I really appreciate your help, and I will be happy to stick with you to closure.
- Creates several randomly named directories in [user]\Application Data with executables in them
- Creates several randomly named files in windows\System32
- a wiacy.exe with multiple process instances seems to be the possible payload, taking processor time hoggishly.
- Apparently came from an email my mom opened
I've tried MBAM, MBAR, AdwCleaner, JRT, RKILL.com, TDSSKILLER. I think it's time for some custom guidance.
Tom
=== Original OTL log (1 of 2) ===
OTL logfile created on: 3/29/2014 1:40:39 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\Program Files (x86)
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.11 Mb Total Physical Memory | 450.97 Mb Available Physical Memory | 44.08% Memory free
2.41 Gb Paging File | 1.87 Gb Available in Paging File | 77.78% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 12.55 Gb Free Space | 22.46% Space Free | Partition Type: NTFS
Drive F: | 7.47 Gb Total Space | 3.19 Gb Free Space | 42.74% Space Free | Partition Type: FAT32
Computer Name: AIS11ZGY41 | User Name: kakdh | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/03/29 12:24:06 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\Program Files (x86)\OTL.exe
PRC - [2014/03/25 17:13:58 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe
PRC - [2013/12/28 01:39:31 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\zimurusa.exe
PRC - [2013/09/20 16:30:00 | 000,577,088 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
PRC - [2013/09/19 15:33:27 | 000,304,660 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\asbiqyofm.exe
PRC - [2013/06/28 17:48:04 | 000,014,624 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2013/04/18 16:03:58 | 000,302,250 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\armuxah.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/03/11 17:06:30 | 001,151,152 | ---- | M] () -- C:\Program Files\AVG SafeGuard toolbar\vprot.exe
PRC - [2013/03/11 17:06:30 | 000,968,880 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
PRC - [2013/01/24 01:00:02 | 000,260,160 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATILAE.EXE
PRC - [2012/10/25 04:45:09 | 000,302,157 | ---- | M] (JinMirumkan S.O.L.) -- C:\Documents and Settings\kakdh\Application Data\Yhpyse\veofel.exe
PRC - [2012/10/25 04:45:09 | 000,302,157 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\qiepcyv.exe
PRC - [2012/09/19 00:38:32 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\ohibihv.exe
PRC - [2012/07/31 11:16:30 | 001,057,920 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
PRC - [2012/05/17 00:00:00 | 000,126,128 | ---- | M] (Seiko Epson Corporation) -- C:\WINDOWS\system32\escsvc.exe
PRC - [2012/04/25 09:38:57 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\otaty.exe
PRC - [2010/11/17 14:49:25 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\bobiwynege.exe
PRC - [2010/08/22 18:13:25 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\udobso.exe
PRC - [2010/08/22 18:13:25 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) -- C:\Documents and Settings\kakdh\Application Data\Opihqo\abbabiu.exe
PRC - [2010/03/28 12:11:47 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\girixayrug.exe
PRC - [2010/01/09 06:24:57 | 000,302,250 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\ocgigihe.exe
PRC - [2010/01/09 06:24:57 | 000,302,250 | ---- | M] (JinMirumkan S.O.L.) -- C:\Documents and Settings\kakdh\Application Data\Egelux\danokoa.exe
PRC - [2009/10/09 09:07:22 | 000,493,248 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
PRC - [2008/12/20 07:50:34 | 002,656,528 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2008/12/20 07:46:58 | 000,558,864 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2008/12/16 21:59:50 | 000,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/11/08 17:00:02 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\avvyacol.exe
PRC - [2008/10/29 18:11:14 | 000,801,544 | ---- | M] (Logitech, Inc.) -- c:\Program Files\Logitech\QuickCam\LU\LogitechUpdate.exe
PRC - [2008/10/29 18:11:06 | 000,300,296 | ---- | M] (Logitech, Inc.) -- c:\Program Files\Logitech\QuickCam\LU\LULnchr.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/06 13:15:16 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\bietug.exe
PRC - [2008/01/16 02:57:01 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) -- C:\Documents and Settings\kakdh\Application Data\Asguhuec\waihle.exe
PRC - [2008/01/16 02:57:01 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\obisi.exe
PRC - [2007/08/13 04:28:01 | 000,290,517 | ---- | M] (nijwwifh nete yzqkgq zopjnaebv qisurhoarg qmrsz) -- C:\Documents and Settings\kakdh\Application Data\Nyofenq\ylcyiw.exe
PRC - [2007/08/13 04:28:01 | 000,290,517 | ---- | M] (nijwwifh nete yzqkgq zopjnaebv qisurhoarg qmrsz) -- C:\WINDOWS\system32\xoahilho.exe
PRC - [2006/08/21 05:13:52 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) -- C:\WINDOWS\system32\vyuvqoqihy.exe
PRC - [2003/05/08 12:00:58 | 000,049,152 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
PRC - [2002/05/22 12:42:36 | 000,299,008 | ---- | M] (Palm, Inc.) -- C:\Program Files\Handspring\HOTSYNC.EXE
========== Modules (No Company Name) ==========
MOD - [2014/03/26 15:35:39 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\2e3fdae8546832614633495638bef8d0\System.ServiceProcess.ni.dll
MOD - [2014/03/26 12:29:04 | 009,099,776 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\4c906eb82e6f56aea01b2a7291fab7ea\System.ni.dll
MOD - [2014/03/26 12:28:51 | 014,416,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\4e62d1d9b7dd2c2d14915abb73c22d50\mscorlib.ni.dll
MOD - [2014/03/25 17:13:58 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe
MOD - [2013/03/11 17:06:30 | 001,151,152 | ---- | M] () -- C:\Program Files\AVG SafeGuard toolbar\vprot.exe
MOD - [2013/03/11 17:06:30 | 000,968,880 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
MOD - [2008/12/20 07:50:34 | 002,656,528 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
MOD - [2008/12/20 07:46:58 | 000,558,864 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2006/11/01 20:48:02 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\DOCUME~1\kakdh\LOCALS~1\Temp\019529~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -- (0195291294167578mcinstcleanup)
SRV - [2014/03/12 11:36:48 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/20 08:40:02 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/12/28 01:39:31 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\zimurusa.exe -- (SecurityCenterServer2057864769)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/20 16:30:00 | 000,577,088 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe -- (EpsonCustomerParticipation)
SRV - [2013/09/19 15:33:27 | 000,304,660 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\asbiqyofm.exe -- (SecurityCenterServer2939595160)
SRV - [2013/06/28 17:48:04 | 000,014,624 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2013/04/18 16:03:58 | 000,302,250 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\armuxah.exe -- (SecurityCenterServer4215045626)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/03/11 17:06:30 | 000,968,880 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe -- (vToolbarUpdater14.2.0)
SRV - [2012/10/25 04:45:09 | 000,302,157 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\qiepcyv.exe -- (SecurityCenterServer2469540606)
SRV - [2012/09/19 00:38:32 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\ohibihv.exe -- (SecurityCenterServer3159990460)
SRV - [2012/05/17 00:00:00 | 000,126,128 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\WINDOWS\system32\escsvc.exe -- (EpsonScanSvc)
SRV - [2012/04/25 09:38:57 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\otaty.exe -- (SecurityCenterServer2646265564)
SRV - [2010/11/17 14:49:25 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\bobiwynege.exe -- (SecurityCenterServer1779182087)
SRV - [2010/08/22 18:13:25 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\udobso.exe -- (SecurityCenterServer1137301153)
SRV - [2010/03/28 12:11:47 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\girixayrug.exe -- (SecurityCenterServer1212904390)
SRV - [2010/01/09 06:24:57 | 000,302,250 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\ocgigihe.exe -- (SecurityCenterServer1882285819)
SRV - [2009/10/09 09:07:22 | 000,493,248 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2009/03/07 14:38:59 | 000,658,432 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/12/16 21:59:50 | 000,150,040 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/11/08 17:00:02 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\avvyacol.exe -- (SecurityCenterServer3068895032)
SRV - [2008/04/06 13:15:16 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\bietug.exe -- (SecurityCenterServer2654536800)
SRV - [2008/01/16 02:57:01 | 000,302,182 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\obisi.exe -- (SecurityCenterServer940684720)
SRV - [2007/08/13 04:28:01 | 000,290,517 | ---- | M] (nijwwifh nete yzqkgq zopjnaebv qisurhoarg qmrsz) [Auto | Running] -- C:\WINDOWS\system32\xoahilho.exe -- (SecurityCenterServer3395936529)
SRV - [2006/08/21 05:13:52 | 000,302,280 | ---- | M] (JinMirumkan S.O.L.) [Auto | Running] -- C:\WINDOWS\system32\vyuvqoqihy.exe -- (SecurityCenterServer3582828085)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/03/11 17:06:30 | 000,033,112 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2011/05/16 19:01:00 | 000,162,544 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VBoxDrv.sys -- (VBoxDrv)
DRV - [2011/05/16 19:01:00 | 000,122,224 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VBoxNetFlt.sys -- (VBoxNetFlt)
DRV - [2011/05/16 19:01:00 | 000,111,280 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV - [2011/05/16 19:01:00 | 000,044,720 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VBoxUSBMon.sys -- (VBoxUSBMon)
DRV - [2010/07/21 16:52:14 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dc3d.sys -- (dc3d)
DRV - [2009/10/09 08:50:50 | 000,020,152 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vpnva.sys -- (vpnva)
DRV - [2008/12/16 23:02:06 | 000,023,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2008/12/16 23:01:42 | 006,364,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2008/12/16 23:01:20 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2008/12/16 23:00:12 | 000,768,024 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2008/12/16 21:58:54 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2006/10/12 23:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/03 23:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/15 15:37:52 | 000,264,440 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\stac97.sys -- (STAC97)
DRV - [2003/09/26 09:41:12 | 000,044,032 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2003/08/29 04:59:24 | 001,101,696 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMSM.sys -- (BCMModem)
DRV - [2002/05/22 12:42:42 | 000,015,326 | ---- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lds.org/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {57281A5A-CF74-4F0F-A854-E29F449E03A9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{57281A5A-CF74-4F0F-A854-E29F449E03A9}: "URL" = http://www.google.co...f8&oe=utf8&rlz=
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AOL Search"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.co...rud=25-03-2013"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mail.google.com/mail/"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.1.0
FF - prefs.js..extensions.enabledAddons: jqs%40sun.com:1.0
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Documents and Settings\kakdh\Local Settings\Application Data\RobloxVersions\version-27973050fb3b494f\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\kakdh\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/02/20 08:39:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/02/20 08:39:48 | 000,000,000 | ---D | M]
[2009/05/01 11:20:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kakdh\Application Data\Mozilla\Extensions
[2014/03/22 07:16:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kakdh\Application Data\Mozilla\Firefox\Profiles\sniywqtc.default\extensions
[2013/11/19 14:00:10 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Documents and Settings\kakdh\Application Data\Mozilla\Firefox\Profiles\sniywqtc.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2014/02/20 08:39:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/02/20 08:40:03 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/04/09 06:13:45 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/15 13:00:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
O1 HOSTS File: ([2009/10/15 05:41:54 | 000,000,732 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [Agevbaywinlyk] "C:\Documents and Settings\kakdh\Application Data\Okalrak\uffilau.exe" File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui File not found
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Fyiqpiyvza] C:\Documents and Settings\kakdh\Application Data\Ebuvhy\tezoliw.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Geceleyqvaruu] C:\Documents and Settings\kakdh\Application Data\Nyofenq\ylcyiw.exe (nijwwifh nete yzqkgq zopjnaebv qisurhoarg qmrsz)
O4 - HKLM..\Run: [Hihyegvuylunaq] C:\Documents and Settings\kakdh\Application Data\Ofbyazg\urizhom.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Huurur] "C:\Documents and Settings\kakdh\Application Data\Kuwoal\etehyw.exe" File not found
O4 - HKLM..\Run: [Ihyfkotowuwaal] C:\Documents and Settings\kakdh\Application Data\Qywoxyol\egdeqa.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Ikuztidomuadybw] C:\Documents and Settings\kakdh\Application Data\Ahedhe\mynousi.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [Nueknyegvuypytl] C:\Documents and Settings\kakdh\Application Data\Paqedaof\arhookp.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Ofyhihi] C:\Documents and Settings\kakdh\Application Data\Agublicu\amsyfa.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Olywovxiisub] C:\Documents and Settings\kakdh\Application Data\Egelux\danokoa.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Ozxooqbuw] C:\Documents and Settings\kakdh\Application Data\Yhpyse\veofel.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Siuxhoagbeegly] C:\Documents and Settings\kakdh\Application Data\Naefgy\yryhz.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Upkeu] C:\Documents and Settings\kakdh\Application Data\Haufacr\pagaol.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKLM..\Run: [Weviyvdepo] C:\Documents and Settings\kakdh\Application Data\Asguhuec\waihle.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Ybypbe] C:\Documents and Settings\kakdh\Application Data\Opihqo\abbabiu.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Yhgon] C:\Documents and Settings\kakdh\Application Data\Ziakuhe\oqihc.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Ytfyzipera] C:\Documents and Settings\kakdh\Application Data\Vahyhe\ovsuf.exe (JinMirumkan S.O.L.)
O4 - HKLM..\Run: [Ytviypy] "C:\Documents and Settings\kakdh\Application Data\Sevael\zodoet.exe" File not found
O4 - HKCU..\Run: [Agevbaywinlyk] "C:\Documents and Settings\kakdh\Application Data\Okalrak\uffilau.exe" File not found
O4 - HKCU..\Run: [dmnkptqb] C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe ()
O4 - HKCU..\Run: [eegkfjcl] C:\Documents and Settings\kakdh\Local Settings\Application Data\dbjkvtvm.exe ()
O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATILAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\kakdh\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Fyiqpiyvza] C:\Documents and Settings\kakdh\Application Data\Ebuvhy\tezoliw.exe (JinMirumkan S.O.L.)
O4 - HKCU..\Run: [Geceleyqvaruu] C:\Documents and Settings\kakdh\Application Data\Nyofenq\ylcyiw.exe (nijwwifh nete yzqkgq zopjnaebv qisurhoarg qmrsz)
O4 - HKCU..\Run: [lkjbtbxt] C:\Documents and Settings\kakdh\Local Settings\Application Data\kwpbikxr.exe ()
O4 - HKCU..\Run: [odqhwkgq] C:\Documents and Settings\kakdh\Local Settings\Application Data\qqdesrpq.exe ()
O4 - HKCU..\Run: [Olywovxiisub] C:\Documents and Settings\kakdh\Application Data\Egelux\danokoa.exe (JinMirumkan S.O.L.)
O4 - HKCU..\Run: [Ozxooqbuw] C:\Documents and Settings\kakdh\Application Data\Yhpyse\veofel.exe (JinMirumkan S.O.L.)
O4 - HKCU..\Run: [qocwkucb] C:\Documents and Settings\kakdh\Local Settings\Application Data\ecokaboc.exe ()
O4 - HKCU..\Run: [Siuxhoagbeegly] C:\Documents and Settings\kakdh\Application Data\Naefgy\yryhz.exe (JinMirumkan S.O.L.)
O4 - HKCU..\Run: [ueqvpnuh] C:\Documents and Settings\kakdh\Local Settings\Application Data\muvlcrsr.exe ()
O4 - HKCU..\Run: [Weviyvdepo] C:\Documents and Settings\kakdh\Application Data\Asguhuec\waihle.exe (JinMirumkan S.O.L.)
O4 - HKCU..\Run: [Ybypbe] C:\Documents and Settings\kakdh\Application Data\Opihqo\abbabiu.exe (JinMirumkan S.O.L.)
O4 - HKCU..\Run: [Ytviypy] "C:\Documents and Settings\kakdh\Application Data\Sevael\zodoet.exe" File not found
O4 - Startup: C:\Documents and Settings\kakdh\Start Menu\Programs\Startup\HotSync Manager.LNK = C:\Program Files\Handspring\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O15 - HKLM\..Trusted Domains: asu.edu ([*.sharepoint] * in Local intranet)
O15 - HKLM\..Trusted Domains: asu.edu ([sharepoint] * in Local intranet)
O15 - HKCU\..Trusted Domains: advancedmd.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: advancedmd.com ([]https in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1270776591171 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1353174351265 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 vpnweb.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = asurite.ad.asu.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C09B598-69C5-447C-AF2F-EB961FB9D01B}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{36870819-2122-4B94-9A56-FF75243FCC28}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\junomsg {C4D10830-379D-11d4-9B2D-00C04F1579A5} - C:\Program Files\Juno\bin\jmsgpph.dll (Juno Online Services, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\ckpNotify: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\kakdh\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kakdh\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/31 16:36:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/09/16 19:19:36 | 000,000,000 | ---D | M] - F:\AutoCAD -- [ FAT32 ]
O32 - AutoRun File - [2000/02/01 13:39:20 | 000,035,980 | ---- | M] () - F:\Autobiog.rtf -- [ FAT32 ]
O33 - MountPoints2\{045e6739-ad16-11de-acb9-000f1f162171}\Shell\AutoRun\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{045e6739-ad16-11de-acb9-000f1f162171}\Shell\open\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{2f0f0bf6-ed36-11db-aad0-000f1f162171}\Shell\AutoRun\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{2f0f0bf6-ed36-11db-aad0-000f1f162171}\Shell\open\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{4760a5af-4bb4-11de-ac01-000f1f162171}\Shell\AutoRun\command - "" = ie.exe
O33 - MountPoints2\{4760a5af-4bb4-11de-ac01-000f1f162171}\Shell\explore\Command - "" = ie.exe
O33 - MountPoints2\{4760a5af-4bb4-11de-ac01-000f1f162171}\Shell\open\Command - "" = ie.exe
O33 - MountPoints2\{b9dbfc6e-4ccf-11e1-9468-000f1f162171}\Shell - "" = AutoRun
O33 - MountPoints2\{b9dbfc6e-4ccf-11e1-9468-000f1f162171}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9dbfc6e-4ccf-11e1-9468-000f1f162171}\Shell\AutoRun\command - "" = E:\videoconvert.exe
O33 - MountPoints2\{ee47f150-dc79-11df-afd8-000f1f162171}\Shell\AutoRun\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{ee47f150-dc79-11df-afd8-000f1f162171}\Shell\open\command - "" = BUBAVII///znaqwerty.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/03/29 11:50:32 | 000,290,517 | ---- | C] (nijwwifh nete yzqkgq zopjnaebv qisurhoarg qmrsz) -- C:\WINDOWS\System32\xoahilho.exe
[2014/03/29 11:50:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Nyofenq
[2014/03/29 03:40:14 | 000,302,182 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\otaty.exe
[2014/03/29 03:39:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Qywoxyol
[2014/03/28 23:41:02 | 000,302,182 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\girixayrug.exe
[2014/03/28 23:40:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Agublicu
[2014/03/28 19:41:05 | 000,302,182 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\avvyacol.exe
[2014/03/28 19:41:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ziakuhe
[2014/03/28 15:44:35 | 000,302,182 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\zimurusa.exe
[2014/03/28 15:44:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Haufacr
[2014/03/28 11:47:00 | 000,302,182 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\obisi.exe
[2014/03/28 11:46:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Asguhuec
[2014/03/28 07:49:18 | 000,302,250 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\armuxah.exe
[2014/03/28 07:49:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Vahyhe
[2014/03/28 03:45:08 | 000,302,250 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\ocgigihe.exe
[2014/03/28 03:45:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Egelux
[2014/03/28 01:33:03 | 000,302,280 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\ohibihv.exe
[2014/03/28 01:32:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ofbyazg
[2014/03/27 19:41:53 | 000,302,280 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\bobiwynege.exe
[2014/03/27 19:41:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ahedhe
[2014/03/27 15:47:08 | 000,302,280 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\bietug.exe
[2014/03/27 15:47:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Paqedaof
[2014/03/27 11:38:50 | 000,302,280 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\udobso.exe
[2014/03/27 11:38:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Opihqo
[2014/03/27 07:43:49 | 000,302,280 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\vyuvqoqihy.exe
[2014/03/27 07:43:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Naefgy
[2014/03/27 03:50:45 | 000,304,660 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\asbiqyofm.exe
[2014/03/27 03:50:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ebuvhy
[2014/03/26 23:39:11 | 000,302,157 | ---- | C] (JinMirumkan S.O.L.) -- C:\WINDOWS\System32\qiepcyv.exe
[2014/03/26 23:39:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Yhpyse
[2014/03/26 19:40:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Kuwoal
[2014/03/26 19:40:24 | 000,000,000 | ---D | C] -- C:\Program Files\WinDirStat
[2014/03/26 19:40:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Start Menu\Programs\WinDirStat
[2014/03/26 19:33:50 | 000,000,000 | ---D | C] -- C:\Program Files\WhatsRunning
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2014/03/26 16:18:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Okalrak
[2014/03/26 12:04:30 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014/03/26 11:16:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Sevael
[2014/03/17 17:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Local Settings\Application Data\IsolatedStorage
[2014/03/17 17:27:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Local Settings\Application Data\Intuit
[2014/03/17 17:21:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Intuit
[2014/03/17 17:17:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2013
[2014/03/17 17:15:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intuit
[2014/03/17 17:12:39 | 000,000,000 | ---D | C] -- C:\Program Files\TurboTax
[2014/03/07 16:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intuit
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/03/29 13:37:18 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\dbjkvtvm.exe
[2014/03/29 13:36:16 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/03/29 13:34:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/03/29 13:34:35 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/03/29 13:33:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/03/29 13:33:08 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2014/03/29 13:33:05 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2014/03/29 13:08:15 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/03/29 13:01:08 | 000,000,917 | ---- | M] () -- C:\WINDOWS\tasks\EPSON XP-410 Series Update {2A9EB505-CA98-4B9A-B77F-F777335D9DF2}.job
[2014/03/29 13:01:08 | 000,000,731 | ---- | M] () -- C:\WINDOWS\tasks\EPSON XP-410 Series Invitation {2A9EB505-CA98-4B9A-B77F-F777335D9DF2}.job
[2014/03/29 13:01:07 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 940684720.job
[2014/03/29 13:01:07 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 4215045626.job
[2014/03/29 13:01:03 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 3582828085.job
[2014/03/29 13:00:59 | 000,000,874 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 3395936529.job
[2014/03/29 13:00:58 | 000,000,876 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 3159990460.job
[2014/03/29 13:00:42 | 000,000,872 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 3068895032.job
[2014/03/29 13:00:40 | 000,000,872 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 2939595160.job
[2014/03/29 13:00:38 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 2654536800.job
[2014/03/29 13:00:37 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 2646265564.job
[2014/03/29 13:00:34 | 000,000,874 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 2057864769.job
[2014/03/29 13:00:34 | 000,000,870 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 2469540606.job
[2014/03/29 13:00:26 | 000,000,872 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 1882285819.job
[2014/03/29 13:00:24 | 000,000,872 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 1779182087.job
[2014/03/29 13:00:23 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 1212904390.job
[2014/03/29 13:00:15 | 000,000,872 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 1137301153.job
[2014/03/29 12:28:06 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1864253520-1647712531-16515117-1510UA.job
[2014/03/29 11:33:40 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2014/03/28 21:28:18 | 000,000,976 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1864253520-1647712531-16515117-1510Core.job
[2014/03/28 20:58:10 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2014/03/28 14:48:45 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qqdesrpq.exe
[2014/03/27 14:27:01 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\muvlcrsr.exe
[2014/03/26 19:40:24 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\kakdh\Desktop\WinDirStat.lnk
[2014/03/26 16:18:08 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\kwpbikxr.exe
[2014/03/26 15:27:05 | 000,342,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/03/26 12:25:32 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2014/03/25 18:31:08 | 000,000,746 | ---- | M] () -- C:\Documents and Settings\kakdh\jobq.dat
[2014/03/25 17:13:58 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe
[2014/03/25 17:12:47 | 000,012,326 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qdvoehob
[2014/03/25 17:11:46 | 000,068,465 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\cbspcbvj
[2014/03/25 17:10:44 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\kakdh\Application Data\SharedSettings.ccs
[2014/03/25 17:05:06 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ecokaboc.exe
[2014/03/25 14:54:23 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\kakdh\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003 (2).lnk
[2014/03/21 16:31:08 | 000,032,768 | ---- | M] () -- C:\Documents and Settings\kakdh\My Documents\T-Shirt.sig
[2014/03/19 08:50:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2014/03/17 20:12:14 | 000,000,286 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2014/03/17 17:17:15 | 000,001,880 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2013.lnk
[2014/03/17 17:09:45 | 000,873,244 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2014/03/17 17:09:45 | 000,238,762 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2014/03/17 14:52:10 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\kakdh\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2014/03/12 11:36:47 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2014/03/12 11:36:47 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/03/29 13:37:18 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\dbjkvtvm.exe
[2014/03/29 11:50:31 | 000,000,874 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 3395936529.job
[2014/03/29 03:40:01 | 000,000,878 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 2646265564.job
[2014/03/28 23:40:51 | 000,000,878 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 1212904390.job
[2014/03/28 19:41:01 | 000,000,872 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 3068895032.job
[2014/03/28 15:44:26 | 000,000,874 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 2057864769.job
[2014/03/28 14:48:45 | 000,118,784 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qqdesrpq.exe
[2014/03/28 11:46:58 | 000,000,878 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 940684720.job
[2014/03/28 07:49:14 | 000,000,868 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 4215045626.job
[2014/03/28 03:45:06 | 000,000,872 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 1882285819.job
[2014/03/28 01:32:59 | 000,000,876 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 3159990460.job
[2014/03/27 19:41:52 | 000,000,872 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 1779182087.job
[2014/03/27 15:47:06 | 000,000,880 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 2654536800.job
[2014/03/27 14:27:00 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\muvlcrsr.exe
[2014/03/27 11:38:49 | 000,000,872 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 1137301153.job
[2014/03/27 07:43:48 | 000,000,868 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 3582828085.job
[2014/03/27 03:50:41 | 000,000,872 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 2939595160.job
[2014/03/26 23:39:08 | 000,000,870 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 2469540606.job
[2014/03/26 19:40:24 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\kakdh\Desktop\WinDirStat.lnk
[2014/03/26 16:18:08 | 000,118,784 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\kwpbikxr.exe
[2014/03/25 17:13:58 | 000,118,784 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe
[2014/03/25 17:12:47 | 000,012,326 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qdvoehob
[2014/03/25 17:11:46 | 000,068,465 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\cbspcbvj
[2014/03/25 17:10:44 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\kakdh\Application Data\SharedSettings.ccs
[2014/03/25 17:06:34 | 002,388,348 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1864253520-1647712531-16515117-1510-0.dat
[2014/03/25 17:06:22 | 000,365,578 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2014/03/25 17:05:06 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ecokaboc.exe
[2014/03/20 15:16:42 | 000,032,768 | ---- | C] () -- C:\Documents and Settings\kakdh\My Documents\T-Shirt.sig
[2014/03/17 17:27:11 | 000,000,286 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2014/03/17 17:17:15 | 000,001,880 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2013.lnk
[2014/01/01 00:24:19 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/11/14 08:40:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2013/11/08 14:27:12 | 000,000,044 | ---- | C] () -- C:\WINDOWS\XP-410.ini
[2013/09/26 18:07:20 | 000,000,468 | ---- | C] () -- C:\WINDOWS\System32\xscan32.dat
[2013/05/19 17:18:53 | 000,000,060 | ---- | C] () -- C:\WINDOWS\KA.INI
[2010/12/20 20:25:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\kakdh\jagex_runescape_preferences2.dat
[2010/12/20 20:23:25 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\kakdh\jagex_runescape_preferences.dat
[2008/03/16 06:28:38 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/02/04 10:43:18 | 000,045,056 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/30 07:30:30 | 000,038,508 | ---- | C] () -- C:\Documents and Settings\kakdh\Application Data\Microsoft Excel.ADR
[2007/11/10 18:53:14 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\kakdh\jobq.dat
[2006/02/08 09:54:59 | 000,002,146 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
========== ZeroAccess Check ==========
[2006/01/31 17:21:11 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 17:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 17:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >
=== More recent OTL log (2 of 2) ===
OTL logfile created on: 4/2/2014 6:50:44 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\kakdh\Desktop\Tom's Malware Fix
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.21 Mb Total Physical Memory | 694.65 Mb Available Physical Memory | 67.89% Memory free
2.41 Gb Paging File | 1.99 Gb Available in Paging File | 82.69% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 12.50 Gb Free Space | 22.36% Space Free | Partition Type: NTFS
Drive F: | 7.47 Gb Total Space | 3.19 Gb Free Space | 42.74% Space Free | Partition Type: FAT32
Computer Name: AIS11ZGY41 | User Name: kakdh | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/03/29 12:24:06 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kakdh\Desktop\Tom's Malware Fix\OTL.exe
PRC - [2013/09/26 00:15:27 | 000,281,769 | ---- | M] (qjnci zuqwkhe sril ntgjeuvyqt) -- C:\Documents and Settings\kakdh\Application Data\Soomasat\wiacy.exe
PRC - [2013/09/20 16:30:00 | 000,577,088 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
PRC - [2013/06/28 17:48:04 | 000,014,624 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2013/05/27 12:43:36 | 000,282,282 | ---- | M] (diistfzs tmtnk ugsrh ktdxdka) -- C:\Documents and Settings\kakdh\Application Data\Ydtuawu\fedyaw.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/03/25 12:29:18 | 001,752,992 | ---- | M] (Bleeping Computer, LLC) -- C:\Documents and Settings\kakdh\Desktop\Tom's Malware Fix\rkill.com
PRC - [2013/01/24 01:00:02 | 000,260,160 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATILAE.EXE
PRC - [2012/07/31 11:16:30 | 001,057,920 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
PRC - [2012/05/17 00:00:00 | 000,126,128 | ---- | M] (Seiko Epson Corporation) -- C:\WINDOWS\system32\escsvc.exe
PRC - [2012/05/10 17:27:38 | 000,287,808 | ---- | M] (yoxvgpkqpl lhokho) -- C:\Documents and Settings\kakdh\Application Data\Egpubau\ylgyadg.exe
PRC - [2011/08/12 20:41:33 | 000,284,713 | ---- | M] (zlma) -- C:\Documents and Settings\kakdh\Application Data\Lioqukov\ywacyxr.exe
PRC - [2009/10/09 09:07:22 | 000,493,248 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
PRC - [2008/12/20 07:50:34 | 002,656,528 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2008/12/20 07:46:58 | 000,558,864 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2008/12/16 21:59:50 | 000,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/13 17:12:14 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2003/05/08 12:00:58 | 000,049,152 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
PRC - [2002/05/22 12:42:36 | 000,299,008 | ---- | M] (Palm, Inc.) -- C:\Program Files\Handspring\HOTSYNC.EXE
========== Modules (No Company Name) ==========
MOD - [2014/03/26 15:35:39 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\2e3fdae8546832614633495638bef8d0\System.ServiceProcess.ni.dll
MOD - [2014/03/26 12:29:04 | 009,099,776 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\4c906eb82e6f56aea01b2a7291fab7ea\System.ni.dll
MOD - [2014/03/26 12:28:51 | 014,416,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\4e62d1d9b7dd2c2d14915abb73c22d50\mscorlib.ni.dll
MOD - [2008/12/20 07:50:34 | 002,656,528 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
MOD - [2008/12/20 07:46:58 | 000,558,864 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\DOCUME~1\kakdh\LOCALS~1\Temp\019529~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -- (0195291294167578mcinstcleanup)
SRV - [2014/03/12 11:36:48 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/20 08:40:02 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/20 16:30:00 | 000,577,088 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe -- (EpsonCustomerParticipation)
SRV - [2013/06/28 17:48:04 | 000,014,624 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/05/17 00:00:00 | 000,126,128 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\WINDOWS\system32\escsvc.exe -- (EpsonScanSvc)
SRV - [2009/11/06 08:48:43 | 000,282,303 | ---- | M] (kyuht) [Auto | Stopped] -- C:\WINDOWS\system32\asduuxwyom.exe -- (SecurityCenterServer3525658166)
SRV - [2009/10/09 09:07:22 | 000,493,248 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2009/03/07 14:38:59 | 000,658,432 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/12/16 21:59:50 | 000,150,040 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/03/11 17:06:30 | 000,033,112 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2011/05/16 19:01:00 | 000,162,544 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VBoxDrv.sys -- (VBoxDrv)
DRV - [2011/05/16 19:01:00 | 000,122,224 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VBoxNetFlt.sys -- (VBoxNetFlt)
DRV - [2011/05/16 19:01:00 | 000,111,280 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV - [2011/05/16 19:01:00 | 000,044,720 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VBoxUSBMon.sys -- (VBoxUSBMon)
DRV - [2010/07/21 16:52:14 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dc3d.sys -- (dc3d)
DRV - [2009/10/09 08:50:50 | 000,020,152 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vpnva.sys -- (vpnva)
DRV - [2008/12/16 23:02:06 | 000,023,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2008/12/16 23:01:42 | 006,364,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2008/12/16 23:01:20 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2008/12/16 23:00:12 | 000,768,024 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2008/12/16 21:58:54 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2006/10/12 23:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/03 23:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/15 15:37:52 | 000,264,440 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\stac97.sys -- (STAC97)
DRV - [2003/09/26 09:41:12 | 000,044,032 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2003/08/29 04:59:24 | 001,101,696 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMSM.sys -- (BCMModem)
DRV - [2002/05/22 12:42:42 | 000,015,326 | ---- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lds.org/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {57281A5A-CF74-4F0F-A854-E29F449E03A9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{57281A5A-CF74-4F0F-A854-E29F449E03A9}: "URL" = http://www.google.co...f8&oe=utf8&rlz=
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AOL Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mail.google.com/mail/"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.1.0
FF - prefs.js..extensions.enabledAddons: jqs%40sun.com:1.0
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Documents and Settings\kakdh\Local Settings\Application Data\RobloxVersions\version-27973050fb3b494f\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\kakdh\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/02/20 08:39:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/02/20 08:39:48 | 000,000,000 | ---D | M]
[2009/05/01 11:20:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kakdh\Application Data\Mozilla\Extensions
[2014/03/22 07:16:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kakdh\Application Data\Mozilla\Firefox\Profiles\sniywqtc.default\extensions
[2013/11/19 14:00:10 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Documents and Settings\kakdh\Application Data\Mozilla\Firefox\Profiles\sniywqtc.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2014/02/20 08:39:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/02/20 08:40:03 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/04/09 06:13:45 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/15 13:00:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
O1 HOSTS File: ([2009/10/15 05:41:54 | 000,000,732 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
O4 - HKLM..\Run: [Agevbaywinlyk] "C:\Documents and Settings\kakdh\Application Data\Okalrak\uffilau.exe" File not found
O4 - HKLM..\Run: [Apgeewe] C:\Documents and Settings\kakdh\Application Data\Hypoufby\qizyav.exe (yoxvgpkqpl lhokho)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui File not found
O4 - HKLM..\Run: [Azyrweigqyzuilg] C:\Documents and Settings\kakdh\Application Data\Iqottaf\bexyra.exe (zlma)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Ezenabzoviyrewd] C:\Documents and Settings\kakdh\Application Data\Unlifaev\xaokwe.exe (diistfzs tmtnk ugsrh ktdxdka)
O4 - HKLM..\Run: [Fyiqpiyvza] "C:\Documents and Settings\kakdh\Application Data\Ebuvhy\tezoliw.exe" File not found
O4 - HKLM..\Run: [Hihyegvuylunaq] "C:\Documents and Settings\kakdh\Application Data\Ofbyazg\urizhom.exe" File not found
O4 - HKLM..\Run: [Huurur] "C:\Documents and Settings\kakdh\Application Data\Kuwoal\etehyw.exe" File not found
O4 - HKLM..\Run: [Ihyfkotowuwaal] "C:\Documents and Settings\kakdh\Application Data\Qywoxyol\egdeqa.exe" File not found
O4 - HKLM..\Run: [Ikuztidomuadybw] "C:\Documents and Settings\kakdh\Application Data\Ahedhe\mynousi.exe" File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [Myozysfuylywpu] C:\Documents and Settings\kakdh\Application Data\Zaokvuib\xehek.exe (diistfzs tmtnk ugsrh ktdxdka)
O4 - HKLM..\Run: [Nueknyegvuypytl] "C:\Documents and Settings\kakdh\Application Data\Paqedaof\arhookp.exe" File not found
O4 - HKLM..\Run: [Ofyhihi] "C:\Documents and Settings\kakdh\Application Data\Agublicu\amsyfa.exe" File not found
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Oxasryruar] C:\Documents and Settings\kakdh\Application Data\Ercuir\zogih.exe (kyuht)
O4 - HKLM..\Run: [Souhiqryqikeor] C:\Documents and Settings\kakdh\Application Data\Ydtuawu\fedyaw.exe (diistfzs tmtnk ugsrh ktdxdka)
O4 - HKLM..\Run: [Upkeu] "C:\Documents and Settings\kakdh\Application Data\Haufacr\pagaol.exe" File not found
O4 - HKLM..\Run: [Vuhoze] C:\Documents and Settings\kakdh\Application Data\Ytgyqal\ewxeah.exe (zlma)
O4 - HKLM..\Run: [Weeltitaed] C:\Documents and Settings\kakdh\Application Data\Lioqukov\ywacyxr.exe (zlma)
O4 - HKLM..\Run: [Wyomeweze] C:\Documents and Settings\kakdh\Application Data\Egpubau\ylgyadg.exe (yoxvgpkqpl lhokho)
O4 - HKLM..\Run: [Ybypbe] "C:\Documents and Settings\kakdh\Application Data\Opihqo\abbabiu.exe" File not found
O4 - HKLM..\Run: [Yhgon] "C:\Documents and Settings\kakdh\Application Data\Ziakuhe\oqihc.exe" File not found
O4 - HKLM..\Run: [Ytfyzipera] "C:\Documents and Settings\kakdh\Application Data\Vahyhe\ovsuf.exe" File not found
O4 - HKLM..\Run: [Ytviypy] "C:\Documents and Settings\kakdh\Application Data\Sevael\zodoet.exe" File not found
O4 - HKLM..\Run: [Yzywxoyvimbuni] C:\Documents and Settings\kakdh\Application Data\Soomasat\wiacy.exe (qjnci zuqwkhe sril ntgjeuvyqt)
O4 - HKCU..\Run: [Agevbaywinlyk] "C:\Documents and Settings\kakdh\Application Data\Okalrak\uffilau.exe" File not found
O4 - HKCU..\Run: [Apgeewe] C:\Documents and Settings\kakdh\Application Data\Hypoufby\qizyav.exe (yoxvgpkqpl lhokho)
O4 - HKCU..\Run: [Azyrweigqyzuilg] C:\Documents and Settings\kakdh\Application Data\Iqottaf\bexyra.exe (zlma)
O4 - HKCU..\Run: [dmnkptqb] C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe ()
O4 - HKCU..\Run: [eegkfjcl] C:\Documents and Settings\kakdh\Local Settings\Application Data\dbjkvtvm.exe ()
O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATILAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Ezenabzoviyrewd] C:\Documents and Settings\kakdh\Application Data\Unlifaev\xaokwe.exe (diistfzs tmtnk ugsrh ktdxdka)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\kakdh\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Fyiqpiyvza] "C:\Documents and Settings\kakdh\Application Data\Ebuvhy\tezoliw.exe" File not found
O4 - HKCU..\Run: [grvluutr] C:\Documents and Settings\kakdh\Local Settings\Application Data\gfnmjasv.exe ()
O4 - HKCU..\Run: [krhfxrjj] C:\Documents and Settings\kakdh\Local Settings\Application Data\mppkbvon.exe ()
O4 - HKCU..\Run: [lkjbtbxt] C:\Documents and Settings\kakdh\Local Settings\Application Data\kwpbikxr.exe ()
O4 - HKCU..\Run: [odqhwkgq] C:\Documents and Settings\kakdh\Local Settings\Application Data\qqdesrpq.exe ()
O4 - HKCU..\Run: [qocwkucb] C:\Documents and Settings\kakdh\Local Settings\Application Data\ecokaboc.exe ()
O4 - HKCU..\Run: [Souhiqryqikeor] C:\Documents and Settings\kakdh\Application Data\Ydtuawu\fedyaw.exe (diistfzs tmtnk ugsrh ktdxdka)
O4 - HKCU..\Run: [tvcqvjws] C:\Documents and Settings\kakdh\Local Settings\Application Data\nmcjfnuf.exe ()
O4 - HKCU..\Run: [ucklrrnp] C:\Documents and Settings\kakdh\Local Settings\Application Data\iremshnq.exe ()
O4 - HKCU..\Run: [ueqvpnuh] C:\Documents and Settings\kakdh\Local Settings\Application Data\muvlcrsr.exe ()
O4 - HKCU..\Run: [umfantfu] C:\Documents and Settings\kakdh\Local Settings\Application Data\vkknekdd.exe ()
O4 - HKCU..\Run: [Vuhoze] C:\Documents and Settings\kakdh\Application Data\Ytgyqal\ewxeah.exe (zlma)
O4 - HKCU..\Run: [Weeltitaed] C:\Documents and Settings\kakdh\Application Data\Lioqukov\ywacyxr.exe (zlma)
O4 - HKCU..\Run: [Wyomeweze] C:\Documents and Settings\kakdh\Application Data\Egpubau\ylgyadg.exe (yoxvgpkqpl lhokho)
O4 - HKCU..\Run: [Ybypbe] "C:\Documents and Settings\kakdh\Application Data\Opihqo\abbabiu.exe" File not found
O4 - HKCU..\Run: [Ytviypy] "C:\Documents and Settings\kakdh\Application Data\Sevael\zodoet.exe" File not found
O4 - HKCU..\Run: [Yzywxoyvimbuni] C:\Documents and Settings\kakdh\Application Data\Soomasat\wiacy.exe (qjnci zuqwkhe sril ntgjeuvyqt)
O4 - Startup: C:\Documents and Settings\kakdh\Start Menu\Programs\Startup\HotSync Manager.LNK = C:\Program Files\Handspring\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O15 - HKLM\..Trusted Domains: asu.edu ([*.sharepoint] * in Local intranet)
O15 - HKLM\..Trusted Domains: asu.edu ([sharepoint] * in Local intranet)
O15 - HKCU\..Trusted Domains: advancedmd.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: advancedmd.com ([]https in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1270776591171 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1353174351265 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 vpnweb.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = asurite.ad.asu.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C09B598-69C5-447C-AF2F-EB961FB9D01B}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{36870819-2122-4B94-9A56-FF75243FCC28}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\junomsg {C4D10830-379D-11d4-9B2D-00C04F1579A5} - C:\Program Files\Juno\bin\jmsgpph.dll (Juno Online Services, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\ckpNotify: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\kakdh\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kakdh\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/31 16:36:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/09/16 19:19:36 | 000,000,000 | ---D | M] - F:\AutoCAD -- [ FAT32 ]
O32 - AutoRun File - [2000/02/01 13:39:20 | 000,035,980 | ---- | M] () - F:\Autobiog.rtf -- [ FAT32 ]
O33 - MountPoints2\{045e6739-ad16-11de-acb9-000f1f162171}\Shell\AutoRun\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{045e6739-ad16-11de-acb9-000f1f162171}\Shell\open\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{2f0f0bf6-ed36-11db-aad0-000f1f162171}\Shell\AutoRun\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{2f0f0bf6-ed36-11db-aad0-000f1f162171}\Shell\open\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{4760a5af-4bb4-11de-ac01-000f1f162171}\Shell\AutoRun\command - "" = ie.exe
O33 - MountPoints2\{4760a5af-4bb4-11de-ac01-000f1f162171}\Shell\explore\Command - "" = ie.exe
O33 - MountPoints2\{4760a5af-4bb4-11de-ac01-000f1f162171}\Shell\open\Command - "" = ie.exe
O33 - MountPoints2\{b9dbfc6e-4ccf-11e1-9468-000f1f162171}\Shell - "" = AutoRun
O33 - MountPoints2\{b9dbfc6e-4ccf-11e1-9468-000f1f162171}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9dbfc6e-4ccf-11e1-9468-000f1f162171}\Shell\AutoRun\command - "" = E:\videoconvert.exe
O33 - MountPoints2\{ee47f150-dc79-11df-afd8-000f1f162171}\Shell\AutoRun\command - "" = BUBAVII///znaqwerty.exe
O33 - MountPoints2\{ee47f150-dc79-11df-afd8-000f1f162171}\Shell\open\command - "" = BUBAVII///znaqwerty.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/04/02 17:52:41 | 000,282,303 | ---- | C] (kyuht) -- C:\WINDOWS\System32\asduuxwyom.exe
[2014/04/02 17:52:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ercuir
[2014/04/02 03:40:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Soomasat
[2014/04/01 23:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Zaokvuib
[2014/04/01 19:46:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Unlifaev
[2014/04/01 15:49:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ydtuawu
[2014/04/01 13:22:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Wadoabx
[2014/04/01 07:44:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Vesole
[2014/04/01 05:55:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Lioqukov
[2014/03/31 19:47:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ytgyqal
[2014/03/31 15:47:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Iqottaf
[2014/03/31 11:41:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Hypoufby
[2014/03/31 07:51:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Egpubau
[2014/03/30 11:49:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Leuskoe
[2014/03/30 03:57:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Agylku
[2014/03/29 23:49:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Ceiweh
[2014/03/29 19:49:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Pawaamf
[2014/03/29 18:42:03 | 000,052,312 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/03/29 17:49:02 | 000,107,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2014/03/29 16:45:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/03/29 15:47:25 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2014/03/29 15:43:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Kusaeb
[2014/03/29 14:55:31 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/03/29 14:53:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Yhpyse
[2014/03/29 14:53:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Nyofenq
[2014/03/29 14:53:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Naefgy
[2014/03/29 14:53:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Egelux
[2014/03/29 14:53:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Asguhuec
[2014/03/26 19:40:24 | 000,000,000 | ---D | C] -- C:\Program Files\WinDirStat
[2014/03/26 19:40:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Start Menu\Programs\WinDirStat
[2014/03/26 19:33:50 | 000,000,000 | ---D | C] -- C:\Program Files\WhatsRunning
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
[2014/03/26 19:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2014/03/26 12:04:30 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014/03/17 17:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Local Settings\Application Data\IsolatedStorage
[2014/03/17 17:27:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Local Settings\Application Data\Intuit
[2014/03/17 17:21:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kakdh\Application Data\Intuit
[2014/03/17 17:17:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2013
[2014/03/17 17:15:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intuit
[2014/03/17 17:12:39 | 000,000,000 | ---D | C] -- C:\Program Files\TurboTax
[2014/03/07 16:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intuit
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/04/02 19:06:04 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/04/02 19:02:41 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Security Center Update - 3525658166.job
[2014/04/02 19:02:29 | 000,000,731 | ---- | M] () -- C:\WINDOWS\tasks\EPSON XP-410 Series Invitation {2A9EB505-CA98-4B9A-B77F-F777335D9DF2}.job
[2014/04/02 19:02:25 | 000,000,917 | ---- | M] () -- C:\WINDOWS\tasks\EPSON XP-410 Series Update {2A9EB505-CA98-4B9A-B77F-F777335D9DF2}.job
[2014/04/02 18:36:01 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/04/02 18:28:31 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1864253520-1647712531-16515117-1510UA.job
[2014/04/02 17:54:27 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\gfnmjasv.exe
[2014/04/02 17:52:35 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\iremshnq.exe
[2014/04/02 17:42:35 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/04/02 17:42:34 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/04/02 17:41:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/04/02 03:06:35 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2014/04/02 00:22:36 | 000,107,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2014/04/01 21:28:03 | 000,000,976 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1864253520-1647712531-16515117-1510Core.job
[2014/04/01 14:39:24 | 000,135,168 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\nmcjfnuf.exe
[2014/04/01 13:10:59 | 000,052,312 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/04/01 13:01:35 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2014/04/01 13:01:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2014/03/31 13:52:42 | 000,126,976 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\mppkbvon.exe
[2014/03/30 13:46:09 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\vkknekdd.exe
[2014/03/29 13:37:18 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\dbjkvtvm.exe
[2014/03/29 11:33:40 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2014/03/28 14:48:45 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qqdesrpq.exe
[2014/03/27 14:27:01 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\muvlcrsr.exe
[2014/03/26 19:40:24 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\kakdh\Desktop\WinDirStat.lnk
[2014/03/26 16:18:08 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\kwpbikxr.exe
[2014/03/26 15:27:05 | 000,342,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/03/26 12:25:32 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2014/03/25 18:31:08 | 000,000,746 | ---- | M] () -- C:\Documents and Settings\kakdh\jobq.dat
[2014/03/25 17:13:58 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe
[2014/03/25 17:12:47 | 000,012,326 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qdvoehob
[2014/03/25 17:11:46 | 000,068,465 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\cbspcbvj
[2014/03/25 17:10:44 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\kakdh\Application Data\SharedSettings.ccs
[2014/03/25 17:05:06 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ecokaboc.exe
[2014/03/25 14:54:23 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\kakdh\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003 (2).lnk
[2014/03/21 16:31:08 | 000,032,768 | ---- | M] () -- C:\Documents and Settings\kakdh\My Documents\T-Shirt.sig
[2014/03/19 08:50:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2014/03/17 20:12:14 | 000,000,286 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2014/03/17 17:17:15 | 000,001,880 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2013.lnk
[2014/03/17 17:09:45 | 000,873,244 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2014/03/17 17:09:45 | 000,238,762 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2014/03/17 14:52:10 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\kakdh\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/04/02 17:54:27 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\gfnmjasv.exe
[2014/04/02 17:52:40 | 000,000,868 | ---- | C] () -- C:\WINDOWS\tasks\Security Center Update - 3525658166.job
[2014/04/02 17:52:35 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\iremshnq.exe
[2014/04/01 14:39:24 | 000,135,168 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\nmcjfnuf.exe
[2014/03/31 13:52:42 | 000,126,976 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\mppkbvon.exe
[2014/03/30 13:46:09 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\vkknekdd.exe
[2014/03/29 13:37:18 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\dbjkvtvm.exe
[2014/03/28 14:48:45 | 000,118,784 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qqdesrpq.exe
[2014/03/27 14:27:00 | 000,122,880 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\muvlcrsr.exe
[2014/03/26 19:40:24 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\kakdh\Desktop\WinDirStat.lnk
[2014/03/26 16:18:08 | 000,118,784 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\kwpbikxr.exe
[2014/03/25 17:13:58 | 000,118,784 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ntjgkghu.exe
[2014/03/25 17:12:47 | 000,012,326 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\qdvoehob
[2014/03/25 17:11:46 | 000,068,465 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\cbspcbvj
[2014/03/25 17:10:44 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\kakdh\Application Data\SharedSettings.ccs
[2014/03/25 17:06:34 | 002,388,348 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1864253520-1647712531-16515117-1510-0.dat
[2014/03/25 17:06:22 | 000,365,578 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2014/03/25 17:05:06 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\ecokaboc.exe
[2014/03/20 15:16:42 | 000,032,768 | ---- | C] () -- C:\Documents and Settings\kakdh\My Documents\T-Shirt.sig
[2014/03/17 17:27:11 | 000,000,286 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2014/03/17 17:17:15 | 000,001,880 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2013.lnk
[2014/01/01 00:24:19 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/11/14 08:40:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2013/11/08 14:27:12 | 000,000,044 | ---- | C] () -- C:\WINDOWS\XP-410.ini
[2013/09/26 18:07:20 | 000,000,468 | ---- | C] () -- C:\WINDOWS\System32\xscan32.dat
[2013/05/19 17:18:53 | 000,000,060 | ---- | C] () -- C:\WINDOWS\KA.INI
[2010/12/20 20:25:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\kakdh\jagex_runescape_preferences2.dat
[2010/12/20 20:23:25 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\kakdh\jagex_runescape_preferences.dat
[2008/03/16 06:28:38 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/02/04 10:43:18 | 000,045,056 | ---- | C] () -- C:\Documents and Settings\kakdh\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/30 07:30:30 | 000,038,508 | ---- | C] () -- C:\Documents and Settings\kakdh\Application Data\Microsoft Excel.ADR
[2007/11/10 18:53:14 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\kakdh\jobq.dat
[2006/02/08 09:54:59 | 000,002,146 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
========== ZeroAccess Check ==========
[2006/01/31 17:21:11 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 17:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 17:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2010/12/25 10:49:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/12/03 17:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bOfCd01522
[2007/08/31 11:02:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2007/08/31 10:53:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2009/10/15 10:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco
[2013/03/11 17:05:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2013/11/08 14:29:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2006/02/03 10:45:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hummingbird
[2010/12/25 10:16:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Network Associates
[2009/03/09 10:49:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2008/06/26 08:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/06/26 08:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2007/09/01 15:50:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2010/05/28 05:24:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transparent
[2009/03/11 19:51:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/11/24 21:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/28 05:24:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
[2009/04/12 12:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2014/03/30 17:13:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Agylku
[2014/03/30 07:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Asguhuec
[2013/07/18 13:52:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Canon
[2014/03/30 17:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Ceiweh
[2011/04/06 20:02:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Cisco
[2012/01/06 11:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Dropbox
[2014/03/30 07:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Egelux
[2014/03/31 07:51:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Egpubau
[2006/02/08 11:37:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Embarcadero
[2013/11/12 11:02:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Epson
[2014/04/02 17:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Ercuir
[2013/03/11 13:21:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Garmin
[2014/03/31 11:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Hypoufby
[2014/03/31 15:47:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Iqottaf
[2014/03/30 07:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Kusaeb
[2009/01/27 18:57:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Leadertech
[2014/03/31 09:03:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Leuskoe
[2014/04/01 05:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Lioqukov
[2014/03/30 07:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Naefgy
[2007/09/01 15:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\NewSoft
[2014/03/30 05:20:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Nyofenq
[2012/09/18 11:57:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\OverDrive
[2014/03/30 17:13:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Pawaamf
[2007/09/01 15:50:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\ScanSoft
[2014/04/02 03:40:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Soomasat
[2011/04/21 10:15:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\SSH
[2012/09/28 08:22:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Transparent
[2013/05/19 18:37:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Unity
[2014/04/01 19:46:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Unlifaev
[2014/04/02 06:15:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Vesole
[2014/04/02 19:44:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Vicywa
[2014/04/02 06:15:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Wadoabx
[2014/04/01 15:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Ydtuawu
[2014/03/30 07:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Yhpyse
[2014/03/31 19:47:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Ytgyqal
[2014/04/01 23:43:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kakdh\Application Data\Zaokvuib
========== Purity Check ==========
< End of report >
Edited by hawstom, 02 April 2014 - 07:57 PM.