O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: 111222.cn ([list1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: pps.tv ([kan] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: pps.tv ([list1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: pps.tv ([tvguide] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: pps.tv ([vodguide] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstream.com ([list1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstream.com ([notice] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstream.com ([xml1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstream.com ([xml2] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstream.com ([xml3] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstream.net ([list1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstv.com ([list1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: ppstv.net ([list1] http in Trusted sites)
O15 - HKU\S-1-5-21-3286712610-3324488593-3930158484-1000\..Trusted Domains: security_PPStream.exe ([]about in Trusted sites)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{176A144B-7DA3-4AB4-9CCE-A12E453016C3}: NameServer = 202.188.0.133,202.188.1.5
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C2976DE-B4C4-4D49-A3B1-21FA98DFDB98}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:
64bit: - Protocol\Filter\ica - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/11/02 21:22:42 | 000,000,000 | ---D | M] - C:\AutoCount Data -- [ NTFS ]
O32 - AutoRun File - [2008/12/19 20:59:21 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/07/14 17:29:38 | 000,000,122 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/10/18 21:29:47 | 000,919,968 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\Ay Wen\Desktop\rkill64.exe
[2012/10/18 21:28:37 | 004,984,103 | ---- | C] (Swearware) -- C:\Users\Ay Wen\Desktop\wen.exe
[2012/10/18 21:27:27 | 001,678,240 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\Ay Wen\Desktop\rkill.exe
[2012/10/18 06:47:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/10/17 22:54:22 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/10/17 22:33:03 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/17 22:33:03 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/17 22:33:03 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/17 22:32:58 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/17 22:32:36 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/15 22:59:20 | 000,000,000 | ---D | C] -- C:\FRST
[2012/10/15 22:01:05 | 002,213,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Ay Wen\Desktop\TDSSKiller.exe
[2012/10/15 21:59:08 | 000,000,000 | ---D | C] -- C:\Users\Ay Wen\AppData\Local\thumbs
[2012/10/15 06:45:21 | 001,456,929 | ---- | C] (Farbar) -- C:\Users\Ay Wen\Desktop\FRST64.exe
[2012/10/14 16:18:53 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Ay Wen\Desktop\aswMBR.exe
[2012/10/14 16:14:03 | 000,000,000 | ---D | C] -- C:\Users\Ay Wen\Desktop\RK_Quarantine
[2012/10/14 12:50:23 | 000,706,431 | R--- | C] (Swearware) -- C:\Users\Ay Wen\Desktop\dds.com
[2012/10/14 11:18:14 | 000,000,000 | ---D | C] -- C:\Windows\Installer2
[2012/10/13 18:08:48 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/10/13 16:23:49 | 000,000,000 | ---D | C] -- C:\ProgramData\RELOADED
[2012/10/13 16:01:47 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012/10/13 15:57:18 | 000,560,184 | ---- | C] (Duplex Secure Ltd.) -- C:\Windows\SysNative\drivers\sptd.sys
[2012/10/13 15:50:53 | 014,294,360 | ---- | C] (DT Soft Ltd) -- C:\Users\Ay Wen\Desktop\DTLite4454-0316.exe
[2012/10/06 22:43:21 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2012/10/05 22:29:44 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012/10/05 22:28:59 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012/10/05 22:28:59 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/10/05 22:05:31 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2012/10/05 22:02:14 | 000,370,048 | ---- | C] (Neuber Software) -- C:\Users\Ay Wen\Desktop\SvchostAnalyzer.exe
[2012/10/02 16:08:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/10/02 16:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2012/10/02 16:08:45 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/10/02 15:49:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/09/30 15:06:24 | 000,000,000 | ---D | C] -- C:\Users\Ay Wen\AppData\Roaming\Malwarebytes
[2012/09/30 12:59:57 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/09/30 12:51:19 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/30 12:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/30 12:51:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/30 12:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/29 19:50:11 | 000,000,000 | ---D | C] -- C:\Users\Ay Wen\AppData\Roaming\LavasoftStatistics
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Ay Wen\Desktop\*.tmp files -> C:\Users\Ay Wen\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/22 20:44:02 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/22 20:36:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3286712610-3324488593-3930158484-1000UA.job
[2012/10/22 17:37:38 | 000,002,034 | -H-- | M] () -- C:\Users\Ay Wen\Documents\Default.rdp
[2012/10/22 15:36:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3286712610-3324488593-3930158484-1000Core.job
[2012/10/18 21:40:19 | 000,013,808 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/18 21:40:19 | 000,013,808 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/18 21:37:26 | 000,792,886 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/18 21:37:26 | 000,673,648 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/10/18 21:37:26 | 000,124,450 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/10/18 21:32:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/18 21:32:32 | 3220,086,784 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/18 21:29:47 | 000,919,968 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\Ay Wen\Desktop\rkill64.exe
[2012/10/18 21:29:27 | 004,984,103 | ---- | M] (Swearware) -- C:\Users\Ay Wen\Desktop\wen.exe
[2012/10/18 21:27:44 | 001,678,240 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\Ay Wen\Desktop\rkill.exe
[2012/10/15 23:13:22 | 000,000,512 | ---- | M] () -- C:\Users\Ay Wen\Desktop\MBR.dat
[2012/10/15 22:00:49 | 002,194,704 | ---- | M] () -- C:\Users\Ay Wen\Desktop\tdsskiller.zip
[2012/10/15 21:46:49 | 000,000,954 | ---- | M] () -- C:\Users\Ay Wen\AppData\Local\bmarchive.bms
[2012/10/15 06:45:32 | 001,456,929 | ---- | M] (Farbar) -- C:\Users\Ay Wen\Desktop\FRST64.exe
[2012/10/14 16:19:55 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Ay Wen\Desktop\aswMBR.exe
[2012/10/14 16:13:02 | 001,422,336 | ---- | M] () -- C:\Users\Ay Wen\Desktop\RogueKiller.exe
[2012/10/14 12:50:18 | 000,706,431 | R--- | M] (Swearware) -- C:\Users\Ay Wen\Desktop\dds.com
[2012/10/14 12:06:46 | 000,302,592 | ---- | M] () -- C:\Users\Ay Wen\Desktop\pnsjz600.exe
[2012/10/13 16:20:11 | 000,000,667 | ---- | M] () -- C:\Users\Public\Desktop\R.A.W Realms of Ancient War.lnk
[2012/10/13 16:04:41 | 000,000,375 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
[2012/10/13 16:01:48 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012/10/13 15:57:35 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012/10/13 15:57:18 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) -- C:\Windows\SysNative\drivers\sptd.sys
[2012/10/13 15:53:37 | 014,294,360 | ---- | M] (DT Soft Ltd) -- C:\Users\Ay Wen\Desktop\DTLite4454-0316.exe
[2012/10/13 15:49:28 | 000,002,048 | ---- | M] () -- C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/10/12 23:58:32 | 000,000,025 | ---- | M] () -- C:\Users\Ay Wen\AppData\Roaming\CoreAVC.ini
[2012/10/12 17:27:22 | 002,213,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Ay Wen\Desktop\TDSSKiller.exe
[2012/10/07 10:08:14 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/10/06 17:31:48 | 000,985,600 | ---- | M] () -- C:\Users\Ay Wen\Desktop\MicrosoftFixit50123.msi
[2012/10/05 22:05:15 | 002,095,024 | ---- | M] () -- C:\Users\Ay Wen\Desktop\SecurityTaskManager_Setup.exe
[2012/10/05 22:02:22 | 000,370,048 | ---- | M] (Neuber Software) -- C:\Users\Ay Wen\Desktop\SvchostAnalyzer.exe
[2012/10/05 21:31:42 | 000,844,954 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/02 15:31:52 | 062,664,192 | ---- | M] () -- C:\Users\Ay Wen\Desktop\ess_nt64_enu.msi
[2012/10/01 00:03:42 | 000,417,416 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/09/30 12:51:20 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Ay Wen\Desktop\*.tmp files -> C:\Users\Ay Wen\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/17 22:33:03 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/17 22:33:03 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/17 22:33:03 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/17 22:33:03 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/17 22:33:03 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/15 22:00:47 | 002,194,704 | ---- | C] () -- C:\Users\Ay Wen\Desktop\tdsskiller.zip
[2012/10/14 18:34:18 | 000,000,512 | ---- | C] () -- C:\Users\Ay Wen\Desktop\MBR.dat
[2012/10/14 16:13:02 | 001,422,336 | ---- | C] () -- C:\Users\Ay Wen\Desktop\RogueKiller.exe
[2012/10/14 12:06:46 | 000,302,592 | ---- | C] () -- C:\Users\Ay Wen\Desktop\pnsjz600.exe
[2012/10/13 16:20:11 | 000,000,667 | ---- | C] () -- C:\Users\Public\Desktop\R.A.W Realms of Ancient War.lnk
[2012/10/13 16:20:11 | 000,000,667 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.A.W Realms of Ancient War.lnk
[2012/10/13 15:57:35 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012/10/06 17:31:45 | 000,985,600 | ---- | C] () -- C:\Users\Ay Wen\Desktop\MicrosoftFixit50123.msi
[2012/10/05 22:29:44 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012/10/05 22:04:56 | 002,095,024 | ---- | C] () -- C:\Users\Ay Wen\Desktop\SecurityTaskManager_Setup.exe
[2012/10/02 15:28:50 | 062,664,192 | ---- | C] () -- C:\Users\Ay Wen\Desktop\ess_nt64_enu.msi
[2012/09/30 12:51:20 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/28 10:04:34 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/07/26 23:56:15 | 000,000,138 | ---- | C] () -- C:\Windows\vsfilter.INI
[2012/04/06 14:50:25 | 000,000,164 | ---- | C] () -- C:\Windows\SysWow64\applet.ini
[2012/04/06 09:29:34 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/04/06 09:29:34 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/03/27 21:25:59 | 000,000,253 | ---- | C] () -- C:\Users\Ay Wen\AppData\Roaming\ANICONFIG_{2C2976DE-B4C4-4D49-A3B1-21FA98DFDB98}.ini
[2012/03/27 21:23:10 | 000,302,080 | ---- | C] () -- C:\Windows\lwd.exe
[2012/03/09 14:06:14 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012/02/01 20:42:33 | 000,000,025 | ---- | C] () -- C:\Users\Ay Wen\AppData\Roaming\CoreAVC.ini
[2011/12/10 17:07:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cd.dat
[2011/09/13 06:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/06/07 15:17:17 | 000,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2011/05/27 02:05:28 | 000,045,286 | ---- | C] () -- C:\Users\Ay Wen\AppData\Roaming\room_v3.dat
[2011/04/27 14:19:30 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011/04/27 14:19:30 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/04/27 14:19:30 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/04/27 14:19:30 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/04/13 22:30:42 | 000,046,742 | ---- | C] () -- C:\Users\Ay Wen\AppData\Roaming\room.dat
[2011/04/10 23:36:12 | 000,011,180 | ---- | C] () -- C:\Users\Ay Wen\gsview64.ini
[2010/11/02 21:44:58 | 000,390,912 | ---- | C] () -- C:\Windows\SysWow64\drivers\snpstd.sys
[2010/11/02 21:44:58 | 000,098,304 | ---- | C] ( ) -- C:\Windows\SysWow64\rsnpstd.dll
[2010/11/02 21:44:58 | 000,061,440 | ---- | C] ( ) -- C:\Windows\SysWow64\csnpstd.dll
[2010/11/02 21:44:58 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\dsnpstd.dll
[2010/11/02 21:44:58 | 000,036,864 | ---- | C] ( ) -- C:\Windows\SysWow64\vsnpstd.dll
[2010/11/02 21:44:58 | 000,015,541 | ---- | C] () -- C:\Windows\snpstd.ini
[2010/11/02 21:44:57 | 000,286,720 | ---- | C] () -- C:\Windows\vsnpstd.exe
[2010/05/12 09:04:29 | 000,000,159 | ---- | C] () -- C:\Users\Ay Wen\AppData\Roaming\default.rss
[2010/02/02 23:19:53 | 000,000,600 | ---- | C] () -- C:\Users\Ay Wen\AppData\Roaming\winscp.rnd
[2010/01/04 11:35:06 | 000,003,584 | ---- | C] () -- C:\Users\Ay Wen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/08 00:51:23 | 000,000,017 | ---- | C] () -- C:\Users\Ay Wen\AppData\Local\resmon.resmoncfg
[2008/05/09 16:08:32 | 000,000,954 | ---- | C] () -- C:\Users\Ay Wen\AppData\Local\bmarchive.bms
========== ZeroAccess Check ==========
[2009/07/14 12:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 13:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 12:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 09:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 09:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2010/05/15 20:50:40 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Acronis
[2011/12/11 00:26:34 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Alawar Entertainment
[2010/11/02 20:55:33 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\AutoCount
[2012/07/26 23:46:49 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Baidu
[2010/04/29 09:45:10 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Bump Technologies, Inc
[2010/11/25 14:59:17 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\CadSoft
[2012/10/13 16:08:26 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\DAEMON Tools Lite
[2011/06/07 15:18:24 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\DassaultSystemes
[2010/07/03 23:00:44 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\DragonicaSCB
[2011/06/07 15:18:25 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\EDrawings
[2010/08/17 20:44:55 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\ESET
[2012/03/31 21:59:44 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\GarenaPlus
[2010/10/31 18:35:45 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Gmote
[2010/04/09 23:16:50 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\GrabPro
[2011/07/07 15:26:23 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\ICAClient
[2011/03/16 00:26:06 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\ImgBurn
[2010/09/22 22:46:58 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\ImTOO
[2012/02/02 06:50:21 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\IObit
[2011/02/10 14:50:55 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\LolClient
[2011/02/01 00:06:56 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Modiac
[2012/05/05 21:14:02 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\MotioninJoy
[2012/01/20 22:06:47 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Motorola
[2010/08/27 08:54:52 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Octoshape
[2012/10/13 15:57:13 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\OpenCandy
[2012/10/15 06:44:30 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Orbit
[2010/10/21 01:32:02 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Outlook
[2011/05/10 22:42:19 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\PC Suite
[2010/09/20 09:02:34 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\PPStream
[2010/08/19 23:28:51 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\ProgSense
[2011/02/24 19:12:25 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\runic games
[2012/09/06 08:48:21 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Samsung
[2010/04/12 01:05:02 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\SystemRequirementsLab
[2012/05/11 22:58:24 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Temp
[2009/10/28 22:44:10 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Thinstall
[2012/05/26 13:28:27 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\TuneUp Software
[2012/03/22 21:12:02 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Western Digital
[2010/10/07 16:42:00 | 000,000,000 | ---D | M] -- C:\Users\Ay Wen\AppData\Roaming\Xunlei
[2012/09/30 11:28:57 | 000,000,000 | ---D | M] -- C:\Users\sai.AyWen-PC\AppData\Roaming\Ad-Aware Antivirus
[2012/09/30 11:33:27 | 000,000,000 | ---D | M] -- C:\Users\sai.AyWen-PC\AppData\Roaming\ESET
[2012/09/30 11:53:54 | 000,000,000 | ---D | M] -- C:\Users\sai.AyWen-PC\AppData\Roaming\GrabPro
[2012/09/30 11:31:07 | 000,000,000 | ---D | M] -- C:\Users\sai.AyWen-PC\AppData\Roaming\Motorola
[2012/09/30 05:56:58 | 000,000,000 | ---D | M] -- C:\Users\sai.AyWen-PC\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/10/22 20:44:04 | 000,002,251 | ---- | M] ()(C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\??7.lnk) -- C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\迅雷7.lnk
[2012/10/22 20:44:04 | 000,002,227 | ---- | M] ()(C:\Users\Ay Wen\Desktop\??7.lnk) -- C:\Users\Ay Wen\Desktop\迅雷7.lnk
[2012/04/21 12:22:12 | 000,002,253 | ---- | C] ()(C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\??7.lnk) -- C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\迅雷7.lnk
[2012/03/25 00:37:11 | 000,387,829 | ---- | C] ()(C:\Users\Ay Wen\Documents\?????????.torrent) -- C:\Users\Ay Wen\Documents\吉沢明步超级大合集.torrent
[2012/02/12 11:09:32 | 000,387,829 | ---- | M] ()(C:\Users\Ay Wen\Documents\?????????.torrent) -- C:\Users\Ay Wen\Documents\吉沢明步超级大合集.torrent
[2011/10/24 22:34:06 | 000,002,229 | ---- | C] ()(C:\Users\Ay Wen\Desktop\??7.lnk) -- C:\Users\Ay Wen\Desktop\迅雷7.lnk
[2011/03/04 14:42:23 | 000,000,706 | ---- | M] ()(C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\????? 2010.lnk) -- C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\酷我音乐盒 2010.lnk
[2010/01/18 21:42:25 | 000,000,706 | ---- | C] ()(C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\????? 2010.lnk) -- C:\Users\Ay Wen\Application Data\Microsoft\Internet Explorer\Quick Launch\酷我音乐盒 2010.lnk
(C:\Users\Ay Wen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????? 2010) -- C:\Users\Ay Wen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\酷我音乐盒 2010
(C:\Users\Ay Wen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) -- C:\Users\Ay Wen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\防御能力
(C:\Users\Ay Wen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) -- C:\Users\Ay Wen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\迅雷软件
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?????1.0) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度地址栏1.0
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\??????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\僼儔儞僗僷儞
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????? 2011) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\蹄扂秞氈碟 2011
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????? 2010) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\酷我音乐盒 2010
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度工具栏
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\防御能力
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷软件
< End of report >