(new TDL4) Keylogged & IE with a mind of its own

Inactive
By Brutal Black
Nov 23, 2011
  1. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    Bah... I just wish I saved a few important files before this happened... Regret is a kick in the teeth. lol
  2. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    That can be always done.

    Let's see, if we can look at your computer booting from an external source.

    Please download OTLPE (filesize 120,9 MB)

    • When downloaded double click on OTLPENet.exe and make sure there is a blank CD in your CD drive. This will automatically create a bootable CD.
    • Reboot your system using the boot CD you just created.
      • Note : If you do not know how to set your computer to boot from CD follow the steps HERE
    • Your system should now display a REATOGO-X-PE desktop.
    • Depending on your type of internet connection, you should be able to get online as well so you can access this topic more easily.
    • Double-click on the OTLPE icon.
    • When asked Do you wish to load the remote registry, select Yes
    • When asked Do you wish to load remote user profile(s) for scanning, select Yes
    • Ensure the box Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start.
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\OTL.txt
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please post the contents of the OTL.txt file in your reply.
  3. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    So no connection unfortunately, but neat... I'm at the desktop. I have no flash drive, if you recall when this topic started I was in the process of moving, you can imagine what it's like to find a flashdrive in this instance.

    Is it possible to burn the txt to the open disc I've been using? It would require I take the OTLPE disc out. I'll await your response before continuing. Worse comes to worse I'd be glad to type out the text manually.
  4. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    You should have a connection there.
    That makes me think it may be something wrong with your ethernet card driver or card itself.

    You can't remove the CD as it runs OS you're just using.

    On a side note, if nothing works you can use OTLPE to backup your files.
  5. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    All processes killed
    ==========OTL================
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ notfound
    Folder C:\Users\gamers\AppData\Roaming\AVG\ not found.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tune up 2011\ Utilities folder moved successfullyC:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tune up 2011 folder moved successfully
    Folder C:\$AVG\ not found.
    C:\Users\gamers\AppData\Roaming\AVG2012\cfgall folder moved sccessfully.
    C:\Users\gamers\AppData\Roaming\AVG2012 folder moved sccessfully.
    C:\ProgramData\AVG2012\log folder moved successfully.
    C:\ProgramData\AVG2012\cfgall folder removed successfully.
    C:\ProgramData\AVG2012\cfg folder moved successfully.
    C:\ProgramData\AVG2012 folder moved successfully.
    C:\Program Files\AVG\AVG PC Tuneup 2011\Data folder moved successfully.
    C:\Program Files\AVG\AVG PC Tuneup 2011 folder moved successfully.
    C:\Program Files\AVG folder moved successfully.
    File C:\ProgramData\~MqGNiCX5SV6ESH not found.
    File C:\ProgramData\~MqGNiCX5SV6ESHr not found.
    File C:\ProgramData\MqGNiCX5SV6ESH not found.
    C:\Users\gamers\Desktop\Eusing Free Registry Cleaner. Ink moved successfully.
    Unable to delete ADS C:\ProgramData\TEMP:0B42277B4
    ========COMMANDS========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes

    User: gamers
    ->Temp folder emptied: 18856982 bytes
    ->Temporary Internet Files folder emptied: 8872299 bytes
    ->Java cache emptied: 0 bytes
    ->Firefox cache emptied: 23882021 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 17954 bytes
  6. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    I do have a connection, it shows the connection X'd out because I have two controllers to plug my ethernet cord into... I only discovered the connection was actually working AFTER I manually typed all of the above out... My eagerness got the best of me there. I'll copy it again although I'm sure I got it all right.
  7. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    All processes killed
    ========== OTL ==========
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.
    Folder C:\Users\gamers\AppData\Roaming\AVG\ not found.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011\Utilities folder moved successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011 folder moved successfully.
    Folder C:\$AVG\ not found.
    C:\Users\gamers\AppData\Roaming\AVG2012\cfgall folder moved successfully.
    C:\Users\gamers\AppData\Roaming\AVG2012 folder moved successfully.
    C:\ProgramData\AVG2012\log folder moved successfully.
    C:\ProgramData\AVG2012\cfgall folder moved successfully.
    C:\ProgramData\AVG2012\Cfg folder moved successfully.
    C:\ProgramData\AVG2012 folder moved successfully.
    C:\Program Files\AVG\AVG PC Tuneup 2011\Data folder moved successfully.
    C:\Program Files\AVG\AVG PC Tuneup 2011 folder moved successfully.
    C:\Program Files\AVG folder moved successfully.
    File C:\ProgramData\~MqGNiCX5Sv6EsH not found.
    File C:\ProgramData\~MqGNiCX5Sv6EsHr not found.
    File C:\ProgramData\MqGNiCX5Sv6EsH not found.
    C:\Users\gamers\Desktop\Eusing Free Registry Cleaner.lnk moved successfully.
    Unable to delete ADS C:\ProgramData\TEMP:0B4227B4 .
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes

    User: gamers
    ->Temp folder emptied: 18856982 bytes
    ->Temporary Internet Files folder emptied: 8872299 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 23882021 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 17954 bytes
    RecycleBin emptied: 0 bytes
  8. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    OK, but now run OTL "Quick scan" and post new log (no custom script needed).
  9. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    You did fine. Go ahead with my previous reply.
  10. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    No luck running OTL, got an "Uable to locate component" error.

    "This application has failed to start because framedyn.dll was not found. Re-installing the application may fix this problem."

    However that was a fresh install. I'll delete the OTL I have and retry.
  11. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    Same error after two fresh installs.
  12. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    I think you're running wrong program.
    You should have OTLPE (not OTL) icon on your desktop.
  13. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    We posted at the same time.
     
  14. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    Indeed I am, re-downloaded it from an earlier page and all. Figured you meant OTL. I'll try the offical one.

    The scan is currently running.
  15. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    OTL logfile created on: 12/4/2011 6:44:03 PM - Run
    OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
    Windows 7 Ultimate (Version = 6.1.7600) - Type = System
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
    3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 465.75 Gb Total Space | 92.23 Gb Free Space | 19.80% Space Free | Partition Type: NTFS
    Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

    Computer Name: REATOGO | User Name: SYSTEM
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
    Using ControlSet: ControlSet001

    ========== Win32 Services (SafeList) ==========


    ========== Driver Services (SafeList) ==========

    DRV - [2010/11/11 22:21:30 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========



    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    IE - HKU\gamers_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=Z133&install_date=20111123
    IE - HKU\gamers_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    IE - HKU\gamers_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 D1 42 98 65 7C CB 01 [binary data]
    IE - HKU\gamers_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\gamers_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



    ========== FireFox ==========

    FF - prefs.js..browser.search.selectedEngine: "Bing"
    FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
    FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.25
    FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
    FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.3.3
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
    FF - prefs.js..extensions.enabledItems: web2pdfextension@web2pdf.adobedotcom:1.0
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
    FF - prefs.js..extensions.enabledItems: {20C3BDFF-DA68-468d-8D9A-F5A6C76B0F9E}:3.13
    FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z133&form=ZGAADF&install_date=20111123&q="
    FF - prefs.js..network.proxy.type: 0

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/12/01 03:06:19 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/02/07 13:09:20 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 12:35:17 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/30 18:12:25 | 000,000,000 | ---D | M]

    [2010/11/23 18:58:15 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\gamers\AppData\Roaming\Mozilla\Extensions
    [2011/11/23 15:19:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gamers\AppData\Roaming\Mozilla\Firefox\Profiles\jxpiwbqm.default\extensions
    [2011/11/23 12:11:25 | 000,000,000 | ---D | M] (Somoto Toolbar) -- C:\Users\gamers\AppData\Roaming\Mozilla\Firefox\Profiles\jxpiwbqm.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}
    [2011/11/19 04:31:20 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Users\gamers\AppData\Roaming\Mozilla\Firefox\Profiles\jxpiwbqm.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
    [2011/11/19 04:31:20 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\gamers\AppData\Roaming\Mozilla\Firefox\Profiles\jxpiwbqm.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
    [2011/03/05 17:55:25 | 000,002,071 | -H-- | M] () -- C:\Users\gamers\AppData\Roaming\Mozilla\Firefox\Profiles\jxpiwbqm.default\searchplugins\absearch-search.xml
    [2011/11/09 12:35:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    File not found (No name found) --
    [2011/11/05 01:53:18 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2011/09/08 23:49:04 | 001,037,112 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
    [2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
    [2011/11/04 22:21:03 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
    [2011/11/04 22:21:03 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

    O1 HOSTS File: ([2011/11/30 15:47:03 | 000,000,027 | ---- | M]) - C:\Windows\System32\Drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - Reg Error: Value error. File not found
    O2 - BHO: (Updater For Comcast Toolbar 3.5) - {164d3751-cac6-4a6d-becd-ea67df61d232} - C:\Program Files\comcasttb\auxi\comcastAu.dll (Visicom Media)
    O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
    O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - Reg Error: Value error. File not found
    O2 - BHO: (Comcast Toolbar) - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll ()
    O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
    O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll ()
    O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - File not found
    O3 - HKLM\..\Toolbar: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found.
    O3 - HKU\gamers_ON_C\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKU\gamers_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
    O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [Recordpad] C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe (NCH Software)
    O4 - HKU\gamers_ON_C..\Run: [ComcastAntispyClient] C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe ()
    O4 - HKU\gamers_ON_C..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
    O4 - HKU\gamers_ON_C..\Run: [EADM] C:\Program Files\Electronic Arts\EADM\EADMUI.exe (Electronic Arts)
    O4 - HKU\gamers_ON_C..\Run: [PlayOn] C:\Program Files\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
    O4 - HKU\gamers_ON_C..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
    O4 - Startup: C:\Users\gamers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\gamers_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\gamers_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\gamers_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
    O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
    O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
    O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
    O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab (Creative Software AutoUpdate Support Package 1)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O32 - Unable to open key or key not present!
    O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/12/04 16:37:47 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\gamers\Desktop\OTL.exe
    [2011/12/04 14:21:44 | 000,000,000 | ---D | C] -- C:\_OTL
    [2011/12/04 02:09:43 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2011/12/03 23:30:49 | 000,000,000 | ---D | C] -- C:\NVIDIA
    [2011/12/03 23:20:57 | 000,000,000 | ---D | C] -- C:\Windows\Java
    [2011/12/03 23:20:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
    [2011/12/03 23:20:56 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
    [2011/12/02 19:53:13 | 000,000,000 | ---D | C] -- C:\FRST
    [2011/12/01 20:30:42 | 000,000,000 | --SD | C] -- C:\Yourname
    [2011/12/01 01:29:07 | 001,566,512 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\gamers\Desktop\tdsskiller.exe
    [2011/11/30 19:44:35 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2011/11/29 21:52:38 | 004,324,789 | R--- | C] (Swearware) -- C:\Users\gamers\Desktop\Yourname.exe
    [2011/11/29 17:15:25 | 000,000,000 | ---D | C] -- C:\Users\gamers\AppData\Local\temp
    [2011/11/29 03:53:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2011/11/29 03:53:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2011/11/29 03:53:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2011/11/29 03:52:24 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
    [2011/11/29 03:46:33 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2011/11/28 16:48:13 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2011/11/24 14:45:25 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\gamers\Desktop\aswMBR.exe
    [2011/11/24 14:30:46 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
    [2011/11/23 12:11:23 | 000,000,000 | ---D | C] -- C:\Program Files\somototoolbar
    [2011/11/23 12:10:34 | 000,000,000 | ---D | C] -- C:\Users\gamers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Temp File Cleaner
    [2011/11/23 12:10:34 | 000,000,000 | ---D | C] -- C:\Program Files\Temp File Cleaner
    [2011/11/23 06:58:06 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\gamers\Desktop\dds.scr
    [2011/11/23 06:45:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2011/11/23 06:42:50 | 000,000,000 | ---D | C] -- C:\Users\gamers\AppData\Roaming\QuickScan
    [2011/11/23 06:39:35 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
    [2011/11/23 06:02:49 | 000,000,000 | ---D | C] -- C:\Users\gamers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
    [2011/11/23 06:02:48 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2011/11/21 17:57:13 | 000,000,000 | ---D | C] -- C:\Users\gamers\AppData\Roaming\Malwarebytes
    [2011/11/21 17:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2011/11/21 17:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2011/11/21 17:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2011/11/20 08:37:55 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
    [2011/11/20 08:18:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
    [2011/11/20 08:18:05 | 000,000,000 | ---D | C] -- C:\Program Files\Eusing Free Registry Cleaner
    [2011/11/19 06:16:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
    [2011/11/19 05:33:25 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2011/11/19 05:33:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2011/11/16 13:33:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FXAA Post-Process Injector
    [2011/11/16 13:20:35 | 000,000,000 | -H-D | C] -- C:\Users\gamers\Documents\Nexus Mod Manager
    [2011/11/16 13:20:35 | 000,000,000 | ---D | C] -- C:\Users\gamers\AppData\Local\Black_Tree_Gaming
    [2011/11/16 13:20:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
    [2011/11/16 13:20:33 | 000,000,000 | ---D | C] -- C:\Program Files\Nexus Mod Manager
    [2011/11/15 17:24:36 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
    [2011/11/10 16:16:23 | 000,000,000 | -H-D | C] -- C:\Users\gamers\AppData\Local\Skyrim
    [2011/11/10 15:57:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
    [2011/11/10 15:50:21 | 000,000,000 | ---D | C] -- C:\Program Files\The Elder Scrolls V Skyrim
    [2011/11/10 15:45:43 | 000,000,000 | ---D | C] -- C:\Elder Scrolls
    [2011/08/12 10:27:39 | 001,187,840 | ---- | C] (Windower Development Team) -- C:\Program Files\Hook.dll
    [2011/08/12 10:27:39 | 000,224,256 | ---- | C] (Aceofspades) -- C:\Program Files\launcher_gui.exe

    ========== Files - Modified Within 30 Days ==========

    [2011/12/04 20:29:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/12/04 16:37:49 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\gamers\Desktop\OTL.exe
    [2011/12/04 16:29:56 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/12/04 16:29:24 | 2415,566,848 | -HS- | M] () -- C:\hiberfil.sys
    [2011/12/04 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
    [2011/12/04 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
    [2011/12/04 16:28:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
    [2011/12/04 16:28:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayOn
    [2011/12/04 16:28:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One-click FLAC to MP3 Converter
    [2011/12/04 16:28:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Midnight Club 2
    [2011/12/04 16:28:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
    [2011/12/04 13:08:14 | 000,000,000 | ---- | M] () -- C:\ProgramData\TEMP
    [2011/12/04 01:50:52 | 000,000,512 | ---- | M] () -- C:\Users\gamers\Desktop\MBR.dat
    [2011/12/04 01:18:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
    [2011/12/02 19:52:44 | 000,858,348 | ---- | M] () -- C:\Users\gamers\Desktop\FRST.exe
    [2011/12/01 20:28:44 | 004,324,789 | R--- | M] (Swearware) -- C:\Users\gamers\Desktop\Yourname.exe
    [2011/12/01 19:58:13 | 000,010,240 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/12/01 19:58:13 | 000,010,240 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/12/01 19:55:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/12/01 01:29:13 | 001,566,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\gamers\Desktop\tdsskiller.exe
    [2011/11/30 15:47:03 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2011/11/29 01:38:10 | 311,721,516 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2011/11/24 14:45:26 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\gamers\Desktop\aswMBR.exe
    [2011/11/24 14:43:07 | 001,008,092 | ---- | M] () -- C:\Users\gamers\Desktop\rkill.com
    [2011/11/23 16:36:20 | 000,001,047 | ---- | M] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
    [2011/11/23 16:36:20 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
    [2011/11/23 12:10:37 | 000,001,047 | ---- | M] () -- C:\Users\gamers\Desktop\Temp File Cleaner.lnk
    [2011/11/23 06:57:46 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\gamers\Desktop\dds.scr
    [2011/11/23 06:56:18 | 000,302,592 | ---- | M] () -- C:\Users\gamers\Desktop\u6gx0ld6.exe
    [2011/11/23 06:02:49 | 000,002,969 | ---- | M] () -- C:\Users\gamers\Desktop\HiJackThis.lnk
    [2011/11/21 17:56:58 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011/11/21 17:56:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2011/11/20 08:21:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Genie
    [2011/11/20 08:21:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearShare
    [2011/11/19 06:23:31 | 000,615,566 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/11/19 06:23:31 | 000,103,682 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/11/19 06:17:51 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    [2011/11/19 05:33:57 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
    [2011/11/19 04:32:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    [2011/11/19 04:32:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
    [2011/11/19 04:32:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft DirectX SDK (June 2010)
    [2011/11/19 04:32:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dictation and Transcription Programs
    [2011/11/19 04:32:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
    [2011/11/19 04:31:29 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
    [2011/11/19 04:31:29 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    [2011/11/19 04:31:29 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    [2011/11/19 04:31:29 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ventrilo
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2 Assassins of Kings
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayOnline
    [2011/11/19 04:31:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
    [2011/11/19 04:31:12 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
    [2011/11/19 04:31:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2011/11/19 04:31:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
    [2011/11/19 04:31:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2011/11/19 04:31:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FXAA Post-Process Injector
    [2011/11/19 04:31:12 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout Mod Manager
    [2011/11/19 04:31:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
    [2011/11/19 04:31:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eidos Interactive
    [2011/11/19 04:31:10 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
    [2011/11/19 04:31:10 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comcast
    [2011/11/19 04:31:10 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet
    [2011/11/19 04:31:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks
    [2011/11/19 04:31:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite
    [2011/11/19 04:31:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
    [2011/11/19 04:31:07 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2011/11/18 15:23:40 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iPhone Explorer
    [2011/11/14 12:26:19 | 000,000,637 | -H-- | M] () -- C:\Users\gamers\Documents\Bob's Burgers.xspf
    [2011/11/10 16:28:09 | 000,001,624 | ---- | M] () -- C:\Users\gamers\Desktop\The Elder Scrolls Skyrim.lnk
    [2011/11/09 12:35:18 | 000,001,108 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    [2011/11/09 12:35:18 | 000,001,096 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk

    ========== Files Created - No Company Name ==========

    [2011/12/03 04:40:09 | 000,000,512 | ---- | C] () -- C:\Users\gamers\Desktop\MBR.dat
    [2011/12/02 19:52:41 | 000,858,348 | ---- | C] () -- C:\Users\gamers\Desktop\FRST.exe
    [2011/11/29 03:53:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2011/11/29 03:53:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2011/11/29 03:53:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2011/11/29 03:53:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2011/11/29 03:53:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2011/11/28 16:48:11 | 311,721,516 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2011/11/24 14:43:06 | 001,008,092 | ---- | C] () -- C:\Users\gamers\Desktop\rkill.com
    [2011/11/23 12:12:33 | 000,000,000 | ---- | C] () -- C:\ProgramData\TEMP
    [2011/11/23 12:10:37 | 000,001,047 | ---- | C] () -- C:\Users\gamers\Desktop\Temp File Cleaner.lnk
    [2011/11/23 06:58:33 | 000,302,592 | ---- | C] () -- C:\Users\gamers\Desktop\u6gx0ld6.exe
    [2011/11/23 06:02:49 | 000,002,969 | ---- | C] () -- C:\Users\gamers\Desktop\HiJackThis.lnk
    [2011/11/21 17:56:58 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011/11/16 13:20:33 | 000,001,047 | ---- | C] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
    [2011/11/14 12:26:19 | 000,000,637 | -H-- | C] () -- C:\Users\gamers\Documents\Bob's Burgers.xspf
    [2011/11/10 16:28:09 | 000,001,624 | ---- | C] () -- C:\Users\gamers\Desktop\The Elder Scrolls Skyrim.lnk
    [2011/11/09 12:35:18 | 000,001,108 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    [2011/11/09 12:35:18 | 000,001,096 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2011/10/07 20:46:59 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2011/10/01 20:32:42 | 000,001,624 | ---- | C] () -- C:\Windows\System32\WLAN.INI
    [2011/08/12 10:27:39 | 000,385,536 | ---- | C] () -- C:\Program Files\launcher.exe
    [2011/08/12 10:27:39 | 000,000,188 | ---- | C] () -- C:\Program Files\launcher.ini
    [2011/08/12 10:27:39 | 000,000,123 | ---- | C] () -- C:\Program Files\Windower Website.url
    [2011/06/04 16:51:04 | 000,000,089 | -HS- | C] () -- C:\ProgramData\.zreglib
    [2011/06/04 16:51:04 | 000,000,002 | -HS- | C] () -- C:\Users\gamers\AppData\Roaming\.zreglib
    [2011/03/29 04:47:57 | 000,176,128 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
    [2011/03/29 04:47:57 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
    [2010/12/23 16:43:22 | 000,000,182 | -H-- | C] () -- C:\Users\gamers\AppData\Roaming\default.rss
    [2010/12/03 08:47:07 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
    [2010/11/20 10:31:31 | 000,625,152 | ---- | C] () -- C:\Windows\System32\mp3tsshx.dll
    [2010/11/10 22:50:07 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
    [2010/11/05 16:30:24 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
    [2009/10/20 12:33:02 | 000,030,688 | ---- | C] () -- C:\Windows\System32\xfiWR.ini
    [2009/09/16 07:20:14 | 000,001,801 | ---- | C] () -- C:\Windows\WRcfg.ini
    [2009/08/19 06:15:08 | 000,000,388 | ---- | C] () -- C:\Windows\WRMCcfg.ini
    [2009/07/13 23:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/13 23:33:53 | 000,267,496 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2009/07/13 21:05:48 | 000,615,566 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2009/07/13 21:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2009/07/13 21:05:48 | 000,103,682 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2009/07/13 21:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2009/07/13 21:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2009/07/13 21:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2009/07/13 19:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
    [2009/07/13 19:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll
    [2009/07/13 18:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/13 18:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
    [2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
    [2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2007/08/07 18:22:22 | 000,141,180 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat

    ========== LOP Check ==========

    [2010/11/12 14:06:56 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\Astroburn Lite
    [2010/11/10 18:43:32 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\BearShareTb
    [2011/11/23 05:51:39 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\BitComet
    [2010/11/12 13:49:09 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\DAEMON Tools Lite
    [2010/11/10 18:49:23 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\MusicNet
    [2011/12/04 13:05:32 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\NCH Swift Sound
    [2011/11/23 06:42:56 | 000,000,000 | ---D | M] -- C:\Users\gamers\AppData\Roaming\QuickScan
    [2011/03/31 00:05:34 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\Recordpad
    [2011/11/28 08:39:18 | 000,000,000 | ---D | M] -- C:\Users\gamers\AppData\Roaming\RIFT
    [2011/12/02 19:58:45 | 000,000,000 | ---D | M] -- C:\Users\gamers\AppData\Roaming\SoftGrid Client
    [2011/02/16 16:28:55 | 000,000,000 | -H-D | M] -- C:\Users\gamers\AppData\Roaming\TP
    [2011/11/19 04:29:09 | 000,000,000 | ---D | M] -- C:\Users\gamers\AppData\Roaming\TuneUp Software
    [2011/11/19 04:31:21 | 000,000,000 | ---D | M] -- C:\Users\gamers\AppData\Roaming\uTorrent
    [2011/11/19 05:30:44 | 000,000,000 | ---D | M] -- C:\ProgramData\Alwil Software
    [2009/07/13 23:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
    [2010/11/12 14:06:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Astroburn Lite
    [2011/11/19 09:18:04 | 000,000,000 | ---D | M] -- C:\ProgramData\AVAST Software
    [2011/02/05 00:52:15 | 000,000,000 | ---D | M] -- C:\ProgramData\BioWare
    [2011/11/23 06:39:35 | 000,000,000 | ---D | M] -- C:\ProgramData\boost_interprocess
    [2011/01/04 14:31:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco Systems
    [2011/11/19 06:16:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
    [2010/11/11 22:20:55 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite
    [2009/07/13 23:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
    [2009/07/13 23:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
    [2011/03/09 01:02:46 | 000,000,000 | ---D | M] -- C:\ProgramData\EA Core
    [2011/12/04 16:27:27 | 000,000,000 | ---D | M] -- C:\ProgramData\Electronic Arts
    [2009/07/13 23:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
    [2010/12/23 15:39:19 | 000,000,000 | ---D | M] -- C:\ProgramData\LightScribe
    [2011/12/04 16:30:06 | 000,000,000 | ---D | M] -- C:\ProgramData\MediaMall
    [2011/11/24 14:25:55 | 000,000,000 | ---D | M] -- C:\ProgramData\MFAData
    [2011/04/06 16:25:46 | 000,000,000 | ---D | M] -- C:\ProgramData\NCH Swift Sound
    [2011/02/07 13:21:23 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe
    [2011/04/07 22:09:33 | 000,000,000 | ---D | M] -- C:\ProgramData\Solidshield
    [2009/07/13 23:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
    [2010/11/11 12:09:26 | 000,000,000 | ---D | M] -- C:\ProgramData\SupportSoft
    [2009/07/13 23:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
    [2011/03/31 12:10:37 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software
    [2011/02/16 18:45:02 | 000,000,000 | ---D | M] -- C:\ProgramData\VirtualizedApplications
    [2010/12/26 11:51:52 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip
    [2011/01/18 11:19:43 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2011/03/31 12:10:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
    [2011/12/02 19:49:48 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========


    < End of report >
  16. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    Bumpy Johnson

    ^

    Making sure it gets spotted
  17. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    Ooops...I didn't get any email notification about your previous post.
    Hold on....
  18. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    I don't see anything malicious or anything what would prevent your computer from starting.

    At this point I must assume that we have some serious Windows corruption and you'll be forced to reinstall.

    I'm sorry. I thought we're almost there....
  19. Brutal Black

    Brutal Black Newcomer, in training Topic Starter Posts: 75

    I sent you a PM regarding the situation, thanks for doing what you could.
  20. Broni

    Broni Malware Annihilator Posts: 45,309   +243

    I replied.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.