[removed]
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(百度在线网络技术(北京)有限公司) C:\Program Files\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduSd\3.0.0.4605\BaiduSdSvc.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduAn\4.0.0.5166\BaiduAnSvc.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCRTP.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(IDT, Inc.) C:\WINDOWS\sttray.exe
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduSd\3.0.0.4605\BaiduSdTray.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduAn\4.0.0.5166\BaiduAnTray.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Comfort Software Group) C:\Program Files\FreeAlarmClock\FreeAlarmClock.exe
(Spotify Ltd) C:\SpotifyWebHelper.exe
() C:\Program Files\baidu\baidu.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Baidu) C:\Program Files\Common Files\Baidu\BDDownload\109\bddownloader.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMDeskTopGC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Documents and Settings\Ralph\My Documents\Downloads\aswMBR.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\…\Run: [IDTSysTrayApp] => C:\WINDOWS\sttray.exe [405504 2007-09-05] (IDT, Inc.)
HKLM\…\Run: [SigmatelSysTrayApp] => C:\WINDOWS\stsystra.exe [282624 2006-07-27] (SigmaTel, Inc.)
HKLM\…\Run: [baidusdTray] => C:\Program Files\Baidu\BaiduSd\3.0.0.4605\BaiduSdTray.exe [3257240 2015-05-05] (百度在线网络技术(北京)有限公司)
HKLM\…\Run: [BaiduAnTray] => C:\Program Files\Baidu\BaiduAn\4.0.0.5166\BaiduAnTray.exe [3042312 2015-05-05] (百度在线网络技术(北京)有限公司)
HKLM\…\Run: [ QQPCTray] => C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCTray.exe [355296 2015-05-05] (Tencent)
HKLM\…\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [FreeAC] => C:\Program Files\FreeAlarmClock\FreeAlarmClock.exe [1553688 2014-02-20] (Comfort Software Group)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [Spotify Web Helper] => C:\SpotifyWebHelper.exe [2021944 2015-05-31] (Spotify Ltd)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [Spotify] => C:\Spotify.exe [7323192 2015-05-31] (Spotify Ltd)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [apphide] => C:\Program Files\baidu\baidu.exe [65536 2015-04-06] ()
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [Bubble Suite] => "C:\Documents and Settings\Ralph\Application Data\Nosibay\Bubble Suite\Bubble Suite.exe" /winstartup
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [MaxComputerCleaner] => C:\Program Files\Max Computer Cleaner\MaxComputerCleaner.exe true
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\MountPoints2: {4da88a1a-d6e0-11e3-9ee5-001d09305347} - E:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\MountPoints2: {62544eca-227d-11e4-873e-001d09305347} - F:\VerizonWirelessUpgradeAssistantSetup.exe -a
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\MountPoints2: {ef456abe-2564-11e4-873f-001d09305347} - F:\VerizonWirelessUpgradeAssistantSetup.exe -a
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMGCShellExt.dll [2015-05-05] (Tencent)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
URLSearchHook: [S-1-5-21-725345543-764733703-1801674531-1006] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\S-1-5-21-725345543-764733703-1801674531-1003 -> {8D6CE8E7-F4C1-4096-9864-21DA27C45BB7} URL =
BHO: WebMonBHO -> {15DEE173-1BE9-4424-81E0-58A87076E9B1} -> C:\Program Files\Baidu\BaiduSd\3.0.0.4605\websafe\WebMonBHO.dll [2014-11-06] (百度在线网络技术(北京)有限公司)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-04-29] (Oracle Corporation)
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-04-29] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-725345543-764733703-1801674531-1003 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll [2014-12-09] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @baidu.com/BaidusdDetectNPPlugin -> C:\Program Files\Baidu\BaiduSd\3.0.0.4605\explugin\npBaiduSDDetectPlug.dll [2014-11-06] (百度在线网络技术(北京)有限公司)
FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-29] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-04-29] (Oracle Corporation)
FF Plugin: @qq.com/QQPCMgr -> C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\npQMExtensionsMozilla.dll [2015-05-05] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-05]
CHR Extension: (Google Docs) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-05]
CHR Extension: (Google Drive) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-05]
CHR Extension: (YouTube) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-05]
CHR Extension: (Google Search) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-05]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-05]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-20]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-20]
CHR Extension: (Gmail) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-05]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BaiduHips; C:\Program Files\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe [64008 2015-04-02] (百度在线网络技术(北京)有限公司)
R2 BDKVRTP; C:\Program Files\Baidu\BaiduSd\3.0.0.4605\BaiduSdSvc.exe [793096 2014-11-06] (百度在线网络技术(北京)有限公司)
R2 BDMRTP; C:\Program Files\Baidu\BaiduAn\4.0.0.5166\BaiduAnSvc.exe [1047048 2015-04-02] (百度在线网络技术(北京)有限公司)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-04-29] (Oracle Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 QQPCRTP; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCRTP.exe [297608 2015-05-05] (Tencent)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [6079848 2015-01-14] (Reimage®)
S3 TAOFrame; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TAOFrame.exe [293728 2015-05-05] (Tencent)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices)
R1 bd0001; C:\WINDOWS\System32\DRIVERS\bd0001.sys [86344 2015-04-02] (Baidu)
R1 bd0002; C:\WINDOWS\System32\DRIVERS\bd0002.sys [168392 2015-05-05] (Baidu)
R1 bd0003; C:\WINDOWS\System32\DRIVERS\bd0003.sys [56904 2014-11-06] (Baidu)
R2 BDArKit; C:\WINDOWS\System32\DRIVERS\BDArKit.sys [145224 2015-04-02] (Baidu Technology)
R1 BDDefense; C:\WINDOWS\System32\drivers\BDDefense.sys [121992 2015-05-18] (Baidu)
R1 BDEnhanceBoost; C:\WINDOWS\System32\DRIVERS\BDEnhanceBoost.sys [48328 2015-04-02] (Baidu)
R1 BDFileDefend; C:\WINDOWS\System32\DRIVERS\BDFileDefend.sys [26824 2014-11-06] (Baidu)
R2 BDMNetMon; C:\WINDOWS\System32\DRIVERS\BDMNetMon.sys [118472 2015-04-02] (Baidu)
R1 BDMWrench; C:\WINDOWS\System32\DRIVERS\BDMWrench.sys [239432 2015-04-02] (Baidu)
R1 BdSandBox; C:\WINDOWS\System32\DRIVERS\BdSandBox.sys [139784 2014-11-06] (Baidu)
S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-05] (Malwarebytes Corporation)
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation)
R0 nvatabus; C:\WINDOWS\system32\Drivers\nvatabus.sys [105472 2006-10-18] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [102400 2008-01-03] (NVIDIA Corporation)
R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMIEProtect.sys [49080 2015-05-05] ()
R1 QMUdisk; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMUdisk.sys [60600 2015-05-05] (Tencent)
R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQSysMon.sys [108344 2015-05-05] (电脑管家)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1171464 2006-07-27] (SigmaTel, Inc.)
R2 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator.sys [77016 2015-05-05] (Tencent)
R2 TAOKernelDriver; C:\WINDOWS\system32\Drivers\TAOKernelXP.sys [139064 2015-05-05] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\WINDOWS\System32\Drivers\TFsFlt.sys [150072 2015-05-05] (电脑管家)
S3 TS888; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TS888.sys [30392 2015-05-05] (Tencent)
R1 TSCPM; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\tscpm.sys [43448 2015-05-05] (电脑管家)
R1 TSDefenseBt; C:\WINDOWS\System32\DRIVERS\TSDefenseBt.sys [14008 2015-05-05] (Tencent)
R0 TsFltMgr; C:\WINDOWS\System32\DRIVERS\TSFLTMGR.SYS [123864 2015-05-05] (电脑管家)
R1 TSKSP; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TSKsp.sys [204568 2015-05-05] (电脑管家)
S3 TSSK; C:\WINDOWS\System32\tssk.sys [67896 2015-05-05] (电脑管家)
R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TSSysKit.sys [101560 2015-05-05] (电脑管家)
R3 cpuz134; \??\C:\DOCUME~1\Ralph\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL; No ImagePath
U3 aswMBR; \??\C:\DOCUME~1\Ralph\LOCALS~1\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\DOCUME~1\Ralph\LOCALS~1\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-05 18:49 - 2015-06-05 18:49 - 00000551 _____ C:\Documents and Settings\Ralph\Desktop\aswMBR.txt
2015-06-05 18:34 - 2012-12-24 09:51 - 00001576 _____ C:\Documents and Settings\Ralph\Desktop\scan.txt
2015-06-05 18:34 - 2012-12-24 09:44 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Ralph\Desktop\OTL.exe
2015-06-05 18:22 - 2015-06-05 18:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\RogueKiller
2015-06-05 18:22 - 2015-06-05 18:22 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-06-05 18:15 - 2015-06-05 18:50 - 00000000 ____D C:\FRST
2015-06-05 18:02 - 2015-06-05 18:02 - 00000332 _____ C:\WINDOWS\Tasks\ReimageUpdater.job
2015-06-05 18:02 - 2015-06-05 18:02 - 00000274 _____ C:\WINDOWS\Tasks\Reimage Reminder.job
2015-06-05 18:01 - 2015-06-05 18:03 - 00000000 ____D C:\rei
2015-06-05 18:01 - 2015-06-05 18:02 - 00000000 ____D C:\Program Files\Reimage
2015-06-05 18:01 - 2015-06-05 18:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Reimage Protector
2015-06-05 18:01 - 2015-06-05 18:01 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Reimage Repair
2015-06-05 18:00 - 2015-06-05 18:03 - 00000156 _____ C:\WINDOWS\Reimage.ini
2015-05-29 20:31 - 2015-05-31 22:10 - 00000000 ____D C:\Bovada
2015-05-29 20:31 - 2015-05-29 20:31 - 00000355 _____ C:\Documents and Settings\All Users\Desktop\BovadaPoker.lnk
2015-05-29 20:31 - 2015-05-29 20:31 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\BovadaPoker
2015-05-29 20:16 - 2015-05-29 20:16 - 00018458 _____ C:\Documents and Settings\Ralph\Desktop\Timberly dildo.xlsx
2015-05-27 20:10 - 2015-05-27 20:10 - 00000000 ____D C:\Documents and Settings\Ralph\Desktop\New Folder (2)
2015-05-27 07:32 - 2015-05-27 07:32 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
2015-05-27 07:31 - 2015-05-27 07:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-05-27 07:31 - 2015-05-27 07:31 - 00000000 ____D C:\Program Files\iPod
2015-05-27 07:25 - 2015-05-27 07:25 - 00001255 _____ C:\Documents and Settings\Ralph\Desktop\CopyTrans Control Center.lnk
2015-05-27 07:25 - 2015-05-27 07:25 - 00000000 ____D C:\Documents and Settings\Ralph\Start Menu\Programs\CopyTrans Control Center
2015-05-27 02:09 - 2015-05-27 02:09 - 00705500 _____ C:\Documents and Settings\Ralph\My Documents\cpe.xlsx
2015-05-20 23:14 - 2015-05-22 16:21 - 00000165 ____H C:\Documents and Settings\Ralph\Desktop\~$Revised Cash Forecast for T and R.xlsx
2015-05-20 18:20 - 2015-05-20 18:20 - 00090112 _____ C:\WINDOWS\Minidump\Mini052015-01.dmp
2015-05-19 07:35 - 2015-05-19 07:35 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
2015-05-18 19:15 - 2015-05-18 19:15 - 00090112 _____ C:\WINDOWS\Minidump\Mini051815-01.dmp
2015-05-18 02:30 - 2012-10-03 16:14 - 00026840 _____ (GEAR Software Inc.) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2015-05-18 01:54 - 2015-05-27 07:36 - 00000000 ____D C:\Program Files\iTunes
2015-05-18 01:52 - 2014-08-15 22:35 - 06112072 _____ (Apple, Inc.) C:\WINDOWS\system32\usbaaplrc.dll
2015-05-18 01:52 - 2014-08-15 22:35 - 00045056 _____ (Apple, Inc.) C:\WINDOWS\system32\Drivers\usbaapl.sys
2015-05-17 17:44 - 2015-06-05 18:49 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-16 21:57 - 2015-06-04 23:57 - 00039764 _____ C:\Documents and Settings\Ralph\Desktop\Revised Cash Forecast for T and R.xlsx
2015-05-10 07:28 - 2015-05-18 04:42 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\WindSolutions
2015-05-10 07:26 - 2015-05-18 04:10 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\WindSolutions
2015-05-10 02:33 - 2015-05-10 02:33 - 00057412 ____H C:\WINDOWS\system32\mlfcache.dat
2015-05-10 00:44 - 2015-05-10 00:44 - 00000000 ____D C:\Program Files\Bonjour
2015-05-09 19:29 - 2015-05-09 19:29 - 00000000 ____D C:\Documents and Settings\Ralph\Local Settings\Application Data\Help
2015-05-09 19:17 - 2015-05-09 20:03 - 00000434 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-05 18:51 - 2014-04-29 12:20 - 00000000 ____D C:\Documents and Settings\Ralph\Local Settings\Temp
2015-06-05 18:23 - 2014-04-29 12:10 - 01709723 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-05 18:17 - 2015-05-05 05:17 - 00000342 _____ C:\WINDOWS\Tasks\Bubble Suite Update.job
2015-06-05 18:06 - 2014-11-28 14:58 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-05 17:50 - 2015-05-05 06:51 - 00000065 _____ C:\WINDOWS\QMNetworkMgr.ini
2015-06-05 17:49 - 2014-04-29 11:56 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-05 17:40 - 2014-04-29 13:09 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-06-05 17:39 - 2015-04-28 17:28 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-06-05 17:38 - 2014-08-22 13:52 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\Spotify
2015-06-05 17:36 - 2014-08-22 13:52 - 00000000 ____D C:\Documents and Settings\Ralph\Local Settings\Application Data\Spotify
2015-06-05 17:36 - 2004-08-04 04:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-06-05 17:35 - 2015-05-05 17:19 - 00000000 ____D C:\WINDOWS\SxsCaPendDel
2015-06-05 17:35 - 2015-05-05 05:40 - 00001028 _____ C:\WINDOWS\Tasks\QpdrbfFJvc.job
2015-06-05 17:35 - 2014-04-29 15:07 - 00000222 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-06-05 17:35 - 2014-04-29 12:20 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-05 17:35 - 2014-04-29 05:50 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-06-05 17:35 - 2014-04-29 05:50 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-06-05 02:06 - 2014-04-29 12:20 - 00032500 _____ C:\WINDOWS\SchedLgU.Txt
2015-06-04 17:30 - 2014-10-13 19:24 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\vlc
2015-06-02 10:43 - 2014-05-14 19:23 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-05-31 09:12 - 2015-04-28 18:36 - 41287224 _____ C:\libcef.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 10457856 _____ C:\icudtl.dat
2015-05-31 09:12 - 2015-04-28 18:36 - 07323192 _____ (Spotify Ltd) C:\Spotify.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 04253463 _____ C:\devtools_resources.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 03457592 _____ (Microsoft Corporation) C:\d3dcompiler_47.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 02106424 _____ (Microsoft Corporation) C:\d3dcompiler_43.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 02021944 _____ (Spotify Ltd) C:\SpotifyWebHelper.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 02018406 _____ C:\cef.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 01488440 _____ C:\libGLESv2.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 00968248 _____ (The Chromium Authors) C:\ffmpegsumo.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 00777272 _____ (Spotify Ltd) C:\SpotifyCrashService.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 00598403 _____ C:\cef_200_percent.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 00444515 _____ C:\cef_100_percent.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 00124472 _____ (Spotify Ltd) C:\SpotifyLauncher.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 00079928 _____ C:\libEGL.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 00073272 _____ C:\wow_helper.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 00000020 _____ C:\inst_ver.dat
2015-05-31 09:12 - 2015-04-28 18:36 - 00000000 ____D C:\locales
2015-05-30 22:14 - 2014-11-28 14:56 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
2015-05-27 07:31 - 2014-05-14 19:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple Computer
2015-05-27 07:29 - 2014-05-14 19:22 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-05-27 07:29 - 2014-05-14 19:22 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple
2015-05-27 00:55 - 2014-04-29 05:49 - 01002965 _____ C:\WINDOWS\iis6.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00902471 _____ C:\WINDOWS\FaxSetup.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00443165 _____ C:\WINDOWS\ocgen.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00417251 _____ C:\WINDOWS\tsoc.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00310536 _____ C:\WINDOWS\comsetup.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00186457 _____ C:\WINDOWS\ntdtcsetup.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00158925 _____ C:\WINDOWS\netfxocm.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00063551 _____ C:\WINDOWS\MedCtrOC.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00050079 _____ C:\WINDOWS\ocmsn.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00046234 _____ C:\WINDOWS\tabletoc.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00045381 _____ C:\WINDOWS\msgsocm.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00001917 _____ C:\WINDOWS\imsins.log
2015-05-27 00:54 - 2014-04-29 05:49 - 00281916 _____ C:\WINDOWS\msmqinst.log
2015-05-27 00:48 - 2014-04-29 11:57 - 00000000 ____D C:\Program Files\7-Zip
2015-05-27 00:47 - 2014-04-29 12:20 - 00000178 ___SH C:\Documents and Settings\Ralph\ntuser.ini
2015-05-20 19:21 - 2014-04-29 15:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2719985$
2015-05-20 18:24 - 2014-09-27 15:21 - 00000000 ____D C:\WINDOWS\Minidump
2015-05-18 20:04 - 2014-12-24 13:52 - 00000000 ____D C:\Documents and Settings\Ralph\Desktop\New Folder
2015-05-18 19:31 - 2015-05-05 05:16 - 00121992 _____ (Baidu) C:\WINDOWS\system32\Drivers\BDDefense.sys
2015-05-18 18:42 - 2015-03-22 14:22 - 00120320 ___SH C:\Documents and Settings\Ralph\Desktop\Thumbs.db
2015-05-18 02:30 - 2014-04-29 05:48 - 00638609 _____ C:\WINDOWS\setupapi.log
2015-05-13 03:11 - 2014-04-29 13:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help
2015-05-13 03:09 - 2014-05-14 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-05-13 03:01 - 2014-04-29 13:56 - 137310008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-10 02:30 - 2014-05-14 19:25 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\Apple Computer
2015-05-09 19:29 - 2014-04-29 05:42 - 00000000 ____D C:\WINDOWS\Help
2015-05-09 19:17 - 2014-04-29 12:20 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-05-09 19:13 - 2014-04-29 05:49 - 00470938 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-08 15:00 - 2014-04-29 15:07 - 00000216 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
==================== Files in the root of some directories =======
2015-05-05 05:16 - 2015-05-05 05:17 - 0000078 _____ () C:\Documents and Settings\Ralph\Application Data\Bubble Suite.installation.log
2015-04-19 06:20 - 2015-04-19 06:20 - 0005872 ____N () C:\Documents and Settings\Ralph\Application Data\QpdrbfFJvc
2015-04-03 09:20 - 2015-04-03 09:20 - 0000664 _____ () C:\Documents and Settings\Ralph\Local Settings\Application Data\d3d9caps.tmp
2014-11-26 23:53 - 2015-04-10 19:42 - 0018944 _____ () C:\Documents and Settings\Ralph\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\Ralph\Local Settings\Temp\dllnt_dump.dll
C:\Documents and Settings\Ralph\Local Settings\Temp\F0212_s_31184.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\G0417_s_71353.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\javasysmo4105773096368611837.dll
C:\Documents and Settings\Ralph\Local Settings\Temp\jre-7u67-windows-i586-iftw.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\jre-8u40-windows-au.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\jre-8u45-windows-au.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\jueDEE.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\oi_{D3469AEE-67E9-43D4-8BB2-17E798A0755E}.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\optprosetup.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\PCMgr_AndroidServer.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\QQPCMgr_Setup.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\qqpcmgr_v10.8.16208.227_71919_Silence.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\ReimagePackage.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\ReiSysUpdate.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\setup3.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\Uninstall.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\UninstallModule.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\vcredist_x86.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\VerizonWirelessSoftwareUpgradeAssistant_1.3.1.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\vlc-2.1.5-win32.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-06-05 18:46:04
—————————–
18:46:04.656 OS Version: Windows 5.1.2600 Service Pack 3
18:46:04.656 Number of processors: 2 586 0x6B02
18:46:04.656 ComputerName: F96F1C4BB UserName: Ralph
18:46:10.562 Initialize success
18:46:12.953 VM: initialized successfully
18:46:12.953 VM: Amd CPU virtualization not supported
18:49:30.796 The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
18:49:48.984 AVAST engine defs: 15060501
18:56:36.343 The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
18:56:59.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port0Path0Target0Lun0
18:56:59.015 Disk 0 Vendor: WDC_WD80 10.0 Size: 76293MB BusType: 1
18:56:59.281 Disk 0 MBR read successfully
18:56:59.281 Disk 0 MBR scan
18:56:59.390 Disk 0 Windows XP default MBR code
18:56:59.390 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76285 MB offset 63
18:56:59.437 Disk 0 default boot code
18:56:59.437 Disk 0 scanning sectors +156232125
18:56:59.531 Disk 0 scanning C:\WINDOWS\system32\drivers
18:57:10.453 Service scanning
18:57:47.937 Modules scanning
18:57:47.953 Disk 0 trace - called modules:
18:57:48.000 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys
18:57:48.000 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89d64998]
18:57:48.000 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000006c[0x89db7720]
18:57:48.000 5 ACPI.sys[b9f62620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port0Path0Target0Lun0[0x89d99030]
18:57:56.468 AVAST engine scan C:\WINDOWS
18:58:12.640 AVAST engine scan C:\WINDOWS\system32
19:00:16.578 AVAST engine scan C:\WINDOWS\system32\drivers
19:00:29.421 AVAST engine scan C:\Documents and Settings\Ralph
19:02:30.703 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\MBR.dat"
19:02:30.718 The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
19:14:18.156 File: C:\Documents and Settings\Ralph\Local Settings\Temp\jueDEE.exe **INFECTED** Win32:GenMaliciousA-FRH [Adw]
19:14:29.343 File: C:\Documents and Settings\Ralph\Local Settings\Temp\nsjD6B.tmp **INFECTED** Win32:Dropper-gen [Drp]
19:14:34.750 File: C:\Documents and Settings\Ralph\Local Settings\Temp\nssC9E.tmp **INFECTED** Win32:Dropper-gen [Drp]
19:14:35.421 File: C:\Documents and Settings\Ralph\Local Settings\Temp\nsxBFE.tmp **INFECTED** Win32:Adware-gen [Adw]
19:14:41.421 File: C:\Documents and Settings\Ralph\Local Settings\Temp\setup3.exe **INFECTED** Win32:Malware-gen
19:14:44.656 File: C:\Documents and Settings\Ralph\Local Settings\Temp\UninstallModule.exe **INFECTED** Win32:Dropper-gen [Drp]
19:15:41.546 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\ET4ZA9AD\WinCheckSetup[1].exe **INFECTED** Win32:Adware-gen [Adw]
19:16:58.546 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\S7GZK32B\FinalInstaller_dotnet4[1].exe **INFECTED** Win32:GenMaliciousA-FRH [Adw]
19:17:05.156 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\S7GZK32B\JOSrv[1].exe **INFECTED** Win32:Rootkit-gen [Rtk]
19:17:18.406 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\S7GZK32B\runasu[1].exe **INFECTED** Win32:Adware-gen [Adw]
19:17:40.484 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\Y76R2LEL\CASrv[1].exe **INFECTED** Win32:Rootkit-gen [Rtk]
19:17:44.562 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\Y76R2LEL\dl[1].htm **INFECTED** Win32:Dropper-gen [Drp]
19:18:13.062 File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\Y76R2LEL\UninstallModule[1].exe **INFECTED** Win32:Dropper-gen [Drp]
19:19:10.703 AVAST engine scan C:\Documents and Settings\All Users
19:27:00.984 Disk 0 statistics 1499453/0/0 @ 0.52 MB/s
19:27:01.015 Scan finished successfully
19:27:18.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\MBR.dat"
19:27:18.203 The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"