FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
fbphotozoom@installdaddy.com: C:\Program Files (x86)\fbphotozoom\fbphotozoom13.xpi [2012/03/08 12:34:26 | 000,102,233 | ---- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/28 12:14:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/02/03 14:16:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Joe\AppData\Roaming\Mozilla\Extensions
[2012/06/02 20:55:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\sc2358e3.default\extensions
[2012/06/02 20:55:17 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\sc2358e3.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2012/03/08 12:35:21 | 000,000,000 | ---D | M] (Incredibar Toolbar) -- C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\sc2358e3.default\extensions\
ffxtlbr@incredibar.com
[2012/03/08 12:34:38 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\sc2358e3.default\extensions\
plugin@yontoo.com
[2012/03/08 12:35:08 | 000,002,203 | ---- | M] () -- C:\Users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\sc2358e3.default\searchplugins\MyStart Search.xml
[2012/06/29 01:22:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/10/30 11:10:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) -- C:\PROGRAMDATA\AVG SECURE SEARCH\12.2.5.34
[2012/06/28 12:14:42 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/02 20:55:07 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/02 20:55:07 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl\1.4_0\
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgbpjlnkjhllfgfdmieompodgaefjcfh\1.0.6_0\
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2191_0\
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpieaakhacmfleokhjcjnpcnmnmpfkid\1.9_0\
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: No name found = C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Extensions\okpfiebkkmjcnodegbbbiellepfhoglm\1.0.0_0\
O1 HOSTS File: ([2012/11/04 17:23:08 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll File not found
O2:
64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (BitLord Security Bar Toolbar) - {8c5878d0-6106-423b-aaa8-144c143dbf44} - C:\Program Files (x86)\Bitlord_1.2\prxtbBit0.dll (Conduit Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (BitLord Security Bar Toolbar) - {8c5878d0-6106-423b-aaa8-144c143dbf44} - C:\Program Files (x86)\Bitlord_1.2\prxtbBit0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (BitLord Security Bar Toolbar) - {8C5878D0-6106-423B-AAA8-144C143DBF44} - C:\Program Files (x86)\Bitlord_1.2\prxtbBit0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (BitLord Security Bar Toolbar) - {8C5878D0-6106-423B-AAA8-144C143DBF44} - C:\Program Files (x86)\Bitlord_1.2\prxtbBit0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000\..\Toolbar\WebBrowser: (BitLord Security Bar Toolbar) - {8C5878D0-6106-423B-AAA8-144C143DBF44} - C:\Program Files (x86)\Bitlord_1.2\prxtbBit0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004\..\Toolbar\WebBrowser: (BitLord Security Bar Toolbar) - {8C5878D0-6106-423B-AAA8-144C143DBF44} - C:\Program Files (x86)\Bitlord_1.2\prxtbBit0.dll (Conduit Ltd.)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000..\Run: [Facebook Update] C:\Users\Joe\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000..\Run: [Spotify Web Helper] C:\Users\Joe\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004..\Run: [Facebook Update] C:\Users\Joe\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004..\Run: [Spotify Web Helper] C:\Users\Joe\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2752146502-3419167249-1329659457-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:
64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16:
64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00656CFE-058C-4D4F-AB28-72D2E0FAC4AD}: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/11/04 17:59:36 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/11/04 17:07:52 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/11/04 17:01:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/11/04 17:01:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/11/04 17:01:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/11/04 17:00:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/11/04 16:59:49 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/11/04 14:16:30 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/11/04 13:04:35 | 000,000,000 | ---D | C] -- C:\Users\Joe\AppData\Roaming\Malwarebytes
[2012/11/04 13:04:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/04 13:04:26 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/11/04 13:04:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/11/04 13:04:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/11/04 12:59:16 | 000,000,000 | ---D | C] -- C:\Users\Joe\Desktop\RK_Quarantine
[2012/11/04 12:54:02 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/11/04 12:53:20 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Joe\Desktop\TDSSKiller.exe
[2012/11/04 11:59:14 | 000,000,000 | ---D | C] -- C:\Users\Joe\AppData\Roaming\U3
[2012/11/04 11:35:51 | 001,459,963 | ---- | C] (Farbar) -- C:\Users\Joe\Desktop\FRST64.exe
[2012/11/04 11:20:38 | 000,000,000 | ---D | C] -- C:\Users\Joe\Documents\Andrew's flash
[2012/11/04 10:49:23 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/11/04 10:21:27 | 000,000,000 | ---D | C] -- C:\FRST
[2012/11/04 01:05:50 | 000,000,000 | ---D | C] -- C:\Users\Joe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mega Codec Pack
[2012/11/04 01:05:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mega Codec Pack
[2012/11/02 22:00:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Premium
[2012/11/02 22:00:04 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/11/04 18:06:38 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/04 18:06:38 | 000,021,888 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/04 18:05:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2752146502-3419167249-1329659457-1000UA.job
[2012/11/04 18:03:35 | 000,779,724 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/04 18:03:35 | 000,660,520 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/04 18:03:35 | 000,121,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/04 17:59:35 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/04 17:59:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/04 17:59:00 | 3206,619,136 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/04 17:58:04 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/04 17:49:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2752146502-3419167249-1329659457-1000UA.job
[2012/11/04 17:43:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/04 17:23:08 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/11/04 15:05:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2752146502-3419167249-1329659457-1000Core.job
[2012/11/04 14:01:23 | 000,000,512 | ---- | M] () -- C:\Users\Joe\Desktop\MBR.dat
[2012/11/04 13:04:27 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/04 12:58:24 | 000,430,592 | ---- | M] () -- C:\Users\Joe\Desktop\RogueKiller.exe
[2012/11/04 12:53:11 | 002,195,061 | ---- | M] () -- C:\Users\Joe\Desktop\tdsskiller.zip
[2012/11/04 10:21:16 | 001,459,963 | ---- | M] (Farbar) -- C:\Users\Joe\Desktop\FRST64.exe
[2012/11/04 10:05:21 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2752146502-3419167249-1329659457-1000Core.job
[2012/10/31 21:49:22 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Joe\Desktop\TDSSKiller.exe
[2012/10/22 20:32:54 | 000,965,077 | ---- | M] () -- C:\Users\Joe\Documents\Mongolian econmy mess.pdf
[2012/10/22 20:27:26 | 000,318,168 | ---- | M] () -- C:\Users\Joe\Documents\Improving health care access for urban poor.pdf
[2012/10/19 10:24:07 | 012,171,224 | ---- | M] () -- C:\Users\Joe\Documents\Urban Migration.pdf
[2012/10/19 10:20:39 | 000,984,574 | ---- | M] () -- C:\Users\Joe\Documents\Financing health in Japan and Mongolia.pdf
[2012/10/19 10:17:19 | 002,846,346 | ---- | M] () -- C:\Users\Joe\Documents\Mongolia_Infectious disease.pdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/11/04 17:01:27 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/11/04 17:01:27 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/11/04 17:01:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/11/04 17:01:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/11/04 17:01:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/11/04 13:30:55 | 000,000,512 | ---- | C] () -- C:\Users\Joe\Desktop\MBR.dat
[2012/11/04 13:04:27 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/04 12:58:21 | 000,430,592 | ---- | C] () -- C:\Users\Joe\Desktop\RogueKiller.exe
[2012/11/04 12:52:44 | 002,195,061 | ---- | C] () -- C:\Users\Joe\Desktop\tdsskiller.zip
[2012/10/22 20:32:54 | 000,965,077 | ---- | C] () -- C:\Users\Joe\Documents\Mongolian econmy mess.pdf
[2012/10/22 20:27:26 | 000,318,168 | ---- | C] () -- C:\Users\Joe\Documents\Improving health care access for urban poor.pdf
[2012/10/19 10:24:07 | 012,171,224 | ---- | C] () -- C:\Users\Joe\Documents\Urban Migration.pdf
[2012/10/19 10:20:39 | 000,984,574 | ---- | C] () -- C:\Users\Joe\Documents\Financing health in Japan and Mongolia.pdf
[2012/10/19 10:17:19 | 002,846,346 | ---- | C] () -- C:\Users\Joe\Documents\Mongolia_Infectious disease.pdf
[2012/10/01 20:27:43 | 000,001,456 | ---- | C] () -- C:\Users\Joe\AppData\Local\Adobe Save for Web 13.0 Prefs
[2012/07/04 22:21:44 | 000,000,218 | ---- | C] () -- C:\Users\Joe\.recently-used.xbel
[2012/02/29 12:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/01/21 15:53:29 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2011/11/11 20:08:00 | 000,007,602 | ---- | C] () -- C:\Users\Joe\AppData\Local\Resmon.ResmonCfg
[2011/10/23 16:33:00 | 000,283,304 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/23 16:32:59 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/23 15:26:12 | 000,773,448 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/10/23 13:55:41 | 000,036,068 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2011/10/23 13:54:44 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/10/23 13:54:41 | 000,024,353 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011/09/28 16:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/03/01 14:29:29 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
========== ZeroAccess Check ==========
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 21:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 19:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/10/12 09:45:46 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012/10/12 09:45:46 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/11/02 22:23:55 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\BitLord
[2012/01/24 18:26:07 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/01/22 16:48:53 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/10/23 13:58:40 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\DeviceVm
[2012/10/01 19:12:33 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\EveHQ
[2012/04/09 14:44:38 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\EVEMon
[2012/02/13 16:31:17 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\Indicium Technologies
[2011/10/23 15:59:00 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\LolClient
[2012/03/08 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\Mumble
[2011/10/26 21:15:47 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\OpenOffice.org
[2011/10/23 14:35:06 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\Origin
[2012/01/30 13:24:04 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\Petroglyph
[2011/10/23 17:30:35 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\Python-Eggs
[2012/05/08 20:47:27 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\SoftGrid Client
[2012/11/02 23:50:20 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\Spotify
[2012/07/13 08:10:16 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\The Creative Assembly
[2011/10/23 15:27:02 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\TP
[2012/04/02 18:32:54 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\TS3Client
[2012/09/26 11:14:13 | 000,000,000 | ---D | M] -- C:\Users\Joe\AppData\Roaming\TuneUp Software
========== Purity Check ==========
< End of report >