Confused Newby
Posts: 24 +0
Good Evening Broni,
You helped me about 3 weeks ago now trying to get rid of this virus before my computer crashed on me. I'm now back on line and ready to resume the fix where we left off as no settings on computer have changed from the repair at the old data from the previous thread should still apply. Are we able to reactivate the old thread?? if not here is the last data requested from the Farbar recovery scan tool x 64:
Scan result of Farbar Recovery Scan Tool Version: 10-07-01
Ran by SYSTEM at 01-08-01 :01:50
Running from F:\
Windows Vista (TM) Home Premium Service Pack 1 (X6) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [157160 008-08-1] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] RAVCpl6.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [1968 008-0-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [5560 007-1-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [5195 007-1-10] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [86580 008-0-18] (TOSHIBA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [50008 010-0-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" -set Silent "1" SplashURL "" [1111568 011-10-08] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [19715 011-0-10] (Trend Micro Inc.)
HKLM-x\...\Run: [NDSTray.exe] NDSTray.exe [x]
HKLM-x\...\Run: [cfFncEnabler.exe] cfFncEnabler.exe [x]
HKLM-x\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [610 008-01-0] (Advanced Micro Devices, Inc.)
HKLM-x\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [1779 008-09-5] (Chicony)
HKLM-x\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office1\BCSSync.exe" /DelayServices [9150 010-0-1] (Microsoft Corporation)
HKLM-x\...\Run: [DATAMNGR] C:\PROGRA~\SEARCH~\Datamngr\DATAMN~1.EXE [169608 01-0-8] (Bandoo Media, inc)
HKLM-x\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [590 011-11-01] (Apple Inc.)
HKLM-x\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [176 011-1-07] (Apple Inc.)
HKLM-x\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [871 01-01-01] (Adobe Systems Incorporated)
HKLM-x\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [5696 01-01-17] (Sun Microsystems, Inc.)
HKLM-x\...\Run: [] [x]
HKLM-x\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1917 01-01-0] (Ask)
HKLM-x\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [96056 01-0-7] (RealNetworks, Inc.)
HKLM-x\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [796 01-0-7] (Adobe Systems Incorporated)
HKLM-x\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [690 01-07-0] (Malwarebytes Corporation)
HKU\Administrator\...\Run: [WindowsWelcomeCenter] rundll.exe oobefldr.dll,ShowWelcomeCenter [8656 009-0-10] (Microsoft Corporation)
HKU\Administrator\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 009-0-10] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll.exe oobefldr.dll,ShowWelcomeCenter [8656 009-0-10] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 009-0-10] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll.exe oobefldr.dll,ShowWelcomeCenter [8656 009-0-10] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\JAMES INGLISH\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\JAMES INGLISH\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [180 008-01-0] (Microsoft Corporation)
HKU\JAMES INGLISH\...\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe [819 011-01-17] ()
HKU\JAMES INGLISH\...\Run: [Akamai NetSession Interface] "C:\Users\JAMES INGLISH\AppData\Local\Akamai\netsession_win.exe" [77 01-05-5] (Akamai Technologies, Inc)
HKU\JAMES INGLISH\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [908 009-05-1] (Google Inc.)
HKU\JAMES INGLISH\...\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s [95579 01-05-0] (Samsung)
HKU\JAMES INGLISH\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [51 01-05-0] (Samsung Electronics Co., Ltd.)
HKU\JAMES INGLISH\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [19 01-05-0] ()
HKU\JAMES INGLISH\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17176 01-06-0] (Skype Technologies S.A.)
HKLM\...\Runonce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM\WerFault.exe -k -rq [x]
HKLM-x\...\RunOnce: [Malwarebytes Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [690 01-07-0] (Malwarebytes Corporation)
HKLM-x\...\RunOnce: [InnoSetupRegFile.0000000001] "C:\Windows\is-DSVIL.exe" /REG /REGSVRMODE [7110 01-08-01] ()
Tcpip\Parameters: [DhcpNameServer] 10.0.0.18
AppInit_DLLs: C:\PROGRA~\SEARCH~\Datamngr\x6\datamngr.dll C:\PROGRA~\SEARCH~\Datamngr\x6\IEBHO.dll C:\PROGRA~\SEARCH~1\SEARCH~1\x6\datamngr.dll C:\PROGRA~\SEARCH~1\SEARCH~1\x6\IEBHO.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HD Writer AE 1.0.lnk
ShortcutTarget: HD Writer AE 1.0.lnk -> C:\Program Files (x86)\Panasonic\HD Writer AE 1\HDWriterAutoStart.exe (Panasonic Corporation)
Startup: C:\Users\JAMES INGLISH\Start Menu\Programs\Startup\Corel Registration.lnk
ShortcutTarget: Corel Registration.lnk -> C:\Program Files (x86)\Corel\Graphics9\Register\Remind.exe (IntelliQuest Communications, Inc.)
==================== Services (Whitelisted) ======
Akamai; C:\program files (x86)\common files\akamai/netsession_win_f7fccd.dll [199 01-07-10] (Akamai Technologies, Inc)
jswpsapi; C:\Program Files (x86)\Jumpstart\jswpsapi.exe [9568 008-0-15] (Atheros Communications, Inc.)
MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [6559 01-07-0] (Malwarebytes Corporation)
MSSQL$MSSMLBIZ; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [9908 010-1-09] (Microsoft Corporation)
MSSQL$SQLEXPRESS; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [9908 010-1-09] (Microsoft Corporation)
TNaviSrv; C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [81 008-0-10] (TOSHIBA Corporation)
TomTomHOMEService; C:\Users\JAMES INGLISH\Downloads\TomTom HOME \TomTomHOMEService.exe [959 011-1-05] (TomTom)
WSWNA100; C:\Program Files (x86)\NETGEAR\WNA100\WifiSvc.exe [8515 010-08-5] ()
Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=qb -dt=60000 [x]
========================== Drivers (Whitelisted) =============
0 ACPI; C:\Windows\System\Drivers\ACPI.sys [5608 009-0-10] (Microsoft Corporation)
adp9xx; C:\Windows\System\Drivers\adp9xx.sys [8656 008-01-0] (Adaptec, Inc.)
adpahci; C:\Windows\System\Drivers\adpahci.sys [58 008-01-0] (Adaptec, Inc.)
adpu160m; C:\Windows\System\Drivers\adpu160m.sys [1650 008-01-0] (Adaptec, Inc.)
adpu0; C:\Windows\System\Drivers\adpu0.sys [18591 008-01-0] (Adaptec, Inc.)
1 AFD; C:\Windows\System\Drivers\AFD.sys [099 01-01-0] (Microsoft Corporation)
agp0; C:\Windows\System\Drivers\agp0.sys [6568 008-01-0] (Microsoft Corporation)
aic78xx; C:\Windows\system\drivers\djsvs.sys [88168 006-11-0] (Adaptec, Inc.)
amdide; C:\Windows\System\Drivers\amdide.sys [15976 008-01-0] (Microsoft Corporation)
AmdK8; C:\Windows\System\Drivers\AmdK8.sys [50688 008-01-0] (Microsoft Corporation)
arc; C:\Windows\System\Drivers\arc.sys [90680 008-01-0] (Adaptec, Inc.)
arcsas; C:\Windows\System\Drivers\arcsas.sys [9119 008-01-0] (Adaptec, Inc.)
AsyncMac; C:\Windows\System\Drivers\AsyncMac.sys [016 008-01-0] (Microsoft Corporation)
0 atapi; C:\Windows\System\Drivers\atapi.sys [095 009-0-10] (Microsoft Corporation)
atikmdag; C:\Windows\System\Drivers\atikmdag.sys [600 008-05-1] (ATI Technologies Inc.)
0 AtiPcie; C:\Windows\System\Drivers\AtiPcie.sys [16656 006-11-07] (ATI Technologies Inc.)
blbdrive; C:\Windows\System\Drivers\blbdrive.sys [5596 008-01-0] (Microsoft Corporation)
bowser; C:\Windows\System\Drivers\bowser.sys [906 011-0-18] (Microsoft Corporation)
BrFiltLo; C:\Windows\System\Drivers\BrFiltLo.sys [18 006-09-18] (Brother Industries, Ltd.)
BrFiltUp; C:\Windows\System\Drivers\BrFiltUp.sys [870 006-09-18] (Brother Industries, Ltd.)
Brserid; C:\Windows\System\Drivers\Brserid.sys [8658 006-11-0] (Brother Industries Ltd.)
BrSerWdm; C:\Windows\System\Drivers\BrSerWdm.sys [710 006-09-18] (Brother Industries Ltd.)
BrUsbMdm; C:\Windows\System\Drivers\BrUsbMdm.sys [1976 006-09-18] (Brother Industries Ltd.)
BrUsbSer; C:\Windows\System\Drivers\BrUsbSer.sys [170 006-09-19] (Brother Industries Ltd.)
BTHMODEM; C:\Windows\System\Drivers\BTHMODEM.sys [50688 006-11-0] (Microsoft Corporation)
cdfs; C:\Windows\System\Drivers\cdfs.sys [906 008-01-0] (Microsoft Corporation)
1 cdrbsdrv; C:\Windows\System\Drivers\cdrbsdrv.sys [908 006-08-] (B.H.A Corporation)
1 cdrom; C:\Windows\System\Drivers\cdrom.sys [7987 009-0-10] (Microsoft Corporation)
circlass; C:\Windows\System\Drivers\circlass.sys [198 008-01-0] (Microsoft Corporation)
CmBatt; C:\Windows\System\Drivers\CmBatt.sys [1779 008-01-0] (Microsoft Corporation)
0 Compbatt; C:\Windows\System\Drivers\Compbatt.sys [608 008-01-0] (Microsoft Corporation)
0 crcdisk; C:\Windows\System\Drivers\crcdisk.sys [770 008-01-0] (Microsoft Corporation)
1 DfsC; C:\Windows\System\Drivers\DfsC.sys [9779 011-0-1] (Microsoft Corporation)
0 disk; C:\Windows\System\Drivers\disk.sys [670 009-0-10] (Microsoft Corporation)
drmkaud; C:\Windows\System\Drivers\drmkaud.sys [61 008-01-0] (Microsoft Corporation)
DXGKrnl; C:\Windows\System\Drivers\DXGKrnl.sys [90080 011-01-0] (Microsoft Corporation)
E1G60; C:\Windows\System\DRIVERS\E1G60E.sys [16176 008-01-0] (Intel Corporation)
0 Ecache; C:\Windows\System\Drivers\Ecache.sys [15511 009-0-10] (Microsoft Corporation)
ErrDev; C:\Windows\System\Drivers\ErrDev.sys [870 008-01-0] (Microsoft Corporation)
exfat; C:\Windows\System\Drivers\exfat.sys [18790 009-0-10] (Microsoft Corporation)
fastfat; C:\Windows\System\Drivers\fastfat.sys [1981 009-0-10] (Microsoft Corporation)
fdc; C:\Windows\System\Drivers\fdc.sys [9696 008-01-0] (Microsoft Corporation)
0 FileInfo; C:\Windows\System\Drivers\FileInfo.sys [7000 008-01-0] (Microsoft Corporation)
Filetrace; C:\Windows\System\Drivers\Filetrace.sys [80 008-01-0] (Microsoft Corporation)
flpydisk; C:\Windows\System\Drivers\flpydisk.sys [576 008-01-0] (Microsoft Corporation)
0 FltMgr; C:\Windows\System\Drivers\FltMgr.sys [75 009-0-10] (Microsoft Corporation)
fssfltr; C:\Windows\System\Drivers\fssfltr.sys [888 010-09-] (Microsoft Corporation)
1 Fs_Rec; C:\Windows\System\Drivers\Fs_Rec.sys [168 01-0-9] (Microsoft Corporation)
FwLnk; C:\Windows\System\Drivers\FwLnk.sys [870 006-11-19] (TOSHIBA Corporation)
gagp0kx; C:\Windows\System\Drivers\gagp0kx.sys [6815 008-01-0] (Microsoft Corporation)
HdAudAddService; C:\Windows\System\drivers\HdAudio.sys [790 006-11-01] (Microsoft Corporation)
HDAudBus; C:\Windows\System\Drivers\HDAudBus.sys [9876 009-0-10] (Microsoft Corporation)
HidBth; C:\Windows\System\Drivers\HidBth.sys [0 006-11-0] (Microsoft Corporation)
HidIr; C:\Windows\System\Drivers\HidIr.sys [5600 006-11-0] (Microsoft Corporation)
HidUsb; C:\Windows\System\Drivers\HidUsb.sys [1587 009-0-10] (Microsoft Corporation)
HpCISSs; C:\Windows\System\Drivers\HpCISSs.sys [767 008-01-0] (Hewlett-Packard Company)
HTTP; C:\Windows\System\Drivers\HTTP.sys [600 010-0-0] (Microsoft Corporation)
iomp; C:\Windows\System\Drivers\iomp.sys [5896 008-01-0] (Microsoft Corporation)
1 i80prt; C:\Windows\System\Drivers\i80prt.sys [6000 008-01-0] (Microsoft Corporation)
iaStorV; C:\Windows\System\Drivers\iaStorV.sys [9087 008-01-0] (Intel Corporation)
iirsp; C:\Windows\System\Drivers\iirsp.sys [68 006-11-0] (Intel Corp./ICP vortex GmbH)
IntcAzAudAddService; C:\Windows\System\drivers\RTKVHD6.sys [196888 008-0-09] (Realtek Semiconductor Corp.)
intelide; C:\Windows\System\Drivers\intelide.sys [1951 008-01-0] (Microsoft Corporation)
intelppm; C:\Windows\System\Drivers\intelppm.sys [818 008-01-0] (Microsoft Corporation)
IpFilterDriver; C:\Windows\System\DRIVERS\ipfltdrv.sys [6758 009-0-10] (Microsoft Corporation)
IPMIDRV; C:\Windows\System\Drivers\IPMIDRV.sys [7688 008-01-0] (Microsoft Corporation)
IPNAT; C:\Windows\System\Drivers\IPNAT.sys [11571 008-01-0] (Microsoft Corporation)
IRENUM; C:\Windows\System\Drivers\IRENUM.sys [1708 008-01-0] (Microsoft Corporation)
isapnp; C:\Windows\System\Drivers\isapnp.sys [608 008-01-0] (Microsoft Corporation)
iScsiPrt; C:\Windows\System\DRIVERS\msiscsi.sys [1558 009-0-10] (Microsoft Corporation)
1 kbdclass; C:\Windows\System\Drivers\kbdclass.sys [00 008-01-0] (Microsoft Corporation)
kbdhid; C:\Windows\System\Drivers\kbdhid.sys [080 008-01-0] (Microsoft Corporation)
0 KSecDD; C:\Windows\System\Drivers\KSecDD.sys [515968 011-11-16] (Microsoft Corporation)
ksthunk; C:\Windows\System\Drivers\ksthunk.sys [086 008-01-0] (Microsoft Corporation)
lltdio; C:\Windows\System\Drivers\lltdio.sys [599 008-01-0] (Microsoft Corporation)
LSI_FC; C:\Windows\System\Drivers\LSI_FC.sys [1170 008-01-0] (LSI Logic)
LSI_SAS; C:\Windows\System\Drivers\LSI_SAS.sys [105016 008-01-0] (LSI Logic)
LSI_SCSI; C:\Windows\System\Drivers\LSI_SCSI.sys [1170 008-01-0] (LSI Logic)
luafv; C:\Windows\System\Drivers\luafv.sys [109568 008-01-0] (Microsoft Corporation)
MBAMProtector; \??\C:\Windows\system\drivers\mbam.sys [90 01-07-0] (Malwarebytes Corporation)
megasas; C:\Windows\System\Drivers\megasas.sys [5896 008-01-0] (LSI Corporation)
MegaSR; C:\Windows\System\Drivers\MegaSR.sys [88 008-01-0] (LSI Corporation, Inc.)
Modem; C:\Windows\System\Drivers\Modem.sys [08 008-01-0] (Microsoft Corporation)
monitor; C:\Windows\System\Drivers\monitor.sys [915 008-01-0] (Microsoft Corporation)
1 mouclass; C:\Windows\System\Drivers\mouclass.sys [999 008-01-0] (Microsoft Corporation)
mouhid; C:\Windows\System\Drivers\mouhid.sys [19968 008-01-0] (Microsoft Corporation)
0 MountMgr; C:\Windows\System\Drivers\MountMgr.sys [7000 008-01-0] (Microsoft Corporation)
mpio; C:\Windows\System\Drivers\mpio.sys [18056 008-01-0] (Microsoft Corporation)
mpsdrv; C:\Windows\System\Drivers\mpsdrv.sys [8108 008-01-0] (Microsoft Corporation)
Mraid5x; C:\Windows\System\Drivers\Mraid5x.sys [9016 006-11-0] (LSI Logic Corporation)
MRxDAV; C:\Windows\System\Drivers\MRxDAV.sys [196 009-0-10] (Microsoft Corporation)
mrxsmb; C:\Windows\System\Drivers\mrxsmb.sys [15680 011-0-9] (Microsoft Corporation)
mrxsmb10; C:\Windows\System\Drivers\mrxsmb10.sys [7556 011-07-06] (Microsoft Corporation)
mrxsmb0; C:\Windows\System\Drivers\mrxsmb0.sys [107008 011-0-9] (Microsoft Corporation)
0 msahci; C:\Windows\System\Drivers\msahci.sys [9656 009-0-10] (Microsoft Corporation)
msdsm; C:\Windows\System\Drivers\msdsm.sys [1170 008-01-0] (Microsoft Corporation)
1 Msfs; C:\Windows\System\Drivers\Msfs.sys [611 008-01-0] (Microsoft Corporation)
0 msisadrv; C:\Windows\System\Drivers\msisadrv.sys [17976 008-01-0] (Microsoft Corporation)
MSKSSRV; C:\Windows\System\Drivers\MSKSSRV.sys [11008 008-01-0] (Microsoft Corporation)
MSPCLOCK; C:\Windows\System\Drivers\MSPCLOCK.sys [700 006-11-0] (Microsoft Corporation)
MSPQM; C:\Windows\System\Drivers\MSPQM.sys [6656 006-11-0] (Microsoft Corporation)
MsRPC; C:\Windows\System\Drivers\MsRPC.sys [10760 009-0-10] (Microsoft Corporation)
mssmbios; C:\Windows\System\Drivers\mssmbios.sys [87 008-01-0] (Microsoft Corporation)
MSTEE; C:\Windows\System\Drivers\MSTEE.sys [796 008-01-0] (Microsoft Corporation)
0 Mup; C:\Windows\System\Drivers\Mup.sys [59880 009-0-10] (Microsoft Corporation)
NativeWifiP; C:\Windows\System\DRIVERS\nwifi.sys [1879 009-0-10] (Microsoft Corporation)
0 NDIS; C:\Windows\System\Drivers\NDIS.sys [786 009-0-10] (Microsoft Corporation)
NdisTapi; C:\Windows\System\Drivers\NdisTapi.sys [06 008-01-0] (Microsoft Corporation)
Ndisuio; C:\Windows\System\Drivers\Ndisuio.sys [016 008-01-0] (Microsoft Corporation)
NdisWan; C:\Windows\System\Drivers\NdisWan.sys [1697 009-0-10] (Microsoft Corporation)
NDProxy; C:\Windows\System\Drivers\NDProxy.sys [5990 008-01-0] (Microsoft Corporation)
1 NetBIOS; C:\Windows\System\Drivers\NetBIOS.sys [5 008-01-0] (Microsoft Corporation)
1 netbt; C:\Windows\System\Drivers\netbt.sys [80 009-0-10] (Microsoft Corporation)
NPF; C:\Windows\System\Drivers\NPF.sys [76 010-0-0] (CACE Technologies, Inc.)
1 Npfs; C:\Windows\System\Drivers\Npfs.sys [5 009-0-10] (Microsoft Corporation)
1 nsiproxy; C:\Windows\System\Drivers\nsiproxy.sys [06 008-01-0] (Microsoft Corporation)
Ntfs; C:\Windows\System\Drivers\Ntfs.sys [151596 009-0-10] (Microsoft Corporation)
1 Null; C:\Windows\System\Drivers\Null.sys [61 006-11-0] (Microsoft Corporation)
nvraid; C:\Windows\System\Drivers\nvraid.sys [18056 008-01-0] (NVIDIA Corporation)
nvstor; C:\Windows\System\Drivers\nvstor.sys [58 008-01-0] (NVIDIA Corporation)
nv_agp; C:\Windows\System\Drivers\nv_agp.sys [1650 008-01-0] (Microsoft Corporation)
ohci19; C:\Windows\System\Drivers\ohci19.sys [78 009-0-10] (Microsoft Corporation)
Parport; C:\Windows\System\Drivers\Parport.sys [96768 006-11-0] (Microsoft Corporation)
0 partmgr; C:\Windows\System\Drivers\partmgr.sys [7576 01-0-0] (Microsoft Corporation)
0 pci; C:\Windows\System\Drivers\pci.sys [17866 009-0-10] (Microsoft Corporation)
0 pciide; C:\Windows\System\Drivers\pciide.sys [11 009-0-10] (Microsoft Corporation)
pcmcia; C:\Windows\System\Drivers\pcmcia.sys [068 006-11-0] (Microsoft Corporation)
PEAUTH; C:\Windows\System\Drivers\PEAUTH.sys [7170 006-10-] (Microsoft Corporation)
PptpMiniport; C:\Windows\System\DRIVERS\raspptp.sys [98816 009-0-10] (Microsoft Corporation)
Processor; C:\Windows\System\DRIVERS\processr.sys [710 008-01-0] (Microsoft Corporation)
1 PSched; C:\Windows\System\DRIVERS\pacer.sys [908 009-0-10] (Microsoft Corporation)
QWAVEdrv; C:\Windows\System\Drivers\QWAVEdrv.sys [659 008-01-0] (Microsoft Corporation)
1 RasAcd; C:\Windows\System\Drivers\RasAcd.sys [188 008-01-0] (Microsoft Corporation)
Rasltp; C:\Windows\System\Drivers\Rasltp.sys [198 009-0-10] (Microsoft Corporation)
RasPppoe; C:\Windows\System\Drivers\RasPppoe.sys [50176 009-0-10] (Microsoft Corporation)
RasSstp; C:\Windows\System\Drivers\RasSstp.sys [786 009-0-10] (Microsoft Corporation)
1 rdbss; C:\Windows\System\Drivers\rdbss.sys [877 009-0-10] (Microsoft Corporation)
1 RDPCDD; C:\Windows\System\Drivers\RDPCDD.sys [7168 008-01-0] (Microsoft Corporation)
rdpdr; C:\Windows\System\Drivers\rdpdr.sys [168 008-01-0] (Microsoft Corporation)
1 RDPENCDD; C:\Windows\System\Drivers\RDPENCDD.sys [7168 008-01-0] (Microsoft Corporation)
RDPWD; C:\Windows\System\Drivers\RDPWD.sys [0990 01-05-01] (Microsoft Corporation)
rimmptsk; C:\Windows\System\DRIVERS\rimmpx6.sys [6976 008-0-1] (REDC)
rimsptsk; C:\Windows\System\DRIVERS\rimspx6.sys [5596 007-07-6] (REDC)
rismxdp; C:\Windows\System\DRIVERS\rixdpx6.sys [57856 007-07-7] (REDC)
rspndr; C:\Windows\System\Drivers\rspndr.sys [75776 008-01-0] (Microsoft Corporation)
RTL8169; C:\Windows\System\DRIVERS\Rtlh6.sys [011 010-01-11] (Realtek )
sbpport; C:\Windows\System\Drivers\sbpport.sys [9016 006-11-0] (Microsoft Corporation)
0 SCMNdisP; C:\Windows\System\Drivers\SCMNdisP.sys [51 007-01-19] (Windows (R) Codename Longhorn DDK provider)
sdbus; C:\Windows\System\Drivers\sdbus.sys [11110 009-0-10] (Microsoft Corporation)
Serenum; C:\Windows\System\Drivers\Serenum.sys [00 006-11-0] (Microsoft Corporation)
Serial; C:\Windows\System\Drivers\Serial.sys [908 006-11-0] (Microsoft Corporation)
sermouse; C:\Windows\System\Drivers\sermouse.sys [66 008-01-0] (Microsoft Corporation)
sffdisk; C:\Windows\System\Drivers\sffdisk.sys [188 009-0-10] (Microsoft Corporation)
sffp_mmc; C:\Windows\System\Drivers\sffp_mmc.sys [16 008-01-0] (Microsoft Corporation)
sffp_sd; C:\Windows\System\Drivers\sffp_sd.sys [18 009-0-10] (Microsoft Corporation)
sfloppy; C:\Windows\System\Drivers\sfloppy.sys [168 006-11-0] (Microsoft Corporation)
1 Smb; C:\Windows\System\Drivers\Smb.sys [8806 009-0-10] (Microsoft Corporation)
0 spldr; C:\Windows\System\Drivers\spldr.sys [19 009-0-10] (Microsoft Corporation)
srv; C:\Windows\System\Drivers\srv.sys [50560 011-0-18] (Microsoft Corporation)
srv; C:\Windows\System\Drivers\srv.sys [17618 011-0-9] (Microsoft Corporation)
srvnet; C:\Windows\System\Drivers\srvnet.sys [1590 011-0-9] (Microsoft Corporation)
swenum; C:\Windows\System\Drivers\swenum.sys [10 008-01-0] (Microsoft Corporation)
Symc8xx; C:\Windows\System\Drivers\Symc8xx.sys [956 006-11-0] (LSI Logic)
Sym_hi; C:\Windows\System\Drivers\Sym_hi.sys [68 006-11-0] (LSI Logic)
Sym_u; C:\Windows\System\Drivers\Sym_u.sys [8 006-11-0] (LSI Logic)
0 Tcpip; C:\Windows\System\Drivers\Tcpip.sys [17 01-0-0] (Microsoft Corporation)
Tcpip6; C:\Windows\System\DRIVERS\tcpip.sys [17 01-0-0] (Microsoft Corporation)
tcpipreg; C:\Windows\System\Drivers\tcpipreg.sys [08 009-1-08] (Microsoft Corporation)
tdcmdpst; C:\Windows\System\Drivers\tdcmdpst.sys [77 007-1-11] (TOSHIBA Corporation.)
TDPIPE; C:\Windows\System\Drivers\TDPIPE.sys [168 008-01-0] (Microsoft Corporation)
TDTCP; C:\Windows\System\Drivers\TDTCP.sys [9696 008-01-0] (Microsoft Corporation)
1 tdx; C:\Windows\System\Drivers\tdx.sys [970 009-0-10] (Microsoft Corporation)
1 TermDD; C:\Windows\System\Drivers\TermDD.sys [60 009-0-10] (Microsoft Corporation)
tmactmon; C:\Windows\System\Drivers\tmactmon.sys [9070 011-0-] (Trend Micro Inc.)
tmcomm; C:\Windows\System\Drivers\tmcomm.sys [16 011-0-] (Trend Micro Inc.)
tmevtmgr; C:\Windows\System\Drivers\tmevtmgr.sys [6766 011-0-] (Trend Micro Inc.)
1 tmtdi; C:\Windows\System\Drivers\tmtdi.sys [10555 011-0-] (Trend Micro Inc.)
0 tos_sps6; C:\Windows\System\Drivers\tos_sps6.sys [51968 008-0-10] (TOSHIBA Corporation)
tssecsrv; C:\Windows\System\Drivers\tssecsrv.sys [918 008-01-0] (Microsoft Corporation)
tunmp; C:\Windows\System\Drivers\tunmp.sys [18 008-01-0] (Microsoft Corporation)
tunnel; C:\Windows\System\Drivers\tunnel.sys [9696 010-0-18] (Microsoft Corporation)
0 TVALZ; C:\Windows\System\DRIVERS\TVALZ_O.SYS [6968 007-11-08] (TOSHIBA Corporation)
uagp5; C:\Windows\System\Drivers\uagp5.sys [6718 008-01-0] (Microsoft Corporation)
udfs; C:\Windows\System\Drivers\udfs.sys [99008 009-0-10] (Microsoft Corporation)
uliagpkx; C:\Windows\System\Drivers\uliagpkx.sys [6815 008-01-0] (Microsoft Corporation)
umbus; C:\Windows\System\Drivers\umbus.sys [198 008-01-0] (Microsoft Corporation)
USBAAPL6; C:\Windows\System\Drivers\USBAAPL6.sys [5171 011-08-01] (Apple, Inc.)
usbccgp; C:\Windows\System\Drivers\usbccgp.sys [957 008-01-0] (Microsoft Corporation)
usbcir; C:\Windows\System\Drivers\usbcir.sys [7960 006-11-0] (Microsoft Corporation)
usbehci; C:\Windows\System\Drivers\usbehci.sys [966 009-0-10] (Microsoft Corporation)
usbhub; C:\Windows\System\Drivers\usbhub.sys [790 009-0-10] (Microsoft Corporation)
usbohci; C:\Windows\System\Drivers\usbohci.sys [06 009-0-10] (Microsoft Corporation)
usbprint; C:\Windows\System\Drivers\usbprint.sys [06 008-01-0] (Microsoft Corporation)
USBSTOR; C:\Windows\System\Drivers\USBSTOR.sys [778 009-0-10] (Microsoft Corporation)
usbuhci; C:\Windows\System\Drivers\usbuhci.sys [918 008-01-0] (Microsoft Corporation)
usbvideo; C:\Windows\System\Drivers\usbvideo.sys [16870 008-01-0] (Microsoft Corporation)
vga; C:\Windows\System\Drivers\vga.sys [867 008-01-0] (Microsoft Corporation)
1 VgaSave; C:\Windows\System\drivers\vga.sys [867 008-01-0] (Microsoft Corporation)
0 volmgr; C:\Windows\System\Drivers\volmgr.sys [6708 009-0-10] (Microsoft Corporation)
0 volmgrx; C:\Windows\System\Drivers\volmgrx.sys [080 009-0-10] (Microsoft Corporation)
WacomPen; C:\Windows\System\Drivers\WacomPen.sys [66 006-11-0] (Microsoft Corporation)
Wanarp; C:\Windows\System\Drivers\Wanarp.sys [8658 009-0-10] (Microsoft Corporation)
1 Wanarpv6; C:\Windows\System\DRIVERS\wanarp.sys [8658 009-0-10] (Microsoft Corporation)
Wd; C:\Windows\System\Drivers\Wd.sys [10 008-01-0] (Microsoft Corporation)
0 Wdf01000; C:\Windows\System\Drivers\Wdf01000.sys [88170 008-01-0] (Microsoft Corporation)
WpdUsb; C:\Windows\System\Drivers\WpdUsb.sys [659 009-09-0] (Microsoft Corporation)
wsifsl; C:\Windows\System\Drivers\wsifsl.sys [099 008-01-0] (Microsoft Corporation)
WUDFRd; C:\Windows\System\Drivers\WUDFRd.sys [1085 008-01-0] (Microsoft Corporation)
DIRECTIO; \??\C:\MCDiags\BIT\DirectIo6.sys [x]
DIRECTIO7; \??\C:\MCDiags\BIT\DirectIo6.sys [x]
IpInIp; C:\Windows\System\DRIVERS\ipinip.sys [x]
NwlnkFlt; C:\Windows\System\DRIVERS\nwlnkflt.sys [x]
NwlnkFwd; C:\Windows\System\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
01-08-01 :01 - 01-08-01 :01 - 00000000 ____D C:\FRST
01-08-01 0:51 - 01-08-01 0:51 - 007110 ____A C:\Windows\is-DSVIL.exe
01-08-01 0:51 - 01-08-01 0:51 - 00010550 ____A C:\Windows\is-DSVIL.msg
01-08-01 0:51 - 01-08-01 0:51 - 0000059 ____A C:\Windows\is-DSVIL.lst
01-07-10 0:01 - 01-07-10 0:01 - 000017 ____A C:\Users\JAMES INGLISH\Desktop\aswMBR.txt
01-07-10 0:01 - 01-07-10 0:01 - 0000051 ____A C:\Users\JAMES INGLISH\Desktop\MBR.dat
01-07-10 18:0 - 01-07-10 18:0 - 006970 ____A C:\Windows\Minidump\Mini07111-01.dmp
01-07-10 17:5 - 01-07-10 17:5 - 00005 ____A C:\Users\JAMES INGLISH\Desktop\RKreport[1].txt
01-07-10 17:5 - 01-07-10 17:5 - 00000000 ____D C:\Users\JAMES INGLISH\Desktop\RK_Quarantine
01-07-10 17:5 - 01-07-10 17:5 - 0719 ____A (AVAST Software) C:\Users\JAMES INGLISH\Desktop\aswMBR.exe
01-07-10 17:51 - 01-07-10 17:51 - 01558016 ____A C:\Users\JAMES INGLISH\Desktop\RogueKiller.exe
01-07-10 17:50 - 01-07-10 17:50 - 01558016 ____A C:\Users\JAMES INGLISH\Downloads\RogueKiller.exe
01-07-10 17:7 - 01-07-10 17:7 - 000856 ____A C:\Users\JAMES INGLISH\Desktop\DDS.txt
01-07-10 17:6 - 01-07-10 17:6 - 0001888 ____A C:\Users\JAMES INGLISH\Desktop\Attach.txt
01-07-10 1:58 - 01-07-10 1:58 - 0060760 ____R (Swearware) C:\Users\JAMES INGLISH\Desktop\dds.scr
01-07-10 1:51 - 01-07-10 15: - 00000000 ____A C:\Users\JAMES INGLISH\Desktop\gmer.log
01-07-10 06:1 - 01-07-10 06:15 - 00059 ____A C:\Users\JAMES INGLISH\Desktop\ccep8px.exe
01-07-10 0:51 - 01-08-01 0:51 - 00000959 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
01-07-10 00:6 - 008-01-05 06:5 - 00190 ____A C:\Windows\RegBootClean6.exe
01-07-0 19:57 - 01-07-06 01:5 - 00000000 ____D C:\Users\JAMES INGLISH\Desktop\my phone july 01
01-07-0 19: - 01-07-0 19: - 1765578 ____A C:\Users\JAMES INGLISH\Desktop\01-07-0 09.5..psd
============ Months Modified Files ========================
01-08-01 0:51 - 006-11-0 07: - 0005 ____A C:\Windows\Tasks\SCHEDLGU.TXT
01-08-01 0:51 - 006-11-0 07: - 00000006 ___AH C:\Windows\Tasks\SA.DAT
01-08-01 0:51 - 006-11-0 07: - 000016 ___AH C:\Windows\System\7B96FB0-76B-97e-B01-9C50E1B77-P-1.C7856-A89-9d-8115-6016D005A0
01-08-01 0:51 - 006-11-0 07: - 000016 ___AH C:\Windows\System\7B96FB0-76B-97e-B01-9C50E1B77-P-0.C7856-A89-9d-8115-6016D005A0
01-08-01 0:5 - 010-0-10 08:1 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
01-08-01 0: - 01-05-0 01:8 - 0000080 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
01-08-01 0: - 006-11-0 0:6 - 0085 ____A C:\Windows\System\PerfStringBackup.INI
01-08-01 0: - 01-0-1 17:5 - 00190 ____A C:\Windows\PFRO.log
01-08-01 0:51 - 01-08-01 0:51 - 007110 ____A C:\Windows\is-DSVIL.exe
01-08-01 0:51 - 01-08-01 0:51 - 00010550 ____A C:\Windows\is-DSVIL.msg
01-08-01 0:51 - 01-08-01 0:51 - 0000059 ____A C:\Windows\is-DSVIL.lst
01-08-01 0:51 - 01-07-10 0:51 - 00000959 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
01-07-1 1:59 - 01-05-0 01:8 - 00618 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW6\FlashPlayerApp.exe
01-07-1 1:59 - 011-09-6 1:5 - 00070 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW6\FlashPlayerCPLApp.cpl
01-07-1 18:01 - 009-05- 1:5 - 010781 ____A C:\Windows\WindowsUpdate.log
01-07-10 0:01 - 01-07-10 0:01 - 000017 ____A C:\Users\JAMES INGLISH\Desktop\aswMBR.txt
01-07-10 0:01 - 01-07-10 0:01 - 0000051 ____A C:\Users\JAMES INGLISH\Desktop\MBR.dat
01-07-10 18:0 - 01-07-10 18:0 - 006970 ____A C:\Windows\Minidump\Mini07111-01.dmp
01-07-10 18:0 - 01-0-19 05:15 - 057899 ____A C:\Windows\MEMORY.DMP
01-07-10 17:5 - 01-07-10 17:5 - 00005 ____A C:\Users\JAMES INGLISH\Desktop\RKreport[1].txt
01-07-10 17:5 - 01-07-10 17:5 - 0719 ____A (AVAST Software) C:\Users\JAMES INGLISH\Desktop\aswMBR.exe
01-07-10 17:51 - 01-07-10 17:51 - 01558016 ____A C:\Users\JAMES INGLISH\Desktop\RogueKiller.exe
01-07-10 17:50 - 01-07-10 17:50 - 01558016 ____A C:\Users\JAMES INGLISH\Downloads\RogueKiller.exe
01-07-10 17:7 - 01-07-10 17:7 - 000856 ____A C:\Users\JAMES INGLISH\Desktop\DDS.txt
01-07-10 17:6 - 01-07-10 17:6 - 0001888 ____A C:\Users\JAMES INGLISH\Desktop\Attach.txt
01-07-10 15: - 01-07-10 1:51 - 00000000 ____A C:\Users\JAMES INGLISH\Desktop\gmer.log
01-07-10 1:58 - 01-07-10 1:58 - 0060760 ____R (Swearware) C:\Users\JAMES INGLISH\Desktop\dds.scr
01-07-10 06:15 - 01-07-10 06:1 - 00059 ____A C:\Users\JAMES INGLISH\Desktop\ccep8px.exe
01-07-06 01:50 - 010-10-5 1:6 - 0000006 ____A C:\Users\JAMES INGLISH\AppData\Roaming\Opusbext.dat
01-07-0 19:6 - 010-09-9 0: - 00090 ____A (Malwarebytes Corporation) C:\Windows\System\Drivers\mbam.sys
01-07-0 19: - 01-07-0 19: - 1765578 ____A C:\Users\JAMES INGLISH\Desktop\01-07-0 09.5..psd
01-07-01 01:1 - 01-07-01 01:1 - 168699 ____A C:\Users\JAMES INGLISH\Desktop\01-07-01 16.06.9.psd
01-06-1 15:56 - 01-06-1 15:56 - 00001890 ____A C:\Users\Public\Desktop\Skype.lnk
01-06-1 0:6 - 006-11-0 07:1 - 097816 ____A C:\Windows\System\FNTCACHE.DAT
01-06-1 18: - 006-11-0 0:5 - 589578 ____A (Microsoft Corporation) C:\Windows\System\mrt.exe
01-06-07 1: - 009-07-05 00:1 - 00080 ____A C:\Users\JAMES INGLISH\AppData\Local\DCBCA71-70D8-DAN-EHR8-E0D61DEAFDF.ini
01-06-0 :1 - 01-06-0 :1 - 0079191 ____A C:\Users\JAMES INGLISH\Desktop\Transaction Details - PayPal.mht
01-06-0 1:19 - 01-06-1 00: - 00057880 ____A (Microsoft Corporation) C:\Windows\System\wuauclt.exe
01-06-0 1:19 - 01-06-1 00: - 000056 ____A (Microsoft Corporation) C:\Windows\System\wups.dll
01-06-0 1:19 - 01-06-1 00: - 0895 ____A (Microsoft Corporation) C:\Windows\System\wuaueng.dll
01-06-0 1:19 - 01-06-1 00:10 - 00701976 ____A (Microsoft Corporation) C:\Windows\System\wuapi.dll
01-06-0 1:19 - 01-06-1 00:10 - 0057708 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wuapi.dll
01-06-0 1:19 - 01-06-1 00:10 - 0008 ____A (Microsoft Corporation) C:\Windows\System\wups.dll
01-06-0 1:19 - 01-06-1 00:10 - 000586 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wups.dll
01-06-0 1:15 - 01-06-1 00: - 066 ____A (Microsoft Corporation) C:\Windows\System\wucltux.dll
01-06-0 1:15 - 01-06-1 00:10 - 0009980 ____A (Microsoft Corporation) C:\Windows\System\wudriver.dll
01-06-0 1:1 - 01-06-1 00:10 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wudriver.dll
01-06-01 1:19 - 01-06-0 :59 - 0018675 ____A (Microsoft Corporation) C:\Windows\System\wuwebv.dll
01-06-01 1:19 - 01-06-0 :59 - 0017190 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wuwebv.dll
01-06-01 1:15 - 01-06-0 :59 - 000686 ____A (Microsoft Corporation) C:\Windows\System\wuapp.exe
01-06-01 1:1 - 01-06-0 :59 - 00079 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wuapp.exe
01-05-17 18:7 - 01-06-1 0:01 - 1780760 ____A (Microsoft Corporation) C:\Windows\System\mshtml.dll
01-05-17 18:16 - 01-06-1 0:01 - 1090 ____A (Microsoft Corporation) C:\Windows\System\ieframe.dll
01-05-17 18:06 - 01-06-1 0:01 - 011680 ____A (Microsoft Corporation) C:\Windows\System\jscript9.dll
01-05-17 17:59 - 01-06-1 0:01 - 01918 ____A (Microsoft Corporation) C:\Windows\System\wininet.dll
01-05-17 17:59 - 01-06-1 0:01 - 01608 ____A (Microsoft Corporation) C:\Windows\System\urlmon.dll
01-05-17 17:58 - 01-06-1 0:01 - 01958 ____A (Microsoft Corporation) C:\Windows\System\inetcpl.cpl
01-05-17 17:58 - 01-06-1 0:01 - 007056 ____A (Microsoft Corporation) C:\Windows\System\url.dll
01-05-17 17:56 - 01-06-1 0:01 - 0008550 ____A (Microsoft Corporation) C:\Windows\System\jsproxy.dll
01-05-17 17:55 - 01-06-1 0:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System\jscript.dll
01-05-17 17:55 - 01-06-1 0:01 - 0017056 ____A (Microsoft Corporation) C:\Windows\System\ieUnatt.exe
01-05-17 17:5 - 01-06-1 0:01 - 01768 ____A (Microsoft Corporation) C:\Windows\System\iertutil.dll
01-05-17 17:51 - 01-06-1 0:0 - 0888 ____A (Microsoft Corporation) C:\Windows\System\mshtml.tlb
01-05-17 17:51 - 01-06-1 0:0 - 00096768 ____A (Microsoft Corporation) C:\Windows\System\mshtmled.dll
01-05-17 17:7 - 01-06-1 0:01 - 0080 ____A (Microsoft Corporation) C:\Windows\System\ieui.dll
01-05-17 15:11 - 01-06-1 0:01 - 116 ____A (Microsoft Corporation) C:\Windows\SysWOW6\mshtml.dll
01-05-17 1:8 - 01-06-1 0:01 - 097778 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ieframe.dll
01-05-17 1:5 - 01-06-1 0:01 - 0180019 ____A (Microsoft Corporation) C:\Windows\SysWOW6\jscript9.dll
01-05-17 1:6 - 01-06-1 0:01 - 011087 ____A (Microsoft Corporation) C:\Windows\SysWOW6\urlmon.dll
01-05-17 1:5 - 01-06-1 0:01 - 017968 ____A (Microsoft Corporation) C:\Windows\SysWOW6\inetcpl.cpl
01-05-17 1:5 - 01-06-1 0:01 - 01197 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wininet.dll
01-05-17 1: - 01-06-1 0:01 - 00196 ____A (Microsoft Corporation) C:\Windows\SysWOW6\url.dll
01-05-17 1:1 - 01-06-1 0:01 - 000650 ____A (Microsoft Corporation) C:\Windows\SysWOW6\jsproxy.dll
01-05-17 1:9 - 01-06-1 0:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW6\jscript.dll
01-05-17 1:9 - 01-06-1 0:01 - 00188 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ieUnatt.exe
01-05-17 1:7 - 01-06-1 0:01 - 01790 ____A (Microsoft Corporation) C:\Windows\SysWOW6\iertutil.dll
01-05-17 1:5 - 01-06-1 0:0 - 000716 ____A (Microsoft Corporation) C:\Windows\SysWOW6\mshtmled.dll
01-05-17 1: - 01-06-1 0:0 - 0888 ____A (Microsoft Corporation) C:\Windows\SysWOW6\mshtml.tlb
01-05-17 1:0 - 01-06-1 0:01 - 0017660 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ieui.dll
01-05-15 1:15 - 01-06-1 :0 - 076760 ____A (Microsoft Corporation) C:\Windows\System\wink.sys
01-05-09 :1 - 01-05-07 0: - 00011871 ____A C:\Windows\setupact.log
01-05-07 0: - 01-05-07 0: - 00000000 ____A C:\Windows\setuperr.log
ZeroAccess:
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\@
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\L
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U\00000001.@
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U\800000cb.@
ZeroAccess:
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\@
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\L
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
[008-01-0 18:8] - [008-01-0 18:8] - 06118 ____A (Microsoft Corporation) C:\Windows\System\clbcatq.dll
[008-01-0 18:9] - [008-01-0 18:9] - 05776 ____A (Microsoft Corporation) C:\Windows\SysWOW6\clbcatq.dll
[010-10-1 1:] - [010-06-8 09:1] - 191590 ____A (Microsoft Corporation) C:\Windows\System\ole.dll
[010-10-1 1:] - [010-06-8 09:00] - 11686 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ole.dll
[009-11-0 0:05] - [009-0-10 05:11] - 10657 ____A (Microsoft Corporation) C:\Windows\System\advapi.dll
[009-11-0 0:05] - [009-0-10 0:8] - 0800768 ____A (Microsoft Corporation) C:\Windows\SysWOW6\advapi.dll
[009-11-0 0:07] - [009-0-10 05:11] - 059888 ____A (Microsoft Corporation) C:\Windows\System\COMDLG.dll
[009-11-0 0:07] - [009-0-10 0:8] - 050560 ____A (Microsoft Corporation) C:\Windows\SysWOW6\COMDLG.dll
[009-11-0 0:06] - [009-0-10 05:11] - 0896 ____A (Microsoft Corporation) C:\Windows\System\gdi.dll
[009-11-0 0:06] - [009-0-10 0:6] - 00616 ____A (Microsoft Corporation) C:\Windows\SysWOW6\gdi.dll
[01-06-1 0:01] - [01-05-17 17:5] - 1768 ____A (Microsoft Corporation) C:\Windows\System\IERTUTIL.dll
[01-06-1 0:01] - [01-05-17 1:7] - 1790 ____A (Microsoft Corporation) C:\Windows\SysWOW6\IERTUTIL.dll
[01-0-11 00:] - [01-0-9 07:5] - 007888 ____A (Microsoft Corporation) C:\Windows\System\IMAGEHLP.dll
[01-0-11 00:] - [01-0-9 07:09] - 0157696 ____A (Microsoft Corporation) C:\Windows\SysWOW6\IMAGEHLP.dll
[009-11-0 0:06] - [009-0-10 05:11] - 01680 ____A (Microsoft Corporation) C:\Windows\System\IMM.dll
[009-11-0 0:06] - [009-0-10 0:6] - 0116 ____A (Microsoft Corporation) C:\Windows\SysWOW6\IMM.dll
[011-07-1 :1] - [011-0-1 08:15] - 110880 ____A (Microsoft Corporation) C:\Windows\System\kernel.dll
[011-07-1 :1] - [011-0-1 08:11] - 085968 ____A (Microsoft Corporation) C:\Windows\SysWOW6\kernel.dll
[008-01-0 18:8] - [008-01-0 18:8] - 00768 ____A (Microsoft Corporation) C:\Windows\System\LPK.dll
[009-07-15 1:50] - [009-0-10 :6] - 0055 ____A (Microsoft Corporation) C:\Windows\SysWOW6\LPK.dll
[009-11-0 0:08] - [009-0-10 05:11] - 100896 ____A (Microsoft Corporation) C:\Windows\System\MSCTF.dll
[009-11-0 0:08] - [009-0-10 0:8] - 0807 ____A (Microsoft Corporation) C:\Windows\SysWOW6\MSCTF.dll
[01-0-15 0:09] - [011-1-1 08:8] - 061056 ____A (Microsoft Corporation) C:\Windows\System\MSVCRT.dll
[01-0-15 0:09] - [011-1-1 08:17] - 06808 ____A (Microsoft Corporation) C:\Windows\SysWOW6\MSVCRT.dll
[006-11-0 01:05] - [006-11-0 01:05] - 00007 ____A (Microsoft Corporation) C:\Windows\System\NORMALIZ.dll
[006-11-0 0:17] - [006-11-0 00:] - 000560 ____A (Microsoft Corporation) C:\Windows\SysWOW6\NORMALIZ.dll
[008-01-0 18:9] - [008-01-0 18:9] - 00116 ____A (Microsoft Corporation) C:\Windows\System\NSI.dll
[008-01-0 18:50] - [008-01-0 18:50] - 000819 ____A (Microsoft Corporation) C:\Windows\SysWOW6\NSI.dll
[011-10-1 18:50] - [011-08-5 08:19] - 08760 ____A (Microsoft Corporation) C:\Windows\System\OLEAUT.dll
[011-10-1 18:50] - [011-08-5 08:1] - 05671 ____A (Microsoft Corporation) C:\Windows\SysWOW6\OLEAUT.dll
[009-06-1 0:8] - [009-0- 0:5] - 105600 ____A (Microsoft Corporation) C:\Windows\System\rpcrt.dll
[009-06-1 0:8] - [009-0- 0:15] - 067776 ____A (Microsoft Corporation) C:\Windows\SysWOW6\rpcrt.dll
[009-11-0 0:0] - [009-0-10 05:11] - 19510 ____A (Microsoft Corporation) C:\Windows\System\Setupapi.dll
[009-11-0 0:0] - [009-0-10 0:8] - 159196 ____A (Microsoft Corporation) C:\Windows\SysWOW6\Setupapi.dll
[011-0-10 0:08] - [011-01-1 08:50] - 189980 ____A (Microsoft Corporation) C:\Windows\System\SHELL.dll
[011-0-10 0:08] - [011-01-1 08:5] - 1158608 ____A (Microsoft Corporation) C:\Windows\SysWOW6\SHELL.dll
[011-0-10 0:08] - [011-01-1 08:50] - 05619 ____A (Microsoft Corporation) C:\Windows\System\SHLWAPI.dll
[011-0-10 0:08] - [011-01-1 08:5] - 0580 ____A (Microsoft Corporation) C:\Windows\SysWOW6\SHLWAPI.dll
[01-06-1 0:01] - [01-05-17 17:59] - 1608 ____A (Microsoft Corporation) C:\Windows\System\URLMON.dll
[01-06-1 0:01] - [01-05-17 1:6] - 11087 ____A (Microsoft Corporation) C:\Windows\SysWOW6\URLMON.dll
[009-11-0 0:06] - [009-0-10 05:11] - 080 ____A (Microsoft Corporation) C:\Windows\System\user.dll
[009-11-0 0:06] - [009-0-10 0:6] - 06870 ____A (Microsoft Corporation) C:\Windows\SysWOW6\user.dll
[010-09-1 1:1] - [010-0-16 09:07] - 061568 ____A (Microsoft Corporation) C:\Windows\System\USP10.dll
[010-09-1 1:1] - [010-0-16 08:6] - 0507 ____A (Microsoft Corporation) C:\Windows\SysWOW6\USP10.dll
[01-06-1 0:01] - [01-05-17 17:59] - 1918 ____A (Microsoft Corporation) C:\Windows\System\WININET.dll
[01-06-1 0:01] - [01-05-17 1:5] - 1197 ____A (Microsoft Corporation) C:\Windows\SysWOW6\WININET.dll
[009-11-0 0:0] - [009-0-10 05:11] - 0870 ____A (Microsoft Corporation) C:\Windows\System\WLDAP.dll
[009-11-0 0:0] - [009-0-10 0:8] - 0877 ____A (Microsoft Corporation) C:\Windows\SysWOW6\WLDAP.dll
[009-11-0 0:05] - [009-0-10 05:11] - 0670 ____A (Microsoft Corporation) C:\Windows\System\WS_.dll
[008-01-0 18:50] - [008-01-0 18:50] - 017900 ____A (Microsoft Corporation) C:\Windows\SysWOW6\WS_.dll
========================= Bamital & volsnap Check ============
C:\Windows\System\winlogon.exe => MD5 is legit
C:\Windows\System\wininit.exe => MD5 is legit
C:\Windows\SysWOW6\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW6\explorer.exe => MD5 is legit
C:\Windows\System\svchost.exe => MD5 is legit
C:\Windows\SysWOW6\svchost.exe => MD5 is legit
C:\Windows\System\services.exe BC8115099BD5DBC7A08C5F1FB9 ZeroAccess <==== ATTENTION!.
C:\Windows\System\User.dll => MD5 is legit
C:\Windows\SysWOW6\User.dll => MD5 is legit
C:\Windows\System\userinit.exe => MD5 is legit
C:\Windows\SysWOW6\userinit.exe => MD5 is legit
C:\Windows\System\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 25%
Total physical RAM: 1789.03 MB
Available physical RAM: 1327.41 MB
Total Pagefile: 1609.77 MB
Available Pagefile: 1307.19 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (S3A6815D006) (Fixed) (Total:286.68 GB) (Free:106.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.3 GB) NTFS
4 Drive f: (LEXAR) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3824 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 1500 MB 1024 KB
Partition 2 Primary 287 GB 1501 MB
Partition 3 Primary 10 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E TOSHIBA SYS NTFS Partition 1500 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C S3A6815D006 NTFS Partition 287 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3824 MB 4096 B
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 F LEXAR FAT32 Removable 3824 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-01 04:49
======================= End Of Log ==========================
You helped me about 3 weeks ago now trying to get rid of this virus before my computer crashed on me. I'm now back on line and ready to resume the fix where we left off as no settings on computer have changed from the repair at the old data from the previous thread should still apply. Are we able to reactivate the old thread?? if not here is the last data requested from the Farbar recovery scan tool x 64:
Scan result of Farbar Recovery Scan Tool Version: 10-07-01
Ran by SYSTEM at 01-08-01 :01:50
Running from F:\
Windows Vista (TM) Home Premium Service Pack 1 (X6) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [157160 008-08-1] (Synaptics, Inc.)
HKLM\...\Run: [RtHDVCpl] RAVCpl6.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [1968 008-0-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [5560 007-1-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [5195 007-1-10] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [86580 008-0-18] (TOSHIBA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [50008 010-0-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" -set Silent "1" SplashURL "" [1111568 011-10-08] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [19715 011-0-10] (Trend Micro Inc.)
HKLM-x\...\Run: [NDSTray.exe] NDSTray.exe [x]
HKLM-x\...\Run: [cfFncEnabler.exe] cfFncEnabler.exe [x]
HKLM-x\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [610 008-01-0] (Advanced Micro Devices, Inc.)
HKLM-x\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [1779 008-09-5] (Chicony)
HKLM-x\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office1\BCSSync.exe" /DelayServices [9150 010-0-1] (Microsoft Corporation)
HKLM-x\...\Run: [DATAMNGR] C:\PROGRA~\SEARCH~\Datamngr\DATAMN~1.EXE [169608 01-0-8] (Bandoo Media, inc)
HKLM-x\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [590 011-11-01] (Apple Inc.)
HKLM-x\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [176 011-1-07] (Apple Inc.)
HKLM-x\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [871 01-01-01] (Adobe Systems Incorporated)
HKLM-x\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [5696 01-01-17] (Sun Microsystems, Inc.)
HKLM-x\...\Run: [] [x]
HKLM-x\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1917 01-01-0] (Ask)
HKLM-x\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [96056 01-0-7] (RealNetworks, Inc.)
HKLM-x\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [796 01-0-7] (Adobe Systems Incorporated)
HKLM-x\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [690 01-07-0] (Malwarebytes Corporation)
HKU\Administrator\...\Run: [WindowsWelcomeCenter] rundll.exe oobefldr.dll,ShowWelcomeCenter [8656 009-0-10] (Microsoft Corporation)
HKU\Administrator\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 009-0-10] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll.exe oobefldr.dll,ShowWelcomeCenter [8656 009-0-10] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 009-0-10] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll.exe oobefldr.dll,ShowWelcomeCenter [8656 009-0-10] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\JAMES INGLISH\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [60 008-0-] (TOSHIBA)
HKU\JAMES INGLISH\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [180 008-01-0] (Microsoft Corporation)
HKU\JAMES INGLISH\...\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe [819 011-01-17] ()
HKU\JAMES INGLISH\...\Run: [Akamai NetSession Interface] "C:\Users\JAMES INGLISH\AppData\Local\Akamai\netsession_win.exe" [77 01-05-5] (Akamai Technologies, Inc)
HKU\JAMES INGLISH\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [908 009-05-1] (Google Inc.)
HKU\JAMES INGLISH\...\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s [95579 01-05-0] (Samsung)
HKU\JAMES INGLISH\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [51 01-05-0] (Samsung Electronics Co., Ltd.)
HKU\JAMES INGLISH\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [19 01-05-0] ()
HKU\JAMES INGLISH\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17176 01-06-0] (Skype Technologies S.A.)
HKLM\...\Runonce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM\WerFault.exe -k -rq [x]
HKLM-x\...\RunOnce: [Malwarebytes Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [690 01-07-0] (Malwarebytes Corporation)
HKLM-x\...\RunOnce: [InnoSetupRegFile.0000000001] "C:\Windows\is-DSVIL.exe" /REG /REGSVRMODE [7110 01-08-01] ()
Tcpip\Parameters: [DhcpNameServer] 10.0.0.18
AppInit_DLLs: C:\PROGRA~\SEARCH~\Datamngr\x6\datamngr.dll C:\PROGRA~\SEARCH~\Datamngr\x6\IEBHO.dll C:\PROGRA~\SEARCH~1\SEARCH~1\x6\datamngr.dll C:\PROGRA~\SEARCH~1\SEARCH~1\x6\IEBHO.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HD Writer AE 1.0.lnk
ShortcutTarget: HD Writer AE 1.0.lnk -> C:\Program Files (x86)\Panasonic\HD Writer AE 1\HDWriterAutoStart.exe (Panasonic Corporation)
Startup: C:\Users\JAMES INGLISH\Start Menu\Programs\Startup\Corel Registration.lnk
ShortcutTarget: Corel Registration.lnk -> C:\Program Files (x86)\Corel\Graphics9\Register\Remind.exe (IntelliQuest Communications, Inc.)
==================== Services (Whitelisted) ======
Akamai; C:\program files (x86)\common files\akamai/netsession_win_f7fccd.dll [199 01-07-10] (Akamai Technologies, Inc)
jswpsapi; C:\Program Files (x86)\Jumpstart\jswpsapi.exe [9568 008-0-15] (Atheros Communications, Inc.)
MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [6559 01-07-0] (Malwarebytes Corporation)
MSSQL$MSSMLBIZ; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [9908 010-1-09] (Microsoft Corporation)
MSSQL$SQLEXPRESS; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [9908 010-1-09] (Microsoft Corporation)
TNaviSrv; C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [81 008-0-10] (TOSHIBA Corporation)
TomTomHOMEService; C:\Users\JAMES INGLISH\Downloads\TomTom HOME \TomTomHOMEService.exe [959 011-1-05] (TomTom)
WSWNA100; C:\Program Files (x86)\NETGEAR\WNA100\WifiSvc.exe [8515 010-08-5] ()
Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=qb -dt=60000 [x]
========================== Drivers (Whitelisted) =============
0 ACPI; C:\Windows\System\Drivers\ACPI.sys [5608 009-0-10] (Microsoft Corporation)
adp9xx; C:\Windows\System\Drivers\adp9xx.sys [8656 008-01-0] (Adaptec, Inc.)
adpahci; C:\Windows\System\Drivers\adpahci.sys [58 008-01-0] (Adaptec, Inc.)
adpu160m; C:\Windows\System\Drivers\adpu160m.sys [1650 008-01-0] (Adaptec, Inc.)
adpu0; C:\Windows\System\Drivers\adpu0.sys [18591 008-01-0] (Adaptec, Inc.)
1 AFD; C:\Windows\System\Drivers\AFD.sys [099 01-01-0] (Microsoft Corporation)
agp0; C:\Windows\System\Drivers\agp0.sys [6568 008-01-0] (Microsoft Corporation)
aic78xx; C:\Windows\system\drivers\djsvs.sys [88168 006-11-0] (Adaptec, Inc.)
amdide; C:\Windows\System\Drivers\amdide.sys [15976 008-01-0] (Microsoft Corporation)
AmdK8; C:\Windows\System\Drivers\AmdK8.sys [50688 008-01-0] (Microsoft Corporation)
arc; C:\Windows\System\Drivers\arc.sys [90680 008-01-0] (Adaptec, Inc.)
arcsas; C:\Windows\System\Drivers\arcsas.sys [9119 008-01-0] (Adaptec, Inc.)
AsyncMac; C:\Windows\System\Drivers\AsyncMac.sys [016 008-01-0] (Microsoft Corporation)
0 atapi; C:\Windows\System\Drivers\atapi.sys [095 009-0-10] (Microsoft Corporation)
atikmdag; C:\Windows\System\Drivers\atikmdag.sys [600 008-05-1] (ATI Technologies Inc.)
0 AtiPcie; C:\Windows\System\Drivers\AtiPcie.sys [16656 006-11-07] (ATI Technologies Inc.)
blbdrive; C:\Windows\System\Drivers\blbdrive.sys [5596 008-01-0] (Microsoft Corporation)
bowser; C:\Windows\System\Drivers\bowser.sys [906 011-0-18] (Microsoft Corporation)
BrFiltLo; C:\Windows\System\Drivers\BrFiltLo.sys [18 006-09-18] (Brother Industries, Ltd.)
BrFiltUp; C:\Windows\System\Drivers\BrFiltUp.sys [870 006-09-18] (Brother Industries, Ltd.)
Brserid; C:\Windows\System\Drivers\Brserid.sys [8658 006-11-0] (Brother Industries Ltd.)
BrSerWdm; C:\Windows\System\Drivers\BrSerWdm.sys [710 006-09-18] (Brother Industries Ltd.)
BrUsbMdm; C:\Windows\System\Drivers\BrUsbMdm.sys [1976 006-09-18] (Brother Industries Ltd.)
BrUsbSer; C:\Windows\System\Drivers\BrUsbSer.sys [170 006-09-19] (Brother Industries Ltd.)
BTHMODEM; C:\Windows\System\Drivers\BTHMODEM.sys [50688 006-11-0] (Microsoft Corporation)
cdfs; C:\Windows\System\Drivers\cdfs.sys [906 008-01-0] (Microsoft Corporation)
1 cdrbsdrv; C:\Windows\System\Drivers\cdrbsdrv.sys [908 006-08-] (B.H.A Corporation)
1 cdrom; C:\Windows\System\Drivers\cdrom.sys [7987 009-0-10] (Microsoft Corporation)
circlass; C:\Windows\System\Drivers\circlass.sys [198 008-01-0] (Microsoft Corporation)
CmBatt; C:\Windows\System\Drivers\CmBatt.sys [1779 008-01-0] (Microsoft Corporation)
0 Compbatt; C:\Windows\System\Drivers\Compbatt.sys [608 008-01-0] (Microsoft Corporation)
0 crcdisk; C:\Windows\System\Drivers\crcdisk.sys [770 008-01-0] (Microsoft Corporation)
1 DfsC; C:\Windows\System\Drivers\DfsC.sys [9779 011-0-1] (Microsoft Corporation)
0 disk; C:\Windows\System\Drivers\disk.sys [670 009-0-10] (Microsoft Corporation)
drmkaud; C:\Windows\System\Drivers\drmkaud.sys [61 008-01-0] (Microsoft Corporation)
DXGKrnl; C:\Windows\System\Drivers\DXGKrnl.sys [90080 011-01-0] (Microsoft Corporation)
E1G60; C:\Windows\System\DRIVERS\E1G60E.sys [16176 008-01-0] (Intel Corporation)
0 Ecache; C:\Windows\System\Drivers\Ecache.sys [15511 009-0-10] (Microsoft Corporation)
ErrDev; C:\Windows\System\Drivers\ErrDev.sys [870 008-01-0] (Microsoft Corporation)
exfat; C:\Windows\System\Drivers\exfat.sys [18790 009-0-10] (Microsoft Corporation)
fastfat; C:\Windows\System\Drivers\fastfat.sys [1981 009-0-10] (Microsoft Corporation)
fdc; C:\Windows\System\Drivers\fdc.sys [9696 008-01-0] (Microsoft Corporation)
0 FileInfo; C:\Windows\System\Drivers\FileInfo.sys [7000 008-01-0] (Microsoft Corporation)
Filetrace; C:\Windows\System\Drivers\Filetrace.sys [80 008-01-0] (Microsoft Corporation)
flpydisk; C:\Windows\System\Drivers\flpydisk.sys [576 008-01-0] (Microsoft Corporation)
0 FltMgr; C:\Windows\System\Drivers\FltMgr.sys [75 009-0-10] (Microsoft Corporation)
fssfltr; C:\Windows\System\Drivers\fssfltr.sys [888 010-09-] (Microsoft Corporation)
1 Fs_Rec; C:\Windows\System\Drivers\Fs_Rec.sys [168 01-0-9] (Microsoft Corporation)
FwLnk; C:\Windows\System\Drivers\FwLnk.sys [870 006-11-19] (TOSHIBA Corporation)
gagp0kx; C:\Windows\System\Drivers\gagp0kx.sys [6815 008-01-0] (Microsoft Corporation)
HdAudAddService; C:\Windows\System\drivers\HdAudio.sys [790 006-11-01] (Microsoft Corporation)
HDAudBus; C:\Windows\System\Drivers\HDAudBus.sys [9876 009-0-10] (Microsoft Corporation)
HidBth; C:\Windows\System\Drivers\HidBth.sys [0 006-11-0] (Microsoft Corporation)
HidIr; C:\Windows\System\Drivers\HidIr.sys [5600 006-11-0] (Microsoft Corporation)
HidUsb; C:\Windows\System\Drivers\HidUsb.sys [1587 009-0-10] (Microsoft Corporation)
HpCISSs; C:\Windows\System\Drivers\HpCISSs.sys [767 008-01-0] (Hewlett-Packard Company)
HTTP; C:\Windows\System\Drivers\HTTP.sys [600 010-0-0] (Microsoft Corporation)
iomp; C:\Windows\System\Drivers\iomp.sys [5896 008-01-0] (Microsoft Corporation)
1 i80prt; C:\Windows\System\Drivers\i80prt.sys [6000 008-01-0] (Microsoft Corporation)
iaStorV; C:\Windows\System\Drivers\iaStorV.sys [9087 008-01-0] (Intel Corporation)
iirsp; C:\Windows\System\Drivers\iirsp.sys [68 006-11-0] (Intel Corp./ICP vortex GmbH)
IntcAzAudAddService; C:\Windows\System\drivers\RTKVHD6.sys [196888 008-0-09] (Realtek Semiconductor Corp.)
intelide; C:\Windows\System\Drivers\intelide.sys [1951 008-01-0] (Microsoft Corporation)
intelppm; C:\Windows\System\Drivers\intelppm.sys [818 008-01-0] (Microsoft Corporation)
IpFilterDriver; C:\Windows\System\DRIVERS\ipfltdrv.sys [6758 009-0-10] (Microsoft Corporation)
IPMIDRV; C:\Windows\System\Drivers\IPMIDRV.sys [7688 008-01-0] (Microsoft Corporation)
IPNAT; C:\Windows\System\Drivers\IPNAT.sys [11571 008-01-0] (Microsoft Corporation)
IRENUM; C:\Windows\System\Drivers\IRENUM.sys [1708 008-01-0] (Microsoft Corporation)
isapnp; C:\Windows\System\Drivers\isapnp.sys [608 008-01-0] (Microsoft Corporation)
iScsiPrt; C:\Windows\System\DRIVERS\msiscsi.sys [1558 009-0-10] (Microsoft Corporation)
1 kbdclass; C:\Windows\System\Drivers\kbdclass.sys [00 008-01-0] (Microsoft Corporation)
kbdhid; C:\Windows\System\Drivers\kbdhid.sys [080 008-01-0] (Microsoft Corporation)
0 KSecDD; C:\Windows\System\Drivers\KSecDD.sys [515968 011-11-16] (Microsoft Corporation)
ksthunk; C:\Windows\System\Drivers\ksthunk.sys [086 008-01-0] (Microsoft Corporation)
lltdio; C:\Windows\System\Drivers\lltdio.sys [599 008-01-0] (Microsoft Corporation)
LSI_FC; C:\Windows\System\Drivers\LSI_FC.sys [1170 008-01-0] (LSI Logic)
LSI_SAS; C:\Windows\System\Drivers\LSI_SAS.sys [105016 008-01-0] (LSI Logic)
LSI_SCSI; C:\Windows\System\Drivers\LSI_SCSI.sys [1170 008-01-0] (LSI Logic)
luafv; C:\Windows\System\Drivers\luafv.sys [109568 008-01-0] (Microsoft Corporation)
MBAMProtector; \??\C:\Windows\system\drivers\mbam.sys [90 01-07-0] (Malwarebytes Corporation)
megasas; C:\Windows\System\Drivers\megasas.sys [5896 008-01-0] (LSI Corporation)
MegaSR; C:\Windows\System\Drivers\MegaSR.sys [88 008-01-0] (LSI Corporation, Inc.)
Modem; C:\Windows\System\Drivers\Modem.sys [08 008-01-0] (Microsoft Corporation)
monitor; C:\Windows\System\Drivers\monitor.sys [915 008-01-0] (Microsoft Corporation)
1 mouclass; C:\Windows\System\Drivers\mouclass.sys [999 008-01-0] (Microsoft Corporation)
mouhid; C:\Windows\System\Drivers\mouhid.sys [19968 008-01-0] (Microsoft Corporation)
0 MountMgr; C:\Windows\System\Drivers\MountMgr.sys [7000 008-01-0] (Microsoft Corporation)
mpio; C:\Windows\System\Drivers\mpio.sys [18056 008-01-0] (Microsoft Corporation)
mpsdrv; C:\Windows\System\Drivers\mpsdrv.sys [8108 008-01-0] (Microsoft Corporation)
Mraid5x; C:\Windows\System\Drivers\Mraid5x.sys [9016 006-11-0] (LSI Logic Corporation)
MRxDAV; C:\Windows\System\Drivers\MRxDAV.sys [196 009-0-10] (Microsoft Corporation)
mrxsmb; C:\Windows\System\Drivers\mrxsmb.sys [15680 011-0-9] (Microsoft Corporation)
mrxsmb10; C:\Windows\System\Drivers\mrxsmb10.sys [7556 011-07-06] (Microsoft Corporation)
mrxsmb0; C:\Windows\System\Drivers\mrxsmb0.sys [107008 011-0-9] (Microsoft Corporation)
0 msahci; C:\Windows\System\Drivers\msahci.sys [9656 009-0-10] (Microsoft Corporation)
msdsm; C:\Windows\System\Drivers\msdsm.sys [1170 008-01-0] (Microsoft Corporation)
1 Msfs; C:\Windows\System\Drivers\Msfs.sys [611 008-01-0] (Microsoft Corporation)
0 msisadrv; C:\Windows\System\Drivers\msisadrv.sys [17976 008-01-0] (Microsoft Corporation)
MSKSSRV; C:\Windows\System\Drivers\MSKSSRV.sys [11008 008-01-0] (Microsoft Corporation)
MSPCLOCK; C:\Windows\System\Drivers\MSPCLOCK.sys [700 006-11-0] (Microsoft Corporation)
MSPQM; C:\Windows\System\Drivers\MSPQM.sys [6656 006-11-0] (Microsoft Corporation)
MsRPC; C:\Windows\System\Drivers\MsRPC.sys [10760 009-0-10] (Microsoft Corporation)
mssmbios; C:\Windows\System\Drivers\mssmbios.sys [87 008-01-0] (Microsoft Corporation)
MSTEE; C:\Windows\System\Drivers\MSTEE.sys [796 008-01-0] (Microsoft Corporation)
0 Mup; C:\Windows\System\Drivers\Mup.sys [59880 009-0-10] (Microsoft Corporation)
NativeWifiP; C:\Windows\System\DRIVERS\nwifi.sys [1879 009-0-10] (Microsoft Corporation)
0 NDIS; C:\Windows\System\Drivers\NDIS.sys [786 009-0-10] (Microsoft Corporation)
NdisTapi; C:\Windows\System\Drivers\NdisTapi.sys [06 008-01-0] (Microsoft Corporation)
Ndisuio; C:\Windows\System\Drivers\Ndisuio.sys [016 008-01-0] (Microsoft Corporation)
NdisWan; C:\Windows\System\Drivers\NdisWan.sys [1697 009-0-10] (Microsoft Corporation)
NDProxy; C:\Windows\System\Drivers\NDProxy.sys [5990 008-01-0] (Microsoft Corporation)
1 NetBIOS; C:\Windows\System\Drivers\NetBIOS.sys [5 008-01-0] (Microsoft Corporation)
1 netbt; C:\Windows\System\Drivers\netbt.sys [80 009-0-10] (Microsoft Corporation)
NPF; C:\Windows\System\Drivers\NPF.sys [76 010-0-0] (CACE Technologies, Inc.)
1 Npfs; C:\Windows\System\Drivers\Npfs.sys [5 009-0-10] (Microsoft Corporation)
1 nsiproxy; C:\Windows\System\Drivers\nsiproxy.sys [06 008-01-0] (Microsoft Corporation)
Ntfs; C:\Windows\System\Drivers\Ntfs.sys [151596 009-0-10] (Microsoft Corporation)
1 Null; C:\Windows\System\Drivers\Null.sys [61 006-11-0] (Microsoft Corporation)
nvraid; C:\Windows\System\Drivers\nvraid.sys [18056 008-01-0] (NVIDIA Corporation)
nvstor; C:\Windows\System\Drivers\nvstor.sys [58 008-01-0] (NVIDIA Corporation)
nv_agp; C:\Windows\System\Drivers\nv_agp.sys [1650 008-01-0] (Microsoft Corporation)
ohci19; C:\Windows\System\Drivers\ohci19.sys [78 009-0-10] (Microsoft Corporation)
Parport; C:\Windows\System\Drivers\Parport.sys [96768 006-11-0] (Microsoft Corporation)
0 partmgr; C:\Windows\System\Drivers\partmgr.sys [7576 01-0-0] (Microsoft Corporation)
0 pci; C:\Windows\System\Drivers\pci.sys [17866 009-0-10] (Microsoft Corporation)
0 pciide; C:\Windows\System\Drivers\pciide.sys [11 009-0-10] (Microsoft Corporation)
pcmcia; C:\Windows\System\Drivers\pcmcia.sys [068 006-11-0] (Microsoft Corporation)
PEAUTH; C:\Windows\System\Drivers\PEAUTH.sys [7170 006-10-] (Microsoft Corporation)
PptpMiniport; C:\Windows\System\DRIVERS\raspptp.sys [98816 009-0-10] (Microsoft Corporation)
Processor; C:\Windows\System\DRIVERS\processr.sys [710 008-01-0] (Microsoft Corporation)
1 PSched; C:\Windows\System\DRIVERS\pacer.sys [908 009-0-10] (Microsoft Corporation)
QWAVEdrv; C:\Windows\System\Drivers\QWAVEdrv.sys [659 008-01-0] (Microsoft Corporation)
1 RasAcd; C:\Windows\System\Drivers\RasAcd.sys [188 008-01-0] (Microsoft Corporation)
Rasltp; C:\Windows\System\Drivers\Rasltp.sys [198 009-0-10] (Microsoft Corporation)
RasPppoe; C:\Windows\System\Drivers\RasPppoe.sys [50176 009-0-10] (Microsoft Corporation)
RasSstp; C:\Windows\System\Drivers\RasSstp.sys [786 009-0-10] (Microsoft Corporation)
1 rdbss; C:\Windows\System\Drivers\rdbss.sys [877 009-0-10] (Microsoft Corporation)
1 RDPCDD; C:\Windows\System\Drivers\RDPCDD.sys [7168 008-01-0] (Microsoft Corporation)
rdpdr; C:\Windows\System\Drivers\rdpdr.sys [168 008-01-0] (Microsoft Corporation)
1 RDPENCDD; C:\Windows\System\Drivers\RDPENCDD.sys [7168 008-01-0] (Microsoft Corporation)
RDPWD; C:\Windows\System\Drivers\RDPWD.sys [0990 01-05-01] (Microsoft Corporation)
rimmptsk; C:\Windows\System\DRIVERS\rimmpx6.sys [6976 008-0-1] (REDC)
rimsptsk; C:\Windows\System\DRIVERS\rimspx6.sys [5596 007-07-6] (REDC)
rismxdp; C:\Windows\System\DRIVERS\rixdpx6.sys [57856 007-07-7] (REDC)
rspndr; C:\Windows\System\Drivers\rspndr.sys [75776 008-01-0] (Microsoft Corporation)
RTL8169; C:\Windows\System\DRIVERS\Rtlh6.sys [011 010-01-11] (Realtek )
sbpport; C:\Windows\System\Drivers\sbpport.sys [9016 006-11-0] (Microsoft Corporation)
0 SCMNdisP; C:\Windows\System\Drivers\SCMNdisP.sys [51 007-01-19] (Windows (R) Codename Longhorn DDK provider)
sdbus; C:\Windows\System\Drivers\sdbus.sys [11110 009-0-10] (Microsoft Corporation)
Serenum; C:\Windows\System\Drivers\Serenum.sys [00 006-11-0] (Microsoft Corporation)
Serial; C:\Windows\System\Drivers\Serial.sys [908 006-11-0] (Microsoft Corporation)
sermouse; C:\Windows\System\Drivers\sermouse.sys [66 008-01-0] (Microsoft Corporation)
sffdisk; C:\Windows\System\Drivers\sffdisk.sys [188 009-0-10] (Microsoft Corporation)
sffp_mmc; C:\Windows\System\Drivers\sffp_mmc.sys [16 008-01-0] (Microsoft Corporation)
sffp_sd; C:\Windows\System\Drivers\sffp_sd.sys [18 009-0-10] (Microsoft Corporation)
sfloppy; C:\Windows\System\Drivers\sfloppy.sys [168 006-11-0] (Microsoft Corporation)
1 Smb; C:\Windows\System\Drivers\Smb.sys [8806 009-0-10] (Microsoft Corporation)
0 spldr; C:\Windows\System\Drivers\spldr.sys [19 009-0-10] (Microsoft Corporation)
srv; C:\Windows\System\Drivers\srv.sys [50560 011-0-18] (Microsoft Corporation)
srv; C:\Windows\System\Drivers\srv.sys [17618 011-0-9] (Microsoft Corporation)
srvnet; C:\Windows\System\Drivers\srvnet.sys [1590 011-0-9] (Microsoft Corporation)
swenum; C:\Windows\System\Drivers\swenum.sys [10 008-01-0] (Microsoft Corporation)
Symc8xx; C:\Windows\System\Drivers\Symc8xx.sys [956 006-11-0] (LSI Logic)
Sym_hi; C:\Windows\System\Drivers\Sym_hi.sys [68 006-11-0] (LSI Logic)
Sym_u; C:\Windows\System\Drivers\Sym_u.sys [8 006-11-0] (LSI Logic)
0 Tcpip; C:\Windows\System\Drivers\Tcpip.sys [17 01-0-0] (Microsoft Corporation)
Tcpip6; C:\Windows\System\DRIVERS\tcpip.sys [17 01-0-0] (Microsoft Corporation)
tcpipreg; C:\Windows\System\Drivers\tcpipreg.sys [08 009-1-08] (Microsoft Corporation)
tdcmdpst; C:\Windows\System\Drivers\tdcmdpst.sys [77 007-1-11] (TOSHIBA Corporation.)
TDPIPE; C:\Windows\System\Drivers\TDPIPE.sys [168 008-01-0] (Microsoft Corporation)
TDTCP; C:\Windows\System\Drivers\TDTCP.sys [9696 008-01-0] (Microsoft Corporation)
1 tdx; C:\Windows\System\Drivers\tdx.sys [970 009-0-10] (Microsoft Corporation)
1 TermDD; C:\Windows\System\Drivers\TermDD.sys [60 009-0-10] (Microsoft Corporation)
tmactmon; C:\Windows\System\Drivers\tmactmon.sys [9070 011-0-] (Trend Micro Inc.)
tmcomm; C:\Windows\System\Drivers\tmcomm.sys [16 011-0-] (Trend Micro Inc.)
tmevtmgr; C:\Windows\System\Drivers\tmevtmgr.sys [6766 011-0-] (Trend Micro Inc.)
1 tmtdi; C:\Windows\System\Drivers\tmtdi.sys [10555 011-0-] (Trend Micro Inc.)
0 tos_sps6; C:\Windows\System\Drivers\tos_sps6.sys [51968 008-0-10] (TOSHIBA Corporation)
tssecsrv; C:\Windows\System\Drivers\tssecsrv.sys [918 008-01-0] (Microsoft Corporation)
tunmp; C:\Windows\System\Drivers\tunmp.sys [18 008-01-0] (Microsoft Corporation)
tunnel; C:\Windows\System\Drivers\tunnel.sys [9696 010-0-18] (Microsoft Corporation)
0 TVALZ; C:\Windows\System\DRIVERS\TVALZ_O.SYS [6968 007-11-08] (TOSHIBA Corporation)
uagp5; C:\Windows\System\Drivers\uagp5.sys [6718 008-01-0] (Microsoft Corporation)
udfs; C:\Windows\System\Drivers\udfs.sys [99008 009-0-10] (Microsoft Corporation)
uliagpkx; C:\Windows\System\Drivers\uliagpkx.sys [6815 008-01-0] (Microsoft Corporation)
umbus; C:\Windows\System\Drivers\umbus.sys [198 008-01-0] (Microsoft Corporation)
USBAAPL6; C:\Windows\System\Drivers\USBAAPL6.sys [5171 011-08-01] (Apple, Inc.)
usbccgp; C:\Windows\System\Drivers\usbccgp.sys [957 008-01-0] (Microsoft Corporation)
usbcir; C:\Windows\System\Drivers\usbcir.sys [7960 006-11-0] (Microsoft Corporation)
usbehci; C:\Windows\System\Drivers\usbehci.sys [966 009-0-10] (Microsoft Corporation)
usbhub; C:\Windows\System\Drivers\usbhub.sys [790 009-0-10] (Microsoft Corporation)
usbohci; C:\Windows\System\Drivers\usbohci.sys [06 009-0-10] (Microsoft Corporation)
usbprint; C:\Windows\System\Drivers\usbprint.sys [06 008-01-0] (Microsoft Corporation)
USBSTOR; C:\Windows\System\Drivers\USBSTOR.sys [778 009-0-10] (Microsoft Corporation)
usbuhci; C:\Windows\System\Drivers\usbuhci.sys [918 008-01-0] (Microsoft Corporation)
usbvideo; C:\Windows\System\Drivers\usbvideo.sys [16870 008-01-0] (Microsoft Corporation)
vga; C:\Windows\System\Drivers\vga.sys [867 008-01-0] (Microsoft Corporation)
1 VgaSave; C:\Windows\System\drivers\vga.sys [867 008-01-0] (Microsoft Corporation)
0 volmgr; C:\Windows\System\Drivers\volmgr.sys [6708 009-0-10] (Microsoft Corporation)
0 volmgrx; C:\Windows\System\Drivers\volmgrx.sys [080 009-0-10] (Microsoft Corporation)
WacomPen; C:\Windows\System\Drivers\WacomPen.sys [66 006-11-0] (Microsoft Corporation)
Wanarp; C:\Windows\System\Drivers\Wanarp.sys [8658 009-0-10] (Microsoft Corporation)
1 Wanarpv6; C:\Windows\System\DRIVERS\wanarp.sys [8658 009-0-10] (Microsoft Corporation)
Wd; C:\Windows\System\Drivers\Wd.sys [10 008-01-0] (Microsoft Corporation)
0 Wdf01000; C:\Windows\System\Drivers\Wdf01000.sys [88170 008-01-0] (Microsoft Corporation)
WpdUsb; C:\Windows\System\Drivers\WpdUsb.sys [659 009-09-0] (Microsoft Corporation)
wsifsl; C:\Windows\System\Drivers\wsifsl.sys [099 008-01-0] (Microsoft Corporation)
WUDFRd; C:\Windows\System\Drivers\WUDFRd.sys [1085 008-01-0] (Microsoft Corporation)
DIRECTIO; \??\C:\MCDiags\BIT\DirectIo6.sys [x]
DIRECTIO7; \??\C:\MCDiags\BIT\DirectIo6.sys [x]
IpInIp; C:\Windows\System\DRIVERS\ipinip.sys [x]
NwlnkFlt; C:\Windows\System\DRIVERS\nwlnkflt.sys [x]
NwlnkFwd; C:\Windows\System\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
01-08-01 :01 - 01-08-01 :01 - 00000000 ____D C:\FRST
01-08-01 0:51 - 01-08-01 0:51 - 007110 ____A C:\Windows\is-DSVIL.exe
01-08-01 0:51 - 01-08-01 0:51 - 00010550 ____A C:\Windows\is-DSVIL.msg
01-08-01 0:51 - 01-08-01 0:51 - 0000059 ____A C:\Windows\is-DSVIL.lst
01-07-10 0:01 - 01-07-10 0:01 - 000017 ____A C:\Users\JAMES INGLISH\Desktop\aswMBR.txt
01-07-10 0:01 - 01-07-10 0:01 - 0000051 ____A C:\Users\JAMES INGLISH\Desktop\MBR.dat
01-07-10 18:0 - 01-07-10 18:0 - 006970 ____A C:\Windows\Minidump\Mini07111-01.dmp
01-07-10 17:5 - 01-07-10 17:5 - 00005 ____A C:\Users\JAMES INGLISH\Desktop\RKreport[1].txt
01-07-10 17:5 - 01-07-10 17:5 - 00000000 ____D C:\Users\JAMES INGLISH\Desktop\RK_Quarantine
01-07-10 17:5 - 01-07-10 17:5 - 0719 ____A (AVAST Software) C:\Users\JAMES INGLISH\Desktop\aswMBR.exe
01-07-10 17:51 - 01-07-10 17:51 - 01558016 ____A C:\Users\JAMES INGLISH\Desktop\RogueKiller.exe
01-07-10 17:50 - 01-07-10 17:50 - 01558016 ____A C:\Users\JAMES INGLISH\Downloads\RogueKiller.exe
01-07-10 17:7 - 01-07-10 17:7 - 000856 ____A C:\Users\JAMES INGLISH\Desktop\DDS.txt
01-07-10 17:6 - 01-07-10 17:6 - 0001888 ____A C:\Users\JAMES INGLISH\Desktop\Attach.txt
01-07-10 1:58 - 01-07-10 1:58 - 0060760 ____R (Swearware) C:\Users\JAMES INGLISH\Desktop\dds.scr
01-07-10 1:51 - 01-07-10 15: - 00000000 ____A C:\Users\JAMES INGLISH\Desktop\gmer.log
01-07-10 06:1 - 01-07-10 06:15 - 00059 ____A C:\Users\JAMES INGLISH\Desktop\ccep8px.exe
01-07-10 0:51 - 01-08-01 0:51 - 00000959 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
01-07-10 00:6 - 008-01-05 06:5 - 00190 ____A C:\Windows\RegBootClean6.exe
01-07-0 19:57 - 01-07-06 01:5 - 00000000 ____D C:\Users\JAMES INGLISH\Desktop\my phone july 01
01-07-0 19: - 01-07-0 19: - 1765578 ____A C:\Users\JAMES INGLISH\Desktop\01-07-0 09.5..psd
============ Months Modified Files ========================
01-08-01 0:51 - 006-11-0 07: - 0005 ____A C:\Windows\Tasks\SCHEDLGU.TXT
01-08-01 0:51 - 006-11-0 07: - 00000006 ___AH C:\Windows\Tasks\SA.DAT
01-08-01 0:51 - 006-11-0 07: - 000016 ___AH C:\Windows\System\7B96FB0-76B-97e-B01-9C50E1B77-P-1.C7856-A89-9d-8115-6016D005A0
01-08-01 0:51 - 006-11-0 07: - 000016 ___AH C:\Windows\System\7B96FB0-76B-97e-B01-9C50E1B77-P-0.C7856-A89-9d-8115-6016D005A0
01-08-01 0:5 - 010-0-10 08:1 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
01-08-01 0: - 01-05-0 01:8 - 0000080 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
01-08-01 0: - 006-11-0 0:6 - 0085 ____A C:\Windows\System\PerfStringBackup.INI
01-08-01 0: - 01-0-1 17:5 - 00190 ____A C:\Windows\PFRO.log
01-08-01 0:51 - 01-08-01 0:51 - 007110 ____A C:\Windows\is-DSVIL.exe
01-08-01 0:51 - 01-08-01 0:51 - 00010550 ____A C:\Windows\is-DSVIL.msg
01-08-01 0:51 - 01-08-01 0:51 - 0000059 ____A C:\Windows\is-DSVIL.lst
01-08-01 0:51 - 01-07-10 0:51 - 00000959 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
01-07-1 1:59 - 01-05-0 01:8 - 00618 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW6\FlashPlayerApp.exe
01-07-1 1:59 - 011-09-6 1:5 - 00070 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW6\FlashPlayerCPLApp.cpl
01-07-1 18:01 - 009-05- 1:5 - 010781 ____A C:\Windows\WindowsUpdate.log
01-07-10 0:01 - 01-07-10 0:01 - 000017 ____A C:\Users\JAMES INGLISH\Desktop\aswMBR.txt
01-07-10 0:01 - 01-07-10 0:01 - 0000051 ____A C:\Users\JAMES INGLISH\Desktop\MBR.dat
01-07-10 18:0 - 01-07-10 18:0 - 006970 ____A C:\Windows\Minidump\Mini07111-01.dmp
01-07-10 18:0 - 01-0-19 05:15 - 057899 ____A C:\Windows\MEMORY.DMP
01-07-10 17:5 - 01-07-10 17:5 - 00005 ____A C:\Users\JAMES INGLISH\Desktop\RKreport[1].txt
01-07-10 17:5 - 01-07-10 17:5 - 0719 ____A (AVAST Software) C:\Users\JAMES INGLISH\Desktop\aswMBR.exe
01-07-10 17:51 - 01-07-10 17:51 - 01558016 ____A C:\Users\JAMES INGLISH\Desktop\RogueKiller.exe
01-07-10 17:50 - 01-07-10 17:50 - 01558016 ____A C:\Users\JAMES INGLISH\Downloads\RogueKiller.exe
01-07-10 17:7 - 01-07-10 17:7 - 000856 ____A C:\Users\JAMES INGLISH\Desktop\DDS.txt
01-07-10 17:6 - 01-07-10 17:6 - 0001888 ____A C:\Users\JAMES INGLISH\Desktop\Attach.txt
01-07-10 15: - 01-07-10 1:51 - 00000000 ____A C:\Users\JAMES INGLISH\Desktop\gmer.log
01-07-10 1:58 - 01-07-10 1:58 - 0060760 ____R (Swearware) C:\Users\JAMES INGLISH\Desktop\dds.scr
01-07-10 06:15 - 01-07-10 06:1 - 00059 ____A C:\Users\JAMES INGLISH\Desktop\ccep8px.exe
01-07-06 01:50 - 010-10-5 1:6 - 0000006 ____A C:\Users\JAMES INGLISH\AppData\Roaming\Opusbext.dat
01-07-0 19:6 - 010-09-9 0: - 00090 ____A (Malwarebytes Corporation) C:\Windows\System\Drivers\mbam.sys
01-07-0 19: - 01-07-0 19: - 1765578 ____A C:\Users\JAMES INGLISH\Desktop\01-07-0 09.5..psd
01-07-01 01:1 - 01-07-01 01:1 - 168699 ____A C:\Users\JAMES INGLISH\Desktop\01-07-01 16.06.9.psd
01-06-1 15:56 - 01-06-1 15:56 - 00001890 ____A C:\Users\Public\Desktop\Skype.lnk
01-06-1 0:6 - 006-11-0 07:1 - 097816 ____A C:\Windows\System\FNTCACHE.DAT
01-06-1 18: - 006-11-0 0:5 - 589578 ____A (Microsoft Corporation) C:\Windows\System\mrt.exe
01-06-07 1: - 009-07-05 00:1 - 00080 ____A C:\Users\JAMES INGLISH\AppData\Local\DCBCA71-70D8-DAN-EHR8-E0D61DEAFDF.ini
01-06-0 :1 - 01-06-0 :1 - 0079191 ____A C:\Users\JAMES INGLISH\Desktop\Transaction Details - PayPal.mht
01-06-0 1:19 - 01-06-1 00: - 00057880 ____A (Microsoft Corporation) C:\Windows\System\wuauclt.exe
01-06-0 1:19 - 01-06-1 00: - 000056 ____A (Microsoft Corporation) C:\Windows\System\wups.dll
01-06-0 1:19 - 01-06-1 00: - 0895 ____A (Microsoft Corporation) C:\Windows\System\wuaueng.dll
01-06-0 1:19 - 01-06-1 00:10 - 00701976 ____A (Microsoft Corporation) C:\Windows\System\wuapi.dll
01-06-0 1:19 - 01-06-1 00:10 - 0057708 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wuapi.dll
01-06-0 1:19 - 01-06-1 00:10 - 0008 ____A (Microsoft Corporation) C:\Windows\System\wups.dll
01-06-0 1:19 - 01-06-1 00:10 - 000586 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wups.dll
01-06-0 1:15 - 01-06-1 00: - 066 ____A (Microsoft Corporation) C:\Windows\System\wucltux.dll
01-06-0 1:15 - 01-06-1 00:10 - 0009980 ____A (Microsoft Corporation) C:\Windows\System\wudriver.dll
01-06-0 1:1 - 01-06-1 00:10 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wudriver.dll
01-06-01 1:19 - 01-06-0 :59 - 0018675 ____A (Microsoft Corporation) C:\Windows\System\wuwebv.dll
01-06-01 1:19 - 01-06-0 :59 - 0017190 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wuwebv.dll
01-06-01 1:15 - 01-06-0 :59 - 000686 ____A (Microsoft Corporation) C:\Windows\System\wuapp.exe
01-06-01 1:1 - 01-06-0 :59 - 00079 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wuapp.exe
01-05-17 18:7 - 01-06-1 0:01 - 1780760 ____A (Microsoft Corporation) C:\Windows\System\mshtml.dll
01-05-17 18:16 - 01-06-1 0:01 - 1090 ____A (Microsoft Corporation) C:\Windows\System\ieframe.dll
01-05-17 18:06 - 01-06-1 0:01 - 011680 ____A (Microsoft Corporation) C:\Windows\System\jscript9.dll
01-05-17 17:59 - 01-06-1 0:01 - 01918 ____A (Microsoft Corporation) C:\Windows\System\wininet.dll
01-05-17 17:59 - 01-06-1 0:01 - 01608 ____A (Microsoft Corporation) C:\Windows\System\urlmon.dll
01-05-17 17:58 - 01-06-1 0:01 - 01958 ____A (Microsoft Corporation) C:\Windows\System\inetcpl.cpl
01-05-17 17:58 - 01-06-1 0:01 - 007056 ____A (Microsoft Corporation) C:\Windows\System\url.dll
01-05-17 17:56 - 01-06-1 0:01 - 0008550 ____A (Microsoft Corporation) C:\Windows\System\jsproxy.dll
01-05-17 17:55 - 01-06-1 0:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System\jscript.dll
01-05-17 17:55 - 01-06-1 0:01 - 0017056 ____A (Microsoft Corporation) C:\Windows\System\ieUnatt.exe
01-05-17 17:5 - 01-06-1 0:01 - 01768 ____A (Microsoft Corporation) C:\Windows\System\iertutil.dll
01-05-17 17:51 - 01-06-1 0:0 - 0888 ____A (Microsoft Corporation) C:\Windows\System\mshtml.tlb
01-05-17 17:51 - 01-06-1 0:0 - 00096768 ____A (Microsoft Corporation) C:\Windows\System\mshtmled.dll
01-05-17 17:7 - 01-06-1 0:01 - 0080 ____A (Microsoft Corporation) C:\Windows\System\ieui.dll
01-05-17 15:11 - 01-06-1 0:01 - 116 ____A (Microsoft Corporation) C:\Windows\SysWOW6\mshtml.dll
01-05-17 1:8 - 01-06-1 0:01 - 097778 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ieframe.dll
01-05-17 1:5 - 01-06-1 0:01 - 0180019 ____A (Microsoft Corporation) C:\Windows\SysWOW6\jscript9.dll
01-05-17 1:6 - 01-06-1 0:01 - 011087 ____A (Microsoft Corporation) C:\Windows\SysWOW6\urlmon.dll
01-05-17 1:5 - 01-06-1 0:01 - 017968 ____A (Microsoft Corporation) C:\Windows\SysWOW6\inetcpl.cpl
01-05-17 1:5 - 01-06-1 0:01 - 01197 ____A (Microsoft Corporation) C:\Windows\SysWOW6\wininet.dll
01-05-17 1: - 01-06-1 0:01 - 00196 ____A (Microsoft Corporation) C:\Windows\SysWOW6\url.dll
01-05-17 1:1 - 01-06-1 0:01 - 000650 ____A (Microsoft Corporation) C:\Windows\SysWOW6\jsproxy.dll
01-05-17 1:9 - 01-06-1 0:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW6\jscript.dll
01-05-17 1:9 - 01-06-1 0:01 - 00188 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ieUnatt.exe
01-05-17 1:7 - 01-06-1 0:01 - 01790 ____A (Microsoft Corporation) C:\Windows\SysWOW6\iertutil.dll
01-05-17 1:5 - 01-06-1 0:0 - 000716 ____A (Microsoft Corporation) C:\Windows\SysWOW6\mshtmled.dll
01-05-17 1: - 01-06-1 0:0 - 0888 ____A (Microsoft Corporation) C:\Windows\SysWOW6\mshtml.tlb
01-05-17 1:0 - 01-06-1 0:01 - 0017660 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ieui.dll
01-05-15 1:15 - 01-06-1 :0 - 076760 ____A (Microsoft Corporation) C:\Windows\System\wink.sys
01-05-09 :1 - 01-05-07 0: - 00011871 ____A C:\Windows\setupact.log
01-05-07 0: - 01-05-07 0: - 00000000 ____A C:\Windows\setuperr.log
ZeroAccess:
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\@
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\L
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U\00000001.@
C:\Windows\Installer\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U\800000cb.@
ZeroAccess:
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\@
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\L
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U
C:\Users\JAMES INGLISH\AppData\Local\{5c17f1d0-966-e7cf-8ec-be005d187f5}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
[008-01-0 18:8] - [008-01-0 18:8] - 06118 ____A (Microsoft Corporation) C:\Windows\System\clbcatq.dll
[008-01-0 18:9] - [008-01-0 18:9] - 05776 ____A (Microsoft Corporation) C:\Windows\SysWOW6\clbcatq.dll
[010-10-1 1:] - [010-06-8 09:1] - 191590 ____A (Microsoft Corporation) C:\Windows\System\ole.dll
[010-10-1 1:] - [010-06-8 09:00] - 11686 ____A (Microsoft Corporation) C:\Windows\SysWOW6\ole.dll
[009-11-0 0:05] - [009-0-10 05:11] - 10657 ____A (Microsoft Corporation) C:\Windows\System\advapi.dll
[009-11-0 0:05] - [009-0-10 0:8] - 0800768 ____A (Microsoft Corporation) C:\Windows\SysWOW6\advapi.dll
[009-11-0 0:07] - [009-0-10 05:11] - 059888 ____A (Microsoft Corporation) C:\Windows\System\COMDLG.dll
[009-11-0 0:07] - [009-0-10 0:8] - 050560 ____A (Microsoft Corporation) C:\Windows\SysWOW6\COMDLG.dll
[009-11-0 0:06] - [009-0-10 05:11] - 0896 ____A (Microsoft Corporation) C:\Windows\System\gdi.dll
[009-11-0 0:06] - [009-0-10 0:6] - 00616 ____A (Microsoft Corporation) C:\Windows\SysWOW6\gdi.dll
[01-06-1 0:01] - [01-05-17 17:5] - 1768 ____A (Microsoft Corporation) C:\Windows\System\IERTUTIL.dll
[01-06-1 0:01] - [01-05-17 1:7] - 1790 ____A (Microsoft Corporation) C:\Windows\SysWOW6\IERTUTIL.dll
[01-0-11 00:] - [01-0-9 07:5] - 007888 ____A (Microsoft Corporation) C:\Windows\System\IMAGEHLP.dll
[01-0-11 00:] - [01-0-9 07:09] - 0157696 ____A (Microsoft Corporation) C:\Windows\SysWOW6\IMAGEHLP.dll
[009-11-0 0:06] - [009-0-10 05:11] - 01680 ____A (Microsoft Corporation) C:\Windows\System\IMM.dll
[009-11-0 0:06] - [009-0-10 0:6] - 0116 ____A (Microsoft Corporation) C:\Windows\SysWOW6\IMM.dll
[011-07-1 :1] - [011-0-1 08:15] - 110880 ____A (Microsoft Corporation) C:\Windows\System\kernel.dll
[011-07-1 :1] - [011-0-1 08:11] - 085968 ____A (Microsoft Corporation) C:\Windows\SysWOW6\kernel.dll
[008-01-0 18:8] - [008-01-0 18:8] - 00768 ____A (Microsoft Corporation) C:\Windows\System\LPK.dll
[009-07-15 1:50] - [009-0-10 :6] - 0055 ____A (Microsoft Corporation) C:\Windows\SysWOW6\LPK.dll
[009-11-0 0:08] - [009-0-10 05:11] - 100896 ____A (Microsoft Corporation) C:\Windows\System\MSCTF.dll
[009-11-0 0:08] - [009-0-10 0:8] - 0807 ____A (Microsoft Corporation) C:\Windows\SysWOW6\MSCTF.dll
[01-0-15 0:09] - [011-1-1 08:8] - 061056 ____A (Microsoft Corporation) C:\Windows\System\MSVCRT.dll
[01-0-15 0:09] - [011-1-1 08:17] - 06808 ____A (Microsoft Corporation) C:\Windows\SysWOW6\MSVCRT.dll
[006-11-0 01:05] - [006-11-0 01:05] - 00007 ____A (Microsoft Corporation) C:\Windows\System\NORMALIZ.dll
[006-11-0 0:17] - [006-11-0 00:] - 000560 ____A (Microsoft Corporation) C:\Windows\SysWOW6\NORMALIZ.dll
[008-01-0 18:9] - [008-01-0 18:9] - 00116 ____A (Microsoft Corporation) C:\Windows\System\NSI.dll
[008-01-0 18:50] - [008-01-0 18:50] - 000819 ____A (Microsoft Corporation) C:\Windows\SysWOW6\NSI.dll
[011-10-1 18:50] - [011-08-5 08:19] - 08760 ____A (Microsoft Corporation) C:\Windows\System\OLEAUT.dll
[011-10-1 18:50] - [011-08-5 08:1] - 05671 ____A (Microsoft Corporation) C:\Windows\SysWOW6\OLEAUT.dll
[009-06-1 0:8] - [009-0- 0:5] - 105600 ____A (Microsoft Corporation) C:\Windows\System\rpcrt.dll
[009-06-1 0:8] - [009-0- 0:15] - 067776 ____A (Microsoft Corporation) C:\Windows\SysWOW6\rpcrt.dll
[009-11-0 0:0] - [009-0-10 05:11] - 19510 ____A (Microsoft Corporation) C:\Windows\System\Setupapi.dll
[009-11-0 0:0] - [009-0-10 0:8] - 159196 ____A (Microsoft Corporation) C:\Windows\SysWOW6\Setupapi.dll
[011-0-10 0:08] - [011-01-1 08:50] - 189980 ____A (Microsoft Corporation) C:\Windows\System\SHELL.dll
[011-0-10 0:08] - [011-01-1 08:5] - 1158608 ____A (Microsoft Corporation) C:\Windows\SysWOW6\SHELL.dll
[011-0-10 0:08] - [011-01-1 08:50] - 05619 ____A (Microsoft Corporation) C:\Windows\System\SHLWAPI.dll
[011-0-10 0:08] - [011-01-1 08:5] - 0580 ____A (Microsoft Corporation) C:\Windows\SysWOW6\SHLWAPI.dll
[01-06-1 0:01] - [01-05-17 17:59] - 1608 ____A (Microsoft Corporation) C:\Windows\System\URLMON.dll
[01-06-1 0:01] - [01-05-17 1:6] - 11087 ____A (Microsoft Corporation) C:\Windows\SysWOW6\URLMON.dll
[009-11-0 0:06] - [009-0-10 05:11] - 080 ____A (Microsoft Corporation) C:\Windows\System\user.dll
[009-11-0 0:06] - [009-0-10 0:6] - 06870 ____A (Microsoft Corporation) C:\Windows\SysWOW6\user.dll
[010-09-1 1:1] - [010-0-16 09:07] - 061568 ____A (Microsoft Corporation) C:\Windows\System\USP10.dll
[010-09-1 1:1] - [010-0-16 08:6] - 0507 ____A (Microsoft Corporation) C:\Windows\SysWOW6\USP10.dll
[01-06-1 0:01] - [01-05-17 17:59] - 1918 ____A (Microsoft Corporation) C:\Windows\System\WININET.dll
[01-06-1 0:01] - [01-05-17 1:5] - 1197 ____A (Microsoft Corporation) C:\Windows\SysWOW6\WININET.dll
[009-11-0 0:0] - [009-0-10 05:11] - 0870 ____A (Microsoft Corporation) C:\Windows\System\WLDAP.dll
[009-11-0 0:0] - [009-0-10 0:8] - 0877 ____A (Microsoft Corporation) C:\Windows\SysWOW6\WLDAP.dll
[009-11-0 0:05] - [009-0-10 05:11] - 0670 ____A (Microsoft Corporation) C:\Windows\System\WS_.dll
[008-01-0 18:50] - [008-01-0 18:50] - 017900 ____A (Microsoft Corporation) C:\Windows\SysWOW6\WS_.dll
========================= Bamital & volsnap Check ============
C:\Windows\System\winlogon.exe => MD5 is legit
C:\Windows\System\wininit.exe => MD5 is legit
C:\Windows\SysWOW6\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW6\explorer.exe => MD5 is legit
C:\Windows\System\svchost.exe => MD5 is legit
C:\Windows\SysWOW6\svchost.exe => MD5 is legit
C:\Windows\System\services.exe BC8115099BD5DBC7A08C5F1FB9 ZeroAccess <==== ATTENTION!.
C:\Windows\System\User.dll => MD5 is legit
C:\Windows\SysWOW6\User.dll => MD5 is legit
C:\Windows\System\userinit.exe => MD5 is legit
C:\Windows\SysWOW6\userinit.exe => MD5 is legit
C:\Windows\System\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 25%
Total physical RAM: 1789.03 MB
Available physical RAM: 1327.41 MB
Total Pagefile: 1609.77 MB
Available Pagefile: 1307.19 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (S3A6815D006) (Fixed) (Total:286.68 GB) (Free:106.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.3 GB) NTFS
4 Drive f: (LEXAR) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3824 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 1500 MB 1024 KB
Partition 2 Primary 287 GB 1501 MB
Partition 3 Primary 10 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E TOSHIBA SYS NTFS Partition 1500 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C S3A6815D006 NTFS Partition 287 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3824 MB 4096 B
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 F LEXAR FAT32 Removable 3824 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-01 04:49
======================= End Of Log ==========================