----------------************** Continuing from the other post ************-------------------
========== Files/Folders - Created Within 30 Days ========== [2015/01/23 12:35:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2015/01/22 20:49:27 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015/01/22 20:00:38 | 000,000,000 | ---D | C] -- C:\FRST
[2015/01/22 00:05:16 | 000,000,000 | ---D | C] -- C:\Users\Tom Jones\.jmc
[2015/01/21 23:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2015/01/21 23:49:49 | 000,000,000 | ---D | C] -- C:\Users\Tom Jones\Desktop\mbar
[2015/01/21 22:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2015/01/21 21:53:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2015/01/15 15:06:11 | 000,000,000 | ---D | C] -- C:\Users\Tom Jones\Documents\FIFA 15
[2015/01/13 16:45:28 | 005,553,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015/01/13 16:45:27 | 003,971,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015/01/13 16:45:27 | 003,916,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015/01/13 16:45:27 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015/01/13 16:45:27 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015/01/13 16:45:27 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015/01/13 16:45:26 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2015/01/13 16:45:26 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2014/12/26 22:56:58 | 000,000,000 | ---D | C] -- C:\Users\Tom Jones\.gradle
[2014/12/26 00:22:00 | 000,000,000 | ---D | C] -- C:\Users\Tom Jones\.AndroidStudio
[2014/12/25 23:59:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Android Studio
[2014/12/25 23:59:06 | 000,000,000 | ---D | C] -- C:\Users\Tom Jones\.android
[2014/12/25 23:58:57 | 000,084,992 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\IntelHaxm.sys
[2014/09/16 23:06:27 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe1289.dll
[2014/09/16 22:57:10 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe92DE.dll
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2015/01/23 12:53:12 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/01/23 12:53:12 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/01/23 12:52:03 | 000,880,194 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/01/23 12:52:03 | 000,731,498 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/01/23 12:52:03 | 000,148,396 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/01/23 12:46:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/01/23 08:13:31 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015/01/23 00:22:00 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-265094073-1043058997-3425087786-1000UA.job
[2015/01/22 21:11:30 | 000,097,496 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2015/01/22 20:55:37 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/01/22 20:55:37 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015/01/22 19:22:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-265094073-1043058997-3425087786-1000Core.job
[2015/01/22 11:23:36 | 000,037,624 | ---- | M] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2015/01/22 00:02:51 | 000,000,085 | ---- | M] () -- C:\Windows\wininit.ini
[2015/01/20 16:15:27 | 000,000,958 | ---- | M] () -- C:\Users\Tom Jones\Desktop\Android Studio.lnk
[2015/01/16 22:23:19 | 000,002,356 | ---- | M] () -- C:\Users\Tom Jones\Desktop\Google Chrome.lnk
[2015/01/06 13:14:01 | 000,000,600 | ---- | M] () -- C:\Users\Tom Jones\AppData\Local\PUTTY.RND
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files Created - No Company Name ========== [2015/01/22 00:02:50 | 000,000,085 | ---- | C] () -- C:\Windows\wininit.ini
[2015/01/21 22:33:15 | 000,037,624 | ---- | C] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2015/01/20 16:15:27 | 000,000,958 | ---- | C] () -- C:\Users\Tom Jones\Desktop\Android Studio.lnk
[2014/10/05 15:08:05 | 000,000,057 | ---- | C] () -- C:\Users\Tom Jones\.gitconfig
[2014/10/05 14:55:06 | 000,001,833 | ---- | C] () -- C:\Users\Tom Jones\.bash_history
[2014/07/01 00:29:30 | 000,000,396 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014/05/29 16:14:15 | 000,008,192 | ---- | C] () -- C:\Users\Tom Jones\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/12/20 23:51:16 | 000,000,212 | ---- | C] () -- C:\Windows\ildasmfnt.bin
[2013/07/20 00:48:09 | 002,580,552 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013/07/01 18:05:35 | 000,000,001 | ---- | C] () -- C:\Users\Tom Jones\AppData\Local\llftool.4.30.agreement
[2013/04/16 22:52:23 | 000,000,322 | ---- | C] () -- C:\Users\Tom Jones\configuration_log.csv
[2012/10/07 15:51:26 | 000,000,600 | ---- | C] () -- C:\Users\Tom Jones\AppData\Local\PUTTY.RND
[2012/03/26 17:26:16 | 000,007,602 | ---- | C] () -- C:\Users\Tom Jones\AppData\Local\resmon.resmoncfg
========== ZeroAccess Check ========== [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 21:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 20:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ========== [2014/11/20 23:45:39 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\.emacs.d
[2014/08/26 23:14:19 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\.mono
[2012/03/24 12:24:09 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Auslogics
[2014/01/26 02:06:42 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\BSplayer PRO
[2014/03/19 11:05:16 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\com.valve.FTP
[2014/05/03 16:31:45 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\FileZilla
[2014/01/21 20:36:22 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\iFunbox_UserCache
[2013/02/03 03:07:13 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Immunity Debugger
[2012/03/24 07:32:39 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Leadertech
[2014/03/08 00:15:05 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Mael
[2013/10/26 00:03:48 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Milestone
[2015/01/20 23:10:21 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\MiniLyrics
[2012/05/30 21:01:56 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\MotioninJoy
[2014/09/07 17:40:03 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Motorola
[2014/09/07 16:47:38 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Motorola Mobility
[2013/04/28 22:49:07 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Mumble
[2014/04/01 11:52:05 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\MySQL
[2014/03/16 19:16:38 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\NetBeans
[2014/08/27 18:25:54 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Notepad++
[2013/12/21 00:41:29 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\NuGet
[2014/10/10 09:51:25 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\OfficeRecovery
[2014/02/22 12:56:28 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Oracle
[2013/07/21 18:41:06 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Origin
[2012/10/26 16:42:46 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\redsn0w
[2014/09/16 22:55:54 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Sony
[2014/12/07 18:45:15 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\SSH
[2014/08/26 23:14:03 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Steam
[2014/04/26 14:07:24 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Sublime Text 3
[2012/11/20 15:05:01 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\SystemRequirementsLab
[2014/04/27 22:14:02 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\TeamViewer
[2013/02/05 04:31:48 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\TightVNC
[2012/05/20 03:19:59 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\Ubisoft
[2015/01/22 20:59:07 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\uTorrent
[2013/12/20 23:53:18 | 000,000,000 | ---D | M] -- C:\Users\Tom Jones\AppData\Roaming\VisualAssist
========== Purity Check ========== ========== Custom Scans ========== < C:\Users\*.vbs /S >[2009/07/14 00:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009/07/14 00:08:49 | 000,032,624 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013/10/12 14:32:49 | 000,000,880 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-265094073-1043058997-3425087786-1000Core.job
[2013/10/12 14:32:49 | 000,000,932 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-265094073-1043058997-3425087786-1000UA.job
< C:\Users\*.bat /S >[2008/11/29 12:05:58 | 000,000,053 | ---- | M] () -- C:\Users\Tom Jones\Downloads\OC\RealTemp_370\RTShutDown.bat
========== Alternate Data Streams ========== @Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:8927A071
< End of report >
---------------------------------------------------------------------------------------------------------------------
3. New Malwarebytes scan produced:
Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 1/23/2015
Scan Time: 1:56:15 PM
Logfile:
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.23.06
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tom Jones
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 821488
Time Elapsed: 1 hr, 2 min, 58 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)