Clevelantis
Posts: 42 +0
OTL (Part 2)
File not found
O4 - HKU\S-1-5-21-577059922-3361006745-2873073242-1000..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\S-1-5-21-577059922-3361006745-2873073242-1000..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {16F67783-7E72-4C39-99C4-4780A8335484} http://www.syncmyride.com/Own/Modules/UpdateCenter/applets/sync.cab (SyncXfer Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FB0FBA6-6420-43BE-950B-BE7DDB297058}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B763E676-6106-4F58-A81A-91ACBB15E641}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{129fd678-c68f-11df-8c9a-001e33d2730f}\Shell - "" = AutoRun
O33 - MountPoints2\{129fd678-c68f-11df-8c9a-001e33d2730f}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
O33 - MountPoints2\{a525ac73-6dae-11e1-a5e3-001e33d2730f}\Shell - "" = AutoRun
O33 - MountPoints2\{a525ac73-6dae-11e1-a5e3-001e33d2730f}\Shell\AutoRun\command - "" = E:\MotoCastSetup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/11 22:32:36 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\August\Desktop\OTL.exe
[2012/09/11 19:10:50 | 000,000,000 | ---D | C] -- C:\$RECYCLE(29).BIN
[2012/09/11 18:37:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/10 22:08:11 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\August\Desktop\aswMBR.exe
[2012/09/10 22:00:14 | 000,000,000 | ---D | C] -- C:\Users\August\Desktop\RK_Quarantine
[2012/09/08 23:00:38 | 000,000,000 | ---D | C] -- C:\Users\August\Desktop\Exploit Removal
[2012/09/08 22:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/08 22:23:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/08 21:51:04 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\August\Desktop\tdsskiller.exe
[2012/09/08 04:02:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/08/30 20:03:05 | 000,000,000 | ---D | C] -- C:\Users\August\AppData\Local\MetaGeek,_LLC
[17 C:\Users\August\Desktop\*.tmp files -> C:\Users\August\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/11 22:38:01 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-577059922-3361006745-2873073242-1000UA.job
[2012/09/11 22:32:39 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\August\Desktop\OTL.exe
[2012/09/11 22:25:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/11 22:20:01 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/11 21:25:36 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/11 21:23:15 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/11 21:23:15 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/11 21:22:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/11 21:22:51 | 4156,542,976 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/10 22:08:40 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\August\Desktop\aswMBR.exe
[2012/09/10 21:59:25 | 001,378,816 | ---- | M] () -- C:\Users\August\Desktop\RogueKiller.exe
[2012/09/10 21:53:23 | 002,193,184 | ---- | M] () -- C:\Users\August\Desktop\tdsskiller.zip
[2012/09/10 19:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-577059922-3361006745-2873073242-1000Core.job
[2012/09/10 17:53:47 | 000,302,592 | ---- | M] () -- C:\Users\August\Desktop\lhx0fu5j.exe
[2012/09/10 17:39:42 | 000,703,516 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/10 17:39:42 | 000,604,752 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/10 17:39:42 | 000,104,420 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/10 17:30:23 | 000,000,919 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/10 17:24:57 | 000,000,732 | ---- | M] () -- C:\Users\August\AppData\Local\d3d9caps64.dat
[2012/09/08 22:01:41 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\August\Desktop\tdsskiller.exe
[2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/03 01:40:09 | 000,002,088 | ---- | M] () -- C:\Users\August\Desktop\Google Chrome.lnk
[2012/09/03 01:40:09 | 000,002,050 | ---- | M] () -- C:\Users\August\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/15 03:29:38 | 000,359,712 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/15 03:05:36 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[17 C:\Users\August\Desktop\*.tmp files -> C:\Users\August\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/10 21:59:24 | 001,378,816 | ---- | C] () -- C:\Users\August\Desktop\RogueKiller.exe
[2012/09/10 21:53:19 | 002,193,184 | ---- | C] () -- C:\Users\August\Desktop\tdsskiller.zip
[2012/09/10 17:53:44 | 000,302,592 | ---- | C] () -- C:\Users\August\Desktop\lhx0fu5j.exe
[2012/09/10 17:26:29 | 4156,542,976 | -HS- | C] () -- C:\hiberfil.sys
[2012/09/10 17:24:57 | 000,000,732 | ---- | C] () -- C:\Users\August\AppData\Local\d3d9caps64.dat
[2012/09/08 22:23:11 | 000,000,919 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/15 03:05:36 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2012/01/18 01:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012/01/18 01:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012/01/18 01:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010/11/29 16:38:41 | 000,233,472 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2010/08/23 19:11:59 | 000,000,680 | ---- | C] () -- C:\Users\August\AppData\Local\d3d9caps.dat
[2010/07/28 20:11:49 | 008,892,928 | ---- | C] () -- C:\ProgramData\atscie.msi
[2010/04/03 15:25:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/08/02 11:05:31 | 000,021,504 | ---- | C] () -- C:\Users\August\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ==========
[2009/12/21 21:06:44 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Absolute Poker
[2010/04/20 20:55:49 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\acccore
[2009/08/15 12:53:32 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\GARMIN
[2009/10/10 17:02:16 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\iGrafx
[2012/05/08 22:16:07 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Leadertech
[2010/04/09 18:32:46 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\MAGIX
[2012/06/23 11:57:10 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Motorola
[2012/06/23 11:45:32 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Motorola Mobility
[2011/12/15 20:03:13 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\toshiba
[2011/05/30 21:38:04 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Trusteer
[2012/06/24 21:56:15 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Ulead Systems
[2009/09/05 13:13:34 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\UltimateBet
[2009/08/02 11:03:02 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\WinBatch
[2011/07/05 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Trusteer
[2011/07/05 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Trusteer
[2011/07/05 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\Mcx1-AUGUST-PC\AppData\Roaming\Trusteer
[2012/09/10 17:30:42 | 000,032,568 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP
FC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
File not found
O4 - HKU\S-1-5-21-577059922-3361006745-2873073242-1000..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\S-1-5-21-577059922-3361006745-2873073242-1000..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {16F67783-7E72-4C39-99C4-4780A8335484} http://www.syncmyride.com/Own/Modules/UpdateCenter/applets/sync.cab (SyncXfer Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FB0FBA6-6420-43BE-950B-BE7DDB297058}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B763E676-6106-4F58-A81A-91ACBB15E641}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{129fd678-c68f-11df-8c9a-001e33d2730f}\Shell - "" = AutoRun
O33 - MountPoints2\{129fd678-c68f-11df-8c9a-001e33d2730f}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
O33 - MountPoints2\{a525ac73-6dae-11e1-a5e3-001e33d2730f}\Shell - "" = AutoRun
O33 - MountPoints2\{a525ac73-6dae-11e1-a5e3-001e33d2730f}\Shell\AutoRun\command - "" = E:\MotoCastSetup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/11 22:32:36 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\August\Desktop\OTL.exe
[2012/09/11 19:10:50 | 000,000,000 | ---D | C] -- C:\$RECYCLE(29).BIN
[2012/09/11 18:37:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/10 22:08:11 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\August\Desktop\aswMBR.exe
[2012/09/10 22:00:14 | 000,000,000 | ---D | C] -- C:\Users\August\Desktop\RK_Quarantine
[2012/09/08 23:00:38 | 000,000,000 | ---D | C] -- C:\Users\August\Desktop\Exploit Removal
[2012/09/08 22:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/08 22:23:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/08 21:51:04 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\August\Desktop\tdsskiller.exe
[2012/09/08 04:02:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/08/30 20:03:05 | 000,000,000 | ---D | C] -- C:\Users\August\AppData\Local\MetaGeek,_LLC
[17 C:\Users\August\Desktop\*.tmp files -> C:\Users\August\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/11 22:38:01 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-577059922-3361006745-2873073242-1000UA.job
[2012/09/11 22:32:39 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\August\Desktop\OTL.exe
[2012/09/11 22:25:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/11 22:20:01 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/11 21:25:36 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/11 21:23:15 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/11 21:23:15 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/11 21:22:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/11 21:22:51 | 4156,542,976 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/10 22:08:40 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\August\Desktop\aswMBR.exe
[2012/09/10 21:59:25 | 001,378,816 | ---- | M] () -- C:\Users\August\Desktop\RogueKiller.exe
[2012/09/10 21:53:23 | 002,193,184 | ---- | M] () -- C:\Users\August\Desktop\tdsskiller.zip
[2012/09/10 19:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-577059922-3361006745-2873073242-1000Core.job
[2012/09/10 17:53:47 | 000,302,592 | ---- | M] () -- C:\Users\August\Desktop\lhx0fu5j.exe
[2012/09/10 17:39:42 | 000,703,516 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/10 17:39:42 | 000,604,752 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/10 17:39:42 | 000,104,420 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/10 17:30:23 | 000,000,919 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/10 17:24:57 | 000,000,732 | ---- | M] () -- C:\Users\August\AppData\Local\d3d9caps64.dat
[2012/09/08 22:01:41 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\August\Desktop\tdsskiller.exe
[2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/03 01:40:09 | 000,002,088 | ---- | M] () -- C:\Users\August\Desktop\Google Chrome.lnk
[2012/09/03 01:40:09 | 000,002,050 | ---- | M] () -- C:\Users\August\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/15 03:29:38 | 000,359,712 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/15 03:05:36 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[17 C:\Users\August\Desktop\*.tmp files -> C:\Users\August\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/10 21:59:24 | 001,378,816 | ---- | C] () -- C:\Users\August\Desktop\RogueKiller.exe
[2012/09/10 21:53:19 | 002,193,184 | ---- | C] () -- C:\Users\August\Desktop\tdsskiller.zip
[2012/09/10 17:53:44 | 000,302,592 | ---- | C] () -- C:\Users\August\Desktop\lhx0fu5j.exe
[2012/09/10 17:26:29 | 4156,542,976 | -HS- | C] () -- C:\hiberfil.sys
[2012/09/10 17:24:57 | 000,000,732 | ---- | C] () -- C:\Users\August\AppData\Local\d3d9caps64.dat
[2012/09/08 22:23:11 | 000,000,919 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/15 03:05:36 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2012/01/18 01:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012/01/18 01:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012/01/18 01:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010/11/29 16:38:41 | 000,233,472 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2010/08/23 19:11:59 | 000,000,680 | ---- | C] () -- C:\Users\August\AppData\Local\d3d9caps.dat
[2010/07/28 20:11:49 | 008,892,928 | ---- | C] () -- C:\ProgramData\atscie.msi
[2010/04/03 15:25:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/08/02 11:05:31 | 000,021,504 | ---- | C] () -- C:\Users\August\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ==========
[2009/12/21 21:06:44 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Absolute Poker
[2010/04/20 20:55:49 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\acccore
[2009/08/15 12:53:32 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\GARMIN
[2009/10/10 17:02:16 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\iGrafx
[2012/05/08 22:16:07 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Leadertech
[2010/04/09 18:32:46 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\MAGIX
[2012/06/23 11:57:10 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Motorola
[2012/06/23 11:45:32 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Motorola Mobility
[2011/12/15 20:03:13 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\toshiba
[2011/05/30 21:38:04 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Trusteer
[2012/06/24 21:56:15 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\Ulead Systems
[2009/09/05 13:13:34 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\UltimateBet
[2009/08/02 11:03:02 | 000,000,000 | ---D | M] -- C:\Users\August\AppData\Roaming\WinBatch
[2011/07/05 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Trusteer
[2011/07/05 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Trusteer
[2011/07/05 10:11:02 | 000,000,000 | ---D | M] -- C:\Users\Mcx1-AUGUST-PC\AppData\Roaming\Trusteer
[2012/09/10 17:30:42 | 000,032,568 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >