This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My computer has adware and is running slower [Solved]

56 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Around 5 days ago, symantec antivirus auto-protect kept constantly giving me pop-ups with new viruses. Now the log adds a new virus every minute. They are called either trojan.generator, trojan.zeroaccess, or backdoor.trojan. When I ran a full system scan, there were no problems in the log. Now when I am on the internet, I have pop-ups for advertisements popping up out of nowhere.

Here is the:

OTL.txt log

OTL logfile created on: 9/28/2012 6:27:33 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paul\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 44.46% Memory free
5.92 Gb Paging File | 3.97 Gb Available in Paging File | 66.96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 154.87 Gb Free Space | 70.98% Space Free | Partition Type: NTFS
Drive D: | 45.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Paul\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (Dell Inc.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (O2FLASH) – C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20120927.018\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20120927.018\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\Windows\System32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\Windows\System32\drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Teefer2) – C:\Windows\System32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (O2MDGRDR) – C:\Windows\System32\drivers\o2mdg.sys (O2Micro )
DRV - (O2SDGRDR) – C:\Windows\System32\drivers\o2sdg.sys (O2Micro )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OEM13Vid) – C:\Windows\System32\drivers\OEM13Vid.sys (Creative Technology Ltd.)
DRV - (OEM13Vfx) – C:\Windows\System32\drivers\OEM13Vfx.sys (EyePower Games Pte. Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{3A434D2D-EFE9-4239-836B-6EFFC9FE9581}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{5033EE8D-A640-41CA-9012-7AFD6DF2C83F}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://friendly-google-search.blogspot.com
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {5033EE8D-A640-41CA-9012-7AFD6DF2C83F}
IE - HKCU\..\SearchScopes\{5033EE8D-A640-41CA-9012-7AFD6DF2C83F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{6B90DB30-EB93-4A7B-8746-774885B5100A}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.3.3.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\fbphotozoom\fbphotozoom14.xpi [2012/03/20 20:52:52 | 000,102,505 | —- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/12 19:54:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/26 22:37:04 | 000,000,000 | —D | M]

[2009/12/20 23:28:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2012/09/25 15:58:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\extensions
[2012/08/27 00:02:56 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012/07/25 14:08:42 | 000,741,958 | —- | M] () (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2010/12/23 00:14:20 | 000,000,913 | —- | M] () – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\searchplugins\conduit.xml
[2012/04/19 18:12:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/12 19:54:53 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/07/18 12:19:40 | 002,998,784 | —- | M] (Tamarack Software, Inc.) – C:\Program Files\mozilla firefox\plugins\nptgeqplugin.dll
[2012/09/12 19:54:50 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/12 19:54:50 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\System32\winrnr.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B82892F4-0671-4942-BCB8-BCB5812C3AE4}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - File not found
NetSvcs: BITS - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2012/09/28 18:23:51 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2012/09/27 20:30:56 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{23FDF748-A959-4BBE-8329-C5F41F151F86}
[2012/09/26 13:57:13 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{ACE51E19-95F0-4636-80FF-CC8C1082A66E}
[2012/09/25 13:32:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/09/25 13:30:56 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/09/25 13:30:55 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/09/25 13:30:55 | 000,000,000 | —D | C] – C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/09/25 13:29:01 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/09/25 10:35:53 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{C74A78A0-95CF-41F3-8E00-8B713D5C07BA}
[2012/09/24 12:33:18 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{94791D2F-AD6E-4FD5-B9D6-8CCFA6B6AB79}
[2012/09/23 02:11:27 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{901DF679-5E20-43A7-A582-BD6460C16A33}
[2012/09/23 00:23:37 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/09/22 16:37:23 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/09/22 16:37:20 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/09/22 16:37:19 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/09/22 16:37:19 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/09/22 16:37:19 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/09/22 16:37:17 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/09/22 16:37:17 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/09/22 16:37:16 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/09/22 14:10:59 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{3897A53D-FD81-4E96-8ADF-3B1323E45E9B}
[2012/09/20 21:50:50 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{CFDBCC1D-D7FB-4707-B89E-955391D4E89B}
[2012/09/19 13:08:34 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{315480F9-C7A6-4442-8050-AA9B09D86A2F}
[2012/09/18 11:07:15 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{9F71D77E-FDDC-408E-85A5-A1B283FA112B}
[2012/09/13 22:26:05 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{B0FE5E3B-8DBF-446B-A795-8D1F97CB7CE0}
[2012/09/12 18:34:04 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{7EAE368A-E43D-4951-82A1-B4220167F154}
[2012/09/11 23:57:45 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2012/09/11 23:56:17 | 000,240,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2012/09/11 23:56:17 | 000,187,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012/09/11 23:49:53 | 000,490,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2012/09/11 21:47:35 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{98647712-8752-4CCB-9D5E-7EAE4C5F5EA7}
[2012/09/10 12:01:52 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{CA891AC9-94DD-4031-8E95-1C10D852D8A7}
[2012/09/09 14:59:56 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{0B8CB423-58FB-488B-8BCE-DF62AC062E6F}
[2012/09/09 02:59:30 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{EA32B385-F3A2-486F-97AE-95DBEBAA6BA5}
[2012/09/08 11:54:56 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{88944712-86D6-47B7-B829-27CB39E946B5}
[2012/09/06 23:45:18 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{54A7F051-F2E1-4199-A055-71A2737357E9}
[2012/09/05 11:48:00 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{43C74597-84E1-4DB5-B2EF-661F5608C0EC}
[2012/09/04 21:51:59 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{600C82E7-43EF-4333-8451-EB031B733A4F}
[2012/09/02 23:48:41 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{2C328A34-430F-4944-A63C-B59E6569270C}
[2012/09/02 11:47:17 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{E27B3069-3352-42D2-858E-2D0D343643C4}
[2012/09/01 15:21:03 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{D198FED2-B677-41CC-9E97-55BC5F20B90F}
[2012/08/31 13:02:03 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\{0C2D45B0-41CA-4FA1-82B3-4E06E805B262}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/28 18:23:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2012/09/28 18:18:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/28 12:27:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/27 20:37:49 | 000,014,256 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/27 20:37:49 | 000,014,256 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/27 20:30:01 | 000,000,372 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2012/09/27 20:28:53 | 2385,211,392 | -HS- | M] () – C:\hiberfil.sys
[2012/09/26 16:36:30 | 000,066,877 | —- | M] () – C:\Users\Paul\Desktop\ResumeMarch13.rtf
[2012/09/25 13:32:06 | 000,001,755 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/25 13:29:54 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/09/25 13:29:54 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/09/23 00:23:39 | 000,000,971 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/17 11:48:19 | 000,002,052 | —- | M] () – C:\Windows\epplauncher.mif
[2012/09/17 11:45:43 | 000,627,082 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/09/17 11:45:43 | 000,107,366 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/09/12 19:54:54 | 000,001,996 | —- | M] () – C:\Users\Paul\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/08 05:10:26 | 000,167,936 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\wpshelper.sys
[2012/09/03 14:00:33 | 000,174,726 | —- | M] () – C:\Users\Paul\Desktop\BikeHelmet.htm
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/09/25 13:32:06 | 000,001,755 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/23 00:23:39 | 000,000,971 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/17 11:48:19 | 000,002,052 | —- | C] () – C:\Windows\epplauncher.mif
[2012/09/03 14:00:30 | 000,174,726 | —- | C] () – C:\Users\Paul\Desktop\BikeHelmet.htm
[2012/04/25 01:25:33 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3b4ce9a7
[2012/04/25 01:25:33 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3ad1a66f
[2012/04/25 01:25:21 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\70eed82b
[2012/04/25 01:25:21 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\702438e5
[2012/04/25 01:25:17 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\bad25afc
[2012/04/25 01:25:17 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\b9ffc7b9
[2012/04/25 01:16:45 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\1eca2c61
[2012/04/25 01:16:45 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\1e07dd9b
[2012/04/25 01:16:33 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\492de2da
[2012/04/25 01:16:33 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\485ed46e
[2012/04/25 01:16:30 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\ac75a77d
[2012/04/25 01:16:30 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\abb72054
[2012/04/25 01:05:39 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\30150202
[2012/04/25 01:05:39 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\2f3534fb
[2012/04/25 01:05:34 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\5da3a4fa
[2012/04/25 01:05:34 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\5cd09e8f
[2012/04/25 01:05:32 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\c70ddcca
[2012/04/25 01:05:32 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\c632ded1
[2012/04/25 01:04:17 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\4f8932d1
[2012/04/25 01:04:17 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\4ef188fc
[2012/04/25 01:04:13 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\85fdb830
[2012/04/25 01:04:13 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\85267ef3
[2012/04/25 01:04:10 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\f349a0b6
[2012/04/25 01:04:10 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\f2751cf2
[2012/04/25 00:10:36 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\774ef04b
[2012/04/25 00:10:36 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\76c78d2f
[2012/04/25 00:10:19 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\5d52859d
[2012/04/25 00:10:19 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\5c8751a0
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\bb2403b0
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\ba064537
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\b8a7ed3b
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\b7e9e6ef
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\b7206a37
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\ae90dafc
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\adca90f3
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\aa14fc62
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\a94d52e8
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\8665e41c
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\858643ba
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\84c3a9b7
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\83fe8c08
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\82beed90
[2012/04/25 00:10:08 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\81e1f44d
[2012/04/24 01:51:46 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\bec4d7c4
[2012/04/24 01:51:46 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\be38b898
[2012/04/24 01:51:34 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\418e3400
[2012/04/24 01:51:34 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\40b819ec
[2012/04/24 01:51:27 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\a4b22dde
[2012/04/24 01:51:27 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\a3e9ee63
[2012/04/24 01:43:39 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\1d1d83f7
[2012/04/24 01:43:39 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\1c9f7c68
[2012/04/24 01:43:31 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\93aba68d
[2012/04/24 01:43:31 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\92c005c6
[2012/04/24 01:43:23 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\20f80714
[2012/04/24 01:43:23 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\202a4993
[2012/04/24 01:31:35 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\cfe46cc6
[2012/04/24 01:31:35 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\cf1f928d
[2012/04/24 01:31:26 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\296cb727
[2012/04/24 01:31:26 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\289e00f2
[2012/04/24 01:31:23 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\783fba63
[2012/04/24 01:31:23 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\77729929
[2012/04/24 01:23:44 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\58ccbb79
[2012/04/24 01:23:44 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\5853376e
[2012/04/24 01:23:32 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\342b71c6
[2012/04/24 01:23:32 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3359774f
[2012/04/24 01:23:29 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\96ced360
[2012/04/24 01:23:29 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\96044c56
[2012/04/24 01:17:04 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\9d8ec91c
[2012/04/24 01:17:04 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\9d19eeff
[2012/04/24 01:16:53 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\8db2de3b
[2012/04/24 01:16:53 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\8cd21bda
[2012/04/24 01:16:49 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\baac298a
[2012/04/24 01:16:49 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\b9da4fa5
[2012/04/24 01:07:33 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\89dbaf4a
[2012/04/24 01:07:33 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\896687b4
[2012/04/24 01:07:19 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\43224e22
[2012/04/24 01:07:19 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\425d74a4
[2012/04/24 01:07:17 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\a7845e89
[2012/04/24 01:07:17 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\a6c1a1ad
[2012/04/24 01:04:06 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\2b1e9a0
[2012/04/24 01:04:06 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\23ebef6
[2012/04/24 01:04:02 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\2e9bad92
[2012/04/24 01:04:02 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\2db3132d
[2012/04/24 01:03:59 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\743a5bb6
[2012/04/24 01:03:59 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\736cce4a
[2012/04/24 01:00:34 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\7b4162b0
[2012/04/24 01:00:34 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\7acb2a09
[2012/04/24 01:00:06 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\81e7d583
[2012/04/24 01:00:06 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\813ed662
[2012/04/24 00:59:43 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\c0f2d975
[2012/04/24 00:59:43 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\c02df36b
[2012/04/24 00:57:18 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\73a90013
[2012/04/24 00:57:18 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\72e3099d
[2012/04/24 00:57:11 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\6e9b1342
[2012/04/24 00:57:11 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\6dd0c133
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3b761382
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3afd9152
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3a480cae
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\39c01c4a
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\38fd6202
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\36a0ff25
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\35d42f00
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\312586c9
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\3058105a
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\240e46aa
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\234e9747
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\227ef9a4
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\21bd0c05
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\20e82977
[2012/04/24 00:57:05 | 000,004,638 | —- | C] () – C:\Users\Paul\AppData\Roaming\200c5039
[2012/04/19 23:44:37 | 000,009,728 | —- | C] () – C:\Users\Paul\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/23 19:22:51 | 000,000,600 | —- | C] () – C:\Users\Paul\AppData\Roaming\winscp.rnd
[2011/07/08 00:15:59 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2010/12/02 03:21:43 | 000,190,888 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/10/23 12:48:05 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat

========== ZeroAccess Check ==========

[2012/09/17 12:13:16 | 000,002,048 | -HS- | M] () – C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\@
[2012/09/17 12:13:16 | 000,056,320 | -HS- | M] () – C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\n
[2012/09/28 12:28:41 | 000,000,000 | -HSD | M] – C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\L
[2012/09/28 18:41:16 | 000,000,000 | -HSD | M] – C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U
[2012/09/25 13:41:20 | 000,000,804 | —- | M] () – C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\L\00000004.@
[2012/09/28 12:27:10 | 000,087,040 | —- | M] () – C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\80000032.@
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[2012/09/27 20:29:41 | 000,005,120 | -HS- | M] () – C:\Windows\assembly\GAC\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = C:\$Recycle.Bin\S-1-5-21-2674026609-1698660912-1609442580-1003\$7acaefb09c1386a0b371b6660cf41e97\n. – File not found

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\n. – [2012/09/17 12:13:16 | 000,056,320 | -HS- | M] ()
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll\system32\wbem\wbemess.dll
"ThreadingModel" = Apartment

========== LOP Check ==========

[2009/12/20 20:16:43 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\acccore
[2012/04/24 00:57:00 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Boilsoft
[2012/04/23 23:29:39 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\ImTOO
[2010/09/07 22:46:53 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\IObit
[2011/12/09 22:48:17 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\ooVoo Details
[2012/03/04 02:58:05 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\redsn0w
[2012/09/28 18:37:16 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\uTorrent
[2012/06/01 18:42:55 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\WinZip

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2012/09/28 18:24:22 | 000,341,994 | —- | M] () MD5=124B50F3E1E3C41FF93E39D300AF1591 – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: EXPLORER.ZIP >
[2006/03/07 00:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_b12560b1c817cfde\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_b3c5cc459f4108f2\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_b1148f09c82553c5\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_b19f2c1ee1420ce6\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_b12660fbc816e935\iexplore.exe
[2011/12/16 04:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_b378134285f73a44\iexplore.exe
[2011/08/20 00:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_b360a432860774ff\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_b3987f3a85deec23\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_b34dce2a8616cbea\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_b1a52ddae13ca4f0\iexplore.exe
[2011/04/22 15:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_b398812085dee94a\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_b402ac8b9f13f917\iexplore.exe
[2011/06/21 01:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_b3c2cf339f43b73b\iexplore.exe
[2011/11/05 00:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_b38fb3ae85e53510\iexplore.exe
[2012/03/21 02:16:35 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_b3e23cc79f2c4cea\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_b1276145c816028c\iexplore.exe
[2011/06/21 01:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_b38113f685ef212c\iexplore.exe
[2011/11/05 00:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_b3d0781f9f391a91\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_b384dff685ed56b3\iexplore.exe
[2011/02/24 01:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_b1a12cb2e1403f94\iexplore.exe
[2011/12/16 05:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_b429fa439ef58435\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2011/02/24 01:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_b1a22cfce13f58eb\iexplore.exe
[2011/04/22 15:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_b3ffe0d59f14dce7\iexplore.exe
[2011/08/20 00:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_b40487279f125c2e\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/03/21 02:16:36 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/03/21 02:16:36 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
[2009/07/13 22:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-DEDDC9B6.PF >
[2012/09/27 22:00:34 | 000,035,456 | —- | M] () MD5=5B95F02E95C934CA3FAFCCA5BE72953B – C:\Windows\Prefetch\WINLOGON.EXE-DEDDC9B6.pf

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2009/11/29 22:55:23 | 000,002,569 | RH– | M] () – C:\dell.sdr
[2012/02/11 18:12:56 | 000,067,646 | —- | M] () – C:\google_chrome.ico
[2012/02/11 18:20:10 | 000,067,646 | —- | M] () – C:\happy_jack_o_lantern.ico
[2012/09/27 20:28:53 | 2385,211,392 | -HS- | M] () – C:\hiberfil.sys
[2010/08/02 23:12:02 | 000,000,696 | -H– | M] () – C:\IPH.PH
[2012/09/27 20:28:51 | 3180,285,952 | -HS- | M] () – C:\pagefile.sys
[2012/06/22 23:52:53 | 000,000,000 | —- | M] () – C:\t17k.2
[2011/06/20 20:55:32 | 000,000,000 | —- | M] () – C:\t1b8.2

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/21 23:03:27 | 000,000,221 | -HS- | M] () – C:\Users\Paul\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/09/28 18:23:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-22 20:38:12

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:1AE68282

< End of report >


Extras.txt log

OTL Extras logfile created on: 9/28/2012 6:27:33 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paul\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 44.46% Memory free
5.92 Gb Paging File | 3.97 Gb Available in Paging File | 66.96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 154.87 Gb Free Space | 70.98% Space Free | Partition Type: NTFS
Drive D: | 45.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE 10.3
"{0AC482EB-315A-464F-859A-1A63BAE4E149}_is1" = Super Mario Bros X version 1.2.1
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{24549038-9956-4EE5-976D-4419AAEA7DD5}_is1" = Boilsoft Video Splitter 6.32
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 20
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{731B0E4D-F4C7-450C-95B0-E1A3176B1C75}" = Dell Backup and Recovery Manager
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9854A5C4-5BE5-46E2-A989-352DD8B37E20}_is1" = WinZip Driver Updater
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE 10.3
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1ClickDownload" = 1ClickDownload
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"CCleaner" = CCleaner
"Creative OEM013" = Laptop Integrated Webcam Driver (1.01.01.0529)
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"ENTERPRISER" = Microsoft Office Enterprise 2007
"HDMI" = Intel® Graphics Media Accelerator Driver
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Peggle" = Peggle (remove only)
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 10" = Counter-Strike
"TVWiz" = Intel® TV Wizard
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.9
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/28/2012 6:40:03 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Zeroaccess.B in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\80000000.@
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.

Error - 9/28/2012 6:41:07 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Gen in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\00000008.@
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 9/28/2012 6:42:05 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Gen.2 in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\00000004.@
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 9/28/2012 6:43:02 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Zeroaccess.C in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\000000cb.@
by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: The file
was deleted successfully.

Error - 9/28/2012 6:43:59 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Zeroaccess.B in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\80000000.@
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.

Error - 9/28/2012 6:44:46 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Gen in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\00000008.@
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 9/28/2012 6:46:13 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Zeroaccess.C in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\000000cb.@
by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: The file
was deleted successfully.

Error - 9/28/2012 6:47:04 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Gen.2 in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\00000004.@
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 9/28/2012 6:47:51 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Zeroaccess.B in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\80000000.@
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.

Error - 9/28/2012 6:48:33 PM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan.Gen in File: C:\$Recycle.Bin\S-1-5-18\$7acaefb09c1386a0b371b6660cf41e97\U\00000008.@
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

[ Media Center Events ]
Error - 6/3/2012 8:45:34 PM | Computer Name = Paul-PC | Source = MCUpdate | ID = 0
Description = 8:45:33 PM - Error connecting to the internet. 8:45:33 PM - Unable
to contact server..

Error - 6/3/2012 11:19:02 PM | Computer Name = Paul-PC | Source = MCUpdate | ID = 0
Description = 11:19:02 PM - Error connecting to the internet. 11:19:02 PM - Unable
to contact server..

Error - 6/4/2012 1:19:00 AM | Computer Name = Paul-PC | Source = MCUpdate | ID = 0
Description = 1:19:00 AM - Error connecting to the internet. 1:19:00 AM - Unable
to contact server..

[ System Events ]
Error - 9/27/2012 8:28:51 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/27/2012 8:29:32 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7003
Description = The IKE and AuthIP IPsec Keying Modules service depends the following
service: BFE. This service might not be installed.

Error - 9/27/2012 8:29:34 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7023
Description = The Function Discovery Resource Publication service terminated with
the following error: %%-2147024891

Error - 9/27/2012 9:03:58 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7031
Description = The Symantec Endpoint Protection service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 10000
milliseconds: Restart the service.

Error - 9/27/2012 9:04:08 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Symantec Endpoint Protection
service, but this action failed with the following error: %%1056

Error - 9/28/2012 12:27:12 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Audio service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 9/28/2012 12:27:12 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7031
Description = The DHCP Client service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 120000 milliseconds:
Restart the service.

Error - 9/28/2012 12:27:12 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Event Log service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 9/28/2012 12:27:12 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7031
Description = The TCP/IP NetBIOS Helper service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 100 milliseconds:
Restart the service.

Error - 9/28/2012 12:29:12 PM | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the DHCP Client service, but this
action failed with the following error: %%1056


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.
———-

Is this a business or work/corporate computer?
Hi Jeff. Yes I definitely still need help. Sorry about the late response I just assumed that my thread wouldn't be looked at for a few days. I use this computer for work and for personal reasons.
Hi,

Thanks for letting me know. :)

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Jeff, the symantec antivirus scanner log is no longer popping up for me with the trojan threats, since yesterday actually. I also haven't had any adware in 2 days. I am a little hesitant on continuing with these fixes. What do you think about this? Here is my combo fix log: ComboFix 12-10-02.02 - Paul 10/02/2012 22:55:09.1.2 - x86 Running from: c:\users\[removed]\Desktop\ComboFix.exe * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Paul\AppData\Roaming\1c9f7c68 c:\users\Paul\AppData\Roaming\1d1d83f7 c:\users\Paul\AppData\Roaming\1e07dd9b c:\users\Paul\AppData\Roaming\1eca2c61 c:\users\Paul\AppData\Roaming\200c5039 c:\users\Paul\AppData\Roaming\202a4993 c:\users\Paul\AppData\Roaming\20e82977 c:\users\Paul\AppData\Roaming\20f80714 c:\users\Paul\AppData\Roaming\21bd0c05 c:\users\Paul\AppData\Roaming\227ef9a4 c:\users\Paul\AppData\Roaming\234e9747 c:\users\Paul\AppData\Roaming\23ebef6 c:\users\Paul\AppData\Roaming\240e46aa c:\users\Paul\AppData\Roaming\289e00f2 c:\users\Paul\AppData\Roaming\296cb727 c:\users\Paul\AppData\Roaming\2b1e9a0 c:\users\Paul\AppData\Roaming\2db3132d c:\users\Paul\AppData\Roaming\2e9bad92 c:\users\Paul\AppData\Roaming\2f3534fb c:\users\Paul\AppData\Roaming\30150202 c:\users\Paul\AppData\Roaming\3058105a c:\users\Paul\AppData\Roaming\312586c9 c:\users\Paul\AppData\Roaming\3359774f c:\users\Paul\AppData\Roaming\342b71c6 c:\users\Paul\AppData\Roaming\35d42f00 c:\users\Paul\AppData\Roaming\36a0ff25 c:\users\Paul\AppData\Roaming\38fd6202 c:\users\Paul\AppData\Roaming\39c01c4a c:\users\Paul\AppData\Roaming\3a480cae c:\users\Paul\AppData\Roaming\3ad1a66f c:\users\Paul\AppData\Roaming\3afd9152 c:\users\Paul\AppData\Roaming\3b4ce9a7 c:\users\Paul\AppData\Roaming\3b761382 c:\users\Paul\AppData\Roaming\40b819ec c:\users\Paul\AppData\Roaming\418e3400 c:\users\Paul\AppData\Roaming\425d74a4 c:\users\Paul\AppData\Roaming\43224e22 c:\users\Paul\AppData\Roaming\485ed46e c:\users\Paul\AppData\Roaming\492de2da c:\users\Paul\AppData\Roaming\4ef188fc c:\users\Paul\AppData\Roaming\4f8932d1 c:\users\Paul\AppData\Roaming\5853376e c:\users\Paul\AppData\Roaming\58ccbb79 c:\users\Paul\AppData\Roaming\5c8751a0 c:\users\Paul\AppData\Roaming\5cd09e8f c:\users\Paul\AppData\Roaming\5d52859d c:\users\Paul\AppData\Roaming\5da3a4fa c:\users\Paul\AppData\Roaming\6dd0c133 c:\users\Paul\AppData\Roaming\6e9b1342 c:\users\Paul\AppData\Roaming\702438e5 c:\users\Paul\AppData\Roaming\70eed82b c:\users\Paul\AppData\Roaming\72e3099d c:\users\Paul\AppData\Roaming\736cce4a c:\users\Paul\AppData\Roaming\73a90013 c:\users\Paul\AppData\Roaming\743a5bb6 c:\users\Paul\AppData\Roaming\76c78d2f c:\users\Paul\AppData\Roaming\774ef04b c:\users\Paul\AppData\Roaming\77729929 c:\users\Paul\AppData\Roaming\783fba63 c:\users\Paul\AppData\Roaming\7acb2a09 c:\users\Paul\AppData\Roaming\7b4162b0 c:\users\Paul\AppData\Roaming\813ed662 c:\users\Paul\AppData\Roaming\81e1f44d c:\users\Paul\AppData\Roaming\81e7d583 c:\users\Paul\AppData\Roaming\82beed90 c:\users\Paul\AppData\Roaming\83fe8c08 c:\users\Paul\AppData\Roaming\84c3a9b7 c:\users\Paul\AppData\Roaming\85267ef3 c:\users\Paul\AppData\Roaming\858643ba c:\users\Paul\AppData\Roaming\85fdb830 c:\users\Paul\AppData\Roaming\8665e41c c:\users\Paul\AppData\Roaming\896687b4 c:\users\Paul\AppData\Roaming\89dbaf4a c:\users\Paul\AppData\Roaming\8cd21bda c:\users\Paul\AppData\Roaming\8db2de3b c:\users\Paul\AppData\Roaming\92c005c6 c:\users\Paul\AppData\Roaming\93aba68d c:\users\Paul\AppData\Roaming\96044c56 c:\users\Paul\AppData\Roaming\96ced360 c:\users\Paul\AppData\Roaming\9d19eeff c:\users\Paul\AppData\Roaming\9d8ec91c c:\users\Paul\AppData\Roaming\a3e9ee63 c:\users\Paul\AppData\Roaming\a4b22dde c:\users\Paul\AppData\Roaming\a6c1a1ad c:\users\Paul\AppData\Roaming\a7845e89 c:\users\Paul\AppData\Roaming\a94d52e8 c:\users\Paul\AppData\Roaming\aa14fc62 c:\users\Paul\AppData\Roaming\abb72054 c:\users\Paul\AppData\Roaming\ac75a77d c:\users\Paul\AppData\Roaming\adca90f3 c:\users\Paul\AppData\Roaming\ae90dafc c:\users\Paul\AppData\Roaming\b7206a37 c:\users\Paul\AppData\Roaming\b7e9e6ef c:\users\Paul\AppData\Roaming\b8a7ed3b c:\users\Paul\AppData\Roaming\b9da4fa5 c:\users\Paul\AppData\Roaming\b9ffc7b9 c:\users\Paul\AppData\Roaming\ba064537 c:\users\Paul\AppData\Roaming\baac298a c:\users\Paul\AppData\Roaming\bad25afc c:\users\Paul\AppData\Roaming\bb2403b0 c:\users\Paul\AppData\Roaming\be38b898 c:\users\Paul\AppData\Roaming\bec4d7c4 c:\users\Paul\AppData\Roaming\c02df36b c:\users\Paul\AppData\Roaming\c0f2d975 c:\users\Paul\AppData\Roaming\c632ded1 c:\users\Paul\AppData\Roaming\c70ddcca c:\users\Paul\AppData\Roaming\cf1f928d c:\users\Paul\AppData\Roaming\cfe46cc6 c:\users\Paul\AppData\Roaming\f2751cf2 c:\users\Paul\AppData\Roaming\f349a0b6 . . ((((((((((((((((((((((((( Files Created from 2012-09-03 to 2012-10-03 ))))))))))))))))))))))))))))))) . . 2012-10-03 03:03 . 2012-10-03 03:03 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-10-03 03:03 . 2012-10-03 03:03 ——– d—–w- c:\users\Edward\AppData\Local\temp 2012-10-03 03:03 . 2012-10-03 03:03 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-03 03:03 . 2012-10-03 03:03 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-09-25 17:32 . 2012-08-21 17:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-09-25 17:30 . 2012-09-25 17:30 ——– d—–w- c:\program files\iPod 2012-09-25 17:30 . 2012-09-25 17:32 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-09-25 17:30 . 2012-09-25 17:32 ——– d—–w- c:\program files\iTunes 2012-09-23 04:23 . 2012-09-23 04:23 ——– d—–w- c:\program files\CCleaner 2012-09-12 23:54 . 2012-09-12 23:54 73696 —-a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll 2012-09-12 03:57 . 2012-08-22 17:16 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-12 03:57 . 2012-07-04 19:45 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-12 03:56 . 2012-08-22 17:16 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-12 03:56 . 2012-08-22 17:16 240496 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-12 03:56 . 2012-08-22 17:16 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-12 03:49 . 2012-08-02 16:57 490496 —-a-w- c:\windows\system32\d3d10level9.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-25 17:29 . 2012-05-17 04:36 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-25 17:29 . 2011-12-30 17:09 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-08 09:10 . 2010-02-02 16:53 167936 —-a-w- c:\windows\system32\drivers\wpshelper.sys 2012-08-21 17:01 . 2010-09-03 20:50 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-07-18 17:47 . 2012-08-15 17:53 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-09 17:42 . 2012-07-09 17:42 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-07-09 17:42 . 2012-07-09 17:42 44032 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2012-09-12 23:54 . 2011-05-06 19:01 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-09-21 896912] "ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-11-20 22453840] "Steam"="c:\program files\Steam\Steam.exe" [2012-08-06 1353080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-29 217088] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-15 458844] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 170520] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.207\McCHSvc.exe [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdg.sys [x] S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdg.sys [x] S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x] S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - IPNAT *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-10-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 17:29] . 2012-10-03 c:\windows\Tasks\AWC Startup.job - c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-02-02 20:33] . . ——- Supplementary Scan ——- . uStart Page = hxxp://friendly-google-search.blogspot.com uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p= FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file) Toolbar-Locked - (no file) WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) SafeBoot-Wdf01000.sys SafeBoot-Symantec Antvirus AddRemove-1ClickDownload - c:\program files\1ClickDownload\uninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\STacSV.exe c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\windows\system32\WLANExt.exe c:\windows\system32\conhost.exe c:\program files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE c:\program files\Dell\Dell Wireless WLAN Card\bcmwltry.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\DRIVERS\o2flash.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\conhost.exe c:\windows\System32\rundll32.exe c:\program files\DellTPad\ApMsgFwd.exe c:\program files\DellTPad\HidFind.exe c:\program files\DellTPad\Apntex.exe c:\windows\system32\conhost.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\sppsvc.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\servicing\TrustedInstaller.exe c:\program files\Common Files\Java\Java Update\jucheck.exe . ************************************************************************** . Completion time: 2012-10-02 23:12:27 - machine was rebooted ComboFix-quarantined-files.txt 2012-10-03 03:12 . Pre-Run: 167,333,683,200 bytes free Post-Run: 168,151,429,120 bytes free . - - End Of File - - A30798B90B6D50E24B23BB9AF22A61D7

I am a little hesitant on continuing with these fixes. What do you think about this?

This is a serious infection that is on your system. If it were my system and had decided to attempt to clean it, I would continue all the way through. An absence of symptoms does not necessarily mean an absence of an infection.
———-
If you would like to continue please do the following…
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    File::
    c:\windows\Tasks\AWC Startup.job
    c:\program files\IObit\Advanced SystemCare 3\AWC.exe

    Firefox::
    FF - ProfilePath - c:\users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Post the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
You are right I should go through with a full disinfection. Here is my log: ComboFix 12-10-04.02 - Paul 10/04/2012 13:56:44.3.2 - x86 Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Paul\Desktop\CFScript.txt * Created a new restore point . FILE :: "c:\program files\IObit\Advanced SystemCare 3\AWC.exe" "c:\windows\Tasks\AWC Startup.job" . . ((((((((((((((((((((((((( Files Created from 2012-09-04 to 2012-10-04 ))))))))))))))))))))))))))))))) . . 2012-10-04 18:05 . 2012-10-04 18:05 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-10-04 18:05 . 2012-10-04 18:05 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-10-04 18:05 . 2012-10-04 18:05 ——– d—–w- c:\users\Edward\AppData\Local\temp 2012-10-04 18:05 . 2012-10-04 18:05 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-03 03:13 . 2012-08-21 20:12 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-25 17:32 . 2012-08-21 17:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-09-25 17:30 . 2012-09-25 17:30 ——– d—–w- c:\program files\iPod 2012-09-25 17:30 . 2012-09-25 17:32 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-09-25 17:30 . 2012-09-25 17:32 ——– d—–w- c:\program files\iTunes 2012-09-23 04:23 . 2012-09-23 04:23 ——– d—–w- c:\program files\CCleaner 2012-09-12 23:54 . 2012-09-12 23:54 73696 —-a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll 2012-09-12 03:57 . 2012-08-22 17:16 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-12 03:57 . 2012-07-04 19:45 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-12 03:56 . 2012-08-22 17:16 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-12 03:56 . 2012-08-22 17:16 240496 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-12 03:56 . 2012-08-22 17:16 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-12 03:49 . 2012-08-02 16:57 490496 —-a-w- c:\windows\system32\d3d10level9.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-30 22:03 . 2010-02-02 16:53 174056 —-a-w- c:\windows\system32\drivers\wpshelper.sys 2012-09-25 17:29 . 2012-05-17 04:36 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-25 17:29 . 2011-12-30 17:09 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-08-21 17:01 . 2010-09-03 20:50 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-07-18 17:47 . 2012-08-15 17:53 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-09 17:42 . 2012-07-09 17:42 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-07-09 17:42 . 2012-07-09 17:42 44032 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2012-09-12 23:54 . 2011-05-06 19:01 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-09-21 896912] "ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-11-20 22453840] "Steam"="c:\program files\Steam\Steam.exe" [2012-08-06 1353080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-29 217088] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-15 458844] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 170520] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.207\McCHSvc.exe [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdg.sys [x] S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdg.sys [x] S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x] S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-10-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 17:29] . 2012-10-04 c:\windows\Tasks\AWC Startup.job - c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-02-02 20:33] . . ——- Supplementary Scan ——- . uStart Page = hxxp://friendly-google-search.blogspot.com uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.1.2.106 10.2.1.101 [removed] FF - ProfilePath - c:\users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\wmk3r8jv.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p= FF - user.js: network.protocol-handler.warn-external.dnupdate - false . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-04 14:07:13 ComboFix-quarantined-files.txt 2012-10-04 18:07 ComboFix2.txt 2012-10-04 17:38 ComboFix3.txt 2012-10-03 03:12 . Pre-Run: 167,861,891,072 bytes free Post-Run: 167,821,578,240 bytes free . - - End Of File - - D5A02BF079BD5F079877DB812E2783BC
How is your system running?
———

Java

Please go to Start > Control Panel > Programs and Features > uninstall all the Java Programs you see, now download the latest Java from the following link and install it:

http://java.com/en/download/index.jsp
———-

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
So I don't really notice any changes to how the system is running. The first time I ran malwarebytes it detected 0 infections. Then I ran eset online scanner and it detected 3 infections. The auto protect for symantec turned on for a few minutes during the scan but I noticed it and turned it off. I hope that it didn't affect the scan. After that, I ran malwarebytes again and it detected 1101 infections. Here is the malwarebytes log: Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.10.04.10 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Paul :: PAUL-PC [administrator] 10/4/2012 11:10:48 PM mbam-log-2012-10-04 (23-30-39).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 250219 Time elapsed: 16 minute(s), 59 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1101 c:\users\paul\appdata\local\temp\dwhf662.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf680.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf6ec.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf6ed.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf70c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf73b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf73c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf74b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf76b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf882.tmp (Rootkit.0Access) -> No action taken. c:\users\paul\appdata\local\temp\dwhf8ff.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf91f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf92e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf9aa.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf9ab.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf9ac.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfa19.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfa47.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfa86.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhfa96.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfaa5.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhfad4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfb6f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfc0c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfc3b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfc4b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhfcc7.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhfd34.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfd53.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhfddf.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfde0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhfe2e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9780.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh97fd.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh983a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh984.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9889.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9906.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh99a1.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9a4d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9a6c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9a9a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9aca.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9af9.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9afa.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9b37.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9bc4.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9c02.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9c6f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9c9f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9d1a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9d69.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9d78.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh9d88.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9d97.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh9e23.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3811.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3830.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh384f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh38a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh38bd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh38ce.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh390b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh392a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3949.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3997.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh39b8.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh39f6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3a23.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3a24.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3a9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3ac0.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3adf.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3b1e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3b5b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3ba.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3baa.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3bd9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3c26.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3c27.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3c37.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh77b1.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh77c1.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh77fe.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh784d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh785c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh786b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh787b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh788c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh789b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh78d9.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh78e9.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7916.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7917.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7926.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7947.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7955.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7a0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7a5f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7a6e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb07b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb09.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb0f8.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb146.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb211.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb220.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb23f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb25e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb26f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb28.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb28f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb2ad.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb2be.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb2cc.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB38.tmp (Trojan.Small) -> No action taken. c:\users\paul\appdata\local\temp\dwhb3d5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb3e6.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb443.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb471.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb4ef.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb52d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb53d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb5a9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb5d8.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhb5d9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhb664.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhdf77.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhdfa6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhdfe4.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe024.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe070.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe08f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe0a0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe0b0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe0ed.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe0ee.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe0fd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe0fe.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe207.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe236.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe2a2.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe2a3.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe2b1.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe2b3.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe300.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe31f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe34.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe35e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe36e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe37d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe38d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe3ea.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe4e3.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhe502.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhe560.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2213.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2241.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2251.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh228e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh22ae.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh22fc.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh231c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh233.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh23c7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh23e6.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2405.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh243.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2434.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2443.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2453.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh24b0.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh252f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh253d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh254d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh256c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh259b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhc7f1.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc80.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhc811.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc89e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhc8ac.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc8fa.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc948.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc958.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhc987.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc988.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc9c5.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhca22.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhca42.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhca43.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhca53.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhca81.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhcaa0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhcae.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhcafe.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhcb0d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhcb2c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhcb2d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhcb7a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhcbb9.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4b15.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4b24.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4b45.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4b53.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4b82.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4bb1.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4bc0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4bf0.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4c1d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4c3e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4c6c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4c6d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4cb9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4cda.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4d27.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4d3.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4d46.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4d67.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4d76.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4d86.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4de3.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4e4f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4e6f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4e8f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4efb.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4f0b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4f0c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4f1b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4f2a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4fa6.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4fe5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5033.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5052.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5072.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5081.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh50e0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh50fe.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh512c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh86fd.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh870c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh87d6.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8806.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8824.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8833.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8844.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8881.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8882.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh88a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh890f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh897b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh898b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh89b9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8a27.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8a46.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8a84.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8ac2.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8ae3.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1038.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1046.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1112.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1121.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh119e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh11ad.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh11ae.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh11cd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh122a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh124a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1269.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1279.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1288.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh129.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh12a7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh12f6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1372.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1381.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1392.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh13a1.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh13c0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh13e0.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh142e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh143d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh143e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh145c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh148b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh14d9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh14e8.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh14f8.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1517.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1546.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1565.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh15c3.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd30a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd338.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd358.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd376.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd377.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd3d4.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd432.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd50c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd51a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd54b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd55a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd598.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd5f5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd5f6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd614.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd615.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd634.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd6ff.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd71d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd73c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd73e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd76c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd7a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd7ca.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd7da.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd876.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd89.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd8a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd8d2.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhd98.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhd9cc.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhda1b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhda2a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhda58.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhda79.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6b33.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6b61.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6b91.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6bee.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6bfc.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6bfd.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6c1c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6c2c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6c5b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6cf6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6cf7.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6d17.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6d73.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6d82.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6d83.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6de0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6e4e.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6e8d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6ebb.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6eeb.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6f09.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6f66.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6fb5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6ff3.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7041.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7042.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7051.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh706f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha46b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha47b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha4a8.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha4e8.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha517.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha584.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha66d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha66e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha68c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha6ab.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha6db.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha72a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha777.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha7b4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha7c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha7e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha860.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha8af.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha8dd.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha8fc.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha8fd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha90d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha9c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwha9e7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwha9e8.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhed7b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhed9a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhed9b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhedc9.tmp (Rootkit.0Access) -> No action taken. c:\users\paul\appdata\local\temp\dwhedd9.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhedf7.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhee08.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhee65.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhee94.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwheeb2.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwheef.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhef01.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhefbc.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhefeb.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhefec.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf00b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhf039.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf049.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf0b5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf0d6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf0e4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf124.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhf134.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbc1f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbc3f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbc9b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbd0a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbd57.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbda4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbdb4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbdf4.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbe12.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbe22.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbe51.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhbe8f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbe9f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbefc.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbf1b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbf6a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbf99.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhbff6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwhc083.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc0b1.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwhc0ef.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2c9d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2ceb.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2d96.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2de4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2df4.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2e42.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2e9f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh2ebf.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2ee.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2ef.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2f2d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2f5b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh2fc7.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3036.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh30e0.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh30e2.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh30f2.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh319c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh31dc.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh31e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh31eb.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3295.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh32b5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh32d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3303.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3371.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh33a0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5d9c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5dda.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5e27.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5e66.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5ec.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5ee3.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5f02.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5f12.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5f40.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5f61.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5fae.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5ffd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh601c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh604a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6059.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6079.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh60a7.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh60b7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh60b8.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh60d6.tmp (Rootkit.0Access) -> No action taken. c:\users\paul\appdata\local\temp\dwh60e7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh60f6.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6105.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6116.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh6135.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh6162.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh61ef.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh620f.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh622d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh625c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh627c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh62b9.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh169c.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh169e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh16bd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1719.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1767.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh178.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh17a7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1842.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh193c.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh193d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh194d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh197.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1a7.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1a84.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1ad2.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1ae1.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1b40.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1bad.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh1bf9.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh1c0a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3cb3.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3d21.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3dec.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3e39.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3e68.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3e87.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3e97.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3e98.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3ef5.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3f24.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh3f90.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh3fb0.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh402d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh404d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh405b.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh407b.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh40aa.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4165.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh4175.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh41f2.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh426d.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh42ac.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh42bc.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh4442.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5227.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5245.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5256.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5275.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5284.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5294.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh52c3.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5340.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh534f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh53bc.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh53fc.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5419.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh5429.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh542a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh5497.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh54a6.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh54e5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh566a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh569a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7f3f.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh7f6d.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh7fab.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8029.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8057.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh80b5.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh80e.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh80e5.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh81cd.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh826a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh827a.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8289.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh828a.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh82d7.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh82e6.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8326.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8345.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8391.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8393.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh83a2.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh83b1.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh83f0.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh84fa.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8537.tmp (Rootkit.Zaccess) -> No action taken. c:\users\paul\appdata\local\temp\dwh8585.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh85e3.tmp (Trojan.Dropper.BCMiner) -> No action taken. c:\users\paul\appdata\local\temp\dwh8660.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH868F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFE6C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFEAA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFF09.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFF66.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFF9.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFFA4.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFFF2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDA98.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDB04.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDB24.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDB53.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDB61.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDB7.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDB90.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDBBF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDBFF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDC1C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDC5B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDC5C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDCC9.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDCD9.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDCE8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDCF7.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDD18.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDD83.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDD85.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDE01.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDE30.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDE7D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDE7E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDEEB.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDEFA.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDF1A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8EF7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8F37.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8F46.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8FD3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8FF0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH903F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9040.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH904F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH907D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9119.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9128.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9158.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9168.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH91C5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH91C6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9233.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9262.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9271.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9290.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH92A0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH92FC.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH932C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH936.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH93C7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9492.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH94B2.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH94C2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9639.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9686.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH96A5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH96D4.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH96F3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9732.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9EA2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9EDE.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9F0.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9FAA.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9FD8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9FE8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9FF8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA008.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA009.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA01.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA045.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA046.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA094.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA13F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA140.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA14F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA17D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA1CC.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA1EB.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA1FA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA20.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA22A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA268.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA287.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA297.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA2A6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA2C6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA2D5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA2E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA2F5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA305.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA323.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA3EF.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCBE7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCC08.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCC45.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCC55.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCCB3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCCC2.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCCC3.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCCF1.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCCF2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCD2F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCD3F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCE09.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCE1A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCE68.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCEF3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCEF5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCF03.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCF71.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCF90.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCFA0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCFC.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCFED.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD00D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD07A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD098.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD134.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD182.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD1B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD200.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD23E.tmp (Rootkit.0Access) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6317.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6355.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6430.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH644F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH646E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH646F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH648E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH651B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH652B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH653A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6568.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6633.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6662.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6672.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6692.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH66DF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH66EE.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH674C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH676B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH677A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH678.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH678A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6816.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6866.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH69BC.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6A87.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB694.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB6A3.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB6A4.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB6C3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB6D2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB6D3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB6F2.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB720.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB73F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB75E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB76D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB77D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB78E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB7EB.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB819.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB83A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB8B6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB8D5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB8E5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB913.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB914.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB932.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB943.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB952.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB980.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB990.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBA3B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBA4C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBA5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBAE8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBB64.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBB73.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBB75.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBBA3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBBE2.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE5EC.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE62C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE63.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE64.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE64B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE679.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE762.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE7A2.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE7F0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE82E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE85D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE89B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE8BB.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE8DA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE8E9.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE946.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE967.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE984.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE9D2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEA02.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEA12.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEAEB.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEAFC.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEB0C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEB4A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEB5A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHEB78.tmp (Rootkit.0Access) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHECCF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH26F2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2720.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2730.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2750.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2760.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH278F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH279E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH281B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2869.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH28B6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH28C6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH28D6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2904.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2915.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2981.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH29B1.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH29FD.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2A1.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2A4C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2A5C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2A6C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2A7C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2A9A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2AF7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2B0.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2B84.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2C1F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2C21.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH712C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7188.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7205.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7215.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH724.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH72DF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH731F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH732D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH732F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH736C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH73CA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH742.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7437.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7456.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7475.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH74A5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7511.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH75AD.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH75DD.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH75FB.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH761B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7659.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH76C5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH76D6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHA3FD.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAA45.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAFC0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHB693.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHBBF0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC13.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC7F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHCBE.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHD2BA.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDA88.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHDF29.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHE5CD.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHED3C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF1F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF660.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHFE4C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAA63.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAA64.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAAA3.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAAF0.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAB1F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAB5C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAB5D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAB6C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAB9C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHABFA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAC95.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAC96.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAD.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAD51.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHADA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHADB.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHADDD.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAE2B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAE78.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAEB7.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAEE5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAF24.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAF63.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHAFB1.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH33CE.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH341B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH341D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH344B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH345B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH346A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3489.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH34C8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH34E6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3515.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3526.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3553.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3583.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3592.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH35A2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH35E1.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH35F0.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH367D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH36BA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH36F8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3718.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3728.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3737.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3775.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH37F2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH449F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH44BE.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH455.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH455A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH455B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH458A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH45B8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4693.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH46E1.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH46F0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4730.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH474.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH475.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH477D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH47DB.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4858.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4868.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4877.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH48B5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH48C5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4921.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4923.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4931.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4980.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH49AE.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4A0C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4A1B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4A2C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4A59.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4A5A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF22C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF22D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF26B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF29A.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF2E7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF2F8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF307.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF325.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF345.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF383.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF3A4.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF3D1.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF3E2.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF400.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF45E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF46F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF47E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF49D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF4AC.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF4BB.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF4DA.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF528.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF5D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF5D5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHF623.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC14C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC19C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC1BA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC247.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC295.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC312.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC35F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC36E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC36F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC38F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC3BE.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC3CC.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC3EC.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC449.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC4C7.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC4E6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC52.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC5EE.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC62D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC64C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC66C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC6D8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC774.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWHC7E3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH56E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5746.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5764.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH57D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5948.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5957.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5977.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH59A6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH59E3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH59E4.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5A9F.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5AAF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5B1C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5B4C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5B99.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5BC8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5C16.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5C34.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5C43.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5C63.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5C73.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5C83.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5CA3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5CC1.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1CC6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1CD4.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1CD5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1CE5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1DBF.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1DED.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1E0D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1E1D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1E4C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1E69.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1E9A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1EC9.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1ED7.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1F16.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1FD1.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2010.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH203E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH206C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH206D.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH20AA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH21.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2139.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2185.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2195.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH21A6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH21B5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7B19.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7B38.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7B49.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7BB7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7BD5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7BE.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7C03.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7C33.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7C81.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7CD0.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7D0C.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7D1D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7D5A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7DC8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7DE7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7E.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7E45.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7E46.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7EA3.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7EE.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8B22.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8B70.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8BAE.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8C4A.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8C98.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8CC6.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8CE6.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8CF5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8D05.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8D34.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8D91.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8DFE.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8E4B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8E5C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8E8B.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8EAA.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8EC8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8ECA.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH15E1.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH1CB5.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2202.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2665.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH2C5E.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH33BF.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3801.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH3CA3.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4490.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH4AF5.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH515B.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH56D8.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH5D3D.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH62E8.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH6AF3.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH711C.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7723.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7ABD.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH7F1F.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH86AD.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8B11.tmp (Trojan.Dropper.BCMiner) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH8EE7.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9740.tmp (Rootkit.Zaccess) -> No action taken. C:\Users\Paul\AppData\Local\Temp\DWH9E42.tmp (Trojan.Dropper.BCMiner) -> No action taken. (end) Here is the eset scanner log: C:\Users\Paul\Downloads\YouTubeDownloaderSetup265.exe a variant of Win32/Toolbar.Widgi application C:\Users\Paul\Downloads\YouTubeDownloaderSetup33.exe a variant of Win32/Toolbar.Widgi application C:\Users\Paul\Downloads\[PC_Game]_Super_Mario_Bros_X_-_Full_Version.exe multiple threats
Hi,

That Malwarebytes log is certainly interesting…after seeing that I think we need to get a look at your system in a different way.

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

FRST

Download the 32 bit version for your system of FRST and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

———-
Jeff, Here is the ckfiles log: CKScanner - Additional Security Risks - These are not necessarily bad c:\users\paul\downloads\noad_1.3.100 cracked by cnpda-wonderful.ipa scanner sequence 3.NA.11.GMAPAD —– EOF —– Here is the frst log: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-10-2012 01 Ran by [removed] at 05-10-2012 13:30:27 Running from F:\ Windows 7 Professional (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [217088 2009-06-28] (Alps Electric Co., Ltd.) HKLM\…\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe [458844 2009-07-15] (IDT, Inc.) HKLM\…\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4562944 2009-07-16] (Dell Inc.) HKLM\…\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.) HKLM\…\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe [36864 2008-01-07] (Creative Technology Ltd.) HKLM\…\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM\…\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [115560 2009-07-08] (Symantec Corporation) HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-09-08] (Apple Inc.) HKLM\…\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47904 2010-10-08] (Apple Inc.) HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.) HKLM\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-01-03] (Adobe Systems Incorporated) HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.) HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKU\Edward\…\Run: [Aim] "C:\Program Files\AIM\aim.exe" /d locale=en-US [x] HKU\Edward\…\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent [1353080 2012-08-05] (Valve Corporation) HKU\Edward\…\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 [280576 2012-06-03] (Microsoft Corporation) HKU\Guest\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-09-08] (Apple Inc.) HKU\Paul\…\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED [896912 2012-09-20] (BitTorrent, Inc.) HKU\Paul\…\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized [22453840 2011-11-20] (ooVoo LLC) HKU\Paul\…\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent [1353080 2012-08-05] (Valve Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.) ==================== Services (Whitelisted) =================== 2 ccEvtMgr; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [108392 2009-07-08] (Symantec Corporation) 2 ccSetMgr; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [108392 2009-07-08] (Symantec Corporation) 3 LiveUpdate; "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" [3093880 2009-07-13] (Symantec Corporation) 3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe" [237008 2011-06-17] (McAfee, Inc.) 2 O2FLASH; C:\Windows\System32\DRIVERS\o2flash.exe [65536 2007-02-12] (O2Micro International) 2 SmcService; "C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" [1864888 2009-09-17] (Symantec Corporation) 4 SNAC; "C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" [341320 2009-09-17] (Symantec Corporation) 2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\STacSV.exe [221266 2009-07-15] (IDT, Inc.) 2 Symantec AntiVirus; "C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe" [2477304 2009-09-17] (Symantec Corporation) 2 wltrysvc; "C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE" "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe" [3086848 2009-07-16] (Dell Inc.) ==================== Drivers (Whitelisted) ==================== 3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2009-07-16] (Broadcom Corporation) 1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-08-08] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-08-08] (Symantec Corporation) 3 NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20121004.002\NAVENG.SYS [92704 2012-09-13] (Symantec Corporation) 3 NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20121004.002\NAVEX15.SYS [1601184 2012-09-13] (Symantec Corporation) 3 O2MDGRDR; C:\Windows\System32\DRIVERS\o2mdg.sys [58528 2009-05-22] (O2Micro ) 3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdg.sys [41504 2009-05-07] (O2Micro ) 3 OEM13Vfx; C:\Windows\System32\DRIVERS\OEM13Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.) 3 OEM13Vid; C:\Windows\System32\DRIVERS\OEM13Vid.sys [235840 2008-05-28] (Creative Technology Ltd.) 1 SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [421424 2009-08-26] (Symantec Corporation) 1 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [281648 2009-08-25] (Symantec Corporation) 3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [320560 2009-08-25] (Symantec Corporation) 1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [43696 2009-08-25] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [124976 2010-02-02] (Symantec Corporation) 3 SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [26416 2009-09-03] (Symantec Corporation) 1 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [188080 2009-09-03] (Symantec Corporation) 4 SysPlant; C:\Windows\SYSTEM32\Drivers\SysPlant.sys [92488 2009-09-17] (Symantec Corporation) 3 Teefer2; C:\Windows\System32\DRIVERS\teefer2.sys [50064 2009-05-27] (Symantec Corporation) 1 WPS; \??\C:\Windows\system32\drivers\wpsdrvnt.sys [42312 2009-09-17] (Symantec Corporation) 3 WpsHelper; \??\C:\Windows\system32\drivers\WpsHelper.sys [174056 2012-09-30] (Symantec Corporation) 3 catchme; \??\C:\Users\Paul\AppData\Local\Temp\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2012-10-05 09:13 - 2012-10-05 09:13 - 00905956 ____A (Farbar) C:\Users\Paul\Downloads\FRST.exe 2012-10-05 09:10 - 2012-10-05 09:10 - 00000192 ____A C:\Users\Paul\Desktop\ckfiles.txt 2012-10-05 09:07 - 2012-10-05 09:07 - 00458240 ____A () C:\Users\Paul\Desktop\CKScanner.exe 2012-10-04 16:23 - 2012-10-04 16:23 - 00000000 ____A C:\t1bk.2 2012-10-04 12:41 - 2012-10-04 12:41 - 02322184 ____A (ESET) C:\Users\Paul\Downloads\esetsmartinstaller_enu.exe 2012-10-04 12:41 - 2012-10-04 12:41 - 00000000 ____D C:\Program Files\ESET 2012-10-04 12:24 - 2012-10-04 12:24 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-10-04 12:24 - 2012-10-04 12:24 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2012-10-04 12:24 - 2012-09-07 13:04 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-10-04 12:23 - 2012-10-04 12:23 - 10524080 ____A (Malwarebytes Corporation ) C:\Users\Paul\Downloads\mbam-setup-1.65.0.1400(1).exe 2012-10-04 12:09 - 2012-10-04 12:09 - 00000000 ____D C:\Program Files\Common Files\Java 2012-10-04 12:09 - 2012-10-04 12:08 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2012-10-04 12:09 - 2012-10-04 12:08 - 00246760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-10-04 12:08 - 2012-10-04 12:08 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-10-04 12:08 - 2012-10-04 12:08 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-10-04 12:08 - 2012-10-04 12:08 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll 2012-10-04 12:07 - 2012-10-04 12:07 - 00894952 ____A (Oracle Corporation) C:\Users\Paul\Downloads\jxpiinstall.exe 2012-10-04 10:07 - 2012-10-04 10:07 - 00008829 ____A C:\ComboFix.txt 2012-10-02 19:13 - 2012-08-21 12:12 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe 2012-10-02 18:53 - 2012-10-04 10:07 - 00000000 ____D C:\Qoobox 2012-10-02 18:53 - 2012-10-02 19:11 - 00000000 ____D C:\Windows\erdnt 2012-10-02 18:53 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2012-10-02 18:53 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2012-10-02 18:53 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-10-02 18:53 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-10-02 18:53 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-10-02 18:53 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2012-10-02 18:53 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2012-10-02 18:53 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2012-10-02 18:50 - 2012-10-04 09:21 - 04762471 ____R (Swearware) C:\Users\Paul\Desktop\ComboFix.exe 2012-10-02 16:53 - 2012-10-02 16:53 - 00000000 ____D C:\Users\Paul\AppData\Local\{2B0CB641-3574-4B4A-877C-DB46939B1E64} 2012-10-02 16:52 - 2012-10-02 16:52 - 00000000 ____A C:\t1fc.2 2012-10-02 16:52 - 2012-10-02 16:52 - 00000000 ____A C:\t1fc.1 2012-10-01 18:47 - 2012-10-01 18:48 - 00000000 ____D C:\Users\Paul\AppData\Local\{28A3E1EF-F6C2-44F5-B656-8F4C3072689B} 2012-09-30 18:47 - 2012-10-01 06:47 - 00000000 ____D C:\Users\Paul\AppData\Local\{C74A00F8-609C-45D7-9010-E44E0E1F7F08} 2012-09-30 06:46 - 2012-09-30 06:47 - 00000000 ____D C:\Users\Paul\AppData\Local\{172CD134-DF6F-484B-9128-ACD0912EE158} 2012-09-28 20:27 - 2012-09-29 10:43 - 00000000 ____D C:\Users\Paul\AppData\Local\{E20A9160-4629-4AFF-BD84-53463A18CC9F} 2012-09-28 14:23 - 2012-09-28 14:23 - 00602112 ____A (OldTimer Tools) C:\Users\Paul\Desktop\OTL.exe 2012-09-27 16:30 - 2012-09-28 08:27 - 00000000 ____D C:\Users\Paul\AppData\Local\{23FDF748-A959-4BBE-8329-C5F41F151F86} 2012-09-26 09:57 - 2012-09-26 09:57 - 00000000 ____D C:\Users\Paul\AppData\Local\{ACE51E19-95F0-4636-80FF-CC8C1082A66E} 2012-09-26 09:55 - 2012-10-04 10:09 - 00002048 ____A C:\Windows\PFRO.log 2012-09-25 09:32 - 2012-09-25 09:32 - 00001755 ____A C:\Users\Public\Desktop\iTunes.lnk 2012-09-25 09:32 - 2012-08-21 09:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys 2012-09-25 09:30 - 2012-09-25 09:32 - 00000000 ____D C:\Users\All Users\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-09-25 09:30 - 2012-09-25 09:32 - 00000000 ____D C:\Program Files\iTunes 2012-09-25 09:30 - 2012-09-25 09:30 - 00000000 ____D C:\Program Files\iPod 2012-09-25 09:27 - 2012-09-25 09:28 - 78545304 ____A (Apple Inc.) C:\Users\Paul\Downloads\iTunesSetup.exe 2012-09-25 06:35 - 2012-09-25 06:36 - 00000000 ____D C:\Users\Paul\AppData\Local\{C74A78A0-95CF-41F3-8E00-8B713D5C07BA} 2012-09-24 08:33 - 2012-09-24 08:33 - 00000000 ____D C:\Users\Paul\AppData\Local\{94791D2F-AD6E-4FD5-B9D6-8CCFA6B6AB79} 2012-09-22 22:11 - 2012-09-23 10:11 - 00000000 ____D C:\Users\Paul\AppData\Local\{901DF679-5E20-43A7-A582-BD6460C16A33} 2012-09-22 21:00 - 2012-10-05 08:31 - 00001848 ____A C:\Windows\setupact.log 2012-09-22 21:00 - 2012-09-22 21:00 - 00000000 ____A C:\Windows\setuperr.log 2012-09-22 20:23 - 2012-09-22 20:23 - 00000971 ____A C:\Users\Public\Desktop\CCleaner.lnk 2012-09-22 20:23 - 2012-09-22 20:23 - 00000000 ____D C:\Program Files\CCleaner 2012-09-22 20:22 - 2012-09-22 20:22 - 03927560 ____A (Piriform Ltd) C:\Users\Paul\Downloads\ccsetup322.exe 2012-09-22 12:37 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-09-22 12:37 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-09-22 12:37 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-09-22 12:37 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-09-22 12:37 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-09-22 12:37 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-09-22 12:37 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-09-22 12:37 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-09-22 12:37 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-09-22 12:37 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-09-22 12:37 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-09-22 12:37 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-09-22 12:37 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-09-22 12:37 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-09-22 12:37 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-09-22 12:37 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-09-22 10:10 - 2012-09-22 10:11 - 00000000 ____D C:\Users\Paul\AppData\Local\{3897A53D-FD81-4E96-8ADF-3B1323E45E9B} 2012-09-20 17:50 - 2012-09-20 17:51 - 00000000 ____D C:\Users\Paul\AppData\Local\{CFDBCC1D-D7FB-4707-B89E-955391D4E89B} 2012-09-19 09:08 - 2012-09-19 09:08 - 00000000 ____D C:\Users\Paul\AppData\Local\{315480F9-C7A6-4442-8050-AA9B09D86A2F} 2012-09-18 07:07 - 2012-09-18 21:08 - 00000000 ____D C:\Users\Paul\AppData\Local\{9F71D77E-FDDC-408E-85A5-A1B283FA112B} 2012-09-17 07:48 - 2012-09-17 07:48 - 00002052 ____A C:\Windows\epplauncher.mif 2012-09-17 07:47 - 2012-09-17 07:48 - 10288512 ____A (Microsoft Corporation) C:\Users\Paul\Downloads\mseinstall.exe 2012-09-17 07:44 - 2012-09-17 07:44 - 10524080 ____A (Malwarebytes Corporation ) C:\Users\Paul\Downloads\mbam-setup-1.65.0.1400.exe 2012-09-13 18:26 - 2012-09-17 10:18 - 00000000 ____D C:\Users\Paul\AppData\Local\{B0FE5E3B-8DBF-446B-A795-8D1F97CB7CE0} 2012-09-12 14:34 - 2012-09-12 14:34 - 00000000 ____D C:\Users\Paul\AppData\Local\{7EAE368A-E43D-4951-82A1-B4220167F154} 2012-09-11 19:57 - 2012-08-22 09:16 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys 2012-09-11 19:57 - 2012-07-04 11:45 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys 2012-09-11 19:56 - 2012-08-22 09:16 - 01292144 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2012-09-11 19:56 - 2012-08-22 09:16 - 00240496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys 2012-09-11 19:56 - 2012-08-22 09:16 - 00187760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2012-09-11 19:49 - 2012-08-02 08:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2012-09-11 17:47 - 2012-09-11 17:47 - 00000000 ____D C:\Users\Paul\AppData\Local\{98647712-8752-4CCB-9D5E-7EAE4C5F5EA7} 2012-09-10 08:01 - 2012-09-10 08:02 - 00000000 ____D C:\Users\Paul\AppData\Local\{CA891AC9-94DD-4031-8E95-1C10D852D8A7} 2012-09-09 10:59 - 2012-09-09 11:00 - 00000000 ____D C:\Users\Paul\AppData\Local\{0B8CB423-58FB-488B-8BCE-DF62AC062E6F} 2012-09-08 22:59 - 2012-09-08 22:59 - 00000000 ____D C:\Users\Paul\AppData\Local\{EA32B385-F3A2-486F-97AE-95DBEBAA6BA5} 2012-09-08 07:54 - 2012-09-08 07:55 - 00000000 ____D C:\Users\Paul\AppData\Local\{88944712-86D6-47B7-B829-27CB39E946B5} 2012-09-06 19:45 - 2012-09-07 08:00 - 00000000 ____D C:\Users\Paul\AppData\Local\{54A7F051-F2E1-4199-A055-71A2737357E9} 2012-09-05 07:48 - 2012-09-05 07:48 - 00000000 ____D C:\Users\Paul\AppData\Local\{43C74597-84E1-4DB5-B2EF-661F5608C0EC} ==================== 3 Months Modified Files ================== 2012-10-05 09:23 - 2009-07-13 20:55 - 01812642 ____A C:\Windows\WindowsUpdate.log 2012-10-05 09:18 - 2012-05-16 20:36 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-10-05 09:13 - 2012-10-05 09:13 - 00905956 ____A (Farbar) C:\Users\Paul\Downloads\FRST.exe 2012-10-05 09:10 - 2012-10-05 09:10 - 00000192 ____A C:\Users\Paul\Desktop\ckfiles.txt 2012-10-05 09:07 - 2012-10-05 09:07 - 00458240 ____A () C:\Users\Paul\Desktop\CKScanner.exe 2012-10-05 08:38 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-10-05 08:38 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-10-05 08:31 - 2012-09-22 21:00 - 00001848 ____A C:\Windows\setupact.log 2012-10-05 08:31 - 2010-02-02 09:34 - 00000372 ____A C:\Windows\Tasks\AWC Startup.job 2012-10-05 08:31 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-10-04 16:23 - 2012-10-04 16:23 - 00000000 ____A C:\t1bk.2 2012-10-04 12:41 - 2012-10-04 12:41 - 02322184 ____A (ESET) C:\Users\Paul\Downloads\esetsmartinstaller_enu.exe 2012-10-04 12:24 - 2012-10-04 12:24 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-10-04 12:23 - 2012-10-04 12:23 - 10524080 ____A (Malwarebytes Corporation ) C:\Users\Paul\Downloads\mbam-setup-1.65.0.1400(1).exe 2012-10-04 12:08 - 2012-10-04 12:09 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2012-10-04 12:08 - 2012-10-04 12:09 - 00246760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-10-04 12:08 - 2012-10-04 12:08 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-10-04 12:08 - 2012-10-04 12:08 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-10-04 12:08 - 2012-10-04 12:08 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll 2012-10-04 12:08 - 2010-06-10 10:04 - 00746984 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2012-10-04 12:07 - 2012-10-04 12:07 - 00894952 ____A (Oracle Corporation) C:\Users\Paul\Downloads\jxpiinstall.exe 2012-10-04 10:09 - 2012-09-26 09:55 - 00002048 ____A C:\Windows\PFRO.log 2012-10-04 10:07 - 2012-10-04 10:07 - 00008829 ____A C:\ComboFix.txt 2012-10-04 10:05 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini 2012-10-04 09:21 - 2012-10-02 18:50 - 04762471 ____R (Swearware) C:\Users\Paul\Desktop\ComboFix.exe 2012-10-02 18:53 - 2009-07-13 20:53 - 00032642 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-10-02 16:52 - 2012-10-02 16:52 - 00000000 ____A C:\t1fc.2 2012-10-02 16:52 - 2012-10-02 16:52 - 00000000 ____A C:\t1fc.1 2012-09-30 14:03 - 2010-02-02 08:53 - 00174056 ____A (Symantec Corporation) C:\Windows\System32\Drivers\wpshelper.sys 2012-09-28 14:23 - 2012-09-28 14:23 - 00602112 ____A (OldTimer Tools) C:\Users\Paul\Desktop\OTL.exe 2012-09-25 09:32 - 2012-09-25 09:32 - 00001755 ____A C:\Users\Public\Desktop\iTunes.lnk 2012-09-25 09:29 - 2012-05-16 20:36 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2012-09-25 09:29 - 2011-12-30 09:09 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-09-25 09:28 - 2012-09-25 09:27 - 78545304 ____A (Apple Inc.) C:\Users\Paul\Downloads\iTunesSetup.exe 2012-09-22 21:00 - 2012-09-22 21:00 - 00000000 ____A C:\Windows\setuperr.log 2012-09-22 20:23 - 2012-09-22 20:23 - 00000971 ____A C:\Users\Public\Desktop\CCleaner.lnk 2012-09-22 20:22 - 2012-09-22 20:22 - 03927560 ____A (Piriform Ltd) C:\Users\Paul\Downloads\ccsetup322.exe 2012-09-17 07:48 - 2012-09-17 07:48 - 00002052 ____A C:\Windows\epplauncher.mif 2012-09-17 07:48 - 2012-09-17 07:47 - 10288512 ____A (Microsoft Corporation) C:\Users\Paul\Downloads\mseinstall.exe 2012-09-17 07:45 - 2009-11-29 17:07 - 00730320 ____A C:\Windows\System32\PerfStringBackup.INI 2012-09-17 07:44 - 2012-09-17 07:44 - 10524080 ____A (Malwarebytes Corporation ) C:\Users\Paul\Downloads\mbam-setup-1.65.0.1400.exe 2012-09-12 14:37 - 2009-12-15 21:09 - 62164608 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-09-07 13:04 - 2012-10-04 12:24 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-09-03 10:00 - 2012-09-03 10:00 - 00174726 ____A C:\Users\Paul\Desktop\BikeHelmet.htm 2012-08-23 23:27 - 2012-09-22 12:37 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-23 23:03 - 2012-09-22 12:37 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-23 22:59 - 2012-09-22 12:37 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-08-23 22:51 - 2012-09-22 12:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-23 22:51 - 2012-09-22 12:37 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-23 22:51 - 2012-09-22 12:37 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-23 22:49 - 2012-09-22 12:37 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-23 22:48 - 2012-09-22 12:37 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-23 22:47 - 2012-09-22 12:37 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-08-23 22:47 - 2012-09-22 12:37 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-08-23 22:47 - 2012-09-22 12:37 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-08-23 22:45 - 2012-09-22 12:37 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-08-23 22:44 - 2012-09-22 12:37 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-23 22:44 - 2012-09-22 12:37 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-23 22:43 - 2012-09-22 12:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-08-23 22:40 - 2012-09-22 12:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-08-22 09:16 - 2012-09-11 19:57 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys 2012-08-22 09:16 - 2012-09-11 19:56 - 01292144 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2012-08-22 09:16 - 2012-09-11 19:56 - 00240496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys 2012-08-22 09:16 - 2012-09-11 19:56 - 00187760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2012-08-21 12:12 - 2012-10-02 19:13 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe 2012-08-21 09:01 - 2012-09-25 09:32 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys 2012-08-21 09:01 - 2010-09-03 12:50 - 00106928 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi.dll 2012-08-15 13:38 - 2009-07-13 20:33 - 00418312 ____A C:\Windows\System32\FNTCACHE.DAT 2012-08-02 08:57 - 2012-09-11 19:49 - 00490496 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2012-08-01 09:27 - 2012-08-01 09:27 - 05414584 ____A C:\Users\Paul\Downloads\YTDSetup.exe 2012-08-01 09:27 - 2012-08-01 09:27 - 00001253 ____A C:\Users\Public\Desktop\YTD Video Downloader.lnk 2012-07-18 09:47 - 2012-08-15 09:53 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-15 18:22 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini 2012-07-09 09:42 - 2012-07-09 09:42 - 04547984 ____A (Apple, Inc.) C:\Windows\System32\usbaaplrc.dll 2012-07-09 09:42 - 2012-07-09 09:42 - 00044032 ____A (Apple, Inc.) C:\Windows\System32\Drivers\usbaapl.sys ZeroAccess: C:\Windows\assembly\GAC\Desktop.ini ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-09-25 09:23:40 Restore point made on: 2012-09-25 09:30:21 Restore point made on: 2012-10-02 20:22:09 Restore point made on: 2012-10-04 12:04:35 Restore point made on: 2012-10-04 12:08:37 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 4056.96 MB Available physical RAM: 3537.99 MB Total Pagefile: 4055.23 MB Available Pagefile: 3554.16 MB Total Virtual: 2047.88 MB Available Virtual: 1968.7 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:157.5 GB) NTFS 2 Drive e: (BS A 1st Course) (CDROM) (Total:0.04 GB) (Free:0 GB) CDFS 3 Drive f: (USB Disk) (Removable) (Total:1.87 GB) (Free:1.25 GB) FAT 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 5 Drive y: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:11.56 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 232 GB 0 B Disk 1 Online 1920 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 39 MB 31 KB Partition 2 Primary 14 GB 40 MB Partition 3 Primary 218 GB 14 GB ========================================================= Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 FAT Partition 39 MB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y RECOVERY NTFS Partition 14 GB Healthy ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 218 GB Healthy ========================================================= Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 1911 MB 16 KB ========================================================= Disk: 1 Partition 1 Type : 06 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F USB Disk FAT Removable 1911 MB Healthy ========================================================= Last Boot: 2012-09-28 20:07 ==================== End Of Log ============================
Hi,

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

C:\Windows\assembly\GAC\Desktop.ini

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
———-

Run a new scan with Malwarebytes and then remove all entries found.
———-

Post the logs created by Malwarebytes and FRST. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI