This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Trouble [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I've recently reinstalled windows and had to use windows update and manually reinstall some drivers.
It's Windows Vis Home Prem SP2
Yesterday I had a suspicion I donwloaded a trojan and upon rebooting immediately in safe mode MBAM found and deleted 5 threats.
The only reason I'm posting today is because i learned the hard way how trojans can be extremely difficult to detect and delete, so I would really appreciate the extra help just to ensure I managed to get the little tyke before it had a chance to wreak any havoc. I have only been running in safemode w/networking since the attack.
Thanks :)

PS. Avast (free version) didn't pick it up, would MSE be a more reliable antivirus? I've been recommended it…

OTL.txt:
OTL logfile created on: 02/04/2012 16:56:01 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\James\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.93 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 82.68% Memory free
6.06 Gb Paging File | 5.72 Gb Available in Paging File | 94.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.33 Gb Total Space | 153.56 Gb Free Space | 69.07% Space Free | Partition Type: NTFS
Drive D: | 10.55 Gb Total Space | 1.80 Gb Free Space | 17.04% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\James\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9134
IE - HKCU\..\SearchScopes,DefaultScope = {E88E0043-C9D4-4e33-8555-FEE4F5B63060}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={79F9CB1…mp;d=2012-03-30 10:51:23&v;=10.2.0.3&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060}: "URL" = http://go.mail.ru/search?q={searchTerms}&a;…n=1&fr;=ietb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "http://www.mail.ru/"
FF - prefs.js..browser.search.defaulturl: "http://go.mail.ru/search?fr=fftb&utf8in;&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {ab91efd4-6975-4081-8552-1b3922ed79e2}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:7.0.1426
FF - prefs.js..keyword.URL: "http://go.mail.ru/search?utf8in=1&fr;=fftbUFix&q;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/03/27 14:29:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/29 17:56:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/30 11:22:08 | 000,000,000 | —D | M]

[2012/03/27 16:28:44 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Extensions
[2012/04/01 16:49:20 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0l74cvg8.default\extensions
[2012/03/29 11:05:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0l74cvg8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/03/27 17:14:02 | 000,000,000 | —D | M] (HP Detect) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0l74cvg8.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
[2012/03/27 16:26:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/27 14:29:37 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/03/29 17:56:25 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/03/30 10:51:12 | 000,003,749 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/29 17:56:26 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/03/29 17:56:26 | 000,000,769 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/03/29 17:56:26 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41FA04C7-70F4-474F-94D3-0F4EE206AC4E}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A41946F0-88E7-42A5-A6DE-766C80AA4C59}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{845987be-778c-11e1-843b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{845987be-778c-11e1-843b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MSWorks\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2012/04/02 16:53:58 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL.exe
[2012/04/01 16:57:47 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
[2012/04/01 16:57:47 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2012/04/01 16:57:30 | 000,225,280 | —- | C] (Propellerhead Software AB) – C:\Windows\System32\rewire.dll
[2012/04/01 16:57:26 | 000,000,000 | —D | C] – C:\Users\James\Documents\Image-Line
[2012/04/01 16:57:09 | 001,554,944 | —- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) – C:\Windows\System32\vorbis.acm
[2012/04/01 16:57:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
[2012/04/01 16:56:11 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2012/04/01 16:56:10 | 000,000,000 | —D | C] – C:\Program Files\VstPlugins
[2012/04/01 16:55:59 | 000,000,000 | —D | C] – C:\Program Files\Outsim
[2012/04/01 16:50:48 | 000,000,000 | —D | C] – C:\Program Files\Image-Line
[2012/03/30 17:02:50 | 000,000,000 | —D | C] – C:\Users\James\Documents\AdobeReaderPatch10.1.2_cpsid_92870-2
[2012/03/30 11:26:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/03/30 11:25:35 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msonpmon.dll
[2012/03/30 11:20:44 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2012/03/30 11:20:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2012/03/30 11:19:17 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2012/03/30 11:18:23 | 000,000,000 | R–D | C] – C:\Users\James\Desktop\Art
[2012/03/30 11:16:01 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2012/03/30 11:14:32 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Microsoft Help
[2012/03/30 11:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2012/03/30 11:10:15 | 000,000,000 | —D | C] – C:\IUware Online
[2012/03/30 10:59:54 | 000,000,000 | —D | C] – C:\Users\James\Documents\Vuze Downloads
[2012/03/30 10:57:35 | 000,000,000 | —D | C] – C:\Users\James\.swt
[2012/03/30 10:57:29 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Azureus
[2012/03/30 10:56:11 | 000,000,000 | —D | C] – C:\Program Files\Vuze
[2012/03/30 10:50:27 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/03/30 10:19:06 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\WinRAR
[2012/03/30 10:07:58 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2012/03/30 09:57:44 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2012/03/30 09:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2012/03/30 09:53:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/03/30 09:39:46 | 000,000,000 | —D | C] – C:\Users\James\Documents\Adobe CS5
[2012/03/29 16:36:26 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/03/29 16:33:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/03/29 16:33:57 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2012/03/29 16:33:11 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2012/03/29 15:46:23 | 001,184,768 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys
[2012/03/29 15:46:23 | 000,000,000 | —D | C] – C:\Windows\System32\nn-NO
[2012/03/29 15:46:22 | 000,397,312 | —- | C] (Atheros) – C:\Windows\System32\athihvs.dll
[2012/03/29 15:46:22 | 000,061,440 | —- | C] (Atheros) – C:\Windows\System32\athihvui.dll
[2012/03/29 15:46:02 | 000,000,000 | —D | C] – C:\Program Files\Cisco
[2012/03/29 15:46:01 | 000,000,000 | —D | C] – C:\Program Files\Atheros
[2012/03/29 15:45:19 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2012/03/29 15:36:44 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2012/03/29 15:24:15 | 000,000,000 | —D | C] – C:\Program Files\Mail.Ru
[2012/03/29 11:48:00 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2012/03/29 11:47:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2012/03/29 11:47:52 | 001,071,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSCOMCTL.OCX
[2012/03/29 11:47:52 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSSTDFMT.DLL
[2012/03/29 11:47:50 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2012/03/29 11:44:09 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Macromedia
[2012/03/29 11:44:09 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Adobe
[2012/03/29 11:42:13 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/03/29 11:19:24 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Template
[2012/03/29 11:17:06 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2012/03/29 11:14:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2012/03/29 11:14:05 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2012/03/29 10:43:23 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2012/03/29 10:40:17 | 000,000,000 | —D | C] – C:\Program Files\Device Doctor
[2012/03/27 19:42:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2012/03/27 19:14:11 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2012/03/27 19:13:59 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/03/27 19:13:59 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/03/27 19:13:58 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/03/27 19:13:58 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/03/27 19:13:58 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/03/27 18:54:33 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2012/03/27 18:48:11 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2012/03/27 18:34:22 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2012/03/27 18:34:21 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2012/03/27 18:34:21 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2012/03/27 18:32:42 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2012/03/27 18:32:42 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2012/03/27 18:32:38 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2012/03/27 18:32:34 | 000,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2012/03/27 18:32:34 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2012/03/27 18:32:34 | 000,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2012/03/27 18:32:34 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2012/03/27 18:32:34 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2012/03/27 18:32:34 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2012/03/27 18:30:22 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2012/03/27 18:29:13 | 000,000,000 | —D | C] – C:\Program Files\IDT
[2012/03/27 18:29:09 | 000,368,640 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestecap.dll
[2012/03/27 18:29:09 | 000,142,848 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestacap.dll
[2012/03/27 18:29:09 | 000,061,440 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestaren.dll
[2012/03/27 18:29:07 | 000,536,576 | —- | C] (IDT, Inc.) – C:\Windows\System32\idtmini1.exe
[2012/03/27 18:29:07 | 000,086,016 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AESTCom.dll
[2012/03/27 18:29:06 | 012,021,852 | —- | C] (IDT, Inc.) – C:\Windows\System32\idtcpl.cpl
[2012/03/27 18:29:06 | 003,567,616 | —- | C] (IDT, Inc.) – C:\Windows\System32\stlang.dll
[2012/03/27 18:29:06 | 000,450,652 | —- | C] (IDT, Inc.) – C:\Windows\sttray.exe
[2012/03/27 18:29:01 | 000,000,000 | —D | C] – C:\Windows\System32\SRSLabs
[2012/03/27 18:20:46 | 000,237,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2012/03/27 18:12:47 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/03/27 18:12:47 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/03/27 18:12:47 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/03/27 18:12:47 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/03/27 18:12:47 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/03/27 18:12:47 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/03/27 18:12:47 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/03/27 18:12:47 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/03/27 18:12:47 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/03/27 18:12:47 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/03/27 18:12:47 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/03/27 18:12:47 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/03/27 18:12:47 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/03/27 18:12:47 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/03/27 18:12:47 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/03/27 18:12:47 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/03/27 18:12:46 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/03/27 18:12:46 | 001,798,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/03/27 18:12:46 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/03/27 18:12:46 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/03/27 18:12:46 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/03/27 18:12:46 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/03/27 18:12:46 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/03/27 18:12:46 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/03/27 18:12:46 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/03/27 18:12:46 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/03/27 18:12:46 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/03/27 18:12:46 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/03/27 18:12:46 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/03/27 18:12:46 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/03/27 18:12:46 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/03/27 18:12:46 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/03/27 18:12:46 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/03/27 18:12:45 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/03/27 18:12:45 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/03/27 18:11:52 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2012/03/27 18:11:52 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2012/03/27 18:11:52 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2012/03/27 18:11:52 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2012/03/27 18:11:52 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2012/03/27 18:11:52 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2012/03/27 18:11:52 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2012/03/27 18:11:49 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2012/03/27 18:11:49 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2012/03/27 18:11:49 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2012/03/27 18:11:49 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2012/03/27 18:11:49 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2012/03/27 18:11:49 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2012/03/27 18:11:49 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2012/03/27 18:11:49 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2012/03/27 18:11:48 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2012/03/27 18:11:48 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2012/03/27 18:11:11 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2012/03/27 18:11:11 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2012/03/27 18:11:11 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2012/03/27 18:11:10 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2012/03/27 18:11:10 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2012/03/27 18:11:10 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2012/03/27 18:08:06 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2012/03/27 18:08:06 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2012/03/27 18:08:06 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2012/03/27 18:06:55 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browserchoice.exe
[2012/03/27 18:05:15 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2012/03/27 18:05:14 | 000,000,000 | —D | C] – C:\Intel
[2012/03/27 18:00:01 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2012/03/27 17:58:55 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2012/03/27 17:58:39 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2012/03/27 17:58:39 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2012/03/27 17:58:39 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2012/03/27 17:58:39 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2012/03/27 17:58:39 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2012/03/27 17:58:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2012/03/27 17:58:37 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2012/03/27 17:58:37 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2012/03/27 17:58:37 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2012/03/27 17:58:36 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2012/03/27 17:58:29 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2012/03/27 17:58:29 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2012/03/27 17:58:29 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2012/03/27 17:58:29 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2012/03/27 17:58:29 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2012/03/27 17:56:34 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/03/27 17:56:33 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/03/27 17:56:26 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2012/03/27 17:55:55 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2012/03/27 17:55:53 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2012/03/27 17:55:53 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2012/03/27 17:55:48 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2012/03/27 17:55:47 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2012/03/27 17:55:45 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/03/27 17:55:44 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2012/03/27 17:55:44 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/03/27 17:54:38 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2012/03/27 17:54:37 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2012/03/27 17:54:35 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2012/03/27 17:54:27 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2012/03/27 17:52:59 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2012/03/27 17:52:41 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2012/03/27 17:52:14 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2012/03/27 17:52:13 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2012/03/27 17:51:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/03/27 17:51:06 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/03/27 17:50:55 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2012/03/27 17:50:37 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/03/27 17:50:36 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/03/27 17:50:33 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2012/03/27 17:50:31 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2012/03/27 17:50:30 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2012/03/27 17:50:28 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2012/03/27 17:50:23 | 002,044,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/03/27 17:50:20 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2012/03/27 17:50:01 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2012/03/27 17:50:01 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2012/03/27 17:50:01 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2012/03/27 17:49:51 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2012/03/27 17:49:44 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2012/03/27 17:49:43 | 000,613,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2012/03/27 17:49:38 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2012/03/27 17:49:38 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2012/03/27 17:49:38 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2012/03/27 17:49:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2012/03/27 17:49:35 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2012/03/27 17:49:29 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2012/03/27 17:49:25 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/03/27 17:30:21 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2012/03/27 17:23:37 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/03/27 17:23:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/03/27 17:23:32 | 000,000,000 | —D | C] – C:\Windows\WinRAR
[2012/03/27 17:23:32 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/03/27 16:34:41 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2012/03/27 16:34:40 | 002,421,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2012/03/27 16:34:21 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2012/03/27 16:34:21 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2012/03/27 16:34:21 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2012/03/27 16:34:13 | 000,171,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2012/03/27 16:34:13 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2012/03/27 16:33:06 | 000,000,000 | —D | C] – C:\Users\James\Desktop\KB971033
[2012/03/27 16:28:35 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Mozilla
[2012/03/27 16:28:35 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Mozilla
[2012/03/27 16:26:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2012/03/27 16:26:25 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/03/27 16:24:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock
[2012/03/27 16:24:39 | 000,000,000 | —D | C] – C:\Program Files\PeerBlock
[2012/03/27 16:22:01 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Malwarebytes
[2012/03/27 16:21:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/27 16:21:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/03/27 16:21:36 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/03/27 16:21:36 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/27 16:06:08 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Compaq Drivers Update Utility
[2012/03/27 15:52:12 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2012/03/27 15:52:11 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2012/03/27 15:51:56 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\InstallShield
[2012/03/27 15:32:38 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\DRPSu
[2012/03/27 15:31:58 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2012/03/27 15:00:39 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\hpqLog
[2012/03/27 14:35:18 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OnlineArmor
[2012/03/27 14:35:18 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2012/03/27 14:34:06 | 000,029,312 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2012/03/27 14:34:06 | 000,025,192 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2012/03/27 14:34:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2012/03/27 14:33:17 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2012/03/27 14:30:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/03/27 14:30:31 | 000,337,880 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012/03/27 14:30:31 | 000,020,696 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2012/03/27 14:30:28 | 000,053,848 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012/03/27 14:30:28 | 000,035,672 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2012/03/27 14:30:27 | 000,612,184 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012/03/27 14:30:26 | 000,057,688 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012/03/27 14:29:43 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2012/03/27 14:29:21 | 000,041,184 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/03/27 14:29:20 | 000,201,352 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012/03/27 14:28:55 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/03/27 14:28:55 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/03/27 07:41:22 | 000,000,000 | —D | C] – C:\Windows\Panther
[2012/03/27 07:23:53 | 000,000,000 | —D | C] – C:\Windows.old.001
[2012/03/26 23:05:46 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/03/26 23:05:46 | 000,000,000 | R–D | C] – C:\Users\James\Searches
[2012/03/26 23:05:46 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/03/26 23:05:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Identities
[2012/03/26 23:05:33 | 000,000,000 | R–D | C] – C:\Users\James\Contacts
[2012/03/26 23:05:32 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\VirtualStore
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\AppData\Local\Temporary Internet Files
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Templates
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Start Menu
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\SendTo
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Recent
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\PrintHood
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\NetHood
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Documents\My Videos
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Documents\My Pictures
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Documents\My Music
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\My Documents
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Local Settings
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\AppData\Local\History
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Cookies
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Application Data
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\AppData\Local\Application Data
[2012/03/26 23:05:27 | 000,000,000 | –SD | C] – C:\Users\James\AppData\Roaming\Microsoft
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Videos
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Saved Games
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Pictures
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Music
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Links
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Favorites
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Downloads
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Documents
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Desktop
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/03/26 23:05:27 | 000,000,000 | -H-D | C] – C:\Users\James\AppData
[2012/03/26 23:05:27 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Temp
[2012/03/26 23:05:27 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Microsoft
[2012/03/26 23:05:27 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Media Center Programs
[2012/03/26 23:02:29 | 000,000,000 | —D | C] – C:\Windows\Debug
[2012/03/26 22:55:55 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2012/03/26 18:03:36 | 000,000,000 | —D | C] – C:\Windows.old.000
[2012/03/26 13:41:12 | 002,068,016 | —- | C] (Kaspersky Lab ZAO) – C:\Users\James\Desktop\TDSSKiller.exe
[2012/03/26 05:28:44 | 000,000,000 | —D | C] – C:\Windows.old
[2012/03/12 10:51:26 | 000,000,000 | -H-D | C] – C:\VritualRoot

========== Files - Modified Within 30 Days ==========

[2012/04/02 16:53:59 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL.exe
[2012/04/02 16:52:12 | 000,607,600 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/02 16:52:12 | 000,107,478 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/02 16:47:46 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/01 17:01:12 | 000,003,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/01 17:01:12 | 000,003,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/01 16:57:30 | 000,000,932 | —- | M] () – C:\Users\James\Desktop\FL Studio 9.lnk
[2012/03/30 17:07:17 | 003,736,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/03/30 16:51:39 | 000,316,676 | —- | M] () – C:\Users\James\Documents\DELF_B1_exemple2.pdf
[2012/03/30 11:21:20 | 000,003,584 | —- | M] () – C:\Users\James\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/30 11:15:58 | 000,000,361 | —- | M] () – C:\Users\James\Desktop\Music - Shortcut.lnk
[2012/03/30 11:15:54 | 000,000,370 | —- | M] () – C:\Users\James\Desktop\Pictures - Shortcut.lnk
[2012/03/30 11:15:51 | 000,000,373 | —- | M] () – C:\Users\James\Desktop\Documents - Shortcut.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | M] () – C:\Users\Public\Desktop\Vuze.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | M] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2012/03/30 10:21:56 | 000,001,000 | —- | M] () – C:\Users\James\Desktop\Adobe Photoshop CS5.lnk
[2012/03/29 16:34:25 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/03/29 11:47:53 | 000,000,876 | —- | M] () – C:\Users\James\Desktop\SpywareBlaster.lnk
[2012/03/29 11:44:05 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/03/29 11:19:22 | 000,000,000 | —- | M] () – C:\Users\James\AppData\Roaming\wklnhst.dat
[2012/03/27 19:03:05 | 000,000,680 | —- | M] () – C:\Users\James\AppData\Local\d3d9caps.dat
[2012/03/27 18:55:46 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/03/27 18:55:24 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/03/27 18:54:06 | 000,000,943 | —- | M] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/27 18:47:43 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2012/03/27 18:12:59 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2012/03/27 18:12:59 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2012/03/27 18:12:47 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/03/27 18:12:47 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/03/27 18:12:47 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/03/27 18:12:47 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/03/27 18:12:47 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/03/27 18:12:47 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/03/27 18:12:47 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/03/27 18:12:47 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/03/27 18:12:47 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/03/27 18:12:47 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/03/27 18:12:47 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/03/27 18:12:47 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/03/27 18:12:47 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/03/27 18:12:47 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012/03/27 18:12:47 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/03/27 18:12:47 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/03/27 18:12:47 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/03/27 18:12:46 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/03/27 18:12:46 | 001,798,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/03/27 18:12:46 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/03/27 18:12:46 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/03/27 18:12:46 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/03/27 18:12:46 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/03/27 18:12:46 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/03/27 18:12:46 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/03/27 18:12:46 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/03/27 18:12:46 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/03/27 18:12:46 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/03/27 18:12:46 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/03/27 18:12:46 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/03/27 18:12:46 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/03/27 18:12:46 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/03/27 18:12:46 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/03/27 18:12:46 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/03/27 18:12:45 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/03/27 18:12:45 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/03/27 18:11:52 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2012/03/27 18:11:52 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2012/03/27 18:11:52 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2012/03/27 18:11:52 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2012/03/27 18:11:52 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2012/03/27 18:11:52 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2012/03/27 18:11:52 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2012/03/27 18:11:49 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2012/03/27 18:11:49 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2012/03/27 18:11:49 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2012/03/27 18:11:49 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2012/03/27 18:11:49 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2012/03/27 18:11:49 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2012/03/27 18:11:49 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2012/03/27 18:11:49 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2012/03/27 18:11:48 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2012/03/27 18:11:48 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2012/03/27 18:11:11 | 000,369,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2012/03/27 18:11:11 | 000,252,928 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2012/03/27 18:11:11 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2012/03/27 18:11:11 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
[2012/03/27 18:11:10 | 000,519,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2012/03/27 18:11:10 | 000,321,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2012/03/27 18:11:10 | 000,189,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2012/03/27 17:02:21 | 000,077,072 | —- | M] () – C:\Users\James\Documents\Student certificate 2011-2012.JPG
[2012/03/27 16:26:30 | 000,001,748 | —- | M] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/27 16:26:30 | 000,001,724 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/03/27 16:24:40 | 000,001,728 | —- | M] () – C:\Users\James\Desktop\PeerBlock.lnk
[2012/03/27 16:21:41 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/27 14:30:32 | 000,001,829 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/03/27 14:30:26 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/03/27 14:28:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2012/03/27 07:41:08 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2012/03/26 22:57:30 | 000,048,744 | —- | M] () – C:\Windows\System32\license.rtf
[2012/03/26 13:41:12 | 002,068,016 | —- | M] (Kaspersky Lab ZAO) – C:\Users\James\Desktop\TDSSKiller.exe
[2012/03/07 00:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/03/07 00:15:14 | 000,201,352 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012/03/07 00:03:51 | 000,612,184 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012/03/07 00:03:38 | 000,337,880 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012/03/07 00:02:00 | 000,035,672 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2012/03/07 00:01:53 | 000,053,848 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012/03/07 00:01:48 | 000,057,688 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012/03/07 00:01:30 | 000,020,696 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys

========== Files Created - No Company Name ==========

[2012/04/01 16:57:30 | 000,000,932 | —- | C] () – C:\Users\James\Desktop\FL Studio 9.lnk
[2012/03/30 16:51:39 | 000,316,676 | —- | C] () – C:\Users\James\Documents\DELF_B1_exemple2.pdf
[2012/03/30 11:21:12 | 000,003,584 | —- | C] () – C:\Users\James\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/30 11:15:58 | 000,000,361 | —- | C] () – C:\Users\James\Desktop\Music - Shortcut.lnk
[2012/03/30 11:15:54 | 000,000,370 | —- | C] () – C:\Users\James\Desktop\Pictures - Shortcut.lnk
[2012/03/30 11:15:51 | 000,000,373 | —- | C] () – C:\Users\James\Desktop\Documents - Shortcut.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | C] () – C:\Users\Public\Desktop\Vuze.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
[2012/03/30 10:21:56 | 000,001,000 | —- | C] () – C:\Users\James\Desktop\Adobe Photoshop CS5.lnk
[2012/03/30 10:03:39 | 000,001,000 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012/03/30 10:01:21 | 000,000,962 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012/03/30 10:00:17 | 000,001,055 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012/03/30 09:56:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012/03/30 09:56:13 | 000,001,308 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012/03/30 09:53:20 | 000,000,874 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/03/29 16:34:25 | 000,001,892 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/03/29 16:34:25 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/03/29 11:47:53 | 000,000,876 | —- | C] () – C:\Users\James\Desktop\SpywareBlaster.lnk
[2012/03/29 11:19:22 | 000,000,000 | —- | C] () – C:\Users\James\AppData\Roaming\wklnhst.dat
[2012/03/27 18:55:46 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/03/27 18:55:24 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/03/27 18:54:47 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2012/03/27 18:47:43 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2012/03/27 18:12:47 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2012/03/27 17:58:32 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2012/03/27 17:58:32 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2012/03/27 17:58:32 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2012/03/27 17:02:17 | 000,077,072 | —- | C] () – C:\Users\James\Documents\Student certificate 2011-2012.JPG
[2012/03/27 16:26:30 | 000,001,748 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/27 16:26:30 | 000,001,724 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/03/27 16:24:40 | 000,001,728 | —- | C] () – C:\Users\James\Desktop\PeerBlock.lnk
[2012/03/27 16:21:41 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/27 15:32:36 | 000,000,943 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/27 14:34:06 | 000,042,152 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2012/03/27 14:34:05 | 000,205,864 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2012/03/27 14:30:32 | 000,001,829 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/03/27 14:28:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2012/03/26 23:05:48 | 000,000,949 | —- | C] () – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/03/26 23:05:45 | 000,000,944 | —- | C] () – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012/03/26 23:05:33 | 000,000,915 | —- | C] () – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2012/03/26 23:05:29 | 000,000,680 | —- | C] () – C:\Users\James\AppData\Local\d3d9caps.dat
[2012/03/26 23:05:27 | 000,000,258 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/03/26 23:05:27 | 000,000,240 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/03/26 06:04:33 | 000,008,192 | R-S- | C] () – C:\BOOTSECT.BAK
[2011/09/15 02:11:16 | 001,048,576 | —- | C] () – C:\Windows\System32\syndata.bin
[2011/02/11 19:10:52 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2011/02/11 19:10:50 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2011/02/11 19:10:50 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2011/02/11 18:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2011/02/11 18:38:44 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config

========== LOP Check ==========

[2012/04/01 17:00:50 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\Azureus
[2012/03/27 16:06:08 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\Compaq Drivers Update Utility
[2012/03/29 15:28:19 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\DRPSu
[2012/03/27 14:35:25 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\OnlineArmor
[2012/03/29 11:19:24 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\Template
[2012/04/01 17:01:13 | 000,012,780 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 14:18:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2012/03/27 07:41:08 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/29 19:03:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/29 19:03:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/04/02 16:47:24 | 3462,578,176 | -HS- | M] () – C:\pagefile.sys
[2012/03/29 15:47:21 | 000,000,184 | —- | M] () – C:\setup.log
[2012/04/01 19:57:24 | 000,107,984 | —- | M] () – C:\TDSSKiller.2.7.23.0_01.04.2012_19.53.35_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/04/11 14:19:50 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 10:46:04 | 000,032,768 | —- | M] (SEIKO EPSON CORPORATION) – C:\Windows\system32\spool\prtprocs\w32x86\EP0NPP01.DLL
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/07 00:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/04/11 15:08:12 | 023,552,000 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2009/04/11 15:07:55 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2009/04/11 15:08:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/27 18:54:06 | 000,000,221 | -HS- | M] () – C:\Users\James\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/04/02 16:53:59 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL.exe
[2012/03/26 13:41:12 | 002,068,016 | —- | M] (Kaspersky Lab ZAO) – C:\Users\James\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-30 10:03:39

========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

—————————————————————————————————————————————————————————-
—————————————————————————————————————————————————————————

Extras.txt:
OTL Extras logfile created on: 02/04/2012 16:56:01 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\James\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.93 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 82.68% Memory free
6.06 Gb Paging File | 5.72 Gb Available in Paging File | 94.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.33 Gb Total Space | 153.56 Gb Free Space | 69.07% Space Free | Partition Type: NTFS
Drive D: | 10.55 Gb Total Space | 1.80 Gb Free Space | 17.04% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17FE3022-4F64-4032-BF2F-4CDBEA46F2E1}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0553FB9E-CD70-4E56-93D3-FDC3CD29B8A9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{312D53E3-A52A-4504-8C57-AF1908D8916D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{6B6C43E8-8B86-4232-BF26-3BDD47A85488}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{9FD83753-CDFF-4BB5-A2D7-C2302C292A0F}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{CF942C9B-4FED-4BAF-8DB7-47745C0DA1A7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D131B648-F11F-482C-89DB-23303B1A3545}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{65482307-FE7D-4E7F-9DEF-3F0E841BC77A}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{99A4344A-C723-4661-A507-D9D939480358}" = Cisco LEAP Module
"{9BFD5911-93E3-42BB-BFCD-50E4BA5B8D67}" = Cisco EAP-FAST Module
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{CD344FA5-6657-47CD-940F-8727EED35595}" = Cisco PEAP Module
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"1AFD0AA05210019264F445722471C9A12AA0D269" = Windows Driver Package - Atheros (AR5416) Net (02/05/2010 7.7.0.481)
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASIO4ALL" = ASIO4ALL
"avast" = avast! Free Antivirus
"C8C34B8E5505C6C11483B29BE7F2D8EF8D2DC9D1" = Windows Driver Package - Atheros (AR5416) Net (02/05/2010 7.7.0.481)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Drumaxx" = Drumaxx
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FL Studio 9" = FL Studio 9
"Hardcore" = Hardcore
"IL Download Manager" = IL Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.28)" = Mozilla Firefox (3.6.28)
"OnlineArmor_is1" = Online Armor 5.5
"PoiZone" = PoiZone
"Sakura" = Sakura
"Sawer" = Sawer
"SpywareBlaster_is1" = SpywareBlaster 4.6
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Toxic Biohazard" = Toxic Biohazard
"WinRAR" = WinRAR

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30/03/2012 11:52:25 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0x17c4, application start time
0x01cd0e8d07f82930.

Error - 30/03/2012 11:54:06 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0xaa4, application start time
0x01cd0e8d208b8320.

Error - 30/03/2012 11:55:30 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0x1358, application start time
0x01cd0e8d5d1df390.

Error - 30/03/2012 12:01:56 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0xa5c, application start time
0x01cd0e8e6bd34060.

Error - 31/03/2012 14:33:21 | Computer Name = James-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 31/03/2012 15:28:44 | Computer Name = James-PC | Source = Application Hang | ID = 1002
Description = The program rundll32.exe version 6.0.6000.16386 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14dc Start Time: 01cd0f72747d3740 Termination Time: 15

Error - 01/04/2012 12:03:53 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

Error - 01/04/2012 12:51:01 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

Error - 01/04/2012 14:50:10 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

Error - 02/04/2012 11:48:20 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 01/04/2012 14:50:13 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 01/04/2012 14:50:21 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 01/04/2012 14:50:21 | Computer Name = James-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 01/04/2012 15:03:47 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:11 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:13 | Computer Name = James-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =

Error - 02/04/2012 11:48:20 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:24 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:32 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 02/04/2012 11:48:32 | Computer Name = James-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Hello TG89 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again TG89

P2P - I see you have P2P software, (Vuze/Azureus), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
===================================================

We can run more scans to get to the root of the problem but first, please include the Malwarebytes log so that I can see what was found and dealt with.

Also, I notice you have run TDSSKiller: please include that log also. A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date).

Logs to include with next post:

CKScanner log
Mbam.txt
TDSSKiller log


Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI