Dear godawgs,
Unfortunately, the OTL fix stopped midway and produced a pop-up error window again. Error window showed:
OTL
Cannot create file C:\users\A0033498\Desktop\cmd.bat.
At the time of the above error, the custom scans/fixes textbox showed the following entries
net config bits start= auto /c
net start bits /c
net stop eventsystem /c
net config eventsystem start= auto /c
net start eventsystem /c
:COMMANDS
[reboot]
No OTL fixes log was found. All other steps ran successfully. The logs are below:
# AdwCleaner v3.205 - Report created 03/05/2014 at 00:27:59
# Updated 28/04/2014 by Xplode
# Operating System : Windows 7 Enterprise (32 bits)
# Username : a0033498 - U715025-PC
# Running from : C:\Users\A0033498\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7600.17267
-\\ Mozilla Firefox v4.0.1 (en-GB)
-\\ Google Chrome v
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=RY_638&co=SG&userid=eaea6202-fd19-c776-c433-759de74b7e4d&searchtype=ds&q={searchTerms}&installDate=16/02/2014
Deleted [Search Provider] : hxxp://www.veoh.com/find/?query={searchTerms}
Deleted [Search Provider] : hxxp://websearch.webisgreat.info/?l=1&q={searchTerms}&pid=2146&r=2014/02/17&hid=17486583733120035179&lg=EN&cc=SG&unqvl=48
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [10008 octets] - [18/04/2014 22:10:18]
AdwCleaner[S0].txt - [8984 octets] - [18/04/2014 22:15:36]
AdwCleaner[R1].txt - [1304 octets] - [18/04/2014 22:34:06]
AdwCleaner[S1].txt - [1304 octets] - [18/04/2014 22:34:33]
AdwCleaner[R2].txt - [1304 octets] - [19/04/2014 02:27:38]
AdwCleaner[R3].txt - [8728 octets] - [02/05/2014 16:27:05]
AdwCleaner[R4].txt - [8263 octets] - [03/05/2014 00:27:32]
AdwCleaner[S2].txt - [2864 octets] - [03/05/2014 00:27:59]
########## EOF - H:\AdwCleaner\AdwCleaner[S2].txt - [2924 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Enterprise x86
Ran by a0033498 on Sat 03/05/2014 at 0:42:11.94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 03/05/2014 at 0:43:40.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Farbar Service Scanner Version: 25-02-2014
Ran by a0033498 (administrator) on 03-05-2014 at 00:48:33
Running from "C:\Users\A0033498\Desktop"
Microsoft Windows 7 Enterprise (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
BITS Service is not running. Checking service configuration:
The start type of BITS service is set to Demand. The default start type is Auto.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.
EventSystem Service is not running. Checking service configuration:
The start type of EventSystem service is set to Disabled. The default start type is Auto.
The ImagePath of EventSystem service is OK.
The ServiceDll of EventSystem service is OK.
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys
[2013-02-14 01:18] - [2013-01-04 12:55] - 1287528 ____A (Microsoft Corporation) BBCEAEFF1FD72A026F827CBB2F4AA8AD
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll
[2012-10-10 15:23] - [2012-06-02 12:45] - 0139264 ____A (Microsoft Corporation) F2FDE6C8DBAAD44CC58D1E07E4AF4EED
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\iphlpsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
OTL logfile created on: 3/5/2014 12:56:07 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\A0033498\Desktop
Enterprise Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00004809 | Country: Singapore | Language: ENE | Date Format: d/M/yyyy
3.00 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 56.92% Memory free
4.95 Gb Paging File | 3.52 Gb Available in Paging File | 71.13% Paging File free
Paging file location(s): c:\pagefile.sys 1000 4000d:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 225.33 Gb Total Space | 113.95 Gb Free Space | 50.57% Space Free | Partition Type: NTFS
Drive D: | 225.33 Gb Total Space | 40.51 Gb Free Space | 17.98% Space Free | Partition Type: NTFS
Drive H: | 4.00 Mb Total Space | 2.20 Mb Free Space | 54.88% Space Free | Partition Type: NTFS
Drive I: | 1378.64 Gb Total Space | 250.37 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
Drive U: | 4.00 Gb Total Space | 3.99 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
Computer Name: U715025-PC | User Name: a0033498 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/05/01 00:30:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\A0033498\Desktop\OTL.exe
PRC - [2014/02/21 22:04:06 | 000,841,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe
PRC - [2014/01/03 08:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\A0033498\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/05/23 19:29:02 | 000,458,904 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
PRC - [2013/01/04 10:59:29 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/08/29 03:23:20 | 001,105,744 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
PRC - [2011/08/26 01:52:34 | 001,828,032 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
PRC - [2011/08/26 01:43:18 | 001,900,904 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
PRC - [2011/06/16 16:46:22 | 000,345,616 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
PRC - [2009/08/03 13:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/21 14:40:50 | 000,174,616 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\LMS.exe
PRC - [2009/07/14 09:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
========== Modules (No Company Name) ==========
MOD - [2014/01/03 08:45:04 | 003,558,400 | ---- | M] () -- C:\Users\A0033498\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/10/19 07:55:02 | 025,100,288 | ---- | M] () -- C:\Users\A0033498\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2011/07/19 05:04:08 | 000,296,448 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_04.dll
========== Services (SafeList) ==========
SRV - [2014/02/21 23:04:05 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/05/10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/05/06 21:33:45 | 000,408,888 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe -- (AltirisAgentProvider)
SRV - [2013/05/06 21:12:37 | 001,548,088 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe -- (AeXNSClient)
SRV - [2011/10/21 15:08:42 | 000,213,376 | ---- | M] (FileOpen Systems Inc.) [Disabled | Stopped] -- C:\Program Files\FileOpen\Services\FileOpenManagerSvc32.exe -- (FileOpenManagerSvc)
SRV - [2011/08/26 01:52:34 | 001,828,032 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe -- (tmlisten)
SRV - [2011/08/26 01:43:18 | 001,900,904 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe -- (ntrtscan)
SRV - [2011/06/16 16:46:22 | 000,345,616 | ---- | M] (Trend Micro Inc.) [On_Demand | Running] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2011/04/15 12:20:54 | 000,689,680 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe -- (TmProxy)
SRV - [2010/10/01 02:52:50 | 000,067,904 | ---- | M] (Nalpeiron Ltd.) [Disabled | Stopped] -- C:\Windows\System32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2010/07/19 11:18:34 | 000,250,145 | ---- | M] (INCA Internet Co., Ltd.) [Disabled | Stopped] -- C:\Windows\System32\npstartersvc.exe -- (nPStarterSVC)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/07/21 14:40:56 | 002,066,968 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe -- (UNS)
SRV - [2009/07/21 14:40:50 | 000,174,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS)
SRV - [2009/07/14 09:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2007/01/31 04:57:12 | 001,198,080 | ---- | M] (United Devices, Inc.) [Disabled | Stopped] -- C:\Program Files\United Devices\mpagent\MPAGENT.EXE -- (mpagent)
SRV - [2002/10/04 04:02:32 | 000,118,784 | ---- | M] () [Disabled | Stopped] -- C:\Windows\System32\urtclsvc.exe -- (urtclientservice)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\nvhda32v.sys -- (NVHDA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lmimirr.sys -- (lmimirr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt)
DRV - File not found [Kernel | Auto | Stopped] -- -- (adfs)
DRV - [2014/04/26 23:24:51 | 000,107,736 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV - [2013/09/02 15:58:46 | 000,263,072 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2013/08/14 15:24:22 | 000,263,968 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys -- (TmFilter)
DRV - [2013/08/14 15:24:10 | 000,036,128 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys -- (TmPreFilter)
DRV - [2013/08/14 14:53:10 | 001,517,600 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Program Files\Trend Micro\OfficeScan Client\vsapiNT.sys -- (VSApiNt)
DRV - [2011/07/20 01:28:40 | 000,068,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2011/07/20 01:28:40 | 000,059,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2010/12/07 14:58:38 | 000,090,448 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2010/09/22 16:17:32 | 000,015,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpdispm.sys -- (RDPDISPM)
DRV - [2010/07/19 11:18:23 | 000,126,048 | ---- | M] (Kings Information & Network) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\kcrtx86.sys -- (kcrtx86)
DRV - [2010/07/19 11:18:23 | 000,021,432 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\JRSKD24.SYS -- (JRSKD24)
DRV - [2010/07/19 11:18:23 | 000,012,728 | ---- | M] (SoftForum Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\JRSUKD25.SYS -- (JRSUKD25)
DRV - [2010/05/13 14:55:18 | 000,047,712 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\NPIdsVt.sys -- (NPIDS)
DRV - [2009/11/09 11:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009/07/14 09:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009/07/14 09:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 09:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009/07/14 08:15:00 | 009,788,480 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/07/14 07:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 07:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/14 07:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2009/06/23 13:28:12 | 000,040,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2009/06/22 11:04:24 | 000,202,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {56D72E4E-A828-49B5-B5E4-646D5F8EEC9E}
IE - HKCU\..\SearchScopes\{56D72E4E-A828-49B5-B5E4-646D5F8EEC9E}: "URL" = http://www.google.co...1I7ADFA_enSG496
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {eaea6202-fd19-c776-c433-759de74b7e4d}:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@softforum.com/npKeyPro: C:\Windows\system32\npKeyPro.dll (SoftForum Co., Ltd.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files\Common Files\Wolfram Research\Browser\8.0.4.2615434\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\A0033498\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\A0033498\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/06/06 15:30:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013/06/05 09:01:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/21 17:05:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/05/01 17:35:47 | 000,000,000 | ---D | M]
[2010/09/23 03:07:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\A0033498\AppData\Roaming\mozilla\Extensions
[2014/05/01 17:35:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions
[2011/05/15 20:04:49 | 000,000,000 | ---D | M] (Zotero) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions\[email protected]
[2011/05/15 20:08:26 | 000,000,000 | ---D | M] (Zotero WinWord Integration) -- C:\Users\A0033498\AppData\Roaming\mozilla\Firefox\Profiles\vwrpn3h1.default\extensions\[email protected]
[2012/06/28 15:31:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/15 00:41:09 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 16:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\A0033498\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012/08/18 02:11:40 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre7\bin\jusched.exe" File not found
O4 - Startup: C:\Users\A0033498\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\A0033498\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\kerberos\parameters: supportedencryptiontypes = 2147483647
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: nus.edu.sg ([]* in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_51)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_51)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 137.132.0.252 137.132.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = stf.nus.edu.sg
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DAA9E2B3-2338-4640-A43F-3A0CC84B359E}: DhcpNameServer = 137.132.0.252 137.132.0.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/11/11 17:41:58 | 000,000,000 | ---D | M] - I:\autocad-viewer -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/05/03 00:33:46 | 001,016,261 | ---- | C] (Thisisu) -- C:\Users\A0033498\Desktop\JRT.exe
[2014/05/02 16:33:34 | 000,000,000 | ---D | C] -- C:\Users\A0033498\Desktop\FRST-OlderVersion
[2014/05/02 16:29:48 | 000,409,600 | ---- | C] (Farbar) -- C:\Users\A0033498\Desktop\FSS.exe
[2014/05/02 16:26:29 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\System32\sqlite3.dll
[2014/05/01 17:35:34 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/05/01 00:30:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\A0033498\Desktop\OTL.exe
[2014/04/29 21:18:27 | 000,000,000 | ---D | C] -- C:\FRST
[2014/04/29 21:09:49 | 001,050,624 | ---- | C] (Farbar) -- C:\Users\A0033498\Desktop\FRST.exe
[2014/04/24 20:41:06 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Local\Skype
[2014/04/24 20:40:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/04/24 20:40:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2014/04/24 20:07:08 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/04/20 22:44:49 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Local\CrashDumps
[2014/04/18 22:26:00 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/04/18 22:25:52 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2014/04/12 23:48:31 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/04/12 23:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/04/12 14:54:08 | 000,000,000 | ---D | C] -- C:\Program Files\Aurora
[2014/04/12 14:40:27 | 000,000,000 | ---D | C] -- C:\Users\A0033498\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aurora
[2014/04/12 14:40:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aurora
[1 C:\Users\A0033498\Desktop\*.tmp files -> C:\Users\A0033498\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/05/03 00:59:31 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/05/03 00:52:01 | 000,012,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/05/03 00:52:01 | 000,012,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/05/03 00:49:19 | 000,785,712 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2014/05/03 00:49:19 | 000,736,996 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2014/05/03 00:49:19 | 000,717,682 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/05/03 00:49:19 | 000,458,038 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2014/05/03 00:49:19 | 000,440,440 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2014/05/03 00:49:19 | 000,165,012 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2014/05/03 00:49:19 | 000,164,502 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2014/05/03 00:49:19 | 000,145,288 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/05/03 00:49:19 | 000,143,148 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2014/05/03 00:49:19 | 000,137,914 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2014/05/03 00:45:15 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/03 00:44:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/05/03 00:33:54 | 001,016,261 | ---- | M] (Thisisu) -- C:\Users\A0033498\Desktop\JRT.exe
[2014/05/03 00:20:36 | 000,001,000 | RHS- | M] () -- C:\Users\A0033498\ntuser.pol
[2014/05/03 00:09:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1086020445-1760312889-1512734326-400438UA.job
[2014/05/03 00:04:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/05/02 23:09:01 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1086020445-1760312889-1512734326-400438Core.job
[2014/05/02 21:10:42 | 000,008,966 | ---- | M] () -- C:\Windows\cfgall.ini
[2014/05/02 16:33:34 | 001,050,624 | ---- | M] (Farbar) -- C:\Users\A0033498\Desktop\FRST.exe
[2014/05/02 16:29:53 | 000,409,600 | ---- | M] (Farbar) -- C:\Users\A0033498\Desktop\FSS.exe
[2014/05/02 16:23:50 | 001,310,621 | ---- | M] () -- C:\Users\A0033498\Desktop\AdwCleaner.exe
[2014/05/01 00:30:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\A0033498\Desktop\OTL.exe
[2014/04/29 23:19:33 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2014/04/26 23:24:51 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/04/26 01:18:42 | 004,052,728 | ---- | M] () -- C:\Users\A0033498\Desktop\JLT_Paper_to_review_Joint_Iterative_Carrier_Synchronization_and_Signal_Detection_Employing_Expectation_Maximization_Dec_2013_Revised.pdf
[2014/04/25 20:51:46 | 000,011,757 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2014/04/25 00:08:57 | 000,000,180 | ---- | M] () -- C:\Windows\hpbafd.ini
[2014/04/13 00:32:56 | 003,970,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/04/13 00:16:14 | 000,181,272 | ---- | M] () -- C:\Windows\RegBootClean.exe
[2014/04/12 20:29:43 | 000,000,036 | ---- | M] () -- C:\Users\A0033498\AppData\Local\housecall.guid.cache
[2014/04/12 20:24:26 | 000,332,728 | ---- | M] () -- C:\Users\A0033498\AppData\Local\census.cache
[2014/04/12 20:24:12 | 000,121,676 | ---- | M] () -- C:\Users\A0033498\AppData\Local\ars.cache
[2014/04/12 20:12:02 | 000,000,010 | ---- | M] () -- C:\Users\A0033498\AppData\Local\sponge.last.runtime.cache
[1 C:\Users\A0033498\Desktop\*.tmp files -> C:\Users\A0033498\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/05/02 16:23:36 | 001,310,621 | ---- | C] () -- C:\Users\A0033498\Desktop\AdwCleaner.exe
[2014/04/29 23:19:33 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2014/04/26 01:18:42 | 004,052,728 | ---- | C] () -- C:\Users\A0033498\Desktop\JLT_Paper_to_review_Joint_Iterative_Carrier_Synchronization_and_Signal_Detection_Employing_Expectation_Maximization_Dec_2013_Revised.pdf
[2014/04/12 20:24:26 | 000,332,728 | ---- | C] () -- C:\Users\A0033498\AppData\Local\census.cache
[2014/04/12 20:24:12 | 000,121,676 | ---- | C] () -- C:\Users\A0033498\AppData\Local\ars.cache
[2014/04/12 20:12:02 | 000,000,010 | ---- | C] () -- C:\Users\A0033498\AppData\Local\sponge.last.runtime.cache
[2014/04/12 20:05:19 | 000,000,036 | ---- | C] () -- C:\Users\A0033498\AppData\Local\housecall.guid.cache
[2014/02/24 14:56:47 | 000,005,472 | ---- | C] () -- C:\Users\A0033498\AppData\Local\recently-used.xbel
[2014/02/22 18:20:32 | 000,000,184 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2014/02/18 00:29:18 | 000,000,086 | ---- | C] () -- C:\Users\A0033498\gsview32.ini
[2013/06/28 10:47:41 | 000,004,096 | -H-- | C] () -- C:\Users\A0033498\AppData\Local\keyfile3.drm
[2013/02/26 10:37:34 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2012/10/18 20:46:01 | 000,004,830 | ---- | C] () -- C:\Users\A0033498\AppData\Roaming\LTspiceIV.ini
[2012/09/25 18:45:35 | 000,000,913 | ---- | C] () -- C:\Windows\MD_MicroDiffs.INI
[2012/09/25 18:45:34 | 000,000,913 | ---- | C] () -- C:\Windows\MD_MacroDiffs.INI
[2012/09/25 18:45:34 | 000,000,817 | ---- | C] () -- C:\Windows\CFX.INI
[2012/09/25 18:45:34 | 000,000,144 | ---- | C] () -- C:\Windows\FifX_v2.INI
[2012/08/16 17:27:13 | 000,000,600 | ---- | C] () -- C:\Users\A0033498\AppData\Local\PUTTY.RND
[2012/07/21 00:11:58 | 000,181,272 | ---- | C] () -- C:\Windows\RegBootClean.exe
[2012/05/29 12:28:06 | 000,180,624 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll
[2012/05/03 09:54:01 | 000,000,600 | ---- | C] () -- C:\Users\A0033498\AppData\Roaming\winscp.rnd
[2011/06/29 10:24:57 | 000,007,602 | ---- | C] () -- C:\Users\A0033498\AppData\Local\Resmon.ResmonCfg
[2010/08/10 15:49:54 | 000,001,000 | RHS- | C] () -- C:\Users\A0033498\ntuser.pol
[2009/11/18 14:49:13 | 000,011,757 | RHS- | C] () -- C:\ProgramData\ntuser.pol
========== ZeroAccess Check ==========
[2009/07/14 12:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 12:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 09:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 09:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/11/27 16:51:43 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/08 13:12:26 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/08/22 11:28:59 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Design Science
[2010/10/12 10:09:36 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Downloaded Installations
[2014/05/03 00:45:31 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Dropbox
[2013/11/29 00:23:33 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\EndNote
[2012/10/08 13:18:33 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Eyes Relax
[2011/12/05 15:21:43 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\FileOpen
[2012/05/29 11:45:12 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Foxit Software
[2014/02/27 12:54:18 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\inkscape
[2012/11/09 11:02:49 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\JAM Software
[2012/08/18 02:09:23 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Juniper Networks
[2013/12/20 09:51:57 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\l2rshell
[2013/10/31 02:06:23 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\LibreOffice
[2010/10/12 10:13:43 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Nitro PDF
[2014/01/29 12:42:03 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Notepad++
[2012/06/27 13:34:57 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\PDF reDirect
[2012/05/29 12:32:12 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\PrimoPDF
[2014/01/11 13:41:34 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Publish or Perish
[2012/09/25 18:41:05 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Softinterface, Inc
[2013/01/02 12:22:22 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\SSH
[2012/09/19 13:03:59 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\System
[2014/04/04 13:04:55 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\texstudio
[2012/08/13 20:35:26 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Windows Live Writer
[2010/08/15 16:11:22 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\Windows SideBar
[2013/10/31 01:30:57 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\WordKutools
[2013/11/23 14:28:29 | 000,000,000 | ---D | M] -- C:\Users\A0033498\AppData\Roaming\xm1
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:5B811727
@Alternate Data Stream - 128 bytes -> C:\Windows:nlsPreferences
< End of report >