SledgeProne
Posts: 91 +0
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-12-2012
Ran by SYSTEM at 05-12-2012 18:01:47
Running from G:\
Microsoft Windows XP (X86) OS Language: English(US)
The current controlset is ControlSet002
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1468296 2009-06-01] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-11-10] (Adobe Systems Incorporated)
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [1313640 1999-12-31] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1387288 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2011-11-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto [3225144 2012-06-09] (SoftPerfect Research)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKU\Administrator\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] "C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe" [x]
HKU\Master Blaster\...\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKU\Master Blaster\...\Run: [Akamai NetSession Interface] "C:\Documents and Settings\Master Blaster\Local Settings\Application Data\Akamai\netsession_win.exe" [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKU\Master Blaster\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation)
HKU\Master Blaster\...\Winlogon: [Shell] explorer.exe,C:\Documents and Settings\Master Blaster\Application Data\skype.dat [87911 2010-12-09] ()
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [X]
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X]
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
==================== Services (Whitelisted) ===================
2 ASTSRV; C:\WINDOWS\system32\ASTSRV.EXE [57344 2008-05-19] (Nalpeiron Ltd.)
2 Eventlog; C:\Windows\System32\services.exe [110592 2009-02-06] (Microsoft Corporation)
2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-29] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-29] (Malwarebytes Corporation)
3 TuneUp.Defrag; C:\Windows\System32\TuneUpDefragService.exe [361288 2011-03-23] (TuneUp Software)
2 TuneUp.ProgramStatisticsSvc; C:\Windows\System32\TUProgSt.exe [604488 2011-03-23] (TuneUp Software)
2 Akamai; c:\program files\common files\akamai/netsession_win_ce5ba24.dll [x]
2 ANC; C:\Windows\System32\k750mdm.dll [x]
4 arrayssl_vpn_service3,0,1,9; [x]
2 ashampoodefragservice; C:\Windows\System32\veteboot.dll [x]
4 AsusACPI; [x]
2 atinevxx; C:\Windows\System32\quickhealfirewall.dll [x]
4 atkdisplf; [x]
4 awhost32; [x]
2 bc_pat_f; C:\Windows\System32\MaVctrl.dll [x]
2 ccproxy; C:\Windows\System32\keymaestro.dll [x]
4 CTDevice_Srv; [x]
2 ctdvda2k; C:\Windows\System32\se58nd5.dll [x]
2 ctxcpubal; C:\Windows\System32\cpuidlep.dll [x]
4 F700iat; [x]
2 G400DH; C:\Windows\System32\AMDPCI.dll [x]
2 GMSIPCI; C:\Windows\System32\sysplant.dll [x]
2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll [x]
2 hpqwmiex; C:\Windows\System32\dlbt_device.dll [x]
4 imountsrv; [x]
2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
2 k750mgmt; C:\Windows\System32\tsircsrv.dll [x]
2 ltmodem5; C:\Windows\System32\g400.dll [x]
2 lvpopflt; C:\Windows\System32\bglivesvc.dll [x]
2 lxcf_device; C:\Windows\System32\nmindexingservice.dll [x]
4 mqdmbus; [x]
2 MSMQ; C:\Windows\System32\ovmsmaccessmanager.dll [x]
2 ofcpfwsvc; C:\Windows\System32\FiltUSBEMPIA.dll [x]
2 ovt519; C:\Windows\System32\SSFS0BB9.dll [x]
2 pav_security; C:\Windows\System32\kpf4.dll [x]
2 pdlnatdl; C:\Windows\System32\pdlndsdl.dll [x]
2 protectionservice; C:\Windows\System32\SenFiltService.dll [x]
2 PSSdk21; C:\Windows\System32\cbidf.dll [x]
2 rismxdp; C:\Windows\System32\CiscoVpnInstallService.dll [x]
3 rpcapd; "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini" [x]
2 s116obex; C:\Windows\System32\transactional.dll [x]
2 StkASSrv; C:\Windows\System32\hdaudbus.dll [x]
2 TIEHDUSB; C:\Windows\System32\cyberpowerups.dll [x]
2 tng-dtmg; C:\Windows\System32\issm.dll [x]
2 tng-dts; C:\Windows\System32\EMCFILT.dll [x]
2 UPATC; C:\Windows\System32\lanmanworkstation.dll [x]
2 vet-filt; C:\Windows\System32\dlcf_device.dll [x]
2 vstor2-ws60; C:\Windows\System32\vaiomediaplatform-mobile-gateway.dll [x]
2 wwsecsvc; C:\Windows\System32\slabser.dll [x]
==================== Drivers (Whitelisted) ====================
3 APLMp50; C:\Windows\System32\Drivers\APLMp50.sys [28224 2006-11-29] (Printing Communications Assoc., Inc. (PCAUSA))
3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [7493120 2011-11-09] (ATI Technologies Inc.)
3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdXP3.sys [101392 2011-03-30] (Advanced Micro Devices)
0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [26248 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
3 EuDisk; C:\Windows\System32\DRIVERS\EuDisk.sys [122504 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
3 EUDSKACS; \??\C:\WINDOWS\system32\drivers\eudskacs.sys [14216 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
0 EUFS; C:\Windows\System32\drivers\eufs.sys [20616 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
2 LBeepKE; C:\Windows\System32\Drivers\LBeepKE.sys [12184 2011-09-02] (Logitech, Inc.)
3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.Sys [42648 2011-09-02] (Logitech, Inc.)
3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.Sys [12184 2011-09-02] (Logitech, Inc.)
3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [39192 2011-09-02] (Logitech, Inc.)
3 MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [22856 2012-09-29] (Malwarebytes Corporation)
1 networx; C:\Windows\System32\drivers\networx.sys [51640 2011-04-15] (NetFilterSDK.com)
2 npf; C:\Windows\System32\drivers\npf.sys [50704 2009-10-20] (CACE Technologies, Inc.)
3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-11-11] (Microsoft Corporation)
3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [54784 2008-08-01] (NVIDIA Corporation)
3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2008-08-01] (NVIDIA Corporation)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12872 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67656 2010-05-10] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 STHDA; C:\Windows\System32\drivers\sthda.sys [1651204 1999-12-31] (IDT, Inc.)
4 ubsvve; C:\Windows\System32\drivers\tnloa.sys [54016 2010-09-15] ()
3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
4 Abiosdsk; [x]
4 abp480n5; [x]
4 adpu160m; [x]
4 Aha154x; [x]
4 aic78u2; [x]
4 aic78xx; [x]
4 AliIde; [x]
4 amsint; [x]
4 asc; [x]
4 asc3350p; [x]
4 asc3550; [x]
4 Atdisk; [x]
3 catchme; \??\C:\DOCUME~1\MASTER~1\LOCALS~1\Temp\catchme.sys [x]
4 cd20xrnt; [x]
1 Changer; [x]
4 CmdIde; [x]
4 Cpqarray; [x]
4 dac2w2k; [x]
4 dac960nt; [x]
4 dpti2o; [x]
3 ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [x]
4 hpn; [x]
4 hpt3xx; [x]
1 i2omgmt; [x]
4 i2omp; [x]
4 ini910u; [x]
4 IntelIde; [x]
1 lbrtfdc; [x]
4 mraid35x; [x]
1 PCIDump; [x]
3 PDCOMP; [x]
3 PDFRAME; [x]
3 PDRELI; [x]
3 PDRFRAME; [x]
4 perc2; [x]
4 perc2hib; [x]
4 ql1080; [x]
4 Ql10wnt; [x]
4 ql12160; [x]
4 ql1240; [x]
4 ql1280; [x]
4 Simbad; [x]
4 Sparrow; [x]
4 symc810; [x]
4 symc8xx; [x]
4 sym_hi; [x]
4 sym_u3; [x]
4 TosIde; [x]
4 ultra; [x]
4 ViaIde; [x]
3 WDICA; [x]
2 zumbus; C:\Windows\System32\DRIVERS\zumbus.sys [x]
==================== NetSvcs (Whitelisted) ===================
NETSVC: vet-filt -> C:\Windows\system32\dlcf_device.dll ==> No File.
NETSVC: lvpopflt -> C:\Windows\system32\bglivesvc.dll ==> No File.
NETSVC: mcredirector -> No Registry Path.
NETSVC: bc_pat_f -> C:\Windows\system32\MaVctrl.dll ==> No File.
NETSVC: rismxdp -> C:\Windows\system32\CiscoVpnInstallService.dll ==> No File.
NETSVC: UPATC -> C:\Windows\system32\lanmanworkstation.dll ==> No File.
NETSVC: CTDevice_Srv -> ==> No File.
NETSVC: imountsrv -> ==> No File.
NETSVC: vstor2-ws60 -> C:\Windows\system32\vaiomediaplatform-mobile-gateway.dll ==> No File.
NETSVC: awhost32 -> ==> No File.
NETSVC: protectionservice -> C:\Windows\system32\SenFiltService.dll ==> No File.
NETSVC: ovt519 -> C:\Windows\system32\SSFS0BB9.dll ==> No File.
NETSVC: lxcf_device -> C:\Windows\system32\nmindexingservice.dll ==> No File.
NETSVC: CBN -> No Registry Path.
NETSVC: Bcim -> No Registry Path.
NETSVC: fsaa -> No Registry Path.
NETSVC: fasttrackinstallerservice -> No Registry Path.
NETSVC: comhost -> No Registry Path.
NETSVC: DVDRC -> No Registry Path.
NETSVC: StkASSrv -> C:\Windows\system32\hdaudbus.dll ==> No File.
NETSVC: s116obex -> C:\Windows\system32\transactional.dll ==> No File.
NETSVC: ltmodem5 -> C:\Windows\system32\g400.dll ==> No File.
NETSVC: PSSdk21 -> C:\Windows\system32\cbidf.dll ==> No File.
NETSVC: hpqwmiex -> C:\Windows\system32\dlbt_device.dll ==> No File.
NETSVC: k750mgmt -> C:\Windows\system32\tsircsrv.dll ==> No File.
NETSVC: pav_security -> C:\Windows\system32\kpf4.dll ==> No File.
NETSVC: TIEHDUSB -> C:\Windows\system32\cyberpowerups.dll ==> No File.
NETSVC: ctdvda2k -> C:\Windows\system32\se58nd5.dll ==> No File.
NETSVC: ctxcpubal -> C:\Windows\system32\cpuidlep.dll ==> No File.
NETSVC: ofcpfwsvc -> C:\Windows\system32\FiltUSBEMPIA.dll ==> No File.
NETSVC: ccproxy -> C:\Windows\system32\keymaestro.dll ==> No File.
NETSVC: G400DH -> C:\Windows\system32\AMDPCI.dll ==> No File.
NETSVC: atinevxx -> C:\Windows\system32\quickhealfirewall.dll ==> No File.
NETSVC: ashampoodefragservice -> C:\Windows\system32\veteboot.dll ==> No File.
NETSVC: agnwifi -> No Registry Path.
NETSVC: SRTSPL -> No Registry Path.
NETSVC: keriomailserver -> No Registry Path.
NETSVC: wmccdsls -> No Registry Path.
NETSVC: aolavupd -> No Registry Path.
NETSVC: hsxhwazl -> No Registry Path.
NETSVC: MSMQ -> C:\Windows\system32\ovmsmaccessmanager.dll ==> No File.
NETSVC: tng-dts -> C:\Windows\system32\EMCFILT.dll ==> No File.
NETSVC: tng-dtmg -> C:\Windows\system32\issm.dll ==> No File.
NETSVC: F700iat -> ==> No File.
NETSVC: arrayssl_vpn_service3,0,1,9 -> ==> No File.
NETSVC: pdlnatdl -> C:\Windows\system32\pdlndsdl.dll ==> No File.
NETSVC: atkdisplf -> ==> No File.
NETSVC: tga -> No Registry Path.
NETSVC: AsusACPI -> ==> No File.
NETSVC: mqdmbus -> ==> No File.
NETSVC: GMSIPCI -> C:\Windows\system32\sysplant.dll ==> No File.
NETSVC: ANC -> C:\Windows\system32\k750mdm.dll ==> No File.
NETSVC: wwsecsvc -> C:\Windows\system32\slabser.dll ==> No File.
NETSVC: ip6fwhlp -> No Registry Path.
NETSVC: mhn -> No Registry Path.
NETSVC: sacsvr -> No Registry Path.
NETSVC: trksvr -> No Registry Path.
==================== One Month Created Files and Folders ========
2012-12-03 02:55 - 2012-12-03 02:55 - 00000000 ____D C:\FRST
2012-11-30 09:19 - 2012-12-05 14:28 - 00000004 ____A C:\Documents and Settings\Master Blaster\Application Data\skype.ini
2012-11-30 02:02 - 2012-11-30 02:02 - 00000353 ____A C:\Documents and Settings\Master Blaster\Desktop\Sissel - O Mio Babbino Caro - YouTube.url
2012-11-29 23:47 - 2012-11-29 23:47 - 00097778 ____A C:\Documents and Settings\Master Blaster\Desktop\OTL.Txt
2012-11-29 23:47 - 2012-11-29 23:47 - 00048308 ____A C:\Documents and Settings\Master Blaster\Desktop\Extras.Txt
2012-11-29 23:39 - 2012-11-29 23:39 - 00602112 ____A (OldTimer Tools) C:\Documents and Settings\Master Blaster\Desktop\OTL.exe
2012-11-29 05:01 - 2012-11-29 05:01 - 00001161 ____A C:\Documents and Settings\Master Blaster\Desktop\What you'll need....url
2012-11-29 04:40 - 2012-11-29 04:40 - 00001631 ____A C:\Documents and Settings\Master Blaster\Desktop\Delta 36-T30 30 T2 Fence System (2).url
2012-11-29 03:24 - 2012-11-29 03:24 - 00019124 ____A C:\ComboFix.txt
2012-11-29 03:05 - 2012-11-29 03:05 - 00000000 ____D C:\Program Files\GPLGS
2012-11-29 03:04 - 2012-09-12 18:32 - 00088688 ____A C:\Windows\System32\cpwmon2k.dll
2012-11-29 02:37 - 2012-11-29 02:37 - 00036363 ____A C:\Windows\CSTBox.INI
2012-11-29 02:28 - 2012-11-29 02:32 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\scans
2012-11-27 01:27 - 2012-11-27 01:27 - 00019195 ____A C:\Documents and Settings\Master Blaster\Desktop\comboscan.txt
2012-11-25 15:07 - 2012-11-25 15:07 - 05006177 ____R (Swearware) C:\Documents and Settings\Master Blaster\Desktop\ComboFix.exe
2012-11-25 13:07 - 2012-11-25 13:07 - 04742932 ____A C:\Documents and Settings\Master Blaster\Desktop\life_of_pi.psd
2012-11-25 03:11 - 2012-11-25 03:11 - 00442200 ____A (Kaspersky Lab ZAO) C:\Documents and Settings\Master Blaster\Desktop\capperkiller.exe
2012-11-24 17:18 - 2012-11-24 17:18 - 00000453 ____A C:\Documents and Settings\Master Blaster\Desktop\One Large Rat Trap Please - TechSpot Forums.url
2012-11-24 17:16 - 2012-11-24 17:16 - 04732416 ____A (AVAST Software) C:\Documents and Settings\Master Blaster\Desktop\aswMBR.exe
2012-11-24 09:21 - 2012-11-24 09:25 - 152292227 ____A C:\bd2b713aac780837a22001e9327c0e83[1]-2012-11-24.flv
2012-11-24 06:36 - 2012-11-24 06:36 - 00025585 ____A C:\Documents and Settings\Master Blaster\Desktop\attach.txt
2012-11-24 06:36 - 2012-11-24 06:36 - 00015803 ____A C:\Documents and Settings\Master Blaster\Desktop\dds.txt
2012-11-24 06:30 - 2012-11-24 06:33 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\storage nov12
2012-11-23 08:12 - 2012-11-23 08:12 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\New Folder
2012-11-23 07:19 - 2012-11-23 07:19 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-22 11:55 - 2012-11-22 11:55 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\song_data
2012-11-22 07:35 - 2012-11-22 07:41 - 79108767 ____A C:\Documents and Settings\Master Blaster\Desktop\012-11-22.flv
2012-11-22 03:52 - 2012-11-22 03:52 - 00110592 ____A C:\Windows\Minidump\Mini112212-01.dmp
2012-11-22 02:44 - 2012-11-22 03:09 - 00000000 ____D C:\Documents and Settings\Master Blaster\.frostwire5
2012-11-22 02:44 - 2012-11-22 02:45 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\FrostWire
2012-11-22 02:41 - 2012-11-22 03:31 - 00000000 ____D C:\Program Files\Real
2012-11-22 02:41 - 2012-11-22 03:31 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\Real
2012-11-22 02:40 - 2012-11-22 03:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Real
2012-11-22 02:40 - 2012-11-22 02:40 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\OpenCandy
2012-11-19 15:23 - 2012-11-25 15:14 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ProtectedData
2012-11-19 14:00 - 2012-11-19 14:00 - 15401600 ____A C:\240P_400K_6203321[3].mp4
2012-11-19 13:56 - 2012-11-19 13:56 - 06350273 ____A C:\general01_H_6493301_01-2012-11-19.mp4
2012-11-19 13:55 - 2012-11-19 13:57 - 43588603 ____A C:\240P_352K_5225320-2012-11-19.mp4
2012-11-19 13:53 - 2012-11-19 13:53 - 11501318 ____A C:\1396_2000-2012-11-19.mp4
2012-11-19 12:17 - 2012-11-19 12:16 - 00110592 ____A C:\Windows\Minidump\Mini111912-01.dmp
2012-11-15 06:07 - 2012-11-15 06:07 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2012-11-15 06:06 - 2012-11-22 08:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
2012-11-15 03:01 - 2012-11-15 06:07 - 00011727 ____A C:\Windows\KB2727528.log
2012-11-15 03:01 - 2012-11-15 06:06 - 00013180 ____A C:\Windows\KB2761226.log
2012-11-14 04:20 - 2012-11-14 04:20 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\DWP
2012-11-08 05:19 - 2012-11-08 05:19 - 00000000 ____D C:\Program Files\WS_FTP
==================== One Month Modified Files and Folders ========
2012-12-05 14:28 - 2012-11-30 09:19 - 00000004 ____A C:\Documents and Settings\Master Blaster\Application Data\skype.ini
2012-12-05 14:28 - 2012-01-18 04:51 - 00524288 ____A C:\Windows\System32\config\ACEEvent.evt
2012-12-05 14:28 - 2009-12-22 02:35 - 00524288 ____A C:\Windows\System32\config\TuneUp.evt
2012-12-05 14:28 - 2009-12-11 08:00 - 01207744 ____A C:\Windows\WindowsUpdate.log
2012-12-05 14:28 - 2009-12-10 23:49 - 00000178 __ASH C:\Documents and Settings\Master Blaster\ntuser.ini
2012-12-05 14:28 - 2009-12-10 23:42 - 00032362 ____A C:\Windows\SchedLgU.Txt
2012-12-05 14:28 - 2009-12-10 23:40 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-05 14:28 - 2009-12-10 14:38 - 00000216 ____A C:\Windows\wiadebug.log
2012-12-05 14:26 - 2010-08-12 06:17 - 00000504 ____A C:\Windows\Tasks\1-Click Maintenance.job
2012-12-05 14:25 - 2012-06-27 02:49 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-12-05 14:25 - 2010-05-07 02:43 - 00000000 ____D C:\Program Files\Common Files\Akamai
2012-12-05 14:25 - 2009-12-10 23:49 - 00000062 __ASH C:\Documents and Settings\Master Blaster\Local Settings\desktop.ini
2012-12-05 14:25 - 2009-12-10 23:42 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2012-12-05 14:25 - 2009-12-10 23:42 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2012-12-05 14:25 - 2009-12-10 14:38 - 00000049 ____A C:\Windows\wiaservc.log
2012-12-05 14:25 - 2001-08-23 07:00 - 00002206 ____A C:\Windows\System32\wpa.dbl
2012-12-04 22:04 - 2012-06-27 02:49 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-12-04 22:03 - 2009-12-12 03:07 - 00000000 __SHD C:\Windows\CSC
2012-12-04 21:59 - 2012-06-09 07:57 - 00047606 ____A C:\Windows\setupapi.log
2012-12-04 21:59 - 2012-05-09 04:16 - 00003218 ____A C:\Windows\setupact.log
2012-12-03 02:55 - 2012-12-03 02:55 - 00000000 ____D C:\FRST
2012-11-30 09:18 - 2012-04-29 04:23 - 00000000 ____D C:\hidownload
2012-11-30 09:17 - 2009-12-13 01:17 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\IDM
2012-11-30 08:59 - 2012-03-17 08:45 - 00000000 ____D C:\IDM
2012-11-30 08:33 - 2012-04-02 04:05 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-11-30 02:02 - 2012-11-30 02:02 - 00000353 ____A C:\Documents and Settings\Master Blaster\Desktop\Sissel - O Mio Babbino Caro - YouTube.url
2012-11-30 01:36 - 2009-12-13 01:17 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\DMCache
2012-11-30 00:26 - 2011-02-21 05:54 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\vlc
2012-11-29 23:47 - 2012-11-29 23:47 - 00097778 ____A C:\Documents and Settings\Master Blaster\Desktop\OTL.Txt
2012-11-29 23:47 - 2012-11-29 23:47 - 00048308 ____A C:\Documents and Settings\Master Blaster\Desktop\Extras.Txt
2012-11-29 23:39 - 2012-11-29 23:39 - 00602112 ____A (OldTimer Tools) C:\Documents and Settings\Master Blaster\Desktop\OTL.exe
2012-11-29 23:30 - 2012-01-12 08:29 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\New Folder
2012-11-29 05:01 - 2012-11-29 05:01 - 00001161 ____A C:\Documents and Settings\Master Blaster\Desktop\What you'll need....url
2012-11-29 04:40 - 2012-11-29 04:40 - 00001631 ____A C:\Documents and Settings\Master Blaster\Desktop\Delta 36-T30 30 T2 Fence System (2).url
2012-11-29 04:03 - 2012-08-07 06:46 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\send
2012-11-29 03:34 - 2009-12-10 14:37 - 00559994 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-29 03:24 - 2012-11-29 03:24 - 00019124 ____A C:\ComboFix.txt
2012-11-29 03:24 - 2012-06-03 23:58 - 00000000 ___AD C:\Qoobox
2012-11-29 03:22 - 2001-08-23 07:00 - 00000227 ____A C:\Windows\system.ini
2012-11-29 03:07 - 2010-02-02 04:10 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\CutePDF Writer
2012-11-29 03:05 - 2012-11-29 03:05 - 00000000 ____D C:\Program Files\GPLGS
2012-11-29 03:04 - 2010-02-02 04:08 - 00000000 ____D C:\Program Files\Acro Software
2012-11-29 03:01 - 2009-12-10 14:29 - 00000000 ____D C:\Windows\Resources
2012-11-29 02:37 - 2012-11-29 02:37 - 00036363 ____A C:\Windows\CSTBox.INI
2012-11-29 02:32 - 2012-11-29 02:28 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\scans
2012-11-28 12:56 - 2012-06-14 05:47 - 00017857 ____A C:\Windows\wmsetup.log
2012-11-28 07:49 - 2011-12-05 13:50 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\shortcuts2
2012-11-27 04:33 - 2009-12-12 22:30 - 00000000 ____D C:\Earth
2012-11-27 01:28 - 2012-04-28 03:31 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\uTorrent
2012-11-27 01:27 - 2012-11-27 01:27 - 00019195 ____A C:\Documents and Settings\Master Blaster\Desktop\comboscan.txt
2012-11-26 16:44 - 2009-12-12 02:14 - 00176128 ____A C:\Documents and Settings\Master Blaster\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-26 07:34 - 2010-04-08 01:09 - 00000116 ____A C:\Windows\NeroDigital.ini
2012-11-25 17:55 - 2012-11-02 04:40 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\Audacity
2012-11-25 15:14 - 2012-11-19 15:23 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ProtectedData
2012-11-25 15:07 - 2012-11-25 15:07 - 05006177 ____R (Swearware) C:\Documents and Settings\Master Blaster\Desktop\ComboFix.exe
2012-11-25 13:07 - 2012-11-25 13:07 - 04742932 ____A C:\Documents and Settings\Master Blaster\Desktop\life_of_pi.psd
2012-11-25 05:52 - 2011-09-05 19:07 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\suki
2012-11-25 03:11 - 2012-11-25 03:11 - 00442200 ____A (Kaspersky Lab ZAO) C:\Documents and Settings\Master Blaster\Desktop\capperkiller.exe
2012-11-24 17:18 - 2012-11-24 17:18 - 00000453 ____A C:\Documents and Settings\Master Blaster\Desktop\One Large Rat Trap Please - TechSpot Forums.url
2012-11-24 17:16 - 2012-11-24 17:16 - 04732416 ____A (AVAST Software) C:\Documents and Settings\Master Blaster\Desktop\aswMBR.exe
2012-11-24 09:25 - 2012-11-24 09:21 - 152292227 ____A C:\bd2b713aac780837a22001e9327c0e83[1]-2012-11-24.flv
2012-11-24 06:36 - 2012-11-24 06:36 - 00025585 ____A C:\Documents and Settings\Master Blaster\Desktop\attach.txt
2012-11-24 06:36 - 2012-11-24 06:36 - 00015803 ____A C:\Documents and Settings\Master Blaster\Desktop\dds.txt
2012-11-24 06:34 - 2011-12-05 13:48 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\all superb
2012-11-24 06:33 - 2012-11-24 06:30 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\storage nov12
2012-11-23 08:17 - 2012-10-09 05:05 - 00000000 ____D C:\Collection
2012-11-23 08:12 - 2012-11-23 08:12 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\New Folder
2012-11-23 07:19 - 2012-11-23 07:19 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-23 03:07 - 2012-04-10 21:47 - 00268808 ____A C:\Documents and Settings\Master Blaster\Local Settings\Application Data\census.cache
2012-11-23 03:06 - 2012-04-10 21:47 - 00209719 ____A C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ars.cache
2012-11-22 11:55 - 2012-11-22 11:55 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\song_data
2012-11-22 10:05 - 2011-11-03 19:41 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\Akamai
2012-11-22 09:19 - 2010-02-21 06:45 - 00000000 ____D C:\Windows\Microsoft.NET
2012-11-22 08:40 - 2010-04-15 05:02 - 00000000 __HDC C:\Windows\$NtUninstallKB980232$
2012-11-22 08:23 - 2009-12-12 22:32 - 00000000 ____D C:\Program Files\Google
2012-11-22 08:22 - 2012-11-15 06:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
2012-11-22 07:51 - 2011-07-18 00:51 - 00000000 ____D C:\Program Files\Zune
2012-11-22 07:46 - 2009-12-12 22:32 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\Google
2012-11-22 07:41 - 2012-11-22 07:35 - 79108767 ____A C:\Documents and Settings\Master Blaster\Desktop\012-11-22.flv
2012-11-22 03:52 - 2012-11-22 03:52 - 00110592 ____A C:\Windows\Minidump\Mini112212-01.dmp
2012-11-22 03:52 - 2009-12-13 07:25 - 00000000 ____D C:\Windows\Minidump
2012-11-22 03:31 - 2012-11-22 02:41 - 00000000 ____D C:\Program Files\Real
2012-11-22 03:31 - 2012-11-22 02:41 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\Real
2012-11-22 03:31 - 2012-11-22 02:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Real
2012-11-22 03:22 - 2012-10-30 05:35 - 00000000 ____D C:\Program Files\Mozilla Firefox
2012-11-22 03:13 - 2010-09-29 00:19 - 00001984 ____A C:\Windows\System32\d3d9caps.dat
2012-11-22 03:09 - 2012-11-22 02:44 - 00000000 ____D C:\Documents and Settings\Master Blaster\.frostwire5
2012-11-22 02:45 - 2012-11-22 02:44 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\FrostWire
2012-11-22 02:41 - 2003-03-19 01:14 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\msvcp71.dll
2012-11-22 02:41 - 2003-02-21 07:42 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\msvcr71.dll
2012-11-22 02:40 - 2012-11-22 02:40 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\OpenCandy
2012-11-22 02:15 - 2010-03-10 04:09 - 00000000 ____D C:\Program Files\PeerBlock
2012-11-22 00:37 - 2012-10-27 23:52 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\volcano
2012-11-19 14:00 - 2012-11-19 14:00 - 15401600 ____A C:\240P_400K_6203321[3].mp4
2012-11-19 13:57 - 2012-11-19 13:55 - 43588603 ____A C:\240P_352K_5225320-2012-11-19.mp4
2012-11-19 13:56 - 2012-11-19 13:56 - 06350273 ____A C:\general01_H_6493301_01-2012-11-19.mp4
2012-11-19 13:53 - 2012-11-19 13:53 - 11501318 ____A C:\1396_2000-2012-11-19.mp4
2012-11-19 12:16 - 2012-11-19 12:17 - 00110592 ____A C:\Windows\Minidump\Mini111912-01.dmp
2012-11-15 06:51 - 2009-12-10 14:36 - 03449912 ____A C:\Windows\System32\FNTCACHE.DAT
2012-11-15 06:08 - 2009-12-11 14:24 - 64010424 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-11-15 06:07 - 2012-11-15 06:07 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2012-11-15 06:07 - 2012-11-15 03:01 - 00011727 ____A C:\Windows\KB2727528.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00177212 ____A C:\Windows\iis6.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00166931 ____A C:\Windows\FaxSetup.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00079812 ____A C:\Windows\ocgen.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00076167 ____A C:\Windows\tsoc.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00054570 ____A C:\Windows\comsetup.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00050000 ____A C:\Windows\msmqinst.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00033166 ____A C:\Windows\ntdtcsetup.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00029241 ____A C:\Windows\netfxocm.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00011475 ____A C:\Windows\MedCtrOC.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00009234 ____A C:\Windows\ocmsn.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00008397 ____A C:\Windows\tabletoc.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00008181 ____A C:\Windows\msgsocm.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00001393 ____A C:\Windows\imsins.log
2012-11-15 06:06 - 2012-11-15 03:01 - 00013180 ____A C:\Windows\KB2761226.log
2012-11-15 06:06 - 2009-12-10 14:37 - 00001393 ____A C:\Windows\imsins.BAK
2012-11-15 03:01 - 2009-12-11 08:23 - 00000000 ___HD C:\Windows\$hf_mig$
2012-11-14 04:20 - 2012-11-14 04:20 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\DWP
2012-11-14 04:02 - 2009-12-12 16:51 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2012-11-13 21:23 - 2012-04-02 04:05 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-11-13 21:23 - 2011-05-17 05:58 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-11-09 20:15 - 2012-09-02 19:17 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\select
2012-11-08 05:43 - 2011-06-24 03:09 - 00000000 ____D C:\mafa
2012-11-08 05:19 - 2012-11-08 05:19 - 00000000 ____D C:\Program Files\WS_FTP
2012-11-08 05:19 - 2009-12-10 23:56 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2012-11-08 05:19 - 2001-08-23 07:00 - 00000656 ____A C:\Windows\win.ini
2012-11-07 22:12 - 2012-07-24 08:55 - 00000784 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-07 22:12 - 2012-04-10 19:17 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-11-06 19:49 - 2012-06-30 00:33 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points (XP) =====================
RP: -> 2012-11-30 03:45 - 024576 _restore{2205B7A6-1EB9-495A-B8BD-4B1F24159255}\RP219
RP: -> 2012-11-29 03:04 - 024576 _restore{2205B7A6-1EB9-495A-B8BD-4B1F24159255}\RP218
RP: -> 2012-11-29 01:07 - 024576 _restore{2205B7A6-1EB9-495A-B8BD-4B1F24159255}\RP217
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 2047.17 MB
Available physical RAM: 1790.75 MB
Total Pagefile: 1877.82 MB
Available Pagefile: 1817.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 2003.18 MB
==================== Partitions =============================
2 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
3 Drive c: () (Fixed) (Total:127.99 GB) (Free:1.24 GB) NTFS ==>[Drive with boot components (Windows XP)]
4 Drive d: (SATA) (Fixed) (Total:149.04 GB) (Free:0.88 GB) NTFS
5 Drive e: (New Volume) (Fixed) (Total:570.65 GB) (Free:0.18 GB) NTFS
6 Drive f: (SATA) (Fixed) (Total:149.05 GB) (Free:0.23 GB) NTFS
7 Drive g: () (Removable) (Total:7.45 GB) (Free:7.45 GB) FAT32
8 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 699 GB 0 B
Disk 1 Online 298 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 128 GB 32 KB
Partition 2 Primary 571 GB 128 GB
=========================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 128 GB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E New Volume NTFS Partition 571 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 149 GB 32 KB
Partition 2 Primary 149 GB 149 GB
=========================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D SATA NTFS Partition 149 GB Healthy
=========================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F SATA NTFS Partition 149 GB Healthy
=========================================================
==================== End Of Log ============================
Ran by SYSTEM at 05-12-2012 18:01:47
Running from G:\
Microsoft Windows XP (X86) OS Language: English(US)
The current controlset is ControlSet002
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1468296 2009-06-01] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-11-10] (Adobe Systems Incorporated)
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [1313640 1999-12-31] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1387288 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2011-11-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto [3225144 2012-06-09] (SoftPerfect Research)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKU\Administrator\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] "C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe" [x]
HKU\Master Blaster\...\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKU\Master Blaster\...\Run: [Akamai NetSession Interface] "C:\Documents and Settings\Master Blaster\Local Settings\Application Data\Akamai\netsession_win.exe" [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKU\Master Blaster\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation)
HKU\Master Blaster\...\Winlogon: [Shell] explorer.exe,C:\Documents and Settings\Master Blaster\Application Data\skype.dat [87911 2010-12-09] ()
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [X]
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X]
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
==================== Services (Whitelisted) ===================
2 ASTSRV; C:\WINDOWS\system32\ASTSRV.EXE [57344 2008-05-19] (Nalpeiron Ltd.)
2 Eventlog; C:\Windows\System32\services.exe [110592 2009-02-06] (Microsoft Corporation)
2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-29] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-29] (Malwarebytes Corporation)
3 TuneUp.Defrag; C:\Windows\System32\TuneUpDefragService.exe [361288 2011-03-23] (TuneUp Software)
2 TuneUp.ProgramStatisticsSvc; C:\Windows\System32\TUProgSt.exe [604488 2011-03-23] (TuneUp Software)
2 Akamai; c:\program files\common files\akamai/netsession_win_ce5ba24.dll [x]
2 ANC; C:\Windows\System32\k750mdm.dll [x]
4 arrayssl_vpn_service3,0,1,9; [x]
2 ashampoodefragservice; C:\Windows\System32\veteboot.dll [x]
4 AsusACPI; [x]
2 atinevxx; C:\Windows\System32\quickhealfirewall.dll [x]
4 atkdisplf; [x]
4 awhost32; [x]
2 bc_pat_f; C:\Windows\System32\MaVctrl.dll [x]
2 ccproxy; C:\Windows\System32\keymaestro.dll [x]
4 CTDevice_Srv; [x]
2 ctdvda2k; C:\Windows\System32\se58nd5.dll [x]
2 ctxcpubal; C:\Windows\System32\cpuidlep.dll [x]
4 F700iat; [x]
2 G400DH; C:\Windows\System32\AMDPCI.dll [x]
2 GMSIPCI; C:\Windows\System32\sysplant.dll [x]
2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll [x]
2 hpqwmiex; C:\Windows\System32\dlbt_device.dll [x]
4 imountsrv; [x]
2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
2 k750mgmt; C:\Windows\System32\tsircsrv.dll [x]
2 ltmodem5; C:\Windows\System32\g400.dll [x]
2 lvpopflt; C:\Windows\System32\bglivesvc.dll [x]
2 lxcf_device; C:\Windows\System32\nmindexingservice.dll [x]
4 mqdmbus; [x]
2 MSMQ; C:\Windows\System32\ovmsmaccessmanager.dll [x]
2 ofcpfwsvc; C:\Windows\System32\FiltUSBEMPIA.dll [x]
2 ovt519; C:\Windows\System32\SSFS0BB9.dll [x]
2 pav_security; C:\Windows\System32\kpf4.dll [x]
2 pdlnatdl; C:\Windows\System32\pdlndsdl.dll [x]
2 protectionservice; C:\Windows\System32\SenFiltService.dll [x]
2 PSSdk21; C:\Windows\System32\cbidf.dll [x]
2 rismxdp; C:\Windows\System32\CiscoVpnInstallService.dll [x]
3 rpcapd; "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini" [x]
2 s116obex; C:\Windows\System32\transactional.dll [x]
2 StkASSrv; C:\Windows\System32\hdaudbus.dll [x]
2 TIEHDUSB; C:\Windows\System32\cyberpowerups.dll [x]
2 tng-dtmg; C:\Windows\System32\issm.dll [x]
2 tng-dts; C:\Windows\System32\EMCFILT.dll [x]
2 UPATC; C:\Windows\System32\lanmanworkstation.dll [x]
2 vet-filt; C:\Windows\System32\dlcf_device.dll [x]
2 vstor2-ws60; C:\Windows\System32\vaiomediaplatform-mobile-gateway.dll [x]
2 wwsecsvc; C:\Windows\System32\slabser.dll [x]
==================== Drivers (Whitelisted) ====================
3 APLMp50; C:\Windows\System32\Drivers\APLMp50.sys [28224 2006-11-29] (Printing Communications Assoc., Inc. (PCAUSA))
3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [7493120 2011-11-09] (ATI Technologies Inc.)
3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdXP3.sys [101392 2011-03-30] (Advanced Micro Devices)
0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [26248 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
3 EuDisk; C:\Windows\System32\DRIVERS\EuDisk.sys [122504 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
3 EUDSKACS; \??\C:\WINDOWS\system32\drivers\eudskacs.sys [14216 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
0 EUFS; C:\Windows\System32\drivers\eufs.sys [20616 2009-12-02] (CHENGDU YIWO Tech Development Co., Ltd)
3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
2 LBeepKE; C:\Windows\System32\Drivers\LBeepKE.sys [12184 2011-09-02] (Logitech, Inc.)
3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.Sys [42648 2011-09-02] (Logitech, Inc.)
3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.Sys [12184 2011-09-02] (Logitech, Inc.)
3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [39192 2011-09-02] (Logitech, Inc.)
3 MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [22856 2012-09-29] (Malwarebytes Corporation)
1 networx; C:\Windows\System32\drivers\networx.sys [51640 2011-04-15] (NetFilterSDK.com)
2 npf; C:\Windows\System32\drivers\npf.sys [50704 2009-10-20] (CACE Technologies, Inc.)
3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-11-11] (Microsoft Corporation)
3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [54784 2008-08-01] (NVIDIA Corporation)
3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2008-08-01] (NVIDIA Corporation)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12872 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67656 2010-05-10] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 STHDA; C:\Windows\System32\drivers\sthda.sys [1651204 1999-12-31] (IDT, Inc.)
4 ubsvve; C:\Windows\System32\drivers\tnloa.sys [54016 2010-09-15] ()
3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
4 Abiosdsk; [x]
4 abp480n5; [x]
4 adpu160m; [x]
4 Aha154x; [x]
4 aic78u2; [x]
4 aic78xx; [x]
4 AliIde; [x]
4 amsint; [x]
4 asc; [x]
4 asc3350p; [x]
4 asc3550; [x]
4 Atdisk; [x]
3 catchme; \??\C:\DOCUME~1\MASTER~1\LOCALS~1\Temp\catchme.sys [x]
4 cd20xrnt; [x]
1 Changer; [x]
4 CmdIde; [x]
4 Cpqarray; [x]
4 dac2w2k; [x]
4 dac960nt; [x]
4 dpti2o; [x]
3 ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [x]
4 hpn; [x]
4 hpt3xx; [x]
1 i2omgmt; [x]
4 i2omp; [x]
4 ini910u; [x]
4 IntelIde; [x]
1 lbrtfdc; [x]
4 mraid35x; [x]
1 PCIDump; [x]
3 PDCOMP; [x]
3 PDFRAME; [x]
3 PDRELI; [x]
3 PDRFRAME; [x]
4 perc2; [x]
4 perc2hib; [x]
4 ql1080; [x]
4 Ql10wnt; [x]
4 ql12160; [x]
4 ql1240; [x]
4 ql1280; [x]
4 Simbad; [x]
4 Sparrow; [x]
4 symc810; [x]
4 symc8xx; [x]
4 sym_hi; [x]
4 sym_u3; [x]
4 TosIde; [x]
4 ultra; [x]
4 ViaIde; [x]
3 WDICA; [x]
2 zumbus; C:\Windows\System32\DRIVERS\zumbus.sys [x]
==================== NetSvcs (Whitelisted) ===================
NETSVC: vet-filt -> C:\Windows\system32\dlcf_device.dll ==> No File.
NETSVC: lvpopflt -> C:\Windows\system32\bglivesvc.dll ==> No File.
NETSVC: mcredirector -> No Registry Path.
NETSVC: bc_pat_f -> C:\Windows\system32\MaVctrl.dll ==> No File.
NETSVC: rismxdp -> C:\Windows\system32\CiscoVpnInstallService.dll ==> No File.
NETSVC: UPATC -> C:\Windows\system32\lanmanworkstation.dll ==> No File.
NETSVC: CTDevice_Srv -> ==> No File.
NETSVC: imountsrv -> ==> No File.
NETSVC: vstor2-ws60 -> C:\Windows\system32\vaiomediaplatform-mobile-gateway.dll ==> No File.
NETSVC: awhost32 -> ==> No File.
NETSVC: protectionservice -> C:\Windows\system32\SenFiltService.dll ==> No File.
NETSVC: ovt519 -> C:\Windows\system32\SSFS0BB9.dll ==> No File.
NETSVC: lxcf_device -> C:\Windows\system32\nmindexingservice.dll ==> No File.
NETSVC: CBN -> No Registry Path.
NETSVC: Bcim -> No Registry Path.
NETSVC: fsaa -> No Registry Path.
NETSVC: fasttrackinstallerservice -> No Registry Path.
NETSVC: comhost -> No Registry Path.
NETSVC: DVDRC -> No Registry Path.
NETSVC: StkASSrv -> C:\Windows\system32\hdaudbus.dll ==> No File.
NETSVC: s116obex -> C:\Windows\system32\transactional.dll ==> No File.
NETSVC: ltmodem5 -> C:\Windows\system32\g400.dll ==> No File.
NETSVC: PSSdk21 -> C:\Windows\system32\cbidf.dll ==> No File.
NETSVC: hpqwmiex -> C:\Windows\system32\dlbt_device.dll ==> No File.
NETSVC: k750mgmt -> C:\Windows\system32\tsircsrv.dll ==> No File.
NETSVC: pav_security -> C:\Windows\system32\kpf4.dll ==> No File.
NETSVC: TIEHDUSB -> C:\Windows\system32\cyberpowerups.dll ==> No File.
NETSVC: ctdvda2k -> C:\Windows\system32\se58nd5.dll ==> No File.
NETSVC: ctxcpubal -> C:\Windows\system32\cpuidlep.dll ==> No File.
NETSVC: ofcpfwsvc -> C:\Windows\system32\FiltUSBEMPIA.dll ==> No File.
NETSVC: ccproxy -> C:\Windows\system32\keymaestro.dll ==> No File.
NETSVC: G400DH -> C:\Windows\system32\AMDPCI.dll ==> No File.
NETSVC: atinevxx -> C:\Windows\system32\quickhealfirewall.dll ==> No File.
NETSVC: ashampoodefragservice -> C:\Windows\system32\veteboot.dll ==> No File.
NETSVC: agnwifi -> No Registry Path.
NETSVC: SRTSPL -> No Registry Path.
NETSVC: keriomailserver -> No Registry Path.
NETSVC: wmccdsls -> No Registry Path.
NETSVC: aolavupd -> No Registry Path.
NETSVC: hsxhwazl -> No Registry Path.
NETSVC: MSMQ -> C:\Windows\system32\ovmsmaccessmanager.dll ==> No File.
NETSVC: tng-dts -> C:\Windows\system32\EMCFILT.dll ==> No File.
NETSVC: tng-dtmg -> C:\Windows\system32\issm.dll ==> No File.
NETSVC: F700iat -> ==> No File.
NETSVC: arrayssl_vpn_service3,0,1,9 -> ==> No File.
NETSVC: pdlnatdl -> C:\Windows\system32\pdlndsdl.dll ==> No File.
NETSVC: atkdisplf -> ==> No File.
NETSVC: tga -> No Registry Path.
NETSVC: AsusACPI -> ==> No File.
NETSVC: mqdmbus -> ==> No File.
NETSVC: GMSIPCI -> C:\Windows\system32\sysplant.dll ==> No File.
NETSVC: ANC -> C:\Windows\system32\k750mdm.dll ==> No File.
NETSVC: wwsecsvc -> C:\Windows\system32\slabser.dll ==> No File.
NETSVC: ip6fwhlp -> No Registry Path.
NETSVC: mhn -> No Registry Path.
NETSVC: sacsvr -> No Registry Path.
NETSVC: trksvr -> No Registry Path.
==================== One Month Created Files and Folders ========
2012-12-03 02:55 - 2012-12-03 02:55 - 00000000 ____D C:\FRST
2012-11-30 09:19 - 2012-12-05 14:28 - 00000004 ____A C:\Documents and Settings\Master Blaster\Application Data\skype.ini
2012-11-30 02:02 - 2012-11-30 02:02 - 00000353 ____A C:\Documents and Settings\Master Blaster\Desktop\Sissel - O Mio Babbino Caro - YouTube.url
2012-11-29 23:47 - 2012-11-29 23:47 - 00097778 ____A C:\Documents and Settings\Master Blaster\Desktop\OTL.Txt
2012-11-29 23:47 - 2012-11-29 23:47 - 00048308 ____A C:\Documents and Settings\Master Blaster\Desktop\Extras.Txt
2012-11-29 23:39 - 2012-11-29 23:39 - 00602112 ____A (OldTimer Tools) C:\Documents and Settings\Master Blaster\Desktop\OTL.exe
2012-11-29 05:01 - 2012-11-29 05:01 - 00001161 ____A C:\Documents and Settings\Master Blaster\Desktop\What you'll need....url
2012-11-29 04:40 - 2012-11-29 04:40 - 00001631 ____A C:\Documents and Settings\Master Blaster\Desktop\Delta 36-T30 30 T2 Fence System (2).url
2012-11-29 03:24 - 2012-11-29 03:24 - 00019124 ____A C:\ComboFix.txt
2012-11-29 03:05 - 2012-11-29 03:05 - 00000000 ____D C:\Program Files\GPLGS
2012-11-29 03:04 - 2012-09-12 18:32 - 00088688 ____A C:\Windows\System32\cpwmon2k.dll
2012-11-29 02:37 - 2012-11-29 02:37 - 00036363 ____A C:\Windows\CSTBox.INI
2012-11-29 02:28 - 2012-11-29 02:32 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\scans
2012-11-27 01:27 - 2012-11-27 01:27 - 00019195 ____A C:\Documents and Settings\Master Blaster\Desktop\comboscan.txt
2012-11-25 15:07 - 2012-11-25 15:07 - 05006177 ____R (Swearware) C:\Documents and Settings\Master Blaster\Desktop\ComboFix.exe
2012-11-25 13:07 - 2012-11-25 13:07 - 04742932 ____A C:\Documents and Settings\Master Blaster\Desktop\life_of_pi.psd
2012-11-25 03:11 - 2012-11-25 03:11 - 00442200 ____A (Kaspersky Lab ZAO) C:\Documents and Settings\Master Blaster\Desktop\capperkiller.exe
2012-11-24 17:18 - 2012-11-24 17:18 - 00000453 ____A C:\Documents and Settings\Master Blaster\Desktop\One Large Rat Trap Please - TechSpot Forums.url
2012-11-24 17:16 - 2012-11-24 17:16 - 04732416 ____A (AVAST Software) C:\Documents and Settings\Master Blaster\Desktop\aswMBR.exe
2012-11-24 09:21 - 2012-11-24 09:25 - 152292227 ____A C:\bd2b713aac780837a22001e9327c0e83[1]-2012-11-24.flv
2012-11-24 06:36 - 2012-11-24 06:36 - 00025585 ____A C:\Documents and Settings\Master Blaster\Desktop\attach.txt
2012-11-24 06:36 - 2012-11-24 06:36 - 00015803 ____A C:\Documents and Settings\Master Blaster\Desktop\dds.txt
2012-11-24 06:30 - 2012-11-24 06:33 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\storage nov12
2012-11-23 08:12 - 2012-11-23 08:12 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\New Folder
2012-11-23 07:19 - 2012-11-23 07:19 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-22 11:55 - 2012-11-22 11:55 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\song_data
2012-11-22 07:35 - 2012-11-22 07:41 - 79108767 ____A C:\Documents and Settings\Master Blaster\Desktop\012-11-22.flv
2012-11-22 03:52 - 2012-11-22 03:52 - 00110592 ____A C:\Windows\Minidump\Mini112212-01.dmp
2012-11-22 02:44 - 2012-11-22 03:09 - 00000000 ____D C:\Documents and Settings\Master Blaster\.frostwire5
2012-11-22 02:44 - 2012-11-22 02:45 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\FrostWire
2012-11-22 02:41 - 2012-11-22 03:31 - 00000000 ____D C:\Program Files\Real
2012-11-22 02:41 - 2012-11-22 03:31 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\Real
2012-11-22 02:40 - 2012-11-22 03:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Real
2012-11-22 02:40 - 2012-11-22 02:40 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\OpenCandy
2012-11-19 15:23 - 2012-11-25 15:14 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ProtectedData
2012-11-19 14:00 - 2012-11-19 14:00 - 15401600 ____A C:\240P_400K_6203321[3].mp4
2012-11-19 13:56 - 2012-11-19 13:56 - 06350273 ____A C:\general01_H_6493301_01-2012-11-19.mp4
2012-11-19 13:55 - 2012-11-19 13:57 - 43588603 ____A C:\240P_352K_5225320-2012-11-19.mp4
2012-11-19 13:53 - 2012-11-19 13:53 - 11501318 ____A C:\1396_2000-2012-11-19.mp4
2012-11-19 12:17 - 2012-11-19 12:16 - 00110592 ____A C:\Windows\Minidump\Mini111912-01.dmp
2012-11-15 06:07 - 2012-11-15 06:07 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2012-11-15 06:06 - 2012-11-22 08:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
2012-11-15 03:01 - 2012-11-15 06:07 - 00011727 ____A C:\Windows\KB2727528.log
2012-11-15 03:01 - 2012-11-15 06:06 - 00013180 ____A C:\Windows\KB2761226.log
2012-11-14 04:20 - 2012-11-14 04:20 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\DWP
2012-11-08 05:19 - 2012-11-08 05:19 - 00000000 ____D C:\Program Files\WS_FTP
==================== One Month Modified Files and Folders ========
2012-12-05 14:28 - 2012-11-30 09:19 - 00000004 ____A C:\Documents and Settings\Master Blaster\Application Data\skype.ini
2012-12-05 14:28 - 2012-01-18 04:51 - 00524288 ____A C:\Windows\System32\config\ACEEvent.evt
2012-12-05 14:28 - 2009-12-22 02:35 - 00524288 ____A C:\Windows\System32\config\TuneUp.evt
2012-12-05 14:28 - 2009-12-11 08:00 - 01207744 ____A C:\Windows\WindowsUpdate.log
2012-12-05 14:28 - 2009-12-10 23:49 - 00000178 __ASH C:\Documents and Settings\Master Blaster\ntuser.ini
2012-12-05 14:28 - 2009-12-10 23:42 - 00032362 ____A C:\Windows\SchedLgU.Txt
2012-12-05 14:28 - 2009-12-10 23:40 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-05 14:28 - 2009-12-10 14:38 - 00000216 ____A C:\Windows\wiadebug.log
2012-12-05 14:26 - 2010-08-12 06:17 - 00000504 ____A C:\Windows\Tasks\1-Click Maintenance.job
2012-12-05 14:25 - 2012-06-27 02:49 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-12-05 14:25 - 2010-05-07 02:43 - 00000000 ____D C:\Program Files\Common Files\Akamai
2012-12-05 14:25 - 2009-12-10 23:49 - 00000062 __ASH C:\Documents and Settings\Master Blaster\Local Settings\desktop.ini
2012-12-05 14:25 - 2009-12-10 23:42 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2012-12-05 14:25 - 2009-12-10 23:42 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2012-12-05 14:25 - 2009-12-10 14:38 - 00000049 ____A C:\Windows\wiaservc.log
2012-12-05 14:25 - 2001-08-23 07:00 - 00002206 ____A C:\Windows\System32\wpa.dbl
2012-12-04 22:04 - 2012-06-27 02:49 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-12-04 22:03 - 2009-12-12 03:07 - 00000000 __SHD C:\Windows\CSC
2012-12-04 21:59 - 2012-06-09 07:57 - 00047606 ____A C:\Windows\setupapi.log
2012-12-04 21:59 - 2012-05-09 04:16 - 00003218 ____A C:\Windows\setupact.log
2012-12-03 02:55 - 2012-12-03 02:55 - 00000000 ____D C:\FRST
2012-11-30 09:18 - 2012-04-29 04:23 - 00000000 ____D C:\hidownload
2012-11-30 09:17 - 2009-12-13 01:17 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\IDM
2012-11-30 08:59 - 2012-03-17 08:45 - 00000000 ____D C:\IDM
2012-11-30 08:33 - 2012-04-02 04:05 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-11-30 02:02 - 2012-11-30 02:02 - 00000353 ____A C:\Documents and Settings\Master Blaster\Desktop\Sissel - O Mio Babbino Caro - YouTube.url
2012-11-30 01:36 - 2009-12-13 01:17 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\DMCache
2012-11-30 00:26 - 2011-02-21 05:54 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\vlc
2012-11-29 23:47 - 2012-11-29 23:47 - 00097778 ____A C:\Documents and Settings\Master Blaster\Desktop\OTL.Txt
2012-11-29 23:47 - 2012-11-29 23:47 - 00048308 ____A C:\Documents and Settings\Master Blaster\Desktop\Extras.Txt
2012-11-29 23:39 - 2012-11-29 23:39 - 00602112 ____A (OldTimer Tools) C:\Documents and Settings\Master Blaster\Desktop\OTL.exe
2012-11-29 23:30 - 2012-01-12 08:29 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\New Folder
2012-11-29 05:01 - 2012-11-29 05:01 - 00001161 ____A C:\Documents and Settings\Master Blaster\Desktop\What you'll need....url
2012-11-29 04:40 - 2012-11-29 04:40 - 00001631 ____A C:\Documents and Settings\Master Blaster\Desktop\Delta 36-T30 30 T2 Fence System (2).url
2012-11-29 04:03 - 2012-08-07 06:46 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\send
2012-11-29 03:34 - 2009-12-10 14:37 - 00559994 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-29 03:24 - 2012-11-29 03:24 - 00019124 ____A C:\ComboFix.txt
2012-11-29 03:24 - 2012-06-03 23:58 - 00000000 ___AD C:\Qoobox
2012-11-29 03:22 - 2001-08-23 07:00 - 00000227 ____A C:\Windows\system.ini
2012-11-29 03:07 - 2010-02-02 04:10 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\CutePDF Writer
2012-11-29 03:05 - 2012-11-29 03:05 - 00000000 ____D C:\Program Files\GPLGS
2012-11-29 03:04 - 2010-02-02 04:08 - 00000000 ____D C:\Program Files\Acro Software
2012-11-29 03:01 - 2009-12-10 14:29 - 00000000 ____D C:\Windows\Resources
2012-11-29 02:37 - 2012-11-29 02:37 - 00036363 ____A C:\Windows\CSTBox.INI
2012-11-29 02:32 - 2012-11-29 02:28 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\scans
2012-11-28 12:56 - 2012-06-14 05:47 - 00017857 ____A C:\Windows\wmsetup.log
2012-11-28 07:49 - 2011-12-05 13:50 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\shortcuts2
2012-11-27 04:33 - 2009-12-12 22:30 - 00000000 ____D C:\Earth
2012-11-27 01:28 - 2012-04-28 03:31 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\uTorrent
2012-11-27 01:27 - 2012-11-27 01:27 - 00019195 ____A C:\Documents and Settings\Master Blaster\Desktop\comboscan.txt
2012-11-26 16:44 - 2009-12-12 02:14 - 00176128 ____A C:\Documents and Settings\Master Blaster\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-26 07:34 - 2010-04-08 01:09 - 00000116 ____A C:\Windows\NeroDigital.ini
2012-11-25 17:55 - 2012-11-02 04:40 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\Audacity
2012-11-25 15:14 - 2012-11-19 15:23 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ProtectedData
2012-11-25 15:07 - 2012-11-25 15:07 - 05006177 ____R (Swearware) C:\Documents and Settings\Master Blaster\Desktop\ComboFix.exe
2012-11-25 13:07 - 2012-11-25 13:07 - 04742932 ____A C:\Documents and Settings\Master Blaster\Desktop\life_of_pi.psd
2012-11-25 05:52 - 2011-09-05 19:07 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\suki
2012-11-25 03:11 - 2012-11-25 03:11 - 00442200 ____A (Kaspersky Lab ZAO) C:\Documents and Settings\Master Blaster\Desktop\capperkiller.exe
2012-11-24 17:18 - 2012-11-24 17:18 - 00000453 ____A C:\Documents and Settings\Master Blaster\Desktop\One Large Rat Trap Please - TechSpot Forums.url
2012-11-24 17:16 - 2012-11-24 17:16 - 04732416 ____A (AVAST Software) C:\Documents and Settings\Master Blaster\Desktop\aswMBR.exe
2012-11-24 09:25 - 2012-11-24 09:21 - 152292227 ____A C:\bd2b713aac780837a22001e9327c0e83[1]-2012-11-24.flv
2012-11-24 06:36 - 2012-11-24 06:36 - 00025585 ____A C:\Documents and Settings\Master Blaster\Desktop\attach.txt
2012-11-24 06:36 - 2012-11-24 06:36 - 00015803 ____A C:\Documents and Settings\Master Blaster\Desktop\dds.txt
2012-11-24 06:34 - 2011-12-05 13:48 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\all superb
2012-11-24 06:33 - 2012-11-24 06:30 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\storage nov12
2012-11-23 08:17 - 2012-10-09 05:05 - 00000000 ____D C:\Collection
2012-11-23 08:12 - 2012-11-23 08:12 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\New Folder
2012-11-23 07:19 - 2012-11-23 07:19 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-23 03:07 - 2012-04-10 21:47 - 00268808 ____A C:\Documents and Settings\Master Blaster\Local Settings\Application Data\census.cache
2012-11-23 03:06 - 2012-04-10 21:47 - 00209719 ____A C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ars.cache
2012-11-22 11:55 - 2012-11-22 11:55 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\song_data
2012-11-22 10:05 - 2011-11-03 19:41 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\Akamai
2012-11-22 09:19 - 2010-02-21 06:45 - 00000000 ____D C:\Windows\Microsoft.NET
2012-11-22 08:40 - 2010-04-15 05:02 - 00000000 __HDC C:\Windows\$NtUninstallKB980232$
2012-11-22 08:23 - 2009-12-12 22:32 - 00000000 ____D C:\Program Files\Google
2012-11-22 08:22 - 2012-11-15 06:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
2012-11-22 07:51 - 2011-07-18 00:51 - 00000000 ____D C:\Program Files\Zune
2012-11-22 07:46 - 2009-12-12 22:32 - 00000000 ____D C:\Documents and Settings\Master Blaster\Local Settings\Application Data\Google
2012-11-22 07:41 - 2012-11-22 07:35 - 79108767 ____A C:\Documents and Settings\Master Blaster\Desktop\012-11-22.flv
2012-11-22 03:52 - 2012-11-22 03:52 - 00110592 ____A C:\Windows\Minidump\Mini112212-01.dmp
2012-11-22 03:52 - 2009-12-13 07:25 - 00000000 ____D C:\Windows\Minidump
2012-11-22 03:31 - 2012-11-22 02:41 - 00000000 ____D C:\Program Files\Real
2012-11-22 03:31 - 2012-11-22 02:41 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\Real
2012-11-22 03:31 - 2012-11-22 02:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Real
2012-11-22 03:22 - 2012-10-30 05:35 - 00000000 ____D C:\Program Files\Mozilla Firefox
2012-11-22 03:13 - 2010-09-29 00:19 - 00001984 ____A C:\Windows\System32\d3d9caps.dat
2012-11-22 03:09 - 2012-11-22 02:44 - 00000000 ____D C:\Documents and Settings\Master Blaster\.frostwire5
2012-11-22 02:45 - 2012-11-22 02:44 - 00000000 ____D C:\Documents and Settings\Master Blaster\My Documents\FrostWire
2012-11-22 02:41 - 2003-03-19 01:14 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\msvcp71.dll
2012-11-22 02:41 - 2003-02-21 07:42 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\msvcr71.dll
2012-11-22 02:40 - 2012-11-22 02:40 - 00000000 ____D C:\Documents and Settings\Master Blaster\Application Data\OpenCandy
2012-11-22 02:15 - 2010-03-10 04:09 - 00000000 ____D C:\Program Files\PeerBlock
2012-11-22 00:37 - 2012-10-27 23:52 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\volcano
2012-11-19 14:00 - 2012-11-19 14:00 - 15401600 ____A C:\240P_400K_6203321[3].mp4
2012-11-19 13:57 - 2012-11-19 13:55 - 43588603 ____A C:\240P_352K_5225320-2012-11-19.mp4
2012-11-19 13:56 - 2012-11-19 13:56 - 06350273 ____A C:\general01_H_6493301_01-2012-11-19.mp4
2012-11-19 13:53 - 2012-11-19 13:53 - 11501318 ____A C:\1396_2000-2012-11-19.mp4
2012-11-19 12:16 - 2012-11-19 12:17 - 00110592 ____A C:\Windows\Minidump\Mini111912-01.dmp
2012-11-15 06:51 - 2009-12-10 14:36 - 03449912 ____A C:\Windows\System32\FNTCACHE.DAT
2012-11-15 06:08 - 2009-12-11 14:24 - 64010424 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-11-15 06:07 - 2012-11-15 06:07 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
2012-11-15 06:07 - 2012-11-15 03:01 - 00011727 ____A C:\Windows\KB2727528.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00177212 ____A C:\Windows\iis6.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00166931 ____A C:\Windows\FaxSetup.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00079812 ____A C:\Windows\ocgen.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00076167 ____A C:\Windows\tsoc.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00054570 ____A C:\Windows\comsetup.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00050000 ____A C:\Windows\msmqinst.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00033166 ____A C:\Windows\ntdtcsetup.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00029241 ____A C:\Windows\netfxocm.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00011475 ____A C:\Windows\MedCtrOC.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00009234 ____A C:\Windows\ocmsn.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00008397 ____A C:\Windows\tabletoc.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00008181 ____A C:\Windows\msgsocm.log
2012-11-15 06:07 - 2012-05-12 05:02 - 00001393 ____A C:\Windows\imsins.log
2012-11-15 06:06 - 2012-11-15 03:01 - 00013180 ____A C:\Windows\KB2761226.log
2012-11-15 06:06 - 2009-12-10 14:37 - 00001393 ____A C:\Windows\imsins.BAK
2012-11-15 03:01 - 2009-12-11 08:23 - 00000000 ___HD C:\Windows\$hf_mig$
2012-11-14 04:20 - 2012-11-14 04:20 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\DWP
2012-11-14 04:02 - 2009-12-12 16:51 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2012-11-13 21:23 - 2012-04-02 04:05 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-11-13 21:23 - 2011-05-17 05:58 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-11-09 20:15 - 2012-09-02 19:17 - 00000000 ____D C:\Documents and Settings\Master Blaster\Desktop\select
2012-11-08 05:43 - 2011-06-24 03:09 - 00000000 ____D C:\mafa
2012-11-08 05:19 - 2012-11-08 05:19 - 00000000 ____D C:\Program Files\WS_FTP
2012-11-08 05:19 - 2009-12-10 23:56 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2012-11-08 05:19 - 2001-08-23 07:00 - 00000656 ____A C:\Windows\win.ini
2012-11-07 22:12 - 2012-07-24 08:55 - 00000784 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-07 22:12 - 2012-04-10 19:17 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-11-06 19:49 - 2012-06-30 00:33 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points (XP) =====================
RP: -> 2012-11-30 03:45 - 024576 _restore{2205B7A6-1EB9-495A-B8BD-4B1F24159255}\RP219
RP: -> 2012-11-29 03:04 - 024576 _restore{2205B7A6-1EB9-495A-B8BD-4B1F24159255}\RP218
RP: -> 2012-11-29 01:07 - 024576 _restore{2205B7A6-1EB9-495A-B8BD-4B1F24159255}\RP217
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 2047.17 MB
Available physical RAM: 1790.75 MB
Total Pagefile: 1877.82 MB
Available Pagefile: 1817.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 2003.18 MB
==================== Partitions =============================
2 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
3 Drive c: () (Fixed) (Total:127.99 GB) (Free:1.24 GB) NTFS ==>[Drive with boot components (Windows XP)]
4 Drive d: (SATA) (Fixed) (Total:149.04 GB) (Free:0.88 GB) NTFS
5 Drive e: (New Volume) (Fixed) (Total:570.65 GB) (Free:0.18 GB) NTFS
6 Drive f: (SATA) (Fixed) (Total:149.05 GB) (Free:0.23 GB) NTFS
7 Drive g: () (Removable) (Total:7.45 GB) (Free:7.45 GB) FAT32
8 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 699 GB 0 B
Disk 1 Online 298 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 128 GB 32 KB
Partition 2 Primary 571 GB 128 GB
=========================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 128 GB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E New Volume NTFS Partition 571 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 149 GB 32 KB
Partition 2 Primary 149 GB 149 GB
=========================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D SATA NTFS Partition 149 GB Healthy
=========================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F SATA NTFS Partition 149 GB Healthy
=========================================================
==================== End Of Log ============================