Hiya! Was hoping someone here could help me, as I've encountered a problem that's got my head spinning. I'm running Windows 7 Professional on a Lenovo B560 Laptop.
I started noticing some virus-like behaviour such as automatic messages being sent through my Skype "XD Check out these fails! <insert probably infected link here>", chrome working very slowly, and my webcam actually turned on all on its own for like 30 seconds. That freaked me out, and prompted me to tape up my camera and start running scans. I ran a full scan (which took like 6 hours for some reason? I don't believe it should have taken this long) with Windows Security Essentials but it found nothing. So I've been told I should try Malwarebytes instead as it is apparently one of the better anti-virus programs out there. I downloaded Malwarebytes from malwarebytes.org, free version and was given a trial program. I ran a full scan and sure enough it found 6 things Windows Security Essentials didn't find. I don't have the log sorry, but i remember it found a bunch of PUP files, something called BitcoinMiner, and the two files winlogon and pcimon. After letting it doing its thing and remove the threats, my computer was working great.
But then when I restart my computer it has trouble logging on. I get pass the users screen and it will load my desktop and taskbar, but nothing else. I can't really click on anything; when I mouse over my taskbar the little blue "waiting" circle on my cursor appears. And it does nothing. It won't go into hibernate either, my only option is to hold the power button until it shuts down. System Restore solves the problem, but I still have all my viruses!!
What's got my head spinning is that I've actually noticed the two files "winlogon" and "pcimon" asking for my permission to run when I log in (with publisher: Unknown"). Obviously, this has never happened, so that was a red flag that those two are definitely viruses. I look up these files and they're windows files? According to what they do, they really shouldn't be asking my permission like this, but they are very important nevertheless. I also found out viruses like to mimic these files, and if my winlogon is a fake I should find the fake in my User Directory, but I can't.
I just want to know what's up. Is Malwarebytes deleting something important? Do I still have viruses and, if so, how do I get rid of them?
Thanks!
OTL Log:
OTL logfile created on: 17/06/2014 2:43:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\testy\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17126)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
5.74 Gb Total Physical Memory | 4.10 Gb Available Physical Memory | 71.49% Memory free
11.48 Gb Paging File | 9.52 Gb Available in Paging File | 82.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 391.24 Gb Free Space | 84.02% Space Free | Partition Type: NTFS
Drive E: | 5.56 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: MISA | User Name: testy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/06/17 14:26:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\testy\Desktop\OTL.exe
PRC - [2014/05/13 19:40:56 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/05/08 09:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/04/14 20:39:56 | 002,308,872 | ---- | M] (FSPro Labs) -- C:\Program Files\My Lockbox\mylbx.exe
PRC - [2007/04/27 19:40:14 | 001,581,056 | ---- | M] (Lenovo(beijing) Limited) -- C:\Program Files (x86)\Lenovo\EnergyCut\utilty.exe
========== Modules (No Company Name) ==========
MOD - [2014/05/13 19:40:54 | 000,414,536 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppgooglenaclpluginchrome.dll
MOD - [2014/05/13 19:40:53 | 013,695,816 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll
MOD - [2014/05/13 19:40:50 | 004,217,672 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
MOD - [2014/05/13 19:40:45 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll
MOD - [2014/05/13 19:40:44 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll
MOD - [2014/05/13 19:40:43 | 001,732,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll
MOD - [2014/04/23 16:05:12 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/04/23 16:04:54 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2007/04/13 20:18:10 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Lenovo\EnergyCut\KbdHook.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014/05/30 05:21:05 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/03/11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/03/11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/05/08 09:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/04/03 20:21:48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014/06/07 13:02:58 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014/03/11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2013/10/01 22:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/03/18 16:51:08 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/23 10:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 10:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/10 22:28:18 | 012,311,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/09/15 07:02:40 | 000,036,656 | ---- | M] (Egis Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FPSensor.sys -- (FPSensor)
DRV:64bit: - [2011/07/01 15:08:04 | 004,745,280 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2011/06/03 23:59:38 | 000,057,648 | ---- | M] (FSPro Labs) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\FSPFltd2.sys -- (FSProFilter2)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 23:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/09/17 19:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:34:18 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Users\testy\AppData\Local\Roblox\Versions\version-4d8b1955ef2740b3\\NPRobloxProxy.dll ()
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\
CHR - Extension: Google Drive = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: YouTube = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.7.1_0\
CHR - Extension: Google Wallet = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\testy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [mylbx] C:\Program Files\My Lockbox\mylbx.exe (FSPro Labs)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [EnergyCut] C:\Program Files (x86)\Lenovo\EnergyCut\EnergyCut.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\EnergyCut\utilty.exe (Lenovo(beijing) Limited)
O4 - HKLM..\Run: [PCI Monitor] C:\Program Files (x86)\PCI Monitor\pcimon.exe (© The Computer Guy Tony )
O4 - HKLM..\Run: [Winlogon] C:\Users\testy\AppData\Roaming\winlogon.exe (© The Computer Guy Tony )
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Winlogon] C:\Users\testy\AppData\Roaming\winlogon.exe (© The Computer Guy Tony )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 199.235.124.213 199.235.124.214
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5DF823DF-502D-4E94-90A2-2A5EF33789A7}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{802FC181-7A86-4503-AE7C-82B67922BBDF}: DhcpNameServer = 199.235.124.213 199.235.124.214
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/29 22:57:32 | 000,054,544 | R--- | M] (Electronic Arts) - E:\Autorun.exe -- [ UDF ]
O32 - AutoRun File - [2008/10/21 19:48:37 | 000,000,045 | R--- | M] () - E:\Autorun.inf -- [ UDF ]
O33 - MountPoints2\{c769d213-ea54-11e3-bfe6-f0def14a573c}\Shell - "" = AutoRun
O33 - MountPoints2\{c769d213-ea54-11e3-bfe6-f0def14a573c}\Shell\AutoRun\command - "" = E:\Autorun.exe -- [2009/04/29 22:57:32 | 000,054,544 | R--- | M] (Electronic Arts)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/06/17 14:26:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\testy\Desktop\OTL.exe
[2014/06/16 23:56:04 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014/06/16 21:20:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/06/16 19:11:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/06/16 19:11:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/06/16 18:48:04 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Roaming\DAEMON Tools Lite
[2014/06/16 18:47:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2014/06/16 18:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2014/06/15 16:26:40 | 000,000,000 | ---D | C] -- C:\Users\testy\javaupdate
[2014/06/13 12:30:58 | 000,000,000 | ---D | C] -- C:\Users\testy\Desktop\Sprites
[2014/06/12 18:28:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PCI Monitor
[2014/06/12 18:28:31 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Roaming\1B94DF9B-8C09-437B-94AF-7C149D758150
[2014/06/12 18:09:37 | 132,583,424 | -HS- | C] (© The Computer Guy Tony ) -- C:\Users\testy\AppData\Roaming\csrss.exe
[2014/06/12 18:07:24 | 133,012,047 | ---- | C] (© The Computer Guy Tony ) -- C:\Users\testy\AppData\Roaming\Photoshop CS6.exe
[2014/06/12 18:02:18 | 132,583,424 | -HS- | C] (© The Computer Guy Tony ) -- C:\Users\testy\AppData\Roaming\winlogon.exe
[2014/06/12 17:35:41 | 000,000,000 | ---D | C] -- C:\Users\testy\Documents\RPGVXAce
[2014/06/12 17:34:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RPG MAKER VX Ace
[2014/06/12 17:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Enterbrain
[2014/06/12 17:32:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Enterbrain
[2014/06/12 17:30:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
[2014/06/12 17:30:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lenovo
[2014/06/12 17:30:05 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Roaming\InstallShield
[2014/06/12 17:30:02 | 000,000,000 | ---D | C] -- C:\Drivers
[2014/06/10 21:42:12 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
[2014/06/10 21:42:08 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Local\Roblox
[2014/06/07 13:24:19 | 000,000,000 | ---D | C] -- C:\Users\testy\Documents\Electronic Arts
[2014/06/07 13:23:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft WSE
[2014/06/07 13:18:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
[2014/06/07 13:18:28 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2014/06/07 13:03:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
[2014/06/07 13:02:58 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2014/06/07 13:02:55 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Roaming\DAEMON Tools Pro
[2014/06/07 13:02:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Pro
[2014/06/07 13:00:57 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro
[2014/06/02 23:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2014/05/22 21:41:54 | 000,000,000 | ---D | C] -- C:\Users\testy\Documents\FirstClass
[2014/05/22 21:41:45 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Roaming\FirstClass
[2014/05/22 21:41:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FirstClass
[2014/05/22 21:39:54 | 000,000,000 | ---D | C] -- C:\Users\testy\Desktop\Games
[2014/05/22 12:06:33 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
[2014/05/19 17:49:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014/05/19 17:49:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2014/05/19 17:49:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2014/05/19 17:45:38 | 000,000,000 | ---D | C] -- C:\Users\testy\AppData\Local\Adobe
[2014/05/18 20:47:45 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2014/05/18 18:23:01 | 000,000,000 | ---D | C] -- C:\Users\testy\jagexcache
[2 C:\Users\testy\Desktop\*.tmp files -> C:\Users\testy\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/06/17 14:47:55 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/17 14:47:54 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/06/17 14:26:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\testy\Desktop\OTL.exe
[2014/06/17 14:19:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/06/17 09:39:38 | 000,021,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/06/17 09:39:38 | 000,021,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/06/17 08:46:41 | 000,781,298 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/06/17 08:46:41 | 000,666,176 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/06/17 08:46:41 | 000,125,820 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/06/17 08:41:11 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/17 08:40:14 | 326,508,543 | -HS- | M] () -- C:\hiberfil.sys
[2014/06/13 12:34:25 | 000,002,009 | ---- | M] () -- C:\Users\testy\Desktop\Photoshop.lnk
[2014/06/12 18:28:27 | 132,583,424 | -HS- | M] (© The Computer Guy Tony ) -- C:\Users\testy\AppData\Roaming\winlogon.exe
[2014/06/12 18:28:27 | 132,583,424 | -HS- | M] (© The Computer Guy Tony ) -- C:\Users\testy\AppData\Roaming\csrss.exe
[2014/06/12 18:13:04 | 000,000,040 | -H-- | M] () -- C:\76C026703A79
[2014/06/12 18:07:35 | 133,012,047 | ---- | M] (© The Computer Guy Tony ) -- C:\Users\testy\AppData\Roaming\Photoshop CS6.exe
[2014/06/12 17:34:38 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\RPG MAKER VX Ace.lnk
[2014/06/12 17:18:53 | 000,001,235 | ---- | M] () -- C:\Users\testy\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 5.lnk
[2014/06/12 17:18:53 | 000,001,211 | ---- | M] () -- C:\Users\testy\Desktop\FrostWire 5.lnk
[2014/06/10 20:15:41 | 413,179,345 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014/06/10 12:08:57 | 000,018,920 | ---- | M] () -- C:\Users\testy\Desktop\Courage.mx6
[2014/06/10 00:14:10 | 000,002,000 | ---- | M] () -- C:\Users\testy\Desktop\Mixcraft 6.lnk
[2014/06/07 13:22:40 | 000,002,086 | ---- | M] () -- C:\Users\Public\Desktop\The Sims™ 3.lnk
[2014/06/07 13:15:01 | 000,001,318 | ---- | M] () -- C:\Users\testy\Desktop\Frostwire.lnk
[2014/06/07 13:03:36 | 000,001,932 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
[2014/06/07 13:02:58 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2014/05/26 11:48:41 | 000,000,925 | ---- | M] () -- C:\Users\testy\Desktop\ .lnk
[2014/05/24 22:53:49 | 000,000,024 | ---- | M] () -- C:\Users\testy\random.dat
[2014/05/24 22:45:01 | 000,000,044 | ---- | M] () -- C:\Users\testy\jagex_cl_runescape_LIVE.dat
[2014/05/22 21:41:47 | 000,001,930 | ---- | M] () -- C:\Users\testy\Desktop\FirstClass.lnk
[2014/05/19 18:09:57 | 000,069,096 | ---- | M] () -- C:\Users\testy\Desktop\Winterspell.mx6
[2014/05/19 16:26:12 | 000,002,657 | ---- | M] () -- C:\Users\testy\Desktop\Microsoft Office Word 2003.lnk
[2014/05/18 20:47:38 | 000,357,384 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/05/18 20:41:49 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2 C:\Users\testy\Desktop\*.tmp files -> C:\Users\testy\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/06/12 18:23:44 | 000,002,009 | ---- | C] () -- C:\Users\testy\Desktop\Photoshop.lnk
[2014/06/12 18:13:04 | 000,000,040 | -H-- | C] () -- C:\76C026703A79
[2014/06/12 17:34:38 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\RPG MAKER VX Ace.lnk
[2014/06/10 00:12:22 | 000,018,920 | ---- | C] () -- C:\Users\testy\Desktop\Courage.mx6
[2014/06/07 13:22:40 | 000,002,086 | ---- | C] () -- C:\Users\Public\Desktop\The Sims™ 3.lnk
[2014/06/07 13:15:01 | 000,001,318 | ---- | C] () -- C:\Users\testy\Desktop\Frostwire.lnk
[2014/06/07 13:03:36 | 000,001,932 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
[2014/05/22 21:41:47 | 000,001,930 | ---- | C] () -- C:\Users\testy\Desktop\FirstClass.lnk
[2014/05/19 17:50:06 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014/05/18 20:46:59 | 413,179,345 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2014/05/18 20:41:49 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2014/05/18 18:23:01 | 000,000,044 | ---- | C] () -- C:\Users\testy\jagex_cl_runescape_LIVE.dat
[2014/05/18 18:23:01 | 000,000,024 | ---- | C] () -- C:\Users\testy\random.dat
[2014/05/18 18:17:06 | 000,069,096 | ---- | C] () -- C:\Users\testy\Desktop\Winterspell.mx6
[2014/05/15 17:55:24 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2014/05/14 00:07:24 | 000,765,700 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/05/28 19:59:14 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\.minecraft
[2014/06/15 18:11:44 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\1B94DF9B-8C09-437B-94AF-7C149D758150
[2014/05/16 19:53:21 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\Acoustica
[2014/06/07 12:49:40 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\Audacity
[2014/06/16 18:51:35 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\DAEMON Tools Lite
[2014/06/07 13:06:17 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\DAEMON Tools Pro
[2014/05/22 21:41:45 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\FirstClass
[2014/05/15 23:13:08 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\Oracle
[2014/05/16 19:53:26 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\SynthMaker
[2014/05/15 22:15:21 | 000,000,000 | ---D | M] -- C:\Users\testy\AppData\Roaming\SYSTEMAX Software Development
========== Purity Check ==========
< End of report >