- | M] () -- C:\Users\User\Desktop\ANB - Shortcut.lnk
[2012/07/15 22:30:52 | 000,001,095 | ---- | M] () -- C:\Users\User\Desktop\deponia - Shortcut.lnk
[2012/07/13 22:08:14 | 000,000,945 | ---- | M] () -- C:\Users\Public\Desktop\F.E.A.R. Extraction Point.lnk
[2012/07/13 22:08:14 | 000,000,931 | ---- | M] () -- C:\Users\Public\Desktop\F.E.A.R. Perseus Mandate.lnk
[2012/07/13 22:08:14 | 000,000,836 | ---- | M] () -- C:\Users\Public\Desktop\F.E.A.R..lnk
[2012/07/13 18:42:41 | 000,001,153 | ---- | M] () -- C:\Users\User\Desktop\Terraria - Shortcut.lnk
[2012/07/13 15:39:11 | 000,000,811 | ---- | M] () -- C:\Users\User\Desktop\GrimTales3_TheWishes_CE - Shortcut.lnk
[2012/07/12 19:46:42 | 000,002,395 | ---- | M] () -- C:\Users\User\Desktop\Google Chrome.lnk
[2012/07/12 16:23:39 | 000,001,563 | ---- | M] () -- C:\Users\User\Desktop\Bioshock2Launcher - Shortcut.lnk
[2012/07/11 14:54:16 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/10 01:09:48 | 000,001,335 | ---- | M] () -- C:\Users\User\Desktop\witn - Shortcut.lnk
[2012/07/08 18:15:53 | 000,000,850 | ---- | M] () -- C:\Users\Public\Desktop\1953 - KGB Unleashed.lnk
[2012/07/06 21:08:31 | 000,001,066 | ---- | M] () -- C:\Users\User\Desktop\DOOM3 - Shortcut.lnk
[2012/07/05 19:55:53 | 000,001,486 | ---- | M] () -- C:\Users\User\Desktop\BmLauncher - Shortcut.lnk
[2012/07/05 15:38:58 | 000,001,213 | ---- | M] () -- C:\Users\User\Desktop\FarCry2 - Shortcut.lnk
[2012/07/04 22:17:16 | 000,001,131 | ---- | M] () -- C:\Users\User\Desktop\Resonance - Shortcut.lnk
[2012/07/04 14:59:13 | 000,000,774 | ---- | M] () -- C:\Users\User\Desktop\Thomas Was Alone.lnk
[2012/07/03 17:16:23 | 000,001,158 | ---- | M] () -- C:\Users\User\Desktop\Slender - Shortcut.lnk
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/02 21:05:24 | 000,000,704 | ---- | M] () -- C:\Users\User\Desktop\Cubemen.lnk
[2012/07/02 02:11:38 | 000,000,825 | ---- | M] () -- C:\Users\User\Desktop\dearesther - Shortcut.lnk
[2012/07/02 01:00:07 | 000,001,136 | ---- | M] () -- C:\Users\Public\Desktop\Spec Ops The Line.lnk
[2012/06/29 16:02:51 | 000,001,556 | ---- | M] () -- C:\Users\User\Desktop\Fierce Tales The Dogs Heart Collectors.lnk
[2012/06/27 15:25:09 | 000,001,126 | ---- | M] () -- C:\Users\Public\Desktop\Salvation Prophecy.lnk
[2012/06/27 02:33:53 | 000,000,975 | ---- | M] () -- C:\Users\User\Desktop\Containment The Zombie Puzzler.lnk
[2012/06/27 01:36:43 | 000,000,747 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty - World at War.lnk
[2012/06/26 18:54:00 | 000,000,868 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/26 15:15:22 | 000,000,798 | ---- | M] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2012/06/26 02:02:08 | 000,001,360 | ---- | M] () -- C:\Users\User\Desktop\deadislandgame - Shortcut.lnk
[2012/06/25 18:39:25 | 000,311,968 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012/06/25 18:09:28 | 000,043,168 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/23 23:45:46 | 000,232,960 | ---- | C] () -- C:\Windows\Installer\{137b3a62-4b9a-bd9d-fce2-fbaac8c326b4}\U\00000008.@
[2012/07/23 20:08:04 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/22 20:30:56 | 000,016,896 | ---- | C] () -- C:\Windows\Installer\{137b3a62-4b9a-bd9d-fce2-fbaac8c326b4}\U\80000000.@
[2012/07/22 15:04:42 | 000,332,749 | ---- | C] () -- C:\Users\User\Desktop\song5.wma
[2012/07/22 14:47:41 | 000,355,199 | ---- | C] () -- C:\Users\User\Documents\song 4.wma
[2012/07/22 03:24:28 | 000,015,978 | ---- | C] () -- C:\Users\User\Desktop\ez jonak tunik.JPG
[2012/07/22 00:02:44 | 000,001,670 | ---- | C] () -- C:\Users\User\Desktop\MOHA - Shortcut.lnk
[2012/07/21 02:19:07 | 000,000,686 | ---- | C] () -- C:\Users\User\Desktop\Audacity.lnk
[2012/07/21 02:19:07 | 000,000,686 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2012/07/19 16:13:14 | 000,001,060 | ---- | C] () -- C:\Users\Public\Desktop\Alien Breed 2 Assault.lnk
[2012/07/19 02:20:20 | 000,000,806 | ---- | C] () -- C:\Users\Public\Desktop\Glowfish.lnk
[2012/07/18 17:19:39 | 000,000,738 | ---- | C] () -- C:\Users\User\Desktop\BFP4f - Shortcut.lnk
[2012/07/17 17:24:40 | 000,000,717 | ---- | C] () -- C:\Users\User\Desktop\ANB - Shortcut.lnk
[2012/07/15 22:30:52 | 000,001,095 | ---- | C] () -- C:\Users\User\Desktop\deponia - Shortcut.lnk
[2012/07/13 22:08:14 | 000,000,945 | ---- | C] () -- C:\Users\Public\Desktop\F.E.A.R. Extraction Point.lnk
[2012/07/13 22:08:14 | 000,000,931 | ---- | C] () -- C:\Users\Public\Desktop\F.E.A.R. Perseus Mandate.lnk
[2012/07/13 22:08:14 | 000,000,836 | ---- | C] () -- C:\Users\Public\Desktop\F.E.A.R..lnk
[2012/07/13 18:42:41 | 000,001,153 | ---- | C] () -- C:\Users\User\Desktop\Terraria - Shortcut.lnk
[2012/07/13 15:39:11 | 000,000,811 | ---- | C] () -- C:\Users\User\Desktop\GrimTales3_TheWishes_CE - Shortcut.lnk
[2012/07/12 16:23:39 | 000,001,563 | ---- | C] () -- C:\Users\User\Desktop\Bioshock2Launcher - Shortcut.lnk
[2012/07/11 23:44:21 | 021,101,536 | ---- | C] () -- C:\Users\User\Desktop\10 Futureworld.m4a
[2012/07/10 01:09:48 | 000,001,335 | ---- | C] () -- C:\Users\User\Desktop\witn - Shortcut.lnk
[2012/07/08 18:15:53 | 000,000,850 | ---- | C] () -- C:\Users\Public\Desktop\1953 - KGB Unleashed.lnk
[2012/07/06 21:08:31 | 000,001,066 | ---- | C] () -- C:\Users\User\Desktop\DOOM3 - Shortcut.lnk
[2012/07/05 19:55:53 | 000,001,486 | ---- | C] () -- C:\Users\User\Desktop\BmLauncher - Shortcut.lnk
[2012/07/05 15:38:58 | 000,001,213 | ---- | C] () -- C:\Users\User\Desktop\FarCry2 - Shortcut.lnk
[2012/07/04 22:17:16 | 000,001,131 | ---- | C] () -- C:\Users\User\Desktop\Resonance - Shortcut.lnk
[2012/07/04 14:59:13 | 000,000,774 | ---- | C] () -- C:\Users\User\Desktop\Thomas Was Alone.lnk
[2012/07/03 17:16:23 | 000,001,158 | ---- | C] () -- C:\Users\User\Desktop\Slender - Shortcut.lnk
[2012/07/02 21:05:24 | 000,000,704 | ---- | C] () -- C:\Users\User\Desktop\Cubemen.lnk
[2012/07/02 02:11:38 | 000,000,825 | ---- | C] () -- C:\Users\User\Desktop\dearesther - Shortcut.lnk
[2012/07/02 01:00:07 | 000,001,136 | ---- | C] () -- C:\Users\Public\Desktop\Spec Ops The Line.lnk
[2012/06/29 16:02:51 | 000,001,556 | ---- | C] () -- C:\Users\User\Desktop\Fierce Tales The Dogs Heart Collectors.lnk
[2012/06/27 15:25:09 | 000,001,126 | ---- | C] () -- C:\Users\Public\Desktop\Salvation Prophecy.lnk
[2012/06/27 02:33:53 | 000,000,975 | ---- | C] () -- C:\Users\User\Desktop\Containment The Zombie Puzzler.lnk
[2012/06/27 01:36:43 | 000,000,747 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty - World at War.lnk
[2012/06/26 15:15:22 | 000,000,798 | ---- | C] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2012/06/26 02:02:08 | 000,001,360 | ---- | C] () -- C:\Users\User\Desktop\deadislandgame - Shortcut.lnk
[2012/06/25 18:09:28 | 000,311,968 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012/06/25 18:09:27 | 000,043,168 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012/06/22 19:35:12 | 000,111,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/06/22 19:35:10 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/06/21 09:37:14 | 003,166,792 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012/06/06 17:51:48 | 000,000,109 | ---- | C] () -- C:\Windows\disney.ini
[2012/05/21 14:00:09 | 000,007,597 | ---- | C] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012/05/06 00:36:07 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012/05/05 21:51:51 | 000,000,000 | ---- | C] () -- C:\Windows\Tomb.INI
[2012/04/26 01:34:01 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/04/24 23:36:09 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{137b3a62-4b9a-bd9d-fce2-fbaac8c326b4}\@
[2012/04/24 20:29:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/04/24 20:23:07 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2012/04/24 20:21:52 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011/09/30 22:42:20 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/08/09 08:30:02 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/08/09 08:23:26 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011/08/09 07:58:38 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/03/25 22:16:08 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/03/17 13:51:46 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/12/17 03:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll

========== LOP Check ==========

[2012/06/02 17:10:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\.minecraft
[2012/05/26 15:27:10 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Anuman
[2012/07/21 02:57:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Audacity
[2012/05/21 00:06:42 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Big Fish Games
[2012/07/12 16:23:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Bioshock2
[2012/06/29 16:03:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\BlamGames
[2012/05/19 16:25:29 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Blue Tea Games
[2012/05/21 00:05:14 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Braid
[2012/04/25 19:31:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2012/04/26 22:47:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DailyMagic
[2012/05/22 20:50:23 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Deep Shadows
[2012/05/03 17:54:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Dropbox
[2012/05/24 22:54:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Eipix
[2012/07/13 15:40:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Elephant Games
[2012/05/12 20:16:30 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ERS Game Studios
[2012/05/05 21:10:08 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Evolved
[2012/06/13 22:42:44 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Fatshark
[2012/06/02 20:02:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Fuzzy Bug Interactive
[2012/05/06 00:36:07 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\GameDevo
[2012/05/08 21:50:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Gatling Gears
[2012/06/10 01:40:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Gogii
[2012/05/20 16:28:14 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Hothead Games
[2012/04/24 15:56:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IDT
[2012/06/13 22:55:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Kalypso Media
[2012/05/01 00:19:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Lazy Turtle Games
[2012/06/07 02:47:09 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Leadertech
[2012/05/03 00:18:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\LegacyInteractive
[2012/06/09 03:10:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mad Head Games
[2012/05/31 19:37:53 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Milestone
[2012/05/04 23:59:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Orneon
[2012/06/02 03:05:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Persha Studia
[2012/07/14 21:36:39 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PunkBuster
[2012/04/27 19:47:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\quickclick
[2012/06/27 02:54:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Rainbow
[2012/05/16 20:20:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Scoregasm
[2012/05/25 01:36:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SMIGames
[2012/05/20 20:21:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Squids
[2012/05/11 01:52:07 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\StokedBigAir
[2012/04/24 12:49:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Synaptics
[2012/06/22 19:17:00 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ubisoft
[2012/07/24 03:39:41 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\uTorrent
[2012/06/14 13:55:34 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\VendelGAMES
[2012/06/24 23:17:06 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Warner Bros. Interactive Entertainment
[2012/05/09 21:10:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ZombieDriver
[2012/06/12 13:15:33 | 000,032,652 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 181 bytes -> C:\ProgramData\Temp:1A15E356
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:D2DDC99D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:ED0B32CA

< End of report >

Attached Thumbnails

  • 1.JPG
  • 2.JPG
  • 3.JPG
  • 4.JPG
  • otl settings.JPG

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi lets get this cleaned up

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image


    :Files
    ipconfig /flushdns /c
    C:\Windows\Installer\{137b3a62-4b9a-bd9d-fce2-fbaac8c326b4}

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0

#3
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Hi essexboy.

So I copied the script under Custom scans and I hit Run Fix,but !! I had BSOD. I was able to reboot it thank god.so what next... :(
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Obviously this one is playing hard to get

Continue with the combofix run next
  • 0

#5
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I ran combofix and when it finished it did't produce a log for me or it did but I cant find it. I checked in C:\ComboFix.txt but nope .There is no Combofix folder in C drive.
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK I feel I know what type this one is

Could you reboot to the safe mode menu and let me know if there is the option "Repair my Computer"

To get to safe mode reboot the computer
Press and hold F8
A menu will appear

If not do you have a USB drive of at least 4 GB
  • 0

#7
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
thank you for your quick reply

So I rebooted to safe mod and there were these options : repair your computer ,safe mod ,safe mod with networking etc.
  • 0

#8
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
and then I started windows normally and here I am again. I think I made a big mistake when I chose to disable avast permanently and not disable avast until computer restarted while I was running combofix . Now I turned on avast again after I restarted my notebook.
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets go a deeper route then

First download this programme to your C drive

Farbar Recovery Scan Tool x64
So it becomes C:\FRST64.exe

Then reboot to the safe mode menu and select repair my computer

You may get some or all of the following screens (dependant on whether it has been used before )


You will see this although yours will say windows 7. Click repair my computer
Posted Image

Select your operating system
Posted Image

Select Command prompt
Posted Image

At the command prompt type the following :

CD..

repeat this until you get the C> command prompt
Type in FRST64.exe

Posted Image

The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the C drive.
Reboot to normal windows locate the FRST.txt copy and paste it to your reply.
  • 0

#10
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Im using a different laptop. I saved the frst exe to my c drive .So i chose repair my computer and then i had to chose keyboard language and then i chose command prompt from the options.I typed cd.. and hit enter and then again and again until these left X:\> then i typed FRST64.exe and now it says frst64 is not recognised as an internal or external command.
  • 0

Advertisements


#11
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
What should I do now?
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK me numpty

From the command prompt type :

C:\frst64.exe
  • 0

#13
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I typed C:\frst64.exe after X:\> but it says C:\frst64.exe is not recognized as an internal or external command,operable program or batch file. Am I doing sth wrong?
  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
No it is me being a total numpty

There is an extra space required in this version of the recovery console

So at the command prompt type :

CD C:

This should bring you to the C> prompt

Then type :

FRST64.exe

If that does not then type :

SYSTEMROOT
CD ..
That will take to C:
  • 0

#15
Havocc

Havocc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
its me again .So I typed CD C: enter and C> appeared and underneath the X:\windows\system32> line so it did not work properly .I then typed SYSTEMROOT and
CD .. in the same line but that did not work either.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP