Hello,
It all started when I try to install bluetooth driver for my Heaedset called CSR.I installed it and when it doesnt run I tried to unsintall it but got Error 2738 could not access VBScript run time for custom action.So I register the dll,run sfc scannow and uninstalled my antivirus.Then i tied to install bluetooth driver for CSR from this website http://www.komeil.co...dset-windows-7. The day after that I noticed I cant do system restore even if there's a rstore point,then it became worst the next day and the system restore stuck on searching.WIth it comes graphics glitches,sometimes crashing my video card's driver,and I noticed I can run any antivirus.First I run rkill.exe it push through,then I run Avast and Malwarebytes both didnt work.Then i run Tdsskiller and it didnt work too,then Gmer which worked.I tried to run Malwarebytes antrootkit and Malwarebytes Chameleon which should work on infected machine and both didnt work.So i decided to uninstall my video cards driver and installd default windws driver to check if itll help,and it did.Some of the gitches were gone and I can finally run Malwarebytes and combofix.This is the log from otl
OTL logfile created on: 12/19/2014 2:22:15 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\MyEminence\Downloads
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 52.42% Memory free
7.81 Gb Paging File | 6.66 Gb Available in Paging File | 85.26% Paging File free
Paging file location(s): c:\pagefile.sys 2000 2000d:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 169.41 Gb Total Space | 7.99 Gb Free Space | 4.72% Space Free | Partition Type: NTFS
Drive D: | 63.48 Gb Total Space | 9.64 Gb Free Space | 15.19% Space Free | Partition Type: NTFS
Computer Name: ME-PC | User Name: MyEminence | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/12/19 02:15:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\MyEminence\Downloads\OTL.exe
PRC - [2014/12/13 22:00:44 | 005,227,112 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2014/11/21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/11/21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/11/21 06:12:46 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
PRC - [2013/12/20 02:37:25 | 001,819,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013/12/20 02:37:25 | 000,930,592 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013/12/10 10:22:32 | 002,279,712 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2013/12/10 10:21:14 | 001,494,304 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2012/11/12 13:59:15 | 000,657,504 | ---- | M] () -- C:\ProgramData\Globe Tattoo Broadband\OnlineUpdate\ouc.exe
PRC - [2011/09/19 16:59:40 | 000,192,832 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2011/09/19 16:59:36 | 000,135,488 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
PRC - [2011/06/24 11:49:46 | 000,269,648 | ---- | M] () -- C:\Program Files\SMART BRO\AssistantServices.exe
PRC - [2011/05/27 15:57:30 | 000,562,592 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/04/29 22:44:56 | 000,092,320 | ---- | M] (Speedbit Ltd.) -- C:\Program Files\Common Files\SpeedBit\SBUpdate\SBUpdate.exe
PRC - [2011/04/29 22:44:54 | 002,918,576 | ---- | M] (SpeedBit Ltd.) -- C:\Program Files\DAP\DAP.exe
PRC - [2011/04/29 18:31:12 | 000,400,760 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\BitTorrent\BitTorrent.exe
PRC - [2011/04/19 16:29:42 | 000,152,576 | ---- | M] () -- C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
PRC - [2011/03/14 23:27:28 | 000,271,712 | ---- | M] () -- C:\ProgramData\DatacardService\HWDeviceService.exe
PRC - [2011/03/14 23:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2011/01/12 22:35:52 | 000,069,864 | ---- | M] (SANDBOXIE L.T.D) -- C:\Program Files\Sandboxie\SbieSvc.exe
PRC - [2010/06/08 19:39:18 | 000,393,216 | ---- | M] () -- C:\Program Files\GenArts\Monsters-AE\bin\JawsServerAE.exe
PRC - [2010/06/04 14:09:46 | 000,704,512 | ---- | M] () -- C:\Program Files\GenArts\Monsters-AE\bin\FlowFinder3MonstersAE32.exe
PRC - [2010/02/09 15:55:52 | 000,049,152 | ---- | M] () -- C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
PRC - [2009/08/24 14:38:06 | 000,068,136 | ---- | M] () -- C:\Program Files\Gigabyte\EasySaver\essvr.exe
PRC - [2009/04/11 21:19:30 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/11 21:19:17 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2007/02/12 12:18:50 | 000,924,160 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
========== Modules (No Company Name) ==========
MOD - [2014/12/13 22:00:13 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2011/04/29 22:44:56 | 000,084,480 | ---- | M] () -- C:\Windows\System32\EasyHook32.dll
MOD - [2011/04/29 22:44:55 | 000,053,248 | ---- | M] () -- C:\Program Files\DAP\zlib.dll
MOD - [2011/04/19 16:29:42 | 000,132,608 | ---- | M] () -- C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkLocalBackup.dll
MOD - [2010/07/05 05:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe -- (CsrBtService)
SRV - File not found [Auto | Stopped] -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe -- (CsrBtOBEXService)
SRV - [2014/12/13 13:51:50 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/12/10 23:05:59 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/11/21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/11/21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/12/10 10:21:14 | 001,494,304 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2012/11/12 13:59:15 | 000,657,504 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Globe Tattoo Broadband\UpdateDog\ouc.exe -- (Globe Tattoo Broadband. RunOuc)
SRV - [2011/09/19 16:59:40 | 000,192,832 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2011/08/15 10:02:12 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2011/06/24 11:49:46 | 000,269,648 | ---- | M] () [Auto | Running] -- C:\Program Files\SMART BRO\AssistantServices.exe -- (UI Assistant Service)
SRV - [2011/05/27 15:57:30 | 000,562,592 | ---- | M] (Affinegy, Inc.) [Auto | Running] -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe -- (AffinegyService)
SRV - [2011/05/02 18:05:28 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/04/19 16:29:42 | 000,152,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe -- (Belkin Local Backup Service)
SRV - [2011/03/14 23:27:28 | 000,271,712 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService.exe -- (HWDeviceService.exe)
SRV - [2011/01/12 22:35:52 | 000,069,864 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2010/06/08 19:39:18 | 000,393,216 | ---- | M] () [Auto | Running] -- C:\Program Files\GenArts\Monsters-AE\bin\JawsServerAE.exe -- (JawsServerAE)
SRV - [2010/06/04 14:09:46 | 000,704,512 | ---- | M] () [Auto | Running] -- C:\Program Files\GenArts\Monsters-AE\bin\FlowFinder3MonstersAE32.exe -- (FlowFinder3MonstersAE32)
SRV - [2010/06/03 11:13:04 | 001,540,096 | ---- | M] (Reprise Software Inc.) [On_Demand | Stopped] -- C:\Program Files\GenArts\rlm\rlm.exe -- (RLM-GenArts)
SRV - [2010/04/06 16:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\System32\AppleChargerSrv.exe -- (AppleChargerSrv)
SRV - [2010/02/09 15:55:52 | 000,049,152 | ---- | M] () [Auto | Running] -- C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe -- (Belkin Network USB Helper)
SRV - [2009/08/24 14:38:06 | 000,068,136 | ---- | M] () [Auto | Running] -- C:\Program Files\Gigabyte\EasySaver\essvr.exe -- (ES lite Service)
SRV - [2008/01/21 10:21:41 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/08/14 00:17:00 | 000,411,136 | ---- | M] (CSR, plc) [Auto | Running] -- C:\Windows\System32\HFGService.dll -- (HFGService)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2007/02/12 12:18:50 | 000,924,160 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\taphss6.sys -- (taphss6)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\MYEMIN~1\AppData\Local\Temp\GPU-Z.sys -- (GPU-Z)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\csrusb.sys -- (csrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\CsrBtPort.sys -- (CsrBtPort)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\TEMP\cpuz135\cpuz135_x32.sys -- (cpuz135)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Marcus\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwrchid.sys -- (btwrchid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwavdt.sys -- (btwavdt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\BthAudioHF.sys -- (BthAudioHF)
DRV - [2014/12/19 02:18:28 | 000,114,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV - [2014/12/19 02:17:43 | 000,017,488 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2014/11/21 06:14:16 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV - [2014/11/21 06:14:06 | 000,023,256 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2014/06/16 14:01:38 | 000,184,192 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudserd.sys -- (ssudserd)
DRV - [2014/06/16 14:01:38 | 000,184,192 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2014/06/16 14:01:38 | 000,089,856 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013/12/20 04:26:04 | 010,471,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012/10/30 12:42:16 | 000,011,136 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2012/10/29 19:42:46 | 000,070,272 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV - [2012/08/20 08:54:20 | 000,027,520 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV - [2012/08/20 08:54:18 | 000,096,000 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2012/08/20 08:54:18 | 000,076,544 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2012/04/20 14:14:22 | 000,249,472 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2011/12/31 09:20:24 | 000,199,168 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2011/05/22 22:51:26 | 000,020,216 | ---- | M] (REALiX) [Kernel | System | Running] -- C:\Program Files\HWiNFO32\HWiNFO32.SYS -- (HWiNFO32)
DRV - [2011/03/26 10:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbvoice.sys -- (ZTEusbvoice)
DRV - [2011/03/26 10:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2011/03/26 10:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2011/03/26 10:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2011/03/26 10:37:12 | 000,009,216 | ---- | M] (MBB Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2011/03/23 10:20:18 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C60x86.sys -- (L1C)
DRV - [2011/02/16 17:52:46 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2011/01/12 22:35:48 | 000,125,672 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2011/01/10 18:16:16 | 000,018,544 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AppleCharger.sys -- (AppleCharger)
DRV - [2010/12/22 05:28:30 | 000,048,128 | ---- | M] (Cambridge Silicon Radio Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bthav.sys -- (csr_a2dp)
DRV - [2010/07/27 09:52:02 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010/05/11 02:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/04/02 09:11:16 | 000,087,536 | ---- | M] (CyberLink Corp.) [2011/05/09 17:25:18] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl -- ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC})
DRV - [2010/02/18 02:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/12/30 11:21:18 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/12/18 11:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2009/09/15 13:59:28 | 000,038,248 | ---- | M] (NVIDIA Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvoclock.sys -- (nvoclock)
DRV - [2009/06/22 16:49:00 | 000,247,320 | ---- | M] (silex technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\sxuptp.sys -- (sxuptp)
DRV - [2008/08/06 16:26:08 | 000,124,928 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/02/12 12:17:40 | 000,033,792 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDRm.sys -- (incdrm)
DRV - [2007/02/12 12:17:24 | 000,031,360 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDPass.sys -- (InCDPass)
DRV - [2007/02/12 12:14:52 | 000,010,624 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\Windows\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2007/02/12 12:14:42 | 000,112,384 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\Windows\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2006/09/24 21:28:46 | 000,005,248 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\System32\speedfan.sys -- (speedfan)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ph.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 A1 53 C5 6A 64 2F 02 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {94E419C3-31B9-40A7-8414-E474140D96EF}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{94E419C3-31B9-40A7-8414-E474140D96EF}: "URL" = http://www.google.co...{outputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://home.speedbit.../?pid=%s&aid=%s"
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.4
FF - user.js..browser.startup.homepage: "http://home.speedbit.../?pid=%s&aid=%s"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/12/13 22:00:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/14 22:22:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/11/24 16:58:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files\Mozilla Firefox2\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox2\plugins [2013/11/24 16:58:08 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011/04/29 22:45:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\MyEminence\AppData\Roaming\IDM\idmmzcc3
[2011/03/12 10:24:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Extensions
[2014/12/13 13:51:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2isryo5x.jamocha\extensions
[2014/09/08 16:11:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2isryo5x.jamocha\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/12/13 13:51:58 | 000,000,000 | ---D | M] ("Flash Video Downloader - YouTube HD Download [4K]") -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2isryo5x.jamocha\extensions\[email protected]
[2014/07/13 00:33:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2k1echgk.SINN\extensions
[2014/04/12 12:42:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7h9u3pwa.AllyEml\extensions
[2014/02/04 17:45:29 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7h9u3pwa.AllyEml\extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}
[2014/04/12 12:14:25 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7h9u3pwa.AllyEml\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/07/13 00:26:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7udqw10n.justbrowse\extensions
[2014/11/09 20:59:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\bpiduon3.Pronjack\extensions
[2014/07/13 00:31:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\e95fwen3.youtube\extensions
[2014/07/13 00:41:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\f0m3bzxo.neweragain\extensions
[2014/07/13 00:35:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\k4aolroc.Witchever\extensions
[2011/11/18 20:09:15 | 000,000,000 | ---D | M] (Mega Manager Integration) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\k4aolroc.Witchever\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2014/07/13 00:37:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\pmsq0194.Desperado\extensions
[2014/07/13 00:40:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\pmw0ypsj.noSa\extensions
[2011/12/05 22:48:07 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\pmw0ypsj.noSa\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/12/05 22:37:07 | 000,000,000 | ---D | M] (Adblock Plus Pop-up Addon) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\pmw0ypsj.noSa\extensions\[email protected]
[2014/07/13 00:44:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\wzlrxbcq.MOCHACHO\extensions
[2013/12/17 18:23:33 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\wzlrxbcq.MOCHACHO\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/01/29 16:14:14 | 000,000,000 | ---D | M] ("Flash Video Downloader") -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\wzlrxbcq.MOCHACHO\extensions\[email protected]
[2014/07/13 00:42:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\xidld2u0.Hastings\extensions
[2014/10/28 17:14:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\yt7spcd8.Serpindor\extensions
[2014/10/28 17:14:54 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\yt7spcd8.Serpindor\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/07/13 00:15:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\ywjnhiw1.default\extensions
[2011/08/16 17:58:55 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\ywjnhiw1.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/10/28 22:39:11 | 000,392,243 | ---- | M] () (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2isryo5x.jamocha\extensions\[email protected]
[2014/09/30 17:02:32 | 000,105,346 | ---- | M] () (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2isryo5x.jamocha\extensions\[email protected]
[2014/11/19 06:41:33 | 000,020,782 | ---- | M] () (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\2isryo5x.jamocha\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
[2014/04/12 12:14:20 | 000,380,083 | ---- | M] () (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7h9u3pwa.AllyEml\extensions\[email protected]
[2014/02/04 17:52:08 | 000,185,839 | ---- | M] () (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7h9u3pwa.AllyEml\extensions\[email protected]
[2014/04/12 12:42:45 | 000,714,654 | ---- | M] () (No name found) -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\7h9u3pwa.AllyEml\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2014/11/09 21:18:44 | 000,002,520 | ---- | M] () -- C:\Users\MyEminence\AppData\Roaming\Mozilla\Firefox\Profiles\ywjnhiw1.default\searchplugins\speedbit.xml
[2013/11/29 16:20:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/08/23 20:54:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/01/22 01:59:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/01/22 01:58:26 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\MyEminence\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2014/12/15 12:32:37 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (Download Accelerator Plus Integration) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CD90BF73-20F6-44EF-993D-BB920303BD2E} - No CLSID value found.
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKCU..\Run: [BitTorrent] C:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [DownloadAccelerator] C:\Program Files\DAP\DAP.EXE (SpeedBit Ltd.)
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O4 - HKCU..\Run: [zASRockInstantBoot] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} http://clients.futur...y/FMSI_v420.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81CE8E85-A8F4-4C39-B093-F1C2DA72357B}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9868F5BD-DB91-49AE-8FF3-F485C69B1313}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E2C173-1BE8-4EEA-84D3-4B07CD078812}: DhcpNameServer = 192.168.0.1 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - Deskscapes - No CLSID value found.
O24 - Desktop WallPaper: C:\po\videocacheview_2\MyMasterChef\QuezonVacation\FromUncleGerryNMom\20141117_091707_tonemapped.jpg
O24 - Desktop BackupWallPaper: C:\po\videocacheview_2\MyMasterChef\QuezonVacation\FromUncleGerryNMom\20141117_091707_tonemapped.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 05:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{04b2a0fd-7254-11e1-9dd2-0025222896a8}\Shell - "" = AutoRun
O33 - MountPoints2\{04b2a0fd-7254-11e1-9dd2-0025222896a8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{07d3489a-7b9d-11de-9c22-0025222896a8}\Shell - "" = AutoRun
O33 - MountPoints2\{07d3489a-7b9d-11de-9c22-0025222896a8}\Shell\AutoRun\command - "" = H:\Autorun.exe
O33 - MountPoints2\{15946b6b-6d5f-11de-8cd9-001e101f4da1}\Shell - "" = AutoRun
O33 - MountPoints2\{15946b6b-6d5f-11de-8cd9-001e101f4da1}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{210892a5-f0d6-11e0-b15d-001e101f859f}\Shell - "" = AutoRun
O33 - MountPoints2\{210892a5-f0d6-11e0-b15d-001e101f859f}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{231ccf19-f34d-11e0-842c-001e101f63cf}\Shell - "" = AutoRun
O33 - MountPoints2\{231ccf19-f34d-11e0-842c-001e101f63cf}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{38d1f3c7-5ea8-11e1-a900-0025222896a8}\Shell - "" = AutoRun
O33 - MountPoints2\{38d1f3c7-5ea8-11e1-a900-0025222896a8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{38d1f3c9-5ea8-11e1-a900-0025222896a8}\Shell - "" = AutoRun
O33 - MountPoints2\{38d1f3c9-5ea8-11e1-a900-0025222896a8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{43597eb5-72ee-11e0-b0c6-001e101f2b52}\Shell - "" = AutoRun
O33 - MountPoints2\{43597eb5-72ee-11e0-b0c6-001e101f2b52}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{46696773-61de-11e1-8fac-0025222896a8}\Shell\AutoRun\command - "" = K:\PMBP_Win.exe
O33 - MountPoints2\{5512e6d5-609e-11e3-8625-9477a1e18dba}\Shell - "" = AutoRun
O33 - MountPoints2\{5512e6d5-609e-11e3-8625-9477a1e18dba}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{5512e6e8-609e-11e3-8625-a3bccb6e203d}\Shell - "" = AutoRun
O33 - MountPoints2\{5512e6e8-609e-11e3-8625-a3bccb6e203d}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{5512e6f4-609e-11e3-8625-9049f7ab1889}\Shell - "" = AutoRun
O33 - MountPoints2\{5512e6f4-609e-11e3-8625-9049f7ab1889}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{5512e6fe-609e-11e3-8625-9efe45c5f993}\Shell - "" = AutoRun
O33 - MountPoints2\{5512e6fe-609e-11e3-8625-9efe45c5f993}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{5512e708-609e-11e3-8625-d644696767c1}\Shell - "" = AutoRun
O33 - MountPoints2\{5512e708-609e-11e3-8625-d644696767c1}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6178bd78-5a68-11e3-816c-74d435355476}\Shell - "" = AutoRun
O33 - MountPoints2\{6178bd78-5a68-11e3-816c-74d435355476}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6178bd9b-5a68-11e3-816c-74d435355476}\Shell - "" = AutoRun
O33 - MountPoints2\{6178bd9b-5a68-11e3-816c-74d435355476}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{88b92766-5cce-11e0-a51c-001e101fe70e}\Shell - "" = AutoRun
O33 - MountPoints2\{88b92766-5cce-11e0-a51c-001e101fe70e}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{88e2c96b-5d8b-11e3-948c-d95ab5731eb1}\Shell - "" = AutoRun
O33 - MountPoints2\{88e2c96b-5d8b-11e3-948c-d95ab5731eb1}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{88e2c987-5d8b-11e3-948c-bae8772016a8}\Shell - "" = AutoRun
O33 - MountPoints2\{88e2c987-5d8b-11e3-948c-bae8772016a8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9541c39c-5cac-11e3-a679-74d435355476}\Shell - "" = AutoRun
O33 - MountPoints2\{9541c39c-5cac-11e3-a679-74d435355476}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b2cc42e8-c064-11e3-989f-001e101f2500}\Shell - "" = AutoRun
O33 - MountPoints2\{b2cc42e8-c064-11e3-989f-001e101f2500}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{d99a7035-49ed-11e0-a4b7-0025222896a8}\Shell - "" = AutoRun
O33 - MountPoints2\{d99a7035-49ed-11e0-a4b7-0025222896a8}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{d99a7045-49ed-11e0-a4b7-001e101f4da1}\Shell - "" = AutoRun
O33 - MountPoints2\{d99a7045-49ed-11e0-a4b7-001e101f4da1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{e805b2d8-6b0f-11de-b10d-0025222896a8}\Shell - "" = AutoRun
O33 - MountPoints2\{e805b2d8-6b0f-11de-b10d-0025222896a8}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{ff813c89-bf71-11e3-8646-74d435355476}\Shell - "" = AutoRun
O33 - MountPoints2\{ff813c89-bf71-11e3-8646-74d435355476}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2099/12/15 19:44:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\Plugins
[2014/12/15 12:38:38 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/12/15 12:38:31 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Local\temp
[2014/12/15 12:30:49 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2014/12/15 11:56:09 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2014/12/14 07:55:38 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/12/14 07:55:38 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/12/14 07:55:38 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/12/14 07:55:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/12/14 07:54:21 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/12/13 22:49:13 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Roaming\AVAST Software
[2014/12/13 22:36:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/12/13 22:36:18 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
[2014/12/13 22:36:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/12/13 22:27:00 | 000,114,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/12/13 22:27:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/12/13 22:26:45 | 000,075,480 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
[2014/12/13 22:07:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
[2014/12/13 22:07:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes Anti-Exploit
[2014/12/13 22:07:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Exploit
[2014/12/13 22:06:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
[2014/12/13 22:06:17 | 000,000,000 | ---D | C] -- C:\Program Files\FileASSASSIN
[2014/12/13 22:00:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014/12/13 22:00:19 | 000,057,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2014/12/13 22:00:18 | 000,423,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys
[2014/12/13 22:00:18 | 000,070,384 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014/12/13 22:00:17 | 000,055,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2014/12/13 22:00:16 | 000,787,800 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014/12/13 22:00:15 | 000,291,352 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014/12/13 22:00:13 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/12/10 22:28:47 | 000,046,592 | ---- | C] (CSR, plc) -- C:\Windows\System32\HFGService_PS.dll
[2014/12/10 09:45:40 | 000,048,128 | ---- | C] (Cambridge Silicon Radio Limited) -- C:\Windows\System32\drivers\bthav.sys
[2014/12/10 03:57:59 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Local\VS Revo Group
[2014/12/10 03:57:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2014/12/10 03:57:53 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
[2014/12/10 03:57:52 | 000,027,192 | ---- | C] (VS Revo Group) -- C:\Windows\System32\drivers\revoflt.sys
[2014/12/10 03:57:50 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2014/12/09 20:25:23 | 000,411,136 | ---- | C] (CSR, plc) -- C:\Windows\System32\HFGService.dll
[2014/12/09 01:28:32 | 000,000,000 | ---D | C] -- C:\BluetoothExchangeFolder
[2014/12/09 00:55:59 | 000,000,000 | ---D | C] -- C:\Drivers
[2014/12/09 00:36:00 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Local\Apps
[2014/12/09 00:35:59 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Local\Deployment
[2014/12/08 22:00:54 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\Documents\Bluetooth Exchange Folder
[2014/12/08 21:54:06 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2014/12/05 23:17:35 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Local\Faculty_of_Organization_a
[2014/12/05 23:14:53 | 000,000,000 | ---D | C] -- C:\Program Files\Remoter for Windows
[2014/12/02 20:09:46 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014/12/02 20:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014/12/02 19:21:44 | 005,006,864 | ---- | C] (AVAST Software) -- C:\Users\Public\Desktop\avast_free_antivirus_setup_online.exe
[2014/12/02 16:46:27 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014/11/26 18:34:15 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\Documents\freenote_export
[2014/11/21 12:13:08 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blade and Soul
[2014/11/21 01:59:34 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Local\BNSUpdater
[2014/11/21 01:23:00 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Roaming\Awesomium
[2014/11/21 01:22:00 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\Documents\BnS
[2014/11/21 00:30:15 | 000,000,000 | ---D | C] -- C:\Users\MyEminence\AppData\Roaming\REngLauncher
[2014/11/20 23:13:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blade and Soul
[4 C:\*.tmp files -> C:\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/12/19 02:28:25 | 000,114,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014/12/19 02:24:03 | 000,647,326 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/12/19 02:24:03 | 000,120,356 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/12/19 02:23:25 | 000,004,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/12/19 02:23:25 | 000,004,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/12/19 02:17:45 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/12/19 02:17:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/12/19 02:15:40 | 000,001,208 | ---- | M] () -- C:\Users\MyEminence\Desktop\My DAP Downloads.lnk
[2014/12/15 13:13:31 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2014/12/15 13:04:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/12/15 12:32:37 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2014/12/14 23:44:04 | 000,000,155 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2014/12/14 07:51:41 | 000,000,899 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/12/13 22:06:17 | 000,000,852 | ---- | M] () -- C:\Users\Public\Desktop\FileASSASSIN.lnk
[2014/12/13 22:05:49 | 000,002,032 | ---- | M] () -- C:\Users\MyEminence\AppData\Local\d3d9caps.dat
[2014/12/13 22:00:46 | 000,001,871 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014/12/13 22:00:37 | 000,787,800 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014/12/13 22:00:29 | 000,423,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys
[2014/12/13 22:00:25 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\avast! Emergency Update.job
[2014/12/13 22:00:14 | 000,206,248 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014/12/13 22:00:14 | 000,070,384 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014/12/13 22:00:14 | 000,057,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2014/12/13 22:00:14 | 000,055,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2014/12/13 22:00:14 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014/12/13 22:00:14 | 000,024,184 | ---- | M] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014/12/13 22:00:13 | 000,291,352 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014/12/13 22:00:13 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/12/12 18:14:01 | 000,000,107 | ---- | M] () -- C:\Windows\System32\list
[2014/12/12 16:28:30 | 000,000,300 | ---- | M] () -- C:\Users\MyEminence\Desktop\MyEminence - Shortcut.lnk
[2014/12/12 06:10:22 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/12/11 23:02:08 | 000,070,656 | ---- | M] () -- C:\Users\MyEminence\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/12/10 03:57:56 | 000,001,089 | ---- | M] () -- C:\Users\MyEminence\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2014/12/10 03:57:56 | 000,001,065 | ---- | M] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2014/12/09 18:42:11 | 000,254,534 | ---- | M] () -- C:\Users\MyEminence\Documents\cc_20141209_184149.reg
[2014/12/09 16:58:31 | 000,001,846 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2014/12/09 01:28:16 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_CsrBtPort_01009.Wdf
[2014/12/09 01:28:06 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_csrusb_01009.Wdf
[2014/12/02 19:23:23 | 005,006,864 | ---- | M] (AVAST Software) -- C:\Users\Public\Desktop\avast_free_antivirus_setup_online.exe
[2014/12/02 18:13:08 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2014/12/01 22:01:27 | 000,000,175 | ---- | M] () -- C:\Windows\System32\drivers\aswSnx.sys.sum
[2014/11/30 21:06:29 | 000,000,212 | ---- | M] () -- C:\PowerDVD10.sim
[2014/11/21 06:14:16 | 000,051,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
[2014/11/21 06:14:10 | 000,075,480 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
[2014/11/21 06:14:06 | 000,023,256 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2014/11/20 23:40:28 | 000,000,783 | ---- | M] () -- C:\Users\Public\Desktop\Blade and Soul.lnk
[4 C:\*.tmp files -> C:\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/12/14 07:55:38 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/12/14 07:55:38 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/12/14 07:55:38 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/12/14 07:55:38 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/12/14 07:55:38 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/12/13 22:36:20 | 000,000,899 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/12/13 22:06:17 | 000,000,852 | ---- | C] () -- C:\Users\Public\Desktop\FileASSASSIN.lnk
[2014/12/13 22:00:46 | 000,001,889 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
[2014/12/13 22:00:46 | 000,001,871 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014/12/13 22:00:25 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\avast! Emergency Update.job
[2014/12/13 22:00:19 | 000,206,248 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014/12/13 22:00:18 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014/12/13 22:00:17 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014/12/12 18:13:59 | 000,000,107 | ---- | C] () -- C:\Windows\System32\list
[2014/12/12 16:28:30 | 000,000,300 | ---- | C] () -- C:\Users\MyEminence\Desktop\MyEminence - Shortcut.lnk
[2014/12/10 03:57:56 | 000,001,089 | ---- | C] () -- C:\Users\MyEminence\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2014/12/10 03:57:56 | 000,001,065 | ---- | C] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2014/12/09 18:41:52 | 000,254,534 | ---- | C] () -- C:\Users\MyEminence\Documents\cc_20141209_184149.reg
[2014/12/09 01:28:16 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_CsrBtPort_01009.Wdf
[2014/12/09 01:28:06 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_csrusb_01009.Wdf
[2014/12/01 22:01:27 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSnx.sys.sum
[2014/11/30 21:06:29 | 000,000,212 | ---- | C] () -- C:\PowerDVD10.sim
[2014/11/20 23:40:28 | 000,000,783 | ---- | C] () -- C:\Users\Public\Desktop\Blade and Soul.lnk
[2014/04/30 19:47:48 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2014/04/30 19:47:48 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2014/04/30 19:47:48 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2014/04/30 19:47:48 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2014/04/30 19:47:46 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2013/11/26 17:29:10 | 000,031,272 | ---- | C] () -- C:\Windows\System32\AppleChargerSrv.exe
[2013/11/26 17:29:10 | 000,018,544 | ---- | C] () -- C:\Windows\System32\drivers\AppleCharger.sys
[2013/11/26 17:12:35 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2011/08/16 20:09:04 | 000,001,100 | ---- | C] () -- C:\Users\MyEminence\AppData\Local\d3d8caps.dat
[2011/03/12 14:56:50 | 000,000,036 | ---- | C] () -- C:\Users\MyEminence\AppData\Local\housecall.guid.cache
[2011/02/25 10:44:28 | 000,070,656 | ---- | C] () -- C:\Users\MyEminence\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/21 13:52:50 | 000,002,032 | ---- | C] () -- C:\Users\MyEminence\AppData\Local\d3d9caps.dat
[2010/01/31 11:06:18 | 000,008,046 | ---- | C] () -- C:\Program Files\Common Files\setupBanner.jpg
[2009/04/14 16:07:42 | 000,037,607 | ---- | C] () -- C:\Program Files\Common Files\license.rtf
========== ZeroAccess Check ==========
[2006/11/02 20:53:06 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2011/01/22 00:35:22 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 21:19:30 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 21:19:19 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/03/02 05:36:24 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Anvil Studio
[2011/05/18 06:44:30 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\AnvSoft
[2014/06/29 00:55:44 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Audacity
[2014/12/13 22:49:13 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\AVAST Software
[2014/11/21 01:23:00 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Awesomium
[2014/12/19 02:39:17 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\BitTorrent
[2012/02/28 20:27:15 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Canon
[2011/04/10 20:48:01 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\DMCache
[2011/07/21 21:42:59 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\fltk.org
[2011/02/23 08:55:24 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Foxit
[2011/02/23 08:55:25 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Foxit Software
[2011/10/07 02:31:00 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\HandBrake
[2014/06/04 08:59:18 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\HDRsoft
[2011/10/27 15:14:16 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\IDM
[2011/11/17 22:02:12 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Megaupload
[2011/10/07 00:30:59 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\mkvtoolnix
[2013/03/11 02:48:32 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\MotioninJoy
[2011/11/26 01:35:58 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Notepad++
[2014/01/27 20:59:44 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Opera Software
[2014/11/24 01:36:10 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\REngLauncher
[2011/09/16 08:07:06 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\runic games
[2014/09/14 21:26:11 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Samsung
[2012/02/19 23:24:18 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\SystemRequirementsLab
[2011/10/11 06:59:39 | 000,000,000 | ---D | M] -- C:\Users\MyEminence\AppData\Roaming\Thinstall
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2011/09/20 01:58:50 | 000,521,669 | ---- | M] ()(C:\Users\MyEminence\Documents\???????????? - The best of The Teen Girls - Update Hard.htm) -- C:\Users\MyEminence\Documents\พิมพ์หน้านี้ - The best of The Teen Girls - Update Hard.htm
[2011/09/20 01:46:47 | 000,521,669 | ---- | C] ()(C:\Users\MyEminence\Documents\???????????? - The best of The Teen Girls - Update Hard.htm) -- C:\Users\MyEminence\Documents\พิมพ์หน้านี้ - The best of The Teen Girls - Update Hard.htm
[2011/09/20 01:46:45 | 000,000,000 | ---D | M](C:\Users\MyEminence\Documents\???????????? - The best of The Teen Girls - Update Hard_files) -- C:\Users\MyEminence\Documents\พิมพ์หน้านี้ - The best of The Teen Girls - Update Hard_files
[2011/09/20 01:46:23 | 000,000,000 | ---D | C](C:\Users\MyEminence\Documents\???????????? - The best of The Teen Girls - Update Hard_files) -- C:\Users\MyEminence\Documents\พิมพ์หน้านี้ - The best of The Teen Girls - Update Hard_files
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:553CA6CA
< End of report >