i've run OTL, exehelper, Rkill, goored with no significant results, though i can supply logs if needed
also run many anti malware programs
avast
spybot
superantispyware
mbam
no significant results from them
also getting an error when i try to access my computer from start menu saying "The remote procedure call failed and did not execute" a few minutes after boot
dont know what could be wrong with it, i only installed windows a few days ago, my guess its some sort of virus causing it
OTL report:
OTL logfile created on: 4/24/2011 6:34:54 PM - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = E:\Documents and settings\My documents\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 81.00% Memory free 8.00 Gb Paging File | 7.00 Gb Available in Paging File | 90.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 55.80 Gb Total Space | 28.10 Gb Free Space | 50.36% Space Free | Partition Type: NTFS Drive E: | 292.97 Gb Total Space | 231.07 Gb Free Space | 78.87% Space Free | Partition Type: NTFS Drive F: | 638.54 Gb Total Space | 327.41 Gb Free Space | 51.28% Space Free | Partition Type: NTFS Drive I: | 7.45 Gb Total Space | 0.17 Gb Free Space | 2.31% Space Free | Partition Type: FAT32 Computer Name: AWESOMEEXTREME2 | User Name: Kieran | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011/04/24 18:25:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- E:\Documents and settings\My documents\Downloads\OTL.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2011/04/24 18:25:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- E:\Documents and settings\My documents\Downloads\OTL.exe MOD - [2010/11/20 03:55:10 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2011/04/21 18:21:58 | 000,203,776 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2011/03/09 01:06:44 | 000,365,568 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service) SRV:[b]64bit:[/b] - [2010/11/15 11:08:10 | 005,716,848 | ---- | M] (Wacom Technology, Corp.) [Auto | Stopped] -- C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe -- (TabletServiceWacom) SRV:[b]64bit:[/b] - [2010/06/30 03:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE) SRV:[b]64bit:[/b] - [2010/06/29 06:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner) SRV:[b]64bit:[/b] - [2010/06/29 06:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner) SRV:[b]64bit:[/b] - [2010/06/29 06:57:15 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV:[b]64bit:[/b] - [2010/06/17 06:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager) SRV:[b]64bit:[/b] - [2009/07/14 11:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2011/04/21 14:03:33 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009/06/11 07:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2011/04/21 18:19:54 | 009,258,496 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2011/04/21 18:16:03 | 000,300,544 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2010/11/20 05:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/11/20 05:32:48 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2010/11/20 05:32:48 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010/11/20 03:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010/11/17 22:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:[b]64bit:[/b] - [2010/11/02 16:07:54 | 000,013,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor) DRV:[b]64bit:[/b] - [2010/10/25 10:59:32 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter) DRV:[b]64bit:[/b] - [2010/10/25 10:59:28 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid) DRV:[b]64bit:[/b] - [2010/06/29 06:33:00 | 000,061,008 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2010/06/09 17:10:16 | 000,046,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\nm3.sys -- (nm3) DRV:[b]64bit:[/b] - [2010/05/31 13:46:50 | 000,333,928 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2010/04/27 11:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:[b]64bit:[/b] - [2010/04/27 11:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:[b]64bit:[/b] - [2010/02/18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64) DRV:[b]64bit:[/b] - [2010/02/18 04:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV) DRV:[b]64bit:[/b] - [2010/02/18 04:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL) DRV:[b]64bit:[/b] - [2009/07/16 13:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor) DRV:[b]64bit:[/b] - [2009/07/14 11:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/14 11:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/14 11:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/06/20 12:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2009/06/11 06:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs) DRV:[b]64bit:[/b] - [2009/06/11 06:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/11 06:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/11 06:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/11 06:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009/02/24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus) DRV - [2011/04/24 16:33:17 | 000,029,392 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWow64\drivers\SECDRV.SYS -- (secdrv) DRV - [2009/02/24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://iat.ninemsn.com.au/tickler/default.aspx IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D9 0F 06 7D C6 FF CB 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/\r" FF - prefs.js..extensions.enabledItems: [email protected]:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4 FF - prefs.js..extensions.enabledItems: [email protected]:0.6.20101009 FF - prefs.js..keyword.URL: "http://au.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_au&p=" FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/24 14:25:19 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/21 12:52:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kieran\AppData\Roaming\Mozilla\Extensions [2011/04/24 14:25:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2011/04/21 12:00:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} File not found (No name found) -- [2011/03/19 03:53:24 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll [2010/01/01 18:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml O1 HOSTS File: ([2011/04/24 18:14:36 | 000,435,951 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 14994 more lines... O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKCU..\Run: [Steam] E:\Program Files\Steam\steam.exe (Valve Corporation) O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O18:[b]64bit:[/b] - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:[b]64bit:[/b] - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011/04/08 12:12:54 | 000,000,000 | ---D | M] - I:\Autopatcher XP & 7 -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011/04/24 17:05:50 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\ElevatedDiagnostics [2011/04/24 17:05:29 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\Diagnostics [2011/04/24 16:44:55 | 000,000,000 | ---D | C] -- C:\Windows\pss [2011/04/24 16:37:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam [2011/04/24 16:34:45 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\AMD [2011/04/24 16:20:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy [2011/04/24 16:20:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2011/04/24 16:20:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy [2011/04/24 16:17:49 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\SUPERAntiSpyware.com [2011/04/24 16:17:49 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com [2011/04/24 16:17:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware [2011/04/24 16:17:47 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE [2011/04/24 16:17:46 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2011/04/24 16:04:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2011/04/24 16:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011/04/24 15:57:13 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Kieran\Desktop\HijackThis.exe [2011/04/24 15:45:45 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Malwarebytes [2011/04/24 15:45:42 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2011/04/24 15:45:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/04/24 15:45:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/04/24 15:45:39 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011/04/24 15:45:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011/04/24 14:21:40 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Kieran\Desktop\mbam-setup-1.50.1.1100.exe [2011/04/24 14:00:54 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Desktop\n7e7md9l.default [2011/04/24 13:30:34 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Documents\Network Monitor 3 [2011/04/24 13:30:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Network Monitor 3.4 [2011/04/24 13:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Network Monitor 3 [2011/04/24 13:26:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2011/04/24 12:50:01 | 000,000,000 | ---D | C] -- C:\Windows\.jagex_cache_32 [2011/04/24 12:44:42 | 000,053,248 | ---- | C] (vbAccelerator) -- C:\Windows\SysWow64\SSUBTMR6.DLL [2011/04/24 12:44:41 | 000,010,752 | ---- | C] (Almeida & Andrade Ltda) -- C:\Windows\SysWow64\aamd532.dll [2011/04/24 12:14:55 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\WinRAR [2011/04/24 12:14:55 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2011/04/24 12:14:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2011/04/24 12:14:55 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2011/04/23 16:32:14 | 000,000,000 | ---D | C] -- C:\Program Files\EA Games [2011/04/23 16:27:12 | 000,000,000 | ---D | C] -- C:\Windows\Sun [2011/04/23 16:14:04 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [2011/04/23 16:13:24 | 000,729,088 | ---- | C] (Indigo Rose Corporation) -- C:\Windows\iun6002.exe [2011/04/23 16:13:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DesertCombat [2011/04/23 16:10:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES [2011/04/23 16:09:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EA GAMES [2011/04/23 13:36:58 | 000,000,000 | ---D | C] -- C:\Mklinks [2011/04/23 13:33:49 | 000,000,000 | ---D | C] -- C:\Derp [2011/04/23 12:37:05 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicDisc [2011/04/23 12:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc [2011/04/23 12:37:02 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysWow64\drivers\mcdbus.sys [2011/04/23 12:37:02 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysNative\drivers\mcdbus.sys [2011/04/23 12:37:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicDisc [2011/04/23 01:47:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock [2011/04/23 01:47:05 | 000,000,000 | ---D | C] -- C:\Program Files\PeerBlock [2011/04/22 22:34:32 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2011/04/22 22:34:32 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Adobe Mini Bridge CS5 [2011/04/22 22:25:07 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\WTablet [2011/04/22 22:25:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TabletPlugins [2011/04/22 22:25:01 | 000,013,312 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacmoumonitor.sys [2011/04/22 22:25:01 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet [2011/04/22 22:24:59 | 000,012,848 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacommousefilter.sys [2011/04/22 22:24:55 | 000,016,168 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacomvhid.sys [2011/04/22 22:24:54 | 000,751,472 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wacom_Tablet.dll [2011/04/22 22:24:54 | 000,644,976 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wacom_Tablet.dll [2011/04/22 22:24:54 | 000,600,432 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wintab32.dll [2011/04/22 22:24:54 | 000,506,736 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wintab32.dll [2011/04/22 22:24:52 | 000,000,000 | ---D | C] -- C:\Program Files\Tablet [2011/04/22 19:31:07 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\CDisplayEx [2011/04/22 19:30:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplayEx [2011/04/22 19:30:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDisplayEx [2011/04/22 14:56:59 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe [2011/04/22 14:37:00 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2011/04/22 14:36:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2011/04/22 14:30:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2011/04/22 09:46:57 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Desktop\New folder [2011/04/22 03:39:49 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2011/04/22 02:40:41 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2011/04/22 02:40:31 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2011/04/21 21:31:33 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Media Player Classic [2011/04/21 19:13:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview [2011/04/21 19:04:12 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll [2011/04/21 19:03:52 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll [2011/04/21 19:02:01 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders [2011/04/21 18:55:24 | 000,000,000 | ---D | C] -- C:\Users\Kieran\dwhelper [2011/04/21 18:43:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 10.0 [2011/04/21 18:40:05 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Desktop\42zby3rn.default [2011/04/21 18:28:36 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI [2011/04/21 18:28:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center [2011/04/21 18:28:32 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD [2011/04/21 18:26:06 | 000,000,000 | ---D | C] -- C:\Soldat [2011/04/21 18:21:54 | 000,203,776 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe [2011/04/21 18:17:38 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll [2011/04/21 18:16:34 | 000,480,256 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe [2011/04/21 18:16:27 | 000,016,384 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll [2011/04/21 16:55:00 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft [2011/04/21 15:44:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA [2011/04/21 14:27:25 | 000,121,936 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2011/04/21 14:27:25 | 000,061,008 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2011/04/21 14:27:25 | 000,051,280 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswTdi.sys [2011/04/21 14:27:25 | 000,028,752 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswRdr.sys [2011/04/21 14:27:25 | 000,020,048 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys [2011/04/21 14:27:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2011/04/21 14:27:19 | 000,165,032 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe [2011/04/21 14:27:19 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\Windows\avastSS.scr [2011/04/21 14:27:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software [2011/04/21 14:27:18 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software [2011/04/21 13:23:53 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Tracing [2011/04/21 12:52:06 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Mozilla [2011/04/21 12:52:06 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\Mozilla [2011/04/21 12:43:02 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\ATI [2011/04/21 12:43:02 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\ATI [2011/04/21 12:39:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics [2011/04/21 12:39:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Renesas Electronics [2011/04/21 12:38:49 | 000,333,928 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys [2011/04/21 12:37:29 | 000,016,896 | ---- | C] (ASUS) -- C:\Windows\AsTaskSched.dll [2011/04/21 12:36:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM [2011/04/21 12:36:37 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2011/04/21 12:36:31 | 002,719,504 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll [2011/04/21 12:36:31 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll [2011/04/21 12:36:31 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll [2011/04/21 12:36:31 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll [2011/04/21 12:36:31 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll [2011/04/21 12:36:29 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll [2011/04/21 12:36:29 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll [2011/04/21 12:36:29 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll [2011/04/21 12:36:29 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll [2011/04/21 12:36:29 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll [2011/04/21 12:36:29 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll [2011/04/21 12:36:28 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll [2011/04/21 12:36:28 | 000,325,904 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll [2011/04/21 12:36:27 | 000,474,896 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll [2011/04/21 12:36:27 | 000,321,440 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll [2011/04/21 12:36:26 | 001,325,328 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll [2011/04/21 12:36:26 | 001,178,384 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll [2011/04/21 12:36:26 | 001,110,800 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll [2011/04/21 12:36:26 | 000,504,592 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll [2011/04/21 12:36:26 | 000,315,152 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll [2011/04/21 12:36:26 | 000,268,560 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll [2011/04/21 12:36:26 | 000,265,488 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll [2011/04/21 12:36:26 | 000,123,664 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll [2011/04/21 12:36:26 | 000,123,152 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll [2011/04/21 12:36:25 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information [2011/04/21 12:36:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek [2011/04/21 12:36:23 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp [2011/04/21 12:36:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield [2011/04/21 12:16:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies [2011/04/21 12:16:09 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies [2011/04/21 12:16:04 | 000,058,880 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst.dll [2011/04/21 12:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies [2011/04/21 12:15:46 | 000,000,000 | ---D | C] -- C:\Program Files\ATI [2011/04/21 12:15:10 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies [2011/04/21 12:08:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live [2011/04/21 12:08:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live [2011/04/21 12:08:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive [2011/04/21 12:03:21 | 000,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\Windows\SysWow64\lameACM.acm [2011/04/21 12:03:21 | 000,237,568 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll [2011/04/21 12:03:21 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\SysWow64\ac3acm.acm [2011/04/21 12:03:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack [2011/04/21 12:03:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack [2011/04/21 12:01:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics [2011/04/21 12:01:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Auslogics [2011/04/21 12:00:53 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\uTorrent [2011/04/21 12:00:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent [2011/04/21 12:00:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2011/04/21 12:00:53 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2011/04/21 12:00:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2011/04/21 12:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2011/04/21 12:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2011/04/21 11:58:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2011/04/21 11:58:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2011/04/21 11:58:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2011/04/21 11:58:37 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Macromedia [2011/04/21 11:58:36 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Adobe [2011/04/21 11:57:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2011/04/21 11:57:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2011/04/21 11:57:17 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2011/04/21 11:56:18 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2011/04/21 11:56:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2011/04/21 11:51:47 | 000,232,648 | ---- | C] (Secure By Design Inc.) -- C:\Users\Kieran\Desktop\Ninite_Air_Auslogics_NET_Firefox_Flash_Flash_IE_Installer.exe [2011/04/21 11:50:04 | 000,000,000 | R--D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011/04/21 11:50:04 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Searches [2011/04/21 11:50:04 | 000,000,000 | R--D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011/04/21 11:50:04 | 000,000,000 | -H-D | C] -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned [2011/04/21 11:49:58 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Identities [2011/04/21 11:49:57 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Contacts [2011/04/21 11:49:56 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\VirtualStore [2011/04/21 11:49:54 | 000,000,000 | --SD | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Videos [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Saved Games [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Pictures [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Music [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Links [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Favorites [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Downloads [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\My Documents [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\Desktop [2011/04/21 11:49:54 | 000,000,000 | R--D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\AppData\Local\Temporary Internet Files [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Templates [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Start Menu [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\SendTo [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Recent [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\PrintHood [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\NetHood [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Documents\My Videos [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Documents\My Pictures [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Documents\My Music [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\My Documents [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Local Settings [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\AppData\Local\History [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Cookies [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\Application Data [2011/04/21 11:49:54 | 000,000,000 | -HSD | C] -- C:\Users\Kieran\AppData\Local\Application Data [2011/04/21 11:49:54 | 000,000,000 | -H-D | C] -- C:\Users\Kieran\AppData [2011/04/21 11:49:54 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\Temp [2011/04/21 11:49:54 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\Microsoft [2011/04/21 11:49:54 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Media Center Programs [2011/04/21 11:49:46 | 000,000,000 | -HSD | C] -- C:\Recovery [2011/04/21 11:48:26 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011/04/24 18:31:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/04/24 18:31:30 | 3219,791,872 | -HS- | M] () -- C:\hiberfil.sys [2011/04/24 18:30:42 | 000,012,720 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/04/24 18:30:42 | 000,012,720 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/04/24 18:14:36 | 000,435,951 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2011/04/24 16:59:31 | 000,007,602 | ---- | M] () -- C:\Users\Kieran\AppData\Local\Resmon.ResmonCfg [2011/04/24 16:39:17 | 000,771,550 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011/04/24 16:39:17 | 000,655,438 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011/04/24 16:39:17 | 000,118,564 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011/04/24 16:33:17 | 000,029,392 | ---- | M] () -- C:\Windows\SysWow64\drivers\SECDRV.SYS [2011/04/24 16:22:46 | 000,250,943 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20110424-181436.backup [2011/04/24 16:20:58 | 000,001,286 | ---- | M] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk [2011/04/24 16:20:58 | 000,001,262 | ---- | M] () -- C:\Users\Kieran\Desktop\Spybot - Search & Destroy.lnk [2011/04/24 16:17:47 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2011/04/24 16:06:03 | 000,014,284 | ---- | M] () -- C:\Users\Kieran\Desktop\cc_20110424_160556.reg [2011/04/24 16:04:42 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011/04/24 15:45:42 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/24 14:25:19 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011/04/24 14:24:45 | 004,826,928 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2011/04/24 14:21:40 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Kieran\Desktop\mbam-setup-1.50.1.1100.exe [2011/04/24 14:19:33 | 000,765,362 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/04/24 13:30:31 | 000,001,016 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Network Monitor 3.4.lnk [2011/04/24 13:28:47 | 000,000,129 | ---- | M] () -- C:\Users\Kieran\jagex_runescape_preferences2.dat [2011/04/24 12:57:16 | 000,000,034 | ---- | M] () -- C:\Users\Kieran\jagex_runescape_preferences.dat [2011/04/24 12:14:55 | 000,000,997 | ---- | M] () -- C:\Users\Public\Desktop\WinRAR.lnk [2011/04/23 16:42:27 | 000,000,532 | ---- | M] () -- C:\Windows\eReg.dat [2011/04/23 16:13:34 | 000,002,152 | ---- | M] () -- C:\Users\Kieran\Desktop\DesertCombat.lnk [2011/04/23 16:11:30 | 000,729,088 | ---- | M] (Indigo Rose Corporation) -- C:\Windows\iun6002.exe [2011/04/23 12:37:06 | 000,000,957 | ---- | M] () -- C:\Users\Kieran\Desktop\MagicDisc.lnk [2011/04/23 02:05:25 | 000,000,041 | ---- | M] () -- C:\Users\Kieran\Desktop\Standby.bat [2011/04/23 01:47:05 | 000,001,736 | ---- | M] () -- C:\Users\Kieran\Desktop\PeerBlock.lnk [2011/04/22 19:30:27 | 000,001,059 | ---- | M] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\CDisplayEx.lnk [2011/04/22 19:30:27 | 000,001,035 | ---- | M] () -- C:\Users\Kieran\Desktop\CDisplayEx.lnk [2011/04/22 14:26:57 | 000,001,794 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20110424-162246.backup [2011/04/22 02:42:20 | 000,041,962 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2011/04/22 02:42:20 | 000,041,962 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2011/04/21 18:22:25 | 000,790,592 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap [2011/04/21 18:21:58 | 000,203,776 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe [2011/04/21 18:19:56 | 000,790,592 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap [2011/04/21 18:19:27 | 000,227,586 | ---- | M] () -- C:\Windows\SysNative\atiicdxx.dat [2011/04/21 18:19:06 | 000,058,880 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst.dll [2011/04/21 18:18:27 | 000,030,831 | ---- | M] () -- C:\Windows\atiogl.xml [2011/04/21 18:17:50 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll [2011/04/21 18:16:39 | 000,480,256 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe [2011/04/21 18:16:28 | 000,016,384 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll [2011/04/21 18:16:25 | 000,003,155 | ---- | M] () -- C:\Windows\SysWow64\atipblag.dat [2011/04/21 18:16:25 | 000,003,155 | ---- | M] () -- C:\Windows\SysNative\atipblag.dat [2011/04/21 18:16:19 | 000,152,384 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb [2011/04/21 14:27:25 | 000,001,852 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2011/04/21 14:27:25 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2011/04/21 13:05:53 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2011/04/21 12:52:07 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat [2011/04/21 12:42:49 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin [2011/04/21 12:39:13 | 000,001,769 | ---- | M] () -- C:\Windows\Language_trs.ini [2011/04/21 12:37:29 | 000,016,896 | ---- | M] (ASUS) -- C:\Windows\AsTaskSched.dll [2011/04/21 12:33:12 | 000,030,481 | ---- | M] () -- C:\Windows\Ascd_tmp.ini [2011/04/21 12:08:20 | 000,002,108 | ---- | M] () -- C:\Users\Public\Desktop\Windows Live Messenger .lnk [2011/04/21 12:03:22 | 000,001,295 | ---- | M] () -- C:\Users\Public\Desktop\Media Player Classic.lnk [2011/04/21 12:01:35 | 000,001,250 | ---- | M] () -- C:\Users\Public\Desktop\Auslogics Disk Defrag.lnk [2011/04/21 12:00:53 | 000,000,947 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2011/04/21 11:51:50 | 000,232,648 | ---- | M] (Secure By Design Inc.) -- C:\Users\Kieran\Desktop\Ninite_Air_Auslogics_NET_Firefox_Flash_Flash_IE_Installer.exe [2011/04/21 11:50:23 | 000,001,441 | ---- | M] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/03/29 18:00:00 | 000,080,896 | ---- | M] () -- C:\Windows\SysWow64\ff_vfw.dll [2011/03/29 18:00:00 | 000,000,038 | ---- | M] () -- C:\Windows\avisplitter.ini [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011/04/24 16:33:17 | 000,029,392 | ---- | C] () -- C:\Windows\SysWow64\drivers\SECDRV.SYS [2011/04/24 16:20:58 | 000,001,286 | ---- | C] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk [2011/04/24 16:20:58 | 000,001,262 | ---- | C] () -- C:\Users\Kieran\Desktop\Spybot - Search & Destroy.lnk [2011/04/24 16:17:47 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2011/04/24 16:06:00 | 000,014,284 | ---- | C] () -- C:\Users\Kieran\Desktop\cc_20110424_160556.reg [2011/04/24 16:04:42 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011/04/24 15:45:42 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/24 14:25:19 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2011/04/24 14:25:19 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011/04/24 13:30:31 | 000,001,016 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Network Monitor 3.4.lnk [2011/04/24 13:28:33 | 000,765,362 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/04/24 12:54:31 | 000,000,129 | ---- | C] () -- C:\Users\Kieran\jagex_runescape_preferences2.dat [2011/04/24 12:50:21 | 000,000,034 | ---- | C] () -- C:\Users\Kieran\jagex_runescape_preferences.dat [2011/04/24 12:14:56 | 000,000,997 | ---- | C] () -- C:\Users\Public\Desktop\WinRAR.lnk [2011/04/23 16:13:34 | 000,002,152 | ---- | C] () -- C:\Users\Kieran\Desktop\DesertCombat.lnk [2011/04/23 16:11:14 | 000,000,532 | ---- | C] () -- C:\Windows\eReg.dat [2011/04/23 12:37:06 | 000,000,957 | ---- | C] () -- C:\Users\Kieran\Desktop\MagicDisc.lnk [2011/04/23 02:04:49 | 000,000,041 | ---- | C] () -- C:\Users\Kieran\Desktop\Standby.bat [2011/04/23 01:47:05 | 000,001,736 | ---- | C] () -- C:\Users\Kieran\Desktop\PeerBlock.lnk [2011/04/22 19:30:27 | 000,001,059 | ---- | C] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\CDisplayEx.lnk [2011/04/22 19:30:27 | 000,001,035 | ---- | C] () -- C:\Users\Kieran\Desktop\CDisplayEx.lnk [2011/04/22 14:37:05 | 000,001,075 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5 (64 Bit).lnk [2011/04/22 14:36:36 | 000,001,173 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk [2011/04/22 14:35:59 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk [2011/04/22 02:42:16 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2011/04/22 02:42:16 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2011/04/22 02:40:31 | 3219,791,872 | -HS- | C] () -- C:\hiberfil.sys [2011/04/21 19:04:22 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd [2011/04/21 19:04:11 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml [2011/04/21 19:03:54 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml [2011/04/21 19:03:54 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml [2011/04/21 19:03:54 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml [2011/04/21 18:22:08 | 000,790,592 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap [2011/04/21 18:19:43 | 000,790,592 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap [2011/04/21 18:19:20 | 000,227,586 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat [2011/04/21 18:18:25 | 000,030,831 | ---- | C] () -- C:\Windows\atiogl.xml [2011/04/21 18:16:21 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/04/21 18:16:21 | 000,003,155 | ---- | C] () -- C:\Windows\SysNative\atipblag.dat [2011/04/21 18:16:04 | 000,152,384 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb [2011/04/21 14:27:25 | 000,001,852 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2011/04/21 14:27:25 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt [2011/04/21 13:09:08 | 000,007,602 | ---- | C] () -- C:\Users\Kieran\AppData\Local\Resmon.ResmonCfg [2011/04/21 13:05:53 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2011/04/21 12:52:07 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2011/04/21 12:42:49 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011/04/21 12:38:49 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll [2011/04/21 12:32:52 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini [2011/04/21 12:32:50 | 000,030,481 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [2011/04/21 12:08:21 | 000,002,108 | ---- | C] () -- C:\Users\Public\Desktop\Windows Live Messenger .lnk [2011/04/21 12:03:23 | 000,001,295 | ---- | C] () -- C:\Users\Public\Desktop\Media Player Classic.lnk [2011/04/21 12:03:21 | 000,631,808 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2011/04/21 12:03:21 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2011/04/21 12:03:21 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2011/04/21 12:03:21 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2011/04/21 12:03:21 | 000,000,414 | ---- | C] () -- C:\Windows\SysWow64\lame_acm.xml [2011/04/21 12:03:21 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/04/21 12:01:36 | 000,001,250 | ---- | C] () -- C:\Users\Public\Desktop\Auslogics Disk Defrag.lnk [2011/04/21 12:00:53 | 000,000,947 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk [2011/04/21 11:50:23 | 000,001,441 | ---- | C] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/04/21 11:50:06 | 000,001,413 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2011/04/21 11:50:05 | 000,001,447 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011/04/21 11:49:54 | 000,000,290 | ---- | C] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2011/04/21 11:49:54 | 000,000,272 | ---- | C] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2009/07/14 15:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009/07/14 12:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009/07/14 12:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009/07/14 10:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009/07/14 09:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009/07/14 07:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009/06/11 07:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat [2009/04/02 22:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS [2009/03/30 16:32:40 | 000,032,768 | R--- | C] () -- C:\Windows\DAODx.exe [color=#E56717]========== LOP Check ==========[/color] [2011/04/22 19:58:26 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\CDisplayEx [2011/04/22 22:34:32 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2011/04/23 14:49:03 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\uTorrent [2009/07/14 15:08:49 | 000,006,372 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] < End of report >