Hey staff of malware removal,
I am here because of a persistent problem of slow computer, to which I suspect a hidden malware of some sort that may be taking up memory. I play computer games a lot and whenever I load up my game the memory usage in Task Manager spikes to around 97%. The game thus lags a great deal and I turn off Malwarebytes but the usage still stays the same. Even when I am running only Google Chrome, the physical memory usage is 67%. I don't think this is normal at all and believe there must be some hidden malicious programs running in the background.
Some other indications why I suspect a hidden malware:
1) ComboFix will not scan at all whether in normal or safe mode. I know ComboFix shouldn't be run without supervision, but I have some experience in malware removal and was merely trying to see if ComboFix will detect anything suspicious. But ComboFix will always get stuck at the stage "scanning infected files" and no logs will be produced. I ran it with Malwarebytes turned off.
2) I know my mom has downloaded some dubious monitoring programs for stock trading in the past and I never thought those programs were merely for stock trading. I have since removed them but the computer's speed has not improved.
3) I have noticed this recently: Whenever I shut down my computer a window pops up asking me to "Force close programs". But there was no visible program listed and I don't see the reason for such a window popping up unless there is some cloaked program running without my knowledge.
Below is the OTL file requested. I appreciate any help that can be offered.
-----------------------------------------------------------------------
OTL logfile created on: 24/11/2014 PM 2:50:52 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mac 4\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17420)
Locale: 00001004 | Country: Singapore | Language: ZHI | Date Format: d/M/yyyy
2.17 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 38.25% Memory free
4.33 Gb Paging File | 2.86 Gb Available in Paging File | 65.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 356.48 Gb Total Space | 244.03 Gb Free Space | 68.46% Space Free | Partition Type: NTFS
Drive E: | 108.96 Gb Total Space | 63.42 Gb Free Space | 58.20% Space Free | Partition Type: HFS
Computer Name: MAC4-PC | User Name: Mac 4 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/11/24 14:50:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mac 4\Desktop\OTL.exe
PRC - [2014/11/15 05:15:26 | 000,856,904 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2014/09/12 17:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/08/02 08:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2013/07/02 09:16:32 | 000,507,264 | ---- | M] (Oracle Corporation) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2012/11/23 10:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2011/03/18 18:18:18 | 000,619,288 | ---- | M] (
http://tortoisesvn.net) -- C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/07 17:40:36 | 000,525,112 | ---- | M] (Apple Inc.) -- C:\Program Files\Boot Camp\Bootcamp.exe
PRC - [2011/02/07 17:40:32 | 000,193,848 | ---- | M] () -- C:\Windows\System32\AppleOSSMgr.exe
PRC - [2011/02/07 17:40:32 | 000,099,640 | ---- | M] (Apple Inc.) -- C:\Windows\System32\AppleTimeSrv.exe
PRC - [2011/02/07 17:35:37 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/02/07 17:35:37 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2005/01/10 07:10:00 | 000,193,592 | ---- | M] (SafeNet, Inc) -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
PRC - [2004/07/14 15:36:54 | 000,057,344 | ---- | M] (Primax Electronics Ltd.) -- C:\Windows\System32\ico.exe
========== Modules (No Company Name) ==========
MOD - [2014/11/15 05:15:24 | 014,910,280 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\39.0.2171.65\PepperFlash\pepflashplayer.dll
MOD - [2014/11/15 05:15:23 | 009,009,480 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\39.0.2171.65\pdf.dll
MOD - [2014/11/15 05:15:19 | 001,077,064 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\39.0.2171.65\libglesv2.dll
MOD - [2014/11/15 05:15:17 | 000,211,272 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\39.0.2171.65\libegl.dll
MOD - [2014/11/15 05:15:16 | 001,677,128 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll
MOD - [2011/02/07 17:36:06 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll
========== Services (SafeList) ==========
SRV - [2014/11/12 05:41:24 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/11/06 10:59:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/11/01 20:43:00 | 000,363,208 | ---- | M] (BitRaider, LLC) [On_Demand | Stopped] -- C:\ProgramData\BitRaider\BRSptStub.exe -- (BRSptStub)
SRV - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014/09/12 17:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/06/17 21:22:41 | 000,069,632 | ---- | M] (Macromedia) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2013/05/27 12:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/06/29 19:39:25 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/06/26 14:45:56 | 000,256,000 | R--- | M] () [Auto | Stopped] -- C:\123456\pev.3XE -- (PEVSystemStart)
SRV - [2011/02/07 17:40:32 | 000,193,848 | ---- | M] () [Auto | Running] -- C:\Windows\System32\AppleOSSMgr.exe -- (AppleOSSMgr)
SRV - [2011/02/07 17:40:32 | 000,099,640 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Windows\System32\AppleTimeSrv.exe -- (AppleTimeSrv)
SRV - [2011/02/07 17:35:37 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/07 17:35:37 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2005/01/10 07:10:00 | 000,193,592 | ---- | M] (SafeNet, Inc) [Auto | Running] -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe -- (SentinelProtectionServer)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\windrvr6.sys -- (WinDriver6)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Tencent\QQPCMgr\8.3.9896.222\QMUdisk.sys -- (QMUdisk)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Tencent\QQPCMgr\8.0.9215.228\QMInject.sys -- (QMInject)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2014/11/24 04:16:05 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Users\MAC4~1\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2014/11/01 22:20:29 | 000,066,824 | ---- | M] (BitRaider) [File_System | On_Demand | Stopped] -- C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver.sys -- (BRDriver_1_3_3_E02B25FC)
DRV - [2014/10/01 11:11:24 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV - [2014/10/01 11:11:14 | 000,075,480 | ---- | M] (Malwarebytes Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV - [2014/10/01 11:11:10 | 000,023,256 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2014/04/21 11:15:01 | 000,323,552 | ---- | M] (CSII) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\PECKP.SYS -- (PECKbdProtector)
DRV - [2014/03/06 02:25:56 | 001,641,920 | ---- | M] (Epiphan Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vga2usb.sys -- (VGA2USB)
DRV - [2011/02/07 17:36:23 | 000,269,824 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2011/02/07 17:35:37 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2011/02/07 17:35:33 | 000,014,336 | ---- | M] (Cirrus Logic) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CS420x86.sys -- (CirrusFilter)
DRV - [2011/02/07 17:35:28 | 000,054,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bScsiSDx.sys -- (bScsiSDx)
DRV - [2011/02/07 17:34:56 | 000,006,528 | ---- | M] (Apple Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KeyAgent.sys -- (KeyAgent)
DRV - [2011/02/07 17:34:52 | 000,016,512 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IRFilter.sys -- (IRRemoteFlt)
DRV - [2011/02/07 17:34:42 | 000,029,824 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\applemtp.sys -- (applemtp)
DRV - [2011/02/07 17:34:42 | 000,010,880 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\applemtm.sys -- (applemtm)
DRV - [2011/02/07 17:34:40 | 000,049,536 | ---- | M] (Apple Inc.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\AppleHFS.sys -- (AppleHFS)
DRV - [2011/02/07 17:34:40 | 000,006,784 | ---- | M] (Apple Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AppleMNT.sys -- (AppleMNT)
DRV - [2011/02/07 17:34:39 | 000,025,088 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\KeyMagic.sys -- (KeyMagic)
DRV - [2011/02/07 17:34:38 | 000,012,928 | ---- | M] (Apple Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\MacHALDriver.sys -- (MacHALDriver)
DRV - [2011/02/07 17:34:20 | 000,018,560 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AppleBtBc.sys -- (AppleBtBc)
DRV - [2010/11/21 05:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/21 05:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/21 05:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2009/07/14 07:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009/07/14 07:45:20 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\acpials.sys -- (acpials)
DRV - [2008/07/10 02:49:14 | 000,242,712 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\RsFx0102.sys -- (RsFx0102)
DRV - [2005/11/01 12:14:22 | 000,024,448 | ---- | M] (Terason Division of Teratech Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TT13942k.sys -- (TT1394L2)
DRV - [2005/01/10 07:10:00 | 000,090,168 | ---- | M] (SafeNet, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\sentinel.sys -- (Sentinel)
DRV - [2004/12/15 15:59:14 | 000,013,872 | ---- | M] (Data Encryption Systems Limited) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\dk3drv.sys -- (DK3DRV)
DRV - [2003/02/11 13:25:14 | 000,009,216 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pelusblf.sys -- (pelusblf)
DRV - [2003/01/10 13:55:32 | 000,016,384 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PELMOUSE.SYS -- (pelmouse)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 A5 DA CF F3 63 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {44177982-996D-4b79-B29F-5B60E13A5169}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@kingsfot.com/npkws: C:\Program Files\Kingsoft\kingsoft antivirus\npkws.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@qq.com/npAndroidAssistant: C:\Program Files\Common Files\Tencent\QQPhoneManager\\1.8.101.2154\npQQPhoneManagerExt.dll ()
FF - HKLM\Software\MozillaPlugins\@qq.com/QQPhotoDrawEx: C:\Program Files\Tencent\Qzone\npQQPhotoDrawEx.dll ()
FF - HKLM\Software\MozillaPlugins\@qq.com/QzoneMusic: C:\Program Files\Tencent\QQMusic\QzoneMusic\npQzoneMusic.dll (Tencent)
FF - HKLM\Software\MozillaPlugins\@qq.com/TXSSO: C:\Program Files\Common Files\Tencent\TXSSO\1.2.2.37\Bin\npSSOAxCtrlForPTLogin.dll (Tencent)
FF - HKLM\Software\MozillaPlugins\@tencent.com/npQQMailWebKit,version=1.0.0.1: C:\Program Files\QQMailPlugin\npQQMailWebKit.dll (Tencent)
FF - HKLM\Software\MozillaPlugins\@tencent.com/nptxftnWebKit,version=1.0.0.1: C:\Program Files\QQMailPlugin\nptxftnWebKit.dll (Tencent Technology (Shenzhen) Company Limited)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Mac 4\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_1\
CHR - Extension: No name found = C:\Users\Mac 4\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
O1 HOSTS File: ([2009/06/11 05:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (QQ下载助手浏览器控件) - {C9C7334B-5657-41e1-8F79-F6AACECA05F4} - C:\Program Files\Common Files\Tencent\QQMiniDL\44\Browser\QQIEHelper01.dll File not found
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {65F8A3D2-4C22-4A33-9633-73167EAEEC45} - No CLSID value found.
O4 - HKLM..\Run: [Apple_KbdMgr] C:\Program Files\Boot Camp\Bootcamp.exe (Apple Inc.)
O4 - HKLM..\Run: [kxesc] "C:\Program Files\Kingsoft\kingsoft antivirus\kxetray.exe" -autorun File not found
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: qq.com ([cache.tv] http in Trusted sites)
O15 - HKLM\..Trusted Domains: qq.com ([qqlivecaption] http in Trusted sites)
O15 - HKLM\..Trusted Domains: qq.com ([qqlivehabit] http in Trusted sites)
O15 - HKLM\..Trusted Domains: qq.com ([qqlivesearch] http in Trusted sites)
O15 - HKLM\..Trusted Domains: qq.com ([video_1] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 95599.cn ([easyabc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 95599.cn ([easyabc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 95599.cn ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 95599.cn ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 95599.sh.cn ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 95599.sh.cn ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: abchina.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: abchina.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: abchina.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: icbc.com.cn ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: soso.com ([toolbar] http in Trusted sites)
O15 - HKCU\..Trusted Domains: toolbar.soso.com ([*] * in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD5FB6C4-B58F-4071-A72D-C165E4420358}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{07533c63-6582-11e3-b1d2-c82a141396fa}\Shell - "" = AutoRun
O33 - MountPoints2\{07533c63-6582-11e3-b1d2-c82a141396fa}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{74596685-d0d4-11e2-8740-954917c02740}\Shell - "" = AutoRun
O33 - MountPoints2\{74596685-d0d4-11e2-8740-954917c02740}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{c4858d95-e3e9-11e2-89a4-cdc6ab69c46f}\Shell - "" = AutoRun
O33 - MountPoints2\{c4858d95-e3e9-11e2-89a4-cdc6ab69c46f}\Shell\AutoRun\command - "" = F:\ABCInstall.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/11/24 14:50:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mac 4\Desktop\OTL.exe
[2014/11/24 14:38:54 | 000,000,000 | --SD | C] -- C:\123456
[2014/11/24 03:58:25 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[2014/11/24 03:56:11 | 005,598,306 | R--- | C] (Swearware) -- C:\Users\Mac 4\Desktop\123456.exe
[2014/11/14 05:11:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014/11/13 08:57:39 | 000,000,000 | -HSD | C] -- C:\Users\Mac 4\AppData\Local\EmieBrowserModeList
[2014/11/10 02:23:24 | 000,114,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/11/10 02:23:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/11/10 02:22:52 | 000,075,480 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
[2014/11/10 02:22:52 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
[2014/11/10 02:22:52 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2014/11/10 02:22:52 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/11/10 02:22:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/11/09 03:16:59 | 000,000,000 | ---D | C] -- C:\Users\Mac 4\AppData\Roaming\Mumble
[2014/11/09 03:16:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
[2014/11/09 03:06:40 | 000,000,000 | ---D | C] -- C:\Program Files\Mumble
[2014/11/02 04:38:26 | 000,000,000 | ---D | C] -- C:\Users\Mac 4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks
[2014/11/02 04:38:19 | 000,000,000 | ---D | C] -- C:\Games
[2014/11/01 20:42:58 | 000,000,000 | ---D | C] -- C:\ProgramData\BitRaider
[2 C:\Users\Mac 4\Desktop\*.tmp files -> C:\Users\Mac 4\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/11/24 14:50:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mac 4\Desktop\OTL.exe
[2014/11/24 14:43:48 | 000,028,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/11/24 14:43:47 | 000,028,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/11/24 14:41:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/11/24 14:36:54 | 000,114,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/11/24 14:36:42 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/11/24 03:56:40 | 005,598,306 | R--- | M] (Swearware) -- C:\Users\Mac 4\Desktop\123456.exe
[2014/11/24 03:33:08 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/11/21 12:48:11 | 000,002,137 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/11/14 05:11:13 | 000,001,997 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014/11/13 19:05:56 | 002,648,564 | ---- | M] () -- C:\Users\Mac 4\Desktop\Visa.pdf
[2014/11/13 13:38:52 | 000,526,825 | ---- | M] () -- C:\Users\Mac 4\Desktop\NoCriminalRecordCommitment.pdf
[2014/11/13 03:39:52 | 000,410,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/11/10 02:34:08 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014/11/10 02:23:02 | 000,001,068 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/09 06:44:28 | 000,000,024 | ---- | M] () -- C:\Users\Mac 4\random.dat
[2014/11/09 06:27:37 | 000,000,044 | ---- | M] () -- C:\Users\Mac 4\jagex_cl_runescape_LIVE.dat
[2014/11/09 03:19:33 | 000,002,403 | ---- | M] () -- C:\Users\Mac 4\Desktop\backup mumble data swtor.p12
[2014/11/05 16:44:47 | 000,007,614 | ---- | M] () -- C:\Users\Mac 4\Desktop\mechnicalParts.png
[2014/11/02 04:38:28 | 000,000,777 | ---- | M] () -- C:\Users\Mac 4\Desktop\World of Tanks.lnk
[2014/11/01 20:34:34 | 000,000,000 | ---- | M] () -- C:\end
[2014/10/31 00:25:20 | 000,004,096 | -HS- | M] () -- C:\radial.cdb
[2014/10/26 13:49:49 | 000,633,914 | ---- | M] () -- C:\Users\Mac 4\Desktop\awakeningEN.pdf
[2 C:\Users\Mac 4\Desktop\*.tmp files -> C:\Users\Mac 4\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/11/14 05:11:13 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014/11/14 05:11:13 | 000,001,997 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014/11/13 19:05:56 | 002,648,564 | ---- | C] () -- C:\Users\Mac 4\Desktop\Visa.pdf
[2014/11/13 13:39:14 | 000,526,825 | ---- | C] () -- C:\Users\Mac 4\Desktop\NoCriminalRecordCommitment.pdf
[2014/11/10 02:23:02 | 000,001,068 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/09 03:19:31 | 000,002,403 | ---- | C] () -- C:\Users\Mac 4\Desktop\backup mumble data swtor.p12
[2014/11/05 16:44:47 | 000,007,614 | ---- | C] () -- C:\Users\Mac 4\Desktop\mechnicalParts.png
[2014/11/02 04:38:28 | 000,000,777 | ---- | C] () -- C:\Users\Mac 4\Desktop\World of Tanks.lnk
[2014/10/26 13:49:48 | 000,633,914 | ---- | C] () -- C:\Users\Mac 4\Desktop\awakeningEN.pdf
[2013/12/16 14:01:38 | 000,000,024 | ---- | C] () -- C:\Users\Mac 4\random.dat
[2013/12/16 14:01:37 | 000,000,044 | ---- | C] () -- C:\Users\Mac 4\jagex_cl_runescape_LIVE.dat
[2013/11/09 11:06:49 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/11/09 11:06:49 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/11/09 11:06:49 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/11/09 11:06:49 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/11/09 11:06:49 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/06/09 15:54:14 | 000,113,872 | ---- | C] () -- C:\Windows\System32\EditControl.dll
[2013/06/09 15:54:14 | 000,072,912 | ---- | C] () -- C:\Windows\System32\UploadControl.dll
[2013/06/09 15:54:12 | 000,269,584 | ---- | C] () -- C:\Windows\System32\GPKPCSC.dll
[2013/06/09 15:54:12 | 000,249,136 | ---- | C] () -- C:\Windows\System32\GPKPIN.dll
[2013/06/09 15:54:12 | 000,101,584 | ---- | C] () -- C:\Windows\System32\jcutilHUAUK.dll
[2013/06/09 15:54:12 | 000,093,392 | ---- | C] () -- C:\Windows\System32\jcutilHUAUKLCD.dll
[2013/06/09 15:54:12 | 000,056,528 | ---- | C] () -- C:\Windows\System32\jcutilTdrUKLCD.dll
[2013/06/09 15:54:12 | 000,052,432 | ---- | C] () -- C:\Windows\System32\jcutilgem101101.dll
[2013/06/09 15:54:12 | 000,048,336 | ---- | C] () -- C:\Windows\System32\hmukchk.dll
[2013/06/09 15:54:12 | 000,040,144 | ---- | C] () -- C:\Windows\System32\ChangPIN.dll
[2013/06/09 15:54:12 | 000,029,392 | ---- | C] () -- C:\Windows\System32\GEMPIN01.dll
[2013/06/09 15:54:10 | 000,089,296 | ---- | C] () -- C:\Windows\System32\jcinTHTFUK.dll
[2013/06/09 15:54:10 | 000,081,104 | ---- | C] () -- C:\Windows\System32\jcidTHTFUK.dll
[2013/06/09 15:54:10 | 000,072,912 | ---- | C] () -- C:\Windows\System32\jcinHUAUK.dll
[2013/06/09 15:54:10 | 000,064,720 | ---- | C] () -- C:\Windows\System32\USBKey.dll
[2013/06/09 15:54:10 | 000,064,720 | ---- | C] () -- C:\Windows\System32\jcidHUAUK.dll
[2013/06/09 15:54:10 | 000,060,624 | ---- | C] () -- C:\Windows\System32\GDSetLET.dll
[2013/06/09 15:54:10 | 000,052,432 | ---- | C] () -- C:\Windows\System32\jcinGEM101.dll
[2013/06/09 15:54:10 | 000,052,432 | ---- | C] () -- C:\Windows\System32\jcidGEM101.dll
[2013/06/09 15:54:10 | 000,052,432 | ---- | C] () -- C:\Windows\System32\jcidGD84.dll
[2013/06/09 15:54:10 | 000,048,336 | ---- | C] () -- C:\Windows\System32\jcinGD84.dll
[2013/06/09 15:54:10 | 000,036,048 | ---- | C] () -- C:\Windows\System32\jcinWATCHK.dll
[2013/06/09 15:54:10 | 000,036,048 | ---- | C] () -- C:\Windows\System32\jcidWATCHK.dll
[2013/06/09 15:54:10 | 000,034,512 | ---- | C] () -- C:\Windows\System32\jcinGEM102.dll
[2013/06/09 15:54:10 | 000,030,416 | ---- | C] () -- C:\Windows\System32\jcidGEM102.dll
[2013/06/09 15:54:08 | 000,307,920 | ---- | C] () -- C:\Windows\System32\InputControl.dll
[2013/06/09 15:54:08 | 000,276,688 | ---- | C] () -- C:\Windows\System32\SubmitControl.dll
[2013/06/09 15:54:05 | 000,077,008 | ---- | C] () -- C:\Windows\System32\certInStall.dll
[2013/06/09 15:54:03 | 000,174,288 | ---- | C] () -- C:\Windows\System32\icbcclean.dll
[2013/06/09 13:53:06 | 000,018,760 | ---- | C] () -- C:\Windows\System32\QQVistaHelper.dll
[2011/11/15 23:42:32 | 000,007,605 | ---- | C] () -- C:\Users\Mac 4\AppData\Local\Resmon.ResmonCfg
[2011/08/24 11:21:42 | 000,118,565 | ---- | C] () -- C:\Users\Mac 4\AppData\Local\debuggee.mdmp
[2011/06/28 21:07:47 | 000,000,144 | ---- | C] () -- C:\Users\Mac 4\.qt-license
========== ZeroAccess Check ==========
[2009/07/14 12:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/25 09:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 05:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 09:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014/11/13 18:53:39 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Canon
[2011/08/24 12:53:52 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Galil
[2013/06/09 14:10:39 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\InstallPlugin
[2013/09/22 19:33:52 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Kingsoft
[2014/11/09 05:26:10 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Mumble
[2014/10/02 23:06:30 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\QtProject
[2013/07/26 21:03:03 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\shoujizhushou
[2011/06/28 23:00:15 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Subversion
[2014/02/13 21:03:46 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Tencent
[2013/06/09 21:59:36 | 000,000,000 | ---D | M] -- C:\Users\Mac 4\AppData\Roaming\Wargaming.net
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2014/10/14 22:49:20 | 000,000,000 | ---D | M](C:\Users\Mac 4\Documents\?? ???) -- C:\Users\Mac 4\Documents\넥슨 플러그
[2014/10/14 22:49:20 | 000,000,000 | ---D | C](C:\Users\Mac 4\Documents\?? ???) -- C:\Users\Mac 4\Documents\넥슨 플러그
[2012/01/08 23:38:49 | 000,000,020 | ---- | M] ()(C:\Windows\ü??) -- C:\Windows\üô•
[2012/01/08 23:38:48 | 000,000,020 | ---- | C] ()(C:\Windows\ü??) -- C:\Windows\üô•
< End of report >