Hi,
My computer used to respond quickly to all issued commands and was very reponsive initially. However, lately my computer has dramatically slowed down in responding to inputs such as opening files, opening programs, editing pdf files, editing documents in LaTeX, and etc. The computer freezes and displays a "program not responding" sign almost every now and then.
My computer comes installed with TrendMicro OfficeScan. TrendMicro OfficeScan used to produce pop-ups saying "Bitcoin Trojans" were detected but was unable to remove them. Upon scouring the internet, I had then used RougeKiller and Malwarebytes tool to scan and delete all found infections.
Despite using TrendMicro OfficeScan, and other virus removal tools as mentioned above, I believe my computer is still somehow getting continuously infected and the infection is slowing down the computer. My computer remains to be dramatically slow despite all scanning using virus removal tools. Just recently, Trend Micro OfficeScan again popped up saying that "Mal_Hifrm" virus was found and it continously seems to find some malwares every now and then.
Any help in determining the reason slowing down my computer is greatly appreciated. Thanks a lot for your help.
I have attached the OTL logfile below.
OTL logfile created on: 24/4/2014 7:39:18 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\A0033498\Desktop
Enterprise Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00004809 | Country: Singapore | Language: ENE | Date Format: d/M/yyyy
3.00 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 67.21% Memory free
6.78 Gb Paging File | 4.23 Gb Available in Paging File | 62.37% Paging File free
Paging file location(s): c:\pagefile.sys 1000 4000d:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 225.33 Gb Total Space | 107.66 Gb Free Space | 47.78% Space Free | Partition Type: NTFS
Drive D: | 225.33 Gb Total Space | 40.51 Gb Free Space | 17.98% Space Free | Partition Type: NTFS
Drive H: | 4.00 Mb Total Space | 2.26 Mb Free Space | 56.40% Space Free | Partition Type: NTFS
Drive I: | 1378.64 Gb Total Space | 269.90 Gb Free Space | 19.58% Space Free | Partition Type: NTFS
Drive U: | 4.00 Gb Total Space | 3.99 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
Computer Name: U715025-PC | User Name: a0033498 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/04/24 19:38:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\A0033498\Desktop\OTL.exe
PRC - [2014/02/21 22:04:06 | 000,841,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe
PRC - [2014/01/03 08:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\A0033498\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/11/01 18:30:48 | 010,717,128 | ---- | M] () -- C:\Program Files\TeXstudio\texstudio.exe
PRC - [2013/05/23 19:29:02 | 000,458,904 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
PRC - [2013/05/10 15:57:36 | 000,375,872 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat.exe
PRC - [2013/05/10 00:57:44 | 001,465,920 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files\Adobe\Acrobat 10.0\Acrobat\AcroRd32.exe
PRC - [2013/01/04 10:59:29 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/08/29 03:23:20 | 001,105,744 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
PRC - [2011/08/26 01:52:34 | 001,828,032 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
PRC - [2011/08/26 01:43:18 | 001,900,904 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
PRC - [2011/06/16 16:46:22 | 000,345,616 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
PRC - [2011/03/30 09:12:18 | 000,310,944 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2010/09/25 01:54:32 | 001,786,168 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2010/04/05 14:50:00 | 000,757,064 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WzPreviewer32.exe
PRC - [2010/04/05 14:50:00 | 000,318,792 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WZSRVR32.EXE
PRC - [2009/08/03 13:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/21 14:40:50 | 000,174,616 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\LMS.exe
PRC - [2009/07/14 09:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/14 09:14:28 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
========== Modules (No Company Name) ==========
MOD - [2014/01/03 08:45:04 | 003,558,400 | ---- | M] () -- C:\Users\A0033498\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/11/01 18:30:48 | 010,717,128 | ---- | M] () -- C:\Program Files\TeXstudio\texstudio.exe
MOD - [2013/10/19 07:55:02 | 025,100,288 | ---- | M] () -- C:\Users\A0033498\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013/06/24 18:48:54 | 000,259,072 | ---- | M] () -- C:\Program Files\TeXstudio\liblcms2.dll
MOD - [2013/06/24 18:48:54 | 000,080,896 | ---- | M] () -- C:\Program Files\TeXstudio\libz.dll
MOD - [2013/06/24 18:48:18 | 002,020,352 | ---- | M] () -- C:\Program Files\TeXstudio\libpoppler.dll
MOD - [2013/06/24 18:48:16 | 000,409,600 | ---- | M] () -- C:\Program Files\TeXstudio\libpoppler-qt4.dll
MOD - [2013/06/24 18:48:16 | 000,260,096 | ---- | M] () -- C:\Program Files\TeXstudio\libcurl.dll
MOD - [2013/06/24 18:48:00 | 000,038,912 | ---- | M] () -- C:\Program Files\TeXstudio\libgcc_s_sjlj-1.dll
MOD - [2013/06/24 18:47:22 | 000,473,088 | ---- | M] () -- C:\Program Files\TeXstudio\libfreetype.dll
MOD - [2013/06/24 18:47:22 | 000,318,464 | ---- | M] () -- C:\Program Files\TeXstudio\libtiff3.dll
MOD - [2013/06/24 18:47:10 | 000,199,168 | ---- | M] () -- C:\Program Files\TeXstudio\libjpeg.dll
MOD - [2013/06/24 18:47:06 | 000,153,600 | ---- | M] () -- C:\Program Files\TeXstudio\libpng15.dll
MOD - [2013/06/24 18:47:06 | 000,125,952 | ---- | M] () -- C:\Program Files\TeXstudio\libopenjpeg.dll
MOD - [2013/05/10 15:57:44 | 000,305,728 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 10.0\Acrobat\sqlite.dll
MOD - [2012/07/28 04:51:52 | 006,549,432 | ---- | M] () -- c:\Program Files\Adobe\Acrobat 10.0\Acrobat\authplay.dll
MOD - [2011/07/19 05:04:08 | 000,296,448 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_04.dll
MOD - [2010/04/18 02:09:16 | 000,108,032 | ---- | M] () -- C:\Program Files\TeXstudio\libgcc_s_dw2-1.dll
MOD - [2009/01/11 04:32:40 | 000,011,362 | ---- | M] () -- C:\Program Files\TeXstudio\mingwm10.dll
========== Services (SafeList) ==========
SRV - [2014/04/19 02:38:25 | 000,766,040 | ---- | M] (Webroot) [Auto | Stopped] -- C:\Program Files\Webroot\WRSA.exe -- (WRSVC)
SRV - [2014/02/21 23:04:05 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/06/21 09:53:36 | 000,162,408 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/05/10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/05/06 21:33:45 | 000,408,888 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe -- (AltirisAgentProvider)
SRV - [2013/05/06 21:12:37 | 001,548,088 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe -- (AeXNSClient)
SRV - [2011/10/21 15:08:42 | 000,213,376 | ---- | M] (FileOpen Systems Inc.) [Disabled | Stopped] -- C:\Program Files\FileOpen\Services\FileOpenManagerSvc32.exe -- (FileOpenManagerSvc)
SRV - [2011/08/26 01:52:34 | 001,828,032 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe -- (tmlisten)
SRV - [2011/08/26 01:43:18 | 001,900,904 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe -- (ntrtscan)
SRV - [2011/06/16 16:46:22 | 000,345,616 | ---- | M] (Trend Micro Inc.) [On_Demand | Running] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2011/04/15 12:20:54 | 000,689,680 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe -- (TmProxy)
SRV - [2010/10/01 02:52:50 | 000,067,904 | ---- | M] (Nalpeiron Ltd.) [Disabled | Stopped] -- C:\Windows\System32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2010/07/19 11:18:34 | 000,250,145 | ---- | M] (INCA Internet Co., Ltd.) [Disabled | Stopped] -- C:\Windows\System32\npstartersvc.exe -- (nPStarterSVC)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/07/21 14:40:56 | 002,066,968 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe -- (UNS)
SRV - [2009/07/21 14:40:50 | 000,174,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS)
SRV - [2009/07/14 09:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2007/01/31 04:57:12 | 001,198,080 | ---- | M] (United Devices, Inc.) [Disabled | Stopped] -- C:\Program Files\United Devices\mpagent\MPAGENT.EXE -- (mpagent)
SRV - [2002/10/04 04:02:32 | 000,118,784 | ---- | M] () [Disabled | Stopped] -- C:\Windows\System32\urtclsvc.exe -- (urtclientservice)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Running] -- System32\drivers\WRkrn.sys -- (WRkrn)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\nvhda32v.sys -- (NVHDA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lmimirr.sys -- (lmimirr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt)
DRV - File not found [Kernel | Auto | Stopped] -- -- (adfs)
DRV - [2014/04/24 15:53:57 | 000,107,736 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV - [2013/09/02 15:58:46 | 000,263,072 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2013/08/14 15:24:22 | 000,263,968 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys -- (TmFilter)
DRV - [2013/08/14 15:24:10 | 000,036,128 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys -- (TmPreFilter)
DRV - [2013/08/14 14:53:10 | 001,517,600 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\vsapiNT.sys -- (VSApiNt)
DRV - [2012/02/14 06:08:00 | 000,013,560 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\gfibto.sys -- (gfibto)
DRV - [2011/07/20 01:28:40 | 000,068,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2011/07/20 01:28:40 | 000,059,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2010/12/07 14:58:38 | 000,090,448 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2010/09/22 16:17:32 | 000,015,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpdispm.sys -- (RDPDISPM)
DRV - [2010/07/19 11:18:23 | 000,126,048 | ---- | M] (Kings Information & Network) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\kcrtx86.sys -- (kcrtx86)
DRV - [2010/07/19 11:18:23 | 000,021,432 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\JRSKD24.SYS -- (JRSKD24)
DRV - [2010/07/19 11:18:23 | 000,012,728 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\JRSUKD25.SYS -- (JRSUKD25)
DRV - [2010/05/13 14:55:18 | 000,047,712 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\NPIdsVt.sys -- (NPIDS)
DRV - [2009/11/09 11:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009/07/14 09:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009/07/14 09:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 09:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009/07/14 08:15:00 | 009,788,480 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/07/14 07:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 07:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/14 07:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2009/06/23 13:28:12 | 000,040,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2009/06/22 11:04:24 | 000,202,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {56D72E4E-A828-49B5-B5E4-646D5F8EEC9E}
IE - HKCU\..\SearchScopes\{56D72E4E-A828-49B5-B5E4-646D5F8EEC9E}: "URL" = http://www.google.co...1I7ADFA_enSG496
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {eaea6202-fd19-c776-c433-759de74b7e4d}:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@softforum.com/npKeyPro: C:\Windows\system32\npKeyPro.dll (SoftForum Co., Ltd.)
FF - HKLM\Software\MozillaPlugins\@softforum.com/npxwebplugins: File not found
FF - HKLM\Software\MozillaPlugins\@softforum.com/npxwebplugins_file: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files\Common Files\Wolfram Research\Browser\8.0.4.2615434\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\A0033498\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\A0033498\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/06/06 15:30:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013/06/05 09:01:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/21 17:05:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/05 09:01:22 | 000,000,000 | ---D | M]
[2010/09/23 03:07:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\A0033498\AppData\Roaming\mozilla\Extensions
[2014/04/18 22:15:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions
[2014/02/17 15:10:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions\staged
[2011/05/15 20:04:49 | 000,000,000 | ---D | M] (Zotero) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions\[email protected]
[2011/05/15 20:08:26 | 000,000,000 | ---D | M] (Zotero WinWord Integration) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions\[email protected]
[2013/02/09 00:32:06 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\A0033498\AppData\Roaming\mozilla\firefox\profiles\vwrpn3h1.default\extensions\[email protected]
[2012/06/28 15:31:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/15 00:41:09 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/01/12 16:58:30 | 000,917,816 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2010/01/01 16:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2012/08/18 02:11:40 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - Startup: C:\Users\A0033498\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\A0033498\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\kerberos\parameters: supportedencryptiontypes = 2147483647
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: nus.edu.sg ([]* in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.caminova....le.aspx?lang=en (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.micr...loadManager.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 137.132.0.252 137.132.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = stf.nus.edu.sg
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DAA9E2B3-2338-4640-A43F-3A0CC84B359E}: DhcpNameServer = 137.132.0.252 137.132.0.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/11/11 17:41:58 | 000,000,000 | ---D | M] - I:\autocad-viewer -- [ NTFS ]
O33 - MountPoints2\{23dc31f1-c451-11df-9893-0025110a65b4}\Shell - "" = AutoRun
O33 - MountPoints2\{23dc31f1-c451-11df-9893-0025110a65b4}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{619b8cd6-3baa-11e2-bdb2-0025110a65b4}\Shell - "" = AutoRun
O33 - MountPoints2\{619b8cd6-3baa-11e2-bdb2-0025110a65b4}\Shell\AutoRun\command - "" = G:\INSTALL\READER\ACRORD32.EXE PDF/MAIN.PDF
O33 - MountPoints2\{bd425607-b105-11df-bd45-0025110a65b4}\Shell - "" = AutoRun
O33 - MountPoints2\{bd425607-b105-11df-bd45-0025110a65b4}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/04/24 19:38:45 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\A0033498\Desktop\OTL.exe
[2014/04/20 22:44:49 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Local\CrashDumps
[2014/04/19 02:38:25 | 000,000,000 | ---D | C] -- C:\Program Files\Webroot
[2014/04/19 01:18:26 | 000,000,000 | ---D | C] -- C:\FRST
[2014/04/19 00:56:06 | 000,044,424 | ---- | C] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2014/04/19 00:56:06 | 000,013,560 | ---- | C] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2014/04/19 00:56:03 | 000,000,000 | ---D | C] -- C:\Program Files\VIPRE
[2014/04/19 00:55:53 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Roaming\VIPRE
[2014/04/19 00:55:53 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Local\VIPRE
[2014/04/18 22:26:00 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/04/18 22:25:52 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2014/04/18 21:53:57 | 000,000,000 | ---D | C] -- C:\Users\A0033498\Desktop\RK_Quarantine
[2014/04/12 23:48:31 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/04/12 23:48:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/04/12 23:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/04/12 14:54:08 | 000,000,000 | ---D | C] -- C:\Program Files\Aurora
[2014/04/12 14:40:27 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aurora
[2014/04/12 14:40:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aurora
[1 C:\Users\A0033498\Desktop\*.tmp files -> C:\Users\A0033498\Desktop\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/04/24 19:38:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\A0033498\Desktop\OTL.exe
[2014/04/24 19:09:02 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1086020445-1760312889-1512734326-400438UA.job
[2014/04/24 19:04:08 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/04/24 18:59:02 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/04/24 16:31:07 | 000,057,385 | ---- | M] () -- C:\Users\A0033498\Desktop\11383132255-285973481-ticket.pdf
[2014/04/24 15:53:57 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/04/24 03:59:03 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/04/24 00:37:07 | 000,008,966 | ---- | M] () -- C:\Windows\cfgall.ini
[2014/04/23 23:09:01 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1086020445-1760312889-1512734326-400438Core.job
[2014/04/21 12:34:09 | 000,785,712 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2014/04/21 12:34:09 | 000,736,996 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2014/04/21 12:34:09 | 000,717,682 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/04/21 12:34:09 | 000,458,038 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2014/04/21 12:34:09 | 000,440,440 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2014/04/21 12:34:09 | 000,165,012 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2014/04/21 12:34:09 | 000,164,502 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2014/04/21 12:34:09 | 000,145,288 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/04/21 12:34:09 | 000,143,148 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2014/04/21 12:34:09 | 000,137,914 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2014/04/19 01:14:03 | 000,012,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/04/19 01:14:03 | 000,012,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/04/19 01:07:27 | 000,001,000 | RHS- | M] () -- C:\Users\A0033498\ntuser.pol
[2014/04/19 01:06:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/04/18 21:53:30 | 003,972,608 | ---- | M] () -- C:\Users\A0033498\Desktop\RogueKiller.exe
[2014/04/13 00:32:56 | 003,970,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/04/13 00:16:14 | 000,181,272 | ---- | M] () -- C:\Windows\RegBootClean.exe
[2014/04/12 20:29:43 | 000,000,036 | ---- | M] () -- C:\Users\A0033498\AppData\Local\housecall.guid.cache
[2014/04/12 20:24:26 | 000,332,728 | ---- | M] () -- C:\Users\A0033498\AppData\Local\census.cache
[2014/04/12 20:24:12 | 000,121,676 | ---- | M] () -- C:\Users\A0033498\AppData\Local\ars.cache
[2014/04/12 20:12:02 | 000,000,010 | ---- | M] () -- C:\Users\A0033498\AppData\Local\sponge.last.runtime.cache
[2014/04/12 20:09:13 | 000,000,184 | ---- | M] () -- C:\Windows\hpbafd.ini
[2014/03/31 14:40:12 | 000,596,394 | ---- | M] () -- C:\Users\A0033498\Desktop\Radio-over-fiber systems.pdf
[2014/03/31 14:39:07 | 004,061,224 | ---- | M] () -- C:\Users\A0033498\Desktop\Hybrid Optical-Wireless Access Networks.pdf
[2014/03/31 14:36:43 | 000,734,336 | ---- | M] () -- C:\Users\A0033498\Desktop\Wireless signals transport schemes in fiber wireless systems.pdf
[1 C:\Users\A0033498\Desktop\*.tmp files -> C:\Users\A0033498\Desktop\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/04/24 16:31:07 | 000,057,385 | ---- | C] () -- C:\Users\A0033498\Desktop\11383132255-285973481-ticket.pdf
[2014/04/18 21:53:27 | 003,972,608 | ---- | C] () -- C:\Users\A0033498\Desktop\RogueKiller.exe
[2014/04/12 20:24:26 | 000,332,728 | ---- | C] () -- C:\Users\A0033498\AppData\Local\census.cache
[2014/04/12 20:24:12 | 000,121,676 | ---- | C] () -- C:\Users\A0033498\AppData\Local\ars.cache
[2014/04/12 20:12:02 | 000,000,010 | ---- | C] () -- C:\Users\A0033498\AppData\Local\sponge.last.runtime.cache
[2014/04/12 20:05:19 | 000,000,036 | ---- | C] () -- C:\Users\A0033498\AppData\Local\housecall.guid.cache
[2014/03/31 14:40:12 | 000,596,394 | ---- | C] () -- C:\Users\A0033498\Desktop\Radio-over-fiber systems.pdf
[2014/03/31 14:39:07 | 004,061,224 | ---- | C] () -- C:\Users\A0033498\Desktop\Hybrid Optical-Wireless Access Networks.pdf
[2014/03/31 14:36:43 | 000,734,336 | ---- | C] () -- C:\Users\A0033498\Desktop\Wireless signals transport schemes in fiber wireless systems.pdf
[2014/02/24 14:56:47 | 000,005,472 | ---- | C] () -- C:\Users\A0033498\AppData\Local\recently-used.xbel
[2014/02/22 18:20:32 | 000,000,184 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2014/02/18 00:29:18 | 000,000,086 | ---- | C] () -- C:\Users\A0033498\gsview32.ini
[2013/06/28 10:47:41 | 000,004,096 | -H-- | C] () -- C:\Users\A0033498\AppData\Local\keyfile3.drm
[2013/02/26 10:37:34 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2012/10/18 20:46:01 | 000,004,830 | ---- | C] () -- C:\Users\A0033498\AppData\Roaming\LTspiceIV.ini
[2012/09/25 18:45:35 | 000,000,913 | ---- | C] () -- C:\Windows\MD_MicroDiffs.INI
[2012/09/25 18:45:34 | 000,000,913 | ---- | C] () -- C:\Windows\MD_MacroDiffs.INI
[2012/09/25 18:45:34 | 000,000,817 | ---- | C] () -- C:\Windows\CFX.INI
[2012/09/25 18:45:34 | 000,000,144 | ---- | C] () -- C:\Windows\FifX_v2.INI
[2012/08/16 17:27:13 | 000,000,600 | ---- | C] () -- C:\Users\A0033498\AppData\Local\PUTTY.RND
[2012/07/21 00:11:58 | 000,181,272 | ---- | C] () -- C:\Windows\RegBootClean.exe
[2012/05/29 12:28:06 | 000,180,624 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll
[2012/05/03 09:54:01 | 000,000,600 | ---- | C] () -- C:\Users\A0033498\AppData\Roaming\winscp.rnd
[2011/06/29 10:24:57 | 000,007,602 | ---- | C] () -- C:\Users\A0033498\AppData\Local\Resmon.ResmonCfg
[2010/08/10 15:49:54 | 000,001,000 | RHS- | C] () -- C:\Users\A0033498\ntuser.pol
[2009/11/18 14:49:13 | 000,011,733 | RHS- | C] () -- C:\ProgramData\ntuser.pol
========== ZeroAccess Check ==========
[2009/07/14 12:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 12:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 09:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 09:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/02/18 19:23:54 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\BitComet
[2013/11/27 16:51:43 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/08 13:12:26 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/08/22 11:28:59 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Design Science
[2010/10/12 10:09:36 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Downloaded Installations
[2014/04/23 19:12:45 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Dropbox
[2013/11/29 00:23:33 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\EndNote
[2012/10/08 13:18:33 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Eyes Relax
[2011/12/05 15:21:43 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\FileOpen
[2012/05/29 11:45:12 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Foxit Software
[2014/02/27 12:54:18 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\inkscape
[2012/11/09 11:02:49 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\JAM Software
[2012/08/18 02:09:23 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Juniper Networks
[2013/12/20 09:51:57 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\l2rshell
[2013/10/31 02:06:23 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\LibreOffice
[2010/10/12 10:13:43 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Nitro PDF
[2014/01/29 12:42:03 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Notepad++
[2012/06/27 13:34:57 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\PDF reDirect
[2012/05/29 12:32:12 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\PrimoPDF
[2014/01/11 13:41:34 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Publish or Perish
[2012/09/25 18:41:05 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Softinterface, Inc
[2013/01/02 12:22:22 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\SSH
[2012/09/19 13:03:59 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\System
[2014/04/04 13:04:55 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\texstudio
[2014/04/19 00:55:53 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\VIPRE
[2012/08/13 20:35:26 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Windows Live Writer
[2010/08/15 16:11:22 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Windows SideBar
[2013/10/31 01:30:57 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\WordKutools
[2013/11/23 14:28:29 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\xm1
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:5B811727
@Alternate Data Stream - 128 bytes -> C:\Windows:nlsPreferences
< End of report >
Edited by adai2020, 24 April 2014 - 06:53 AM.