Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by New (administrator) on FAMILYCOMPUTER on 18-07-2014 10:16:47
Running from C:\Documents and Settings\New\My Documents\Downloads
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
https://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html
Download link for 64-Bit Version:
https://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
==================== Processes (Whitelisted) =================
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\WINDOWS\system32\MsPMSPSv.exe
() C:\DOCUME~1\New\LOCALS~1\Temp\wincjll.exe
(Dropbox, Inc.) C:\Documents and Settings\New\Application Data\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Barracuda Networks, Inc.) C:\Documents and Settings\New\Application Data\Copy\CopyAgent.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKU\.DEFAULT\...\Policies\Explorer: [CDRAutoRun] 0
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\Run: [iFunBox Price Watch] => C:\Program Files\iFunbox 2014\iFunBox2014.exe /tray
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_12_0_0_77_Plugin.exe [914824 2014-03-30] (Adobe Systems Incorporated)
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\Policies\system: [enableTaskMgr] 0
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\Policies\system: [DisableTaskMgr] 1
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\Policies\system: [DisableRegistryTools] 1
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\MountPoints2: {2aec11e4-dde6-11e1-a656-0019b92849e3} - E:\LaunchU3.exe -a
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\MountPoints2: {6a747eb4-66a3-11e3-a824-0019b92849e3} - E:\launcher.exe
HKU\S-1-5-21-1614895754-562591055-1801674531-1003\...\MountPoints2: {cc2fd02a-e4b9-11e1-a668-0019b92849e3} - E:\kxfspf.cmd
Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\New\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\start.lnk
ShortcutTarget: start.lnk -> C:\Documents and Settings\New\9p2garka7ur3\69890.vbs (No File)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
ShellIconOverlayIdentifiers: 1aCopyShExtError -> {83BEA36E-7680-4598-A4DF-994426F6E78D} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 2aCopyShExtSynced -> {845B7388-6F85-4F32-9FD5-F02DC7882B89} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 3aCopyShExtSyncing -> {F6378A7A-F753-449B-AE1B-997A96132E61} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 4aCopyShExtSyncingProg1 -> {3A511828-777D-46F8-82F4-5B530C1B3D9E} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 5aCopyShExtSyncingProg2 -> {C8C88204-5B14-40EC-BA72-8AEBC762047E} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 6aCopyShExtSyncingProg3 -> {ACFF45C3-3EEB-4351-86C2-6696BA264239} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 7aCopyShExtSyncingProg4 -> {29AF997F-488B-46F0-AE78-7146F1B89CC3} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: 8aCopyShExtSyncingProg5 -> {03F9AD29-1C78-4B66-8890-B177B5430C53} => C:\Documents and Settings\New\Application Data\Copy\overlay\CopyShExt.dll (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute:
AlternateShell:
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files\IDM\QUICKfind\PlugIns\IEHelp.dll (IDM)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll ()
Handler: tmbp - No CLSID Value -
Handler: tmpx - No CLSID Value -
Winsock: Catalog5 01 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\New\Application Data\Mozilla\Firefox\Profiles\58s0tfcx.default-1404838983112
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=1.6.0_33 - C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @pptv.com/plugin - C:\Program Files\Internet Explorer\PPLite\plugin\1.0.0.54\npplugin2.dll (PPLive Corporation)
FF Plugin: @qq.com/QzoneMusic - C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll No File
FF Plugin: @qq.com/TXSSO - C:\Program Files\Common Files\Tencent\TXSSO\1.2.1.42\Bin\npSSOAxCtrlForPTLogin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Documents and Settings\New\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Documents and Settings\New\Application Data\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Documents and Settings\New\Local Settings\Application Data\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Documents and Settings\New\Local Settings\Application Data\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Documents and Settings\New\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\New\Application Data\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\New\Application Data\mozilla\plugins\npo1d.dll (Google)
FF Extension: Firefox Old Version Update Hotfix - C:\Documents and Settings\New\Application Data\Mozilla\Firefox\Profiles\58s0tfcx.default-1404838983112\Extensions\
firefox-hotfix@mozilla.org.xpi [2014-07-16]
FF Extension: Tamper Data - C:\Documents and Settings\New\Application Data\Mozilla\Firefox\Profiles\58s0tfcx.default-1404838983112\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2014-07-08]
FF Extension: Adblock Plus - C:\Documents and Settings\New\Application Data\Mozilla\Firefox\Profiles\58s0tfcx.default-1404838983112\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-08]
FF HKLM\...\Firefox\Extensions: [
fiddlerhook@fiddler2.com] - C:\Program Files\Fiddler2\New Folder\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - C:\Program Files\Fiddler2\New Folder\Fiddler2\FiddlerHook [2013-08-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-03-22]
FF HKLM\...\Firefox\Extensions: [
tmbepff-7.5@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1107\7.5.1107\firefoxextension
Chrome:
=======
CHR HomePage:
https://www.google.ca/
CHR NewTab: "chrome-extension://mgmiemnjjchgkmgbeljfocdjjnpjnmcg/ntp.html"
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Advanced SystemCare 6) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\Plugin/ASCPlugin_Protect.dll No File
CHR Plugin: (Google Talk Plugin) - C:\Documents and Settings\New\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Documents and Settings\New\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Documents and Settings\New\Application Data\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (ActiveTouch General Plugin Container) - C:\Program Files\Windows Media Player\npatgpc.dll (Cisco WebEx LLC)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (NPPlayerShell) - C:\Documents and Settings\New\Application Data\TrianglePlayer\NPTrianglePlayer.dll No File
CHR Plugin: (GBoxRuner plugin) - C:\Documents and Settings\New\Application Data\gbox\npgboxruner.dll No File
CHR Plugin: (Google Update) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Unity Player) - C:\Documents and Settings\New\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (AdobeAAMDetect) - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (Tencent SSO Platform) - C:\Program Files\Common Files\Tencent\TXSSO\1.2.1.42\Bin\npSSOAxCtrlForPTLogin.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (PPLive PPTV Plugin) - C:\Program Files\Internet Explorer\PPLite\plugin\1.0.0.54\npplugin2.dll (PPLive Corporation)
CHR Plugin: (Java(TM) Platform SE 6 U33) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Pando Web Plugin) - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (QQMusic) - C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.330.5) - C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-27]
CHR Extension: (Rumola - bypass CAPTCHA) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bjjgbdlbgjeoankjijbmheneoekbghcg [2013-01-25]
CHR Extension: (YouTube) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-06]
CHR Extension: (SwagBucks Automator) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\boaomhhoelpgkkiiabmokphjeikjiomp [2013-01-25]
CHR Extension: (Google Search) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-06]
CHR Extension: (Awesome Bookmarks Widget [ANTP]) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cpomkeboefacdfaoklfekfleengjeodf [2013-03-09]
CHR Extension: (HD Tv) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gdphnleahbbooddgjimkaoibgpipekml [2013-03-09]
CHR Extension: (AdBlock) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-10-29]
CHR Extension: (Hola Better Internet) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-06-30]
CHR Extension: (Awesome Weather Widget [ANTP]) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\goeepbfnllchoihkoiecpkkekbpfiboc [2013-03-09]
CHR Extension: (Awesome Calculator Widget [ANTP]) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hmmkgfainefimmjkdnbgejialadhhegh [2013-03-09]
CHR Extension: (Meta-Tile Widget [ANTP]) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ibhffciboaodhfapmcpckhbdpbjjppan [2013-03-09]
CHR Extension: (Arcane Legends) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ibmlkgieigeddcedpbijnpojheoddido [2013-05-22]
CHR Extension: (Digital Clock Widget [ANTP]) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ikimcdcgajipgcoehakmgloecbaacmoj [2013-03-09]
CHR Extension: (Metro Style Clock Widget [ANTP]) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lnmmppckdogcdbnnebgndgnmkdoedoki [2013-03-09]
CHR Extension: (Google Dictionary (by Google)) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2012-09-06]
CHR Extension: (Awesome New Tab Pageâ„¢) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg [2013-03-09]
CHR Extension: (Google Wallet) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Gmail) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-06]
CHR Extension: (Abstract-Blue) - C:\Documents and Settings\New\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\plnacehkknmafkjgkikclamogikoiaaa [2012-10-29]
CHR HKLM\...\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1107\7.5.1107\chrome_tmbep.crx [2012-10-29]
========================== Services (Whitelisted) =================
ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [930104 2014-05-12] (Malwarebytes Corporation)
S4 npggsvc; C:\WINDOWS\system32\GameMon.des [3953632 2012-03-05] (INCA Internet Co., Ltd.)
R2 WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [53248 2001-05-01] (Microsoft Corporation)
S4 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [X]
S4 DTSRVC; No ImagePath
S4 MozillaMaintenance; No ImagePath
S4 PdiService; No ImagePath
S4 RichVideo; No ImagePath
S3 rpcapd; No ImagePath
==================== Drivers (Whitelisted) ====================
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 DCamUSBEMPIA; C:\WINDOWS\System32\DRIVERS\emDevice.sys [100957 2005-12-21] (eMPIA Technology, Inc.)
S3 emAudio; C:\WINDOWS\System32\drivers\emAudio.sys [22528 2006-12-12] (Pinnacle Systems GmbH)
S3 FiltUSBEMPIA; C:\WINDOWS\System32\DRIVERS\emFilter.sys [5245 2005-12-21] (eMPIA Technology, Inc.)
R1 FsVga; C:\WINDOWS\System32\DRIVERS\fsvga.sys [12160 2004-08-12] (Microsoft Corporation)
R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171520 2005-09-24] (Pinnacle Systems GmbH)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-16] (Malwarebytes Corporation)
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-14] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [35088 2010-06-25] (CACE Technologies, Inc.)
R3 PdiPorts; C:\WINDOWS\System32\Drivers\PdiPorts.sys [17328 2012-04-13] (Portrait Displays, Inc.)
S1 Pivot; C:\WINDOWS\System32\drivers\pivot.sys [17465 2010-05-13] (Portrait Displays, Inc.)
S3 pivotmou; C:\WINDOWS\System32\drivers\pivotmou.sys [11323 2010-05-13] (Portrait Displays, Inc.)
S3 ScanUSBEMPIA; C:\WINDOWS\System32\DRIVERS\emScan.sys [4493 2005-12-21] (eMPIA Technology, Inc.)
R3 abp470n5; \??\C:\WINDOWS\system32\drivers\igfll.sys [X]
S0 cerc6; No ImagePath
S3 EagleXNt; No ImagePath
S0 erdnrxx; System32\drivers\mfpiix.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U3 tmeevw;
S3 vwwredzk; vwwredzk.sys [X]
U1 WS2IFSL;
S3 xofhsekc; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-18 10:15 - 2014-07-18 10:16 - 00000000 ____D () C:\FRST
2014-07-18 10:11 - 2014-07-18 10:11 - 00415744 _____ (Farbar) C:\Documents and Settings\New\Desktop\FSS.exe
2014-07-17 22:02 - 2014-07-17 22:02 - 00001528 _____ () C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
2014-07-17 22:02 - 2014-07-17 22:02 - 00000000 ____D () C:\Program Files\ImgBurn
2014-07-17 22:02 - 2014-07-17 22:02 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
2014-07-14 10:40 - 2014-07-14 10:45 - 00000000 ____D () C:\Program Files\HijackThis
2014-07-14 10:24 - 2014-07-14 10:22 - 00482112 _____ (Kaspersky Lab) C:\Documents and Settings\New\Desktop\setup.exe
2014-07-13 10:57 - 2014-07-13 10:57 - 00000000 ____D () C:\Program Files\ESET
2014-07-13 10:57 - 2014-07-13 10:56 - 02425208 _____ (ESET) C:\Documents and Settings\New\Desktop\esetsmartinstaller_enu.exe
2014-07-12 21:19 - 2014-07-12 21:19 - 00000000 ____D () C:\Documents and Settings\New\Local Settings\Application Data\Evernote
2014-07-12 21:19 - 2014-07-12 21:19 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Evernote
2014-07-12 21:18 - 2014-07-12 21:18 - 00000625 _____ () C:\Documents and Settings\New\Desktop\Evernote.lnk
2014-07-12 21:18 - 2014-07-12 21:18 - 00000000 ____D () C:\Program Files\Evernote
2014-07-11 15:21 - 2014-07-03 20:46 - 02085772 _____ () C:\Documents and Settings\New\Desktop\rotmg.swf
2014-07-11 12:07 - 2014-07-11 12:07 - 00000760 _____ () C:\Documents and Settings\New\Desktop\Cheat Engine.lnk
2014-07-11 12:07 - 2014-07-11 12:07 - 00000000 ____D () C:\Program Files\Cheat Engine 6.4
2014-07-11 12:07 - 2014-07-11 12:07 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Cheat Engine 6.4
2014-07-11 10:36 - 2014-07-11 13:19 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2014-07-10 23:04 - 2014-07-10 23:05 - 00000000 ____D () C:\Documents and Settings\New\Application Data\360Login
2014-07-10 23:04 - 2014-07-10 23:05 - 00000000 ____D () C:\Documents and Settings\New\Application Data\360CloudUI
2014-07-10 23:04 - 2014-07-10 23:04 - 00000774 _____ () C:\Documents and Settings\New\Desktop\360云盘.lnk
2014-07-10 23:04 - 2014-07-10 23:04 - 00000000 ____D () C:\Program Files\360
2014-07-10 23:04 - 2014-07-10 23:04 - 00000000 ____D () C:\Documents and Settings\New\Start Menu\Programs\360安全中心
2014-07-10 22:13 - 2014-07-10 22:13 - 00000789 _____ () C:\Documents and Settings\New\Desktop\Higher Score on the ACT.lnk
2014-07-10 22:13 - 2014-07-10 22:13 - 00000000 ____D () C:\Program Files\Kap.ACTc
2014-07-10 22:13 - 2014-07-10 22:13 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Kaplan
2014-07-10 22:11 - 2014-07-11 13:19 - 00000000 ____D () C:\Documents and Settings\New\Desktop\mbar
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmpF6D6A.FOT
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmpF4D6A.FOT
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmp04D6A.FOT
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmp02D6A.FOT
2014-07-10 11:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-07-10 11:23 - 2014-07-10 11:32 - 00000000 ____D () C:\AdwCleaner
2014-07-09 19:37 - 2014-07-09 19:37 - 00006904 _____ () C:\WINDOWS\FaxSetup.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00006638 _____ () C:\WINDOWS\iis6.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00005816 _____ () C:\WINDOWS\ocgen.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00004591 _____ () C:\WINDOWS\tsoc.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00002502 _____ () C:\WINDOWS\comsetup.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001891 _____ () C:\WINDOWS\imsins.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001864 _____ () C:\WINDOWS\msmqinst.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001810 _____ () C:\WINDOWS\ntdtcsetup.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001592 _____ () C:\WINDOWS\netfxocm.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000719 _____ () C:\WINDOWS\MedCtrOC.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000473 _____ () C:\WINDOWS\msgsocm.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000469 _____ () C:\WINDOWS\ocmsn.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000311 _____ () C:\WINDOWS\tabletoc.log
2014-07-09 14:08 - 2014-07-09 14:04 - 11199152 _____ (Adobe Systems, Inc.) C:\Documents and Settings\New\Desktop\flashplayer_14_sa.exe
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp8EB47.FOT
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp71C47.FOT
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp70C47.FOT
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp62C47.FOT
2014-07-08 14:21 - 2014-07-08 14:21 - 00065536 _____ () C:\WINDOWS\Minidump\Mini070814-01.dmp
2014-07-08 13:57 - 2014-07-08 13:57 - 00000000 ____D () C:\Documents and Settings\New\Local Settings\Application Data\UWebKit151
2014-07-08 13:57 - 2014-07-08 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\boost_interprocess
2014-07-08 13:02 - 2014-07-08 13:02 - 00066073 _____ () C:\Documents and Settings\New\Desktop\bookmarks-2014-07-08.json
2014-07-07 13:17 - 2014-07-16 09:12 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-07 13:17 - 2014-07-10 22:11 - 00054232 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-07 13:17 - 2014-07-07 13:17 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-07 13:17 - 2014-07-07 13:17 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-07 13:17 - 2014-07-07 13:17 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-07 13:17 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp546EC.FOT
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp536EC.FOT
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp476EC.FOT
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp466EC.FOT
2014-07-05 21:13 - 2014-07-05 21:13 - 00005632 ___SH () C:\Documents and Settings\Thumbs.db
2014-07-03 16:31 - 2014-07-03 16:31 - 00006058 _____ () C:\Documents and Settings\New\Desktop\PCCLEANER.bat
2014-07-01 16:31 - 2014-07-01 18:58 - 00000000 _RSHD () C:\Documents and Settings\New\9p2garka7ur3
2014-06-26 16:43 - 2014-06-26 16:43 - 00000014 _____ () C:\tristansa.txt
2014-06-19 18:26 - 2014-06-27 13:47 - 00000457 _____ () C:\WINDOWS\setupact.log
2014-06-19 18:26 - 2014-06-19 18:26 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-06-19 17:58 - 2014-06-27 13:47 - 00048444 _____ () C:\WINDOWS\setupapi.log
2014-06-18 17:04 - 2014-07-14 11:07 - 00000235 _____ () C:\WINDOWS\wiadebug.log
==================== One Month Modified Files and Folders =======
2014-07-18 10:17 - 2013-05-20 18:33 - 00000880 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-18 10:17 - 2012-01-19 13:29 - 00000000 ____D () C:\Documents and Settings\New\Local Settings\Temp
2014-07-18 10:16 - 2014-07-18 10:15 - 00000000 ____D () C:\FRST
2014-07-18 10:11 - 2014-07-18 10:11 - 00415744 _____ (Farbar) C:\Documents and Settings\New\Desktop\FSS.exe
2014-07-18 10:10 - 2013-05-09 18:28 - 00000970 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-562591055-1801674531-1003UA.job
2014-07-18 09:23 - 2012-08-16 12:13 - 00000536 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-18 08:19 - 2013-09-12 20:55 - 00000000 ____D () C:\Documents and Settings\New\Application Data\Copy
2014-07-18 08:17 - 2013-05-20 18:33 - 00000876 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-18 07:57 - 2014-04-06 17:53 - 00000310 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-07-18 03:10 - 2013-05-09 18:28 - 00000918 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-562591055-1801674531-1003Core.job
2014-07-18 00:10 - 2014-04-06 19:07 - 00032434 _____ () C:\WINDOWS\SchedLgU.Txt
2014-07-17 22:03 - 2012-08-03 21:58 - 00000000 ____D () C:\Tony
2014-07-17 22:02 - 2014-07-17 22:02 - 00001528 _____ () C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
2014-07-17 22:02 - 2014-07-17 22:02 - 00000000 ____D () C:\Program Files\ImgBurn
2014-07-17 22:02 - 2014-07-17 22:02 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
2014-07-17 17:19 - 2012-08-03 15:23 - 00000000 ____D () C:\Documents and Settings\New\Application Data\Dropbox
2014-07-17 14:31 - 2013-07-03 11:41 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-16 14:09 - 2012-08-03 21:58 - 00000000 ____D () C:\Chong
2014-07-16 09:12 - 2014-07-07 13:17 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-14 14:08 - 2014-04-19 18:10 - 00000000 ____D () C:\Documents and Settings\New\Application Data\DropboxMaster
2014-07-14 11:07 - 2014-06-18 17:04 - 00000235 _____ () C:\WINDOWS\wiadebug.log
2014-07-14 11:07 - 2008-04-14 03:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-07-14 11:06 - 2014-05-29 13:15 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-07-14 11:06 - 2012-01-19 13:28 - 00000178 ___SH () C:\Documents and Settings\LocalService\ntuser.ini
2014-07-14 11:06 - 2012-01-19 13:23 - 01835777 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-14 11:05 - 2013-11-13 04:33 - 00000278 ___SH () C:\Documents and Settings\New\ntuser.ini
2014-07-14 11:05 - 2013-01-19 00:12 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951376-v2$
2014-07-14 11:05 - 2012-01-19 13:28 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-14 10:45 - 2014-07-14 10:40 - 00000000 ____D () C:\Program Files\HijackThis
2014-07-14 10:22 - 2014-07-14 10:24 - 00482112 _____ (Kaspersky Lab) C:\Documents and Settings\New\Desktop\setup.exe
2014-07-13 18:32 - 2012-08-18 22:51 - 00000000 ____D () C:\Softwares
2014-07-13 10:57 - 2014-07-13 10:57 - 00000000 ____D () C:\Program Files\ESET
2014-07-13 10:56 - 2014-07-13 10:57 - 02425208 _____ (ESET) C:\Documents and Settings\New\Desktop\esetsmartinstaller_enu.exe
2014-07-12 21:19 - 2014-07-12 21:19 - 00000000 ____D () C:\Documents and Settings\New\Local Settings\Application Data\Evernote
2014-07-12 21:19 - 2014-07-12 21:19 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Evernote
2014-07-12 21:18 - 2014-07-12 21:18 - 00000625 _____ () C:\Documents and Settings\New\Desktop\Evernote.lnk
2014-07-12 21:18 - 2014-07-12 21:18 - 00000000 ____D () C:\Program Files\Evernote
2014-07-11 22:20 - 2012-08-03 21:19 - 00000000 ____D () C:\AAA
2014-07-11 13:19 - 2014-07-11 10:36 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2014-07-11 13:19 - 2014-07-10 22:11 - 00000000 ____D () C:\Documents and Settings\New\Desktop\mbar
2014-07-11 12:07 - 2014-07-11 12:07 - 00000760 _____ () C:\Documents and Settings\New\Desktop\Cheat Engine.lnk
2014-07-11 12:07 - 2014-07-11 12:07 - 00000000 ____D () C:\Program Files\Cheat Engine 6.4
2014-07-11 12:07 - 2014-07-11 12:07 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Cheat Engine 6.4
2014-07-11 10:37 - 2013-02-13 08:55 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-07-10 23:20 - 2014-03-14 21:17 - 00000000 ____D () C:\Documents and Settings\New\Desktop\Florida
2014-07-10 23:15 - 2013-01-19 10:55 - 00000000 ____D () C:\BBB
2014-07-10 23:13 - 2012-12-24 12:31 - 00000000 ____D () C:\Documents and Settings\New\My Documents\Pinnacle Studio
2014-07-10 23:05 - 2014-07-10 23:04 - 00000000 ____D () C:\Documents and Settings\New\Application Data\360Login
2014-07-10 23:05 - 2014-07-10 23:04 - 00000000 ____D () C:\Documents and Settings\New\Application Data\360CloudUI
2014-07-10 23:04 - 2014-07-10 23:04 - 00000774 _____ () C:\Documents and Settings\New\Desktop\360云盘.lnk
2014-07-10 23:04 - 2014-07-10 23:04 - 00000000 ____D () C:\Program Files\360
2014-07-10 23:04 - 2014-07-10 23:04 - 00000000 ____D () C:\Documents and Settings\New\Start Menu\Programs\360安全中心
2014-07-10 22:37 - 2013-11-23 19:42 - 00000000 ____D () C:\Documents and Settings\New\Desktop\muledump-master
2014-07-10 22:36 - 2013-11-03 10:47 - 00000000 ____D () C:\Documents and Settings\New\Desktop\School
2014-07-10 22:13 - 2014-07-10 22:13 - 00000789 _____ () C:\Documents and Settings\New\Desktop\Higher Score on the ACT.lnk
2014-07-10 22:13 - 2014-07-10 22:13 - 00000000 ____D () C:\Program Files\Kap.ACTc
2014-07-10 22:13 - 2014-07-10 22:13 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Kaplan
2014-07-10 22:11 - 2014-07-07 13:17 - 00054232 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-10 20:16 - 2012-08-03 21:58 - 00000000 ____D () C:\Dave
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmpF6D6A.FOT
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmpF4D6A.FOT
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmp04D6A.FOT
2014-07-10 12:36 - 2014-07-10 12:36 - 00001409 _____ () C:\WINDOWS\system32\tmp02D6A.FOT
2014-07-10 11:32 - 2014-07-10 11:23 - 00000000 ____D () C:\AdwCleaner
2014-07-09 19:41 - 2012-11-15 21:38 - 00000000 ____D () C:\Documents and Settings\New\Application Data\uTorrent
2014-07-09 19:37 - 2014-07-09 19:37 - 00006904 _____ () C:\WINDOWS\FaxSetup.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00006638 _____ () C:\WINDOWS\iis6.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00005816 _____ () C:\WINDOWS\ocgen.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00004591 _____ () C:\WINDOWS\tsoc.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00002502 _____ () C:\WINDOWS\comsetup.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001891 _____ () C:\WINDOWS\imsins.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001864 _____ () C:\WINDOWS\msmqinst.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001810 _____ () C:\WINDOWS\ntdtcsetup.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00001592 _____ () C:\WINDOWS\netfxocm.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000719 _____ () C:\WINDOWS\MedCtrOC.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000473 _____ () C:\WINDOWS\msgsocm.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000469 _____ () C:\WINDOWS\ocmsn.log
2014-07-09 19:37 - 2014-07-09 19:37 - 00000311 _____ () C:\WINDOWS\tabletoc.log
2014-07-09 15:26 - 2012-12-18 17:43 - 00000000 ____D () C:\Documents and Settings\New\Desktop\Tony
2014-07-09 15:15 - 2008-04-14 03:00 - 00001506 _____ () C:\WINDOWS\win.ini
2014-07-09 14:04 - 2014-07-09 14:08 - 11199152 _____ (Adobe Systems, Inc.) C:\Documents and Settings\New\Desktop\flashplayer_14_sa.exe
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp8EB47.FOT
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp71C47.FOT
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp70C47.FOT
2014-07-09 11:48 - 2014-07-09 11:48 - 00001409 _____ () C:\WINDOWS\system32\tmp62C47.FOT
2014-07-08 14:21 - 2014-07-08 14:21 - 00065536 _____ () C:\WINDOWS\Minidump\Mini070814-01.dmp
2014-07-08 14:21 - 2014-04-08 22:14 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Package Cache
2014-07-08 14:21 - 2013-01-19 00:09 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB923561$
2014-07-08 14:21 - 2012-11-04 11:53 - 00000000 ____D () C:\WINDOWS\TDDOWNLOAD
2014-07-08 14:21 - 2012-10-08 11:35 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-08 14:21 - 2012-08-04 11:57 - 2145386496 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-08 13:57 - 2014-07-08 13:57 - 00000000 ____D () C:\Documents and Settings\New\Local Settings\Application Data\UWebKit151
2014-07-08 13:57 - 2014-07-08 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\boost_interprocess
2014-07-08 13:02 - 2014-07-08 13:02 - 00066073 _____ () C:\Documents and Settings\New\Desktop\bookmarks-2014-07-08.json
2014-07-07 13:17 - 2014-07-07 13:17 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-07 13:17 - 2014-07-07 13:17 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-07 13:17 - 2014-07-07 13:17 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-07 13:04 - 2012-08-03 09:38 - 00032256 ____C () C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp546EC.FOT
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp536EC.FOT
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp476EC.FOT
2014-07-06 15:48 - 2014-07-06 15:48 - 00001409 _____ () C:\WINDOWS\system32\tmp466EC.FOT
2014-07-05 21:13 - 2014-07-05 21:13 - 00005632 ___SH () C:\Documents and Settings\Thumbs.db
2014-07-05 21:13 - 2013-05-27 22:10 - 00055296 ___SH () C:\Documents and Settings\New\Desktop\Thumbs.db
2014-07-05 21:13 - 2012-08-07 15:18 - 00007168 __SHC () C:\WINDOWS\Thumbs.db
2014-07-03 20:46 - 2014-07-11 15:21 - 02085772 _____ () C:\Documents and Settings\New\Desktop\rotmg.swf
2014-07-03 16:31 - 2014-07-03 16:31 - 00006058 _____ () C:\Documents and Settings\New\Desktop\PCCLEANER.bat
2014-07-01 18:58 - 2014-07-01 16:31 - 00000000 _RSHD () C:\Documents and Settings\New\9p2garka7ur3
2014-07-01 18:58 - 2013-01-06 19:34 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956803_0$
2014-07-01 18:47 - 2013-12-24 19:12 - 00000000 __SHD () C:\Documents and Settings\All Users\Application Data\EKA
2014-07-01 18:47 - 2013-12-24 18:16 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\UCA
2014-07-01 18:24 - 2013-01-06 16:27 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-07-01 16:57 - 2012-01-19 13:24 - 00002577 ____C () C:\WINDOWS\system32\CONFIG.NT
2014-07-01 16:31 - 2012-01-19 13:29 - 00000000 ____D () C:\Documents and Settings\New
2014-06-27 13:47 - 2014-06-19 18:26 - 00000457 _____ () C:\WINDOWS\setupact.log
2014-06-27 13:47 - 2014-06-19 17:58 - 00048444 _____ () C:\WINDOWS\setupapi.log
2014-06-26 16:43 - 2014-06-26 16:43 - 00000014 _____ () C:\tristansa.txt
2014-06-21 15:13 - 2012-09-03 19:30 - 02462454 _____ () C:\WINDOWS\ACD Wallpaper.bmp
2014-06-21 15:07 - 2012-08-03 21:59 - 00000000 ____D () C:\Family
2014-06-19 20:17 - 2012-01-19 13:24 - 00000000 ____D () C:\DELL
2014-06-19 18:26 - 2014-06-19 18:26 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-06-18 17:02 - 2014-05-29 13:15 - 00000000 _____ () C:\WINDOWS\Sti_Trace.log
Files to move or delete:
====================
C:\Documents and Settings\New\TempWmicBatchFile.bat
Some content of TEMP:
====================
C:\Documents and Settings\Administrator\Local Settings\Temp\swt-win32-3349.dll
C:\Documents and Settings\New\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfnmkjl.dll
C:\Documents and Settings\New\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpftekon.dll
C:\Documents and Settings\New\Local Settings\Temp\wincjll.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================