stormgarde
Posts: 8 +0
Seeing a lot of posts like these, not sure if mine is the same as any of the others...
I am usually pretty good with this stuff. This one has me stumped though. It started with hearing ads playing in the background when nothing was running (I.e. computer booted up, heard an ad for the new spiderman movie without even opening anything). Did a few scans with superantispyware, malwarebytes, and ccleaner. Found some trojans, negligible cookies, and a rootkit. Upon restarting after cleaning the infections, my desktop icons have aligned to the side of the monitor and when I move them and hit refresh, they go right back to where they were before. upon doing some research it would seem that the rootkit is the culprit... I have not dealt with one of these before, and it would seem that cleaning it did not repair the damage it caused.
I checked up on some other programs and noticed that microsoft security essentials apaprently disappeared, and I am unable to enable windows defender. So I downloaded MSE (again?) and started scanning with it. about 15 minutes into the scan it threw the critical problem error and is now stuck in a boot loop.
so that brings me here where apparently this is a hot topic, and from the looks of it you request a farbar log, which I have provided below. This is beyond my virus cleaning capabilities. Please help! Also if you see any unnecessary stuff running, feel free to give me some pointers on clearing them up. The computer is ~4 years old, but still a near-top-of-the-line gaming computer and I would like to have it running at full capacity again.
Scan result of Farbar Recovery Scan Tool Version: 14-08-2012
Ran by SYSTEM at 13-08-2012 19:15:46
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2342800 2009-06-01] (Microsoft Corporation)
HKLM\...\Run: [RunDLLEntry] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry [16896 2007-11-23] (Creative Technology Ltd.)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1680976 2010-10-28] (Logitech, Inc.)
HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [5889816 2011-12-07] (Logitech Inc.)
HKLM\...\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe -expressboot [384232 2012-07-12] (BillP Studios)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry [x]
HKLM-x32\...\Run: [CTSysVol] C:\Program Files (x86)\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r [57344 2005-02-15] (Creative Technology Ltd)
HKLM-x32\...\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{EC6D5F08-1694-431F-8200-3B0A8A61AC5A}\AMBSPISyncService.exe /StartRunKey [1233199 2008-08-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641704 2012-06-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot [384232 2012-07-12] (BillP Studios)
HKU\Will\...\Run: [AdobeBridge] [x]
HKU\Will\...\Run: [Google Update] "C:\Users\Will\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-16] (Google Inc.)
HKU\Will\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5661056 2012-07-09] (SUPERAntiSpyware.com)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\Will\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
==================== Services (Whitelisted) ======
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com)
3 Adobe Version Cue CS4; "C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" -win32service [284016 2008-08-15] (Adobe Systems Incorporated)
2 AEADIFilters; C:\Windows\System32\AEADISRV.EXE [111616 2009-09-17] (Andrea Electronics Corporation)
2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2011-12-06] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
4 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2010-05-24] ()
========================== Drivers (Whitelisted) =============
3 ADIHdAudAddService; C:\Windows\System32\drivers\ADIHdAud.sys [478208 2009-09-17] (Analog Devices, Inc.)
3 AODDriver4.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
2 AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [14392 2007-12-17] ()
3 L6PODX3LV; C:\Windows\System32\Drivers\L6PODX3LV64.sys [770816 2010-09-07] (Line 6)
3 MCfilt; C:\Windows\System32\drivers\MCfilt64.sys [25600 2009-09-17] (Creative Technology Ltd.)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
3 P17; C:\Windows\System32\Drivers\P17.sys [1309696 2009-10-16] (Creative Technology Ltd.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-23] (Duplex Secure Ltd.)
3 ALSysIO; \??\C:\Users\Will\AppData\Local\Temp\ALSysIO64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 19:14 - 2012-08-13 19:15 - 00000000 ____D C:\FRST
2012-08-13 18:06 - 2012-08-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0B6E413111EA478
2012-08-13 18:06 - 2012-08-13 18:06 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uyganlrc.sys
2012-08-13 18:02 - 2012-08-13 18:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B24BF0B1C2B09403
2012-08-13 17:55 - 2012-08-13 17:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D4E46280C8B8F45
2012-08-13 17:50 - 2012-08-13 17:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37EFFD7460A91135
2012-08-13 17:41 - 2012-08-13 17:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB7654E947CB0EFE
2012-08-13 17:27 - 2012-08-13 17:27 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-13 17:27 - 2012-08-13 17:27 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-13 17:27 - 2012-08-13 17:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-13 17:25 - 2012-08-13 17:26 - 12621696 ____A (Microsoft Corporation) C:\Users\Will\Downloads\mseinstall.exe
2012-08-13 17:24 - 2012-08-13 17:28 - 00004199 ____A C:\Windows\WindowsUpdate.log
2012-08-13 17:16 - 2012-08-13 17:16 - 00000000 ____D C:\Users\Will\AppData\Roaming\WinPatrol
2012-08-13 17:16 - 2012-08-13 17:16 - 00000000 ____D C:\Users\All Users\InstallMate
2012-08-13 17:16 - 2012-08-13 17:16 - 00000000 ____D C:\Program Files (x86)\BillP Studios
2012-08-13 17:09 - 2012-08-13 17:09 - 00885448 ____A (BillP Studios) C:\Users\Will\Downloads\wpsetup.exe
2012-08-13 16:55 - 2012-08-13 16:55 - 00000000 ____D C:\Program Files (x86)\ESET
2012-08-13 16:45 - 2012-08-13 16:45 - 00607260 ____A (Swearware) C:\Users\Will\Downloads\dds.com
2012-08-13 16:44 - 2012-08-13 16:44 - 00881494 ____A C:\Users\Will\Downloads\SecurityCheck.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00050477 ____A C:\Users\Will\Downloads\Defogger.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00000650 ____A C:\Users\Will\Downloads\defogger_disable.log
2012-08-13 16:41 - 2012-08-13 16:41 - 00000188 ____A C:\Users\Will\defogger_reenable
2012-08-13 16:35 - 2012-08-13 16:35 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-13 16:30 - 2012-08-13 16:31 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Will\Downloads\tdsskiller.exe
2012-08-12 05:24 - 2012-08-12 05:24 - 00001651 ____A C:\Users\Will\Desktop\Wow - Shortcut.lnk
2012-08-12 04:39 - 2012-08-13 17:43 - 00000726 ____A C:\Windows\PFRO.log
2012-08-12 00:00 - 2012-08-13 18:04 - 00001288 ____A C:\Windows\setupact.log
2012-08-12 00:00 - 2012-08-12 00:00 - 00000000 ____A C:\Windows\setuperr.log
2012-08-11 22:23 - 2012-08-11 22:23 - 03907920 ____A (Piriform Ltd) C:\Users\Will\Downloads\ccsetup321.exe
2012-08-11 22:15 - 2012-08-11 22:15 - 00000000 ____D C:\Users\Will\AppData\Roaming\SUPERAntiSpyware.com
2012-08-11 22:15 - 2012-08-11 22:15 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-08-11 22:15 - 2012-08-11 22:15 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-08-11 22:13 - 2012-08-11 22:14 - 19113832 ____A (SUPERAntiSpyware.com) C:\Users\Will\Downloads\SUPERAntiSpyware.exe
2012-08-07 16:40 - 2012-08-07 16:40 - 00000000 ____D C:\Users\All Users\ATI
2012-08-07 16:40 - 2012-08-07 16:40 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-08-07 16:23 - 2012-08-07 16:29 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\Will\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-07-28 09:34 - 2012-07-28 09:35 - 00000000 ____D C:\Users\Will\Documents\lifted_ultimate_guitar_songs
2012-07-16 16:28 - 2012-08-13 17:38 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001UA.job
2012-07-16 16:28 - 2012-08-13 16:38 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001Core.job
2012-07-15 09:45 - 2012-07-15 09:45 - 00000000 ____D C:\Users\Will\Downloads\Interface368
2012-07-14 17:30 - 2012-07-14 17:31 - 00000000 ____D C:\Users\Will\AppData\Roaming\TS3Client
2012-07-14 17:30 - 2012-07-14 17:30 - 00000000 ____D C:\Users\Will\AppData\Roaming\ts3overlay
2012-07-14 17:29 - 2012-07-14 17:29 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
============ 3 Months Modified Files ========================
2012-08-13 18:06 - 2012-08-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0B6E413111EA478
2012-08-13 18:06 - 2012-08-13 18:06 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uyganlrc.sys
2012-08-13 18:04 - 2012-08-12 00:00 - 00001288 ____A C:\Windows\setupact.log
2012-08-13 18:04 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 18:02 - 2012-08-13 18:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B24BF0B1C2B09403
2012-08-13 17:58 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-13 17:55 - 2012-08-13 17:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D4E46280C8B8F45
2012-08-13 17:52 - 2012-04-07 16:10 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-13 17:50 - 2012-08-13 17:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37EFFD7460A91135
2012-08-13 17:43 - 2012-08-12 04:39 - 00000726 ____A C:\Windows\PFRO.log
2012-08-13 17:41 - 2012-08-13 17:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB7654E947CB0EFE
2012-08-13 17:38 - 2012-07-16 16:28 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001UA.job
2012-08-13 17:28 - 2012-08-13 17:24 - 00004199 ____A C:\Windows\WindowsUpdate.log
2012-08-13 17:27 - 2012-08-13 17:27 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-13 17:27 - 2010-05-24 13:31 - 00760780 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-13 17:26 - 2012-08-13 17:25 - 12621696 ____A (Microsoft Corporation) C:\Users\Will\Downloads\mseinstall.exe
2012-08-13 17:09 - 2012-08-13 17:09 - 00885448 ____A (BillP Studios) C:\Users\Will\Downloads\wpsetup.exe
2012-08-13 16:49 - 2009-07-13 20:45 - 00015344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-13 16:49 - 2009-07-13 20:45 - 00015344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-13 16:45 - 2012-08-13 16:45 - 00607260 ____A (Swearware) C:\Users\Will\Downloads\dds.com
2012-08-13 16:44 - 2012-08-13 16:44 - 00881494 ____A C:\Users\Will\Downloads\SecurityCheck.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00050477 ____A C:\Users\Will\Downloads\Defogger.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00000650 ____A C:\Users\Will\Downloads\defogger_disable.log
2012-08-13 16:41 - 2012-08-13 16:41 - 00000188 ____A C:\Users\Will\defogger_reenable
2012-08-13 16:38 - 2012-07-16 16:28 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001Core.job
2012-08-13 16:31 - 2012-08-13 16:30 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Will\Downloads\tdsskiller.exe
2012-08-12 05:24 - 2012-08-12 05:24 - 00001651 ____A C:\Users\Will\Desktop\Wow - Shortcut.lnk
2012-08-12 00:00 - 2012-08-12 00:00 - 00000000 ____A C:\Windows\setuperr.log
2012-08-11 22:23 - 2012-08-11 22:23 - 03907920 ____A (Piriform Ltd) C:\Users\Will\Downloads\ccsetup321.exe
2012-08-11 22:14 - 2012-08-11 22:13 - 19113832 ____A (SUPERAntiSpyware.com) C:\Users\Will\Downloads\SUPERAntiSpyware.exe
2012-08-11 17:16 - 2009-07-13 21:13 - 00743686 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-07 16:29 - 2012-08-07 16:23 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\Will\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-08-07 13:39 - 2009-07-13 20:45 - 03303728 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-03 18:52 - 2012-04-07 16:10 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 18:52 - 2011-05-15 07:19 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-25 06:09 - 2012-01-13 19:47 - 00003158 ____A C:\Users\Will\Documents\dragon_soul_tank_guide.txt
2012-07-16 16:28 - 2010-05-21 19:59 - 00117504 ____A C:\Users\Will\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-12 16:30 - 2010-12-02 18:32 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-07-10 20:49 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-10 20:46 - 2010-05-25 22:37 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-06 18:17 - 2012-07-06 18:17 - 01287016 ____A (Microsoft Corporation) C:\Users\Will\Downloads\wlsetup-web.exe
2012-07-04 12:12 - 2012-07-04 12:12 - 00000427 ____A C:\Users\Will\Downloads\61166.torrent
2012-07-03 12:46 - 2011-11-26 11:15 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-27 20:34 - 2012-06-27 20:34 - 00061440 ____A C:\Windows\SysWOW64\nvPhotoshopUtil.dll
2012-06-27 20:34 - 2012-06-27 20:34 - 00040960 ____A C:\Windows\SysWOW64\nvISWOW64.dll
2012-06-27 20:34 - 2012-06-27 20:33 - 18518446 ____A (InstallShield Software Corporation) C:\Users\Will\Downloads\Photoshop_Plugins_x64_8.54.0625.1800.exe
2012-06-27 20:34 - 2012-06-27 20:32 - 00151552 ____A C:\Windows\SysWOW64\nvRegDev.dll
2012-06-27 20:33 - 2012-06-27 20:33 - 01815240 ____A (InstallShield Software Corporation) C:\Users\Will\Downloads\DDS_viewer.exe
2012-06-27 20:32 - 2012-06-27 20:31 - 10690888 ____A (InstallShield Software Corporation) C:\Users\Will\Downloads\DDS_Utilities_8.31.1127.1645.exe
2012-06-24 15:49 - 2012-06-24 15:49 - 00013895 ____A C:\Users\Will\Downloads\BSA_Unpacker-4804-1-0.rar
2012-06-24 09:55 - 2012-06-24 09:55 - 00000146 ____A C:\Users\Will\Desktop\Sound - Shortcut.lnk
2012-06-15 06:57 - 2012-06-15 06:57 - 00001070 ____A C:\Users\Will\Documents - Shortcut.lnk
2012-06-14 20:16 - 2012-06-14 17:49 - 3442802688 ____A C:\Users\Will\Downloads\air-nexus2.iso
2012-06-11 19:08 - 2012-07-10 20:49 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 12:50 - 2012-06-11 12:50 - 16457728 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-06-11 12:50 - 2012-06-11 12:50 - 00075264 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-06-11 12:49 - 2012-06-11 12:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-06-11 10:59 - 2012-06-11 10:59 - 10248192 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00070144 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:29 - 2011-12-05 19:18 - 24826368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:24 - 2012-06-11 09:24 - 00924160 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-06-11 09:23 - 2010-08-04 00:54 - 01090560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00532992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00239616 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 09:16 - 2012-06-11 09:16 - 06301696 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-06-11 09:01 - 2010-08-04 00:37 - 06914560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-06-11 08:51 - 2011-01-26 14:32 - 04246528 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-06-11 08:50 - 2012-06-11 08:50 - 02936864 ____A C:\Windows\System32\atiumd6a.cap
2012-06-11 08:45 - 2012-06-11 08:45 - 15703040 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 05480448 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-06-11 08:43 - 2012-06-11 08:43 - 04729344 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-06-11 08:36 - 2011-01-26 14:21 - 06605824 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-06-11 08:27 - 2011-12-05 18:13 - 00539136 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00367616 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:26 - 2011-12-05 18:12 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-06-11 08:26 - 2011-12-05 18:12 - 00017920 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00042496 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-06-11 08:25 - 2011-01-26 14:12 - 00045056 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-06-11 08:25 - 2010-04-06 17:22 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-06-10 16:38 - 2012-06-10 16:38 - 16474544 ____A (Nullsoft, Inc.) C:\Users\Will\Downloads\winamp5623_full_emusic-7plus_all.exe
2012-06-09 20:33 - 2012-06-09 20:33 - 03862112 ____A (Piriform Ltd) C:\Users\Will\Downloads\ccsetup319.exe
2012-06-08 21:43 - 2012-07-10 20:08 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 20:08 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 20:08 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 20:08 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 20:08 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 20:08 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 20:08 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 20:08 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-23 06:16 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-23 06:16 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-23 06:16 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-23 06:16 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 20:45 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 20:45 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 20:45 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 20:45 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 20:45 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 20:45 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 20:45 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 20:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 20:45 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 20:45 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 20:45 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 20:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 20:45 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 20:45 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 20:45 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 20:45 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 20:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 20:45 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 20:45 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 20:45 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 20:45 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 20:45 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 20:45 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 20:45 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 20:45 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 20:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 20:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 20:45 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 20:08 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 20:08 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 20:08 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 20:08 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 20:08 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 20:08 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 20:08 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 20:08 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 20:08 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-25 14:30 - 2012-05-25 14:30 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_lgSSQVGA_01_00_00.Wdf
2012-05-25 14:30 - 2012-05-25 14:30 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_lgSSBW_01_00_00.Wdf
2012-05-21 06:01 - 2012-05-20 13:07 - 00000290 ____A C:\Users\Will\Documents\diablo_3_barbarian_tank_setup.txt
ZeroAccess:
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\@
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\L
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U\00000001.@
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U\80000000.@
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U\800000cb.@
ZeroAccess:
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\@
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\L
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16382.18 MB
Available physical RAM: 15175.64 MB
Total Pagefile: 16380.33 MB
Available Pagefile: 15184.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:596.07 GB) (Free:80.43 GB) NTFS
2 Drive e: (GRMCHPXFREO_EN_DVD) (CDROM) (Total:3 GB) (Free:0 GB) UDF
3 Drive f: (CORSAIR) (Removable) (Total:14.93 GB) (Free:14.93 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 596 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 596 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F CORSAIR FAT32 Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-08-07 05:30
======================= End Of Log ==========================
I am usually pretty good with this stuff. This one has me stumped though. It started with hearing ads playing in the background when nothing was running (I.e. computer booted up, heard an ad for the new spiderman movie without even opening anything). Did a few scans with superantispyware, malwarebytes, and ccleaner. Found some trojans, negligible cookies, and a rootkit. Upon restarting after cleaning the infections, my desktop icons have aligned to the side of the monitor and when I move them and hit refresh, they go right back to where they were before. upon doing some research it would seem that the rootkit is the culprit... I have not dealt with one of these before, and it would seem that cleaning it did not repair the damage it caused.
I checked up on some other programs and noticed that microsoft security essentials apaprently disappeared, and I am unable to enable windows defender. So I downloaded MSE (again?) and started scanning with it. about 15 minutes into the scan it threw the critical problem error and is now stuck in a boot loop.
so that brings me here where apparently this is a hot topic, and from the looks of it you request a farbar log, which I have provided below. This is beyond my virus cleaning capabilities. Please help! Also if you see any unnecessary stuff running, feel free to give me some pointers on clearing them up. The computer is ~4 years old, but still a near-top-of-the-line gaming computer and I would like to have it running at full capacity again.
Scan result of Farbar Recovery Scan Tool Version: 14-08-2012
Ran by SYSTEM at 13-08-2012 19:15:46
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2342800 2009-06-01] (Microsoft Corporation)
HKLM\...\Run: [RunDLLEntry] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry [16896 2007-11-23] (Creative Technology Ltd.)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1680976 2010-10-28] (Logitech, Inc.)
HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [5889816 2011-12-07] (Logitech Inc.)
HKLM\...\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe -expressboot [384232 2012-07-12] (BillP Studios)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry [x]
HKLM-x32\...\Run: [CTSysVol] C:\Program Files (x86)\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r [57344 2005-02-15] (Creative Technology Ltd)
HKLM-x32\...\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{EC6D5F08-1694-431F-8200-3B0A8A61AC5A}\AMBSPISyncService.exe /StartRunKey [1233199 2008-08-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641704 2012-06-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot [384232 2012-07-12] (BillP Studios)
HKU\Will\...\Run: [AdobeBridge] [x]
HKU\Will\...\Run: [Google Update] "C:\Users\Will\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-16] (Google Inc.)
HKU\Will\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5661056 2012-07-09] (SUPERAntiSpyware.com)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\Will\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
==================== Services (Whitelisted) ======
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com)
3 Adobe Version Cue CS4; "C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" -win32service [284016 2008-08-15] (Adobe Systems Incorporated)
2 AEADIFilters; C:\Windows\System32\AEADISRV.EXE [111616 2009-09-17] (Andrea Electronics Corporation)
2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2011-12-06] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
4 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2010-05-24] ()
========================== Drivers (Whitelisted) =============
3 ADIHdAudAddService; C:\Windows\System32\drivers\ADIHdAud.sys [478208 2009-09-17] (Analog Devices, Inc.)
3 AODDriver4.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
2 AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [14392 2007-12-17] ()
3 L6PODX3LV; C:\Windows\System32\Drivers\L6PODX3LV64.sys [770816 2010-09-07] (Line 6)
3 MCfilt; C:\Windows\System32\drivers\MCfilt64.sys [25600 2009-09-17] (Creative Technology Ltd.)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
3 P17; C:\Windows\System32\Drivers\P17.sys [1309696 2009-10-16] (Creative Technology Ltd.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-23] (Duplex Secure Ltd.)
3 ALSysIO; \??\C:\Users\Will\AppData\Local\Temp\ALSysIO64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 19:14 - 2012-08-13 19:15 - 00000000 ____D C:\FRST
2012-08-13 18:06 - 2012-08-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0B6E413111EA478
2012-08-13 18:06 - 2012-08-13 18:06 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uyganlrc.sys
2012-08-13 18:02 - 2012-08-13 18:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B24BF0B1C2B09403
2012-08-13 17:55 - 2012-08-13 17:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D4E46280C8B8F45
2012-08-13 17:50 - 2012-08-13 17:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37EFFD7460A91135
2012-08-13 17:41 - 2012-08-13 17:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB7654E947CB0EFE
2012-08-13 17:27 - 2012-08-13 17:27 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-13 17:27 - 2012-08-13 17:27 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-13 17:27 - 2012-08-13 17:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-13 17:25 - 2012-08-13 17:26 - 12621696 ____A (Microsoft Corporation) C:\Users\Will\Downloads\mseinstall.exe
2012-08-13 17:24 - 2012-08-13 17:28 - 00004199 ____A C:\Windows\WindowsUpdate.log
2012-08-13 17:16 - 2012-08-13 17:16 - 00000000 ____D C:\Users\Will\AppData\Roaming\WinPatrol
2012-08-13 17:16 - 2012-08-13 17:16 - 00000000 ____D C:\Users\All Users\InstallMate
2012-08-13 17:16 - 2012-08-13 17:16 - 00000000 ____D C:\Program Files (x86)\BillP Studios
2012-08-13 17:09 - 2012-08-13 17:09 - 00885448 ____A (BillP Studios) C:\Users\Will\Downloads\wpsetup.exe
2012-08-13 16:55 - 2012-08-13 16:55 - 00000000 ____D C:\Program Files (x86)\ESET
2012-08-13 16:45 - 2012-08-13 16:45 - 00607260 ____A (Swearware) C:\Users\Will\Downloads\dds.com
2012-08-13 16:44 - 2012-08-13 16:44 - 00881494 ____A C:\Users\Will\Downloads\SecurityCheck.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00050477 ____A C:\Users\Will\Downloads\Defogger.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00000650 ____A C:\Users\Will\Downloads\defogger_disable.log
2012-08-13 16:41 - 2012-08-13 16:41 - 00000188 ____A C:\Users\Will\defogger_reenable
2012-08-13 16:35 - 2012-08-13 16:35 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-13 16:30 - 2012-08-13 16:31 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Will\Downloads\tdsskiller.exe
2012-08-12 05:24 - 2012-08-12 05:24 - 00001651 ____A C:\Users\Will\Desktop\Wow - Shortcut.lnk
2012-08-12 04:39 - 2012-08-13 17:43 - 00000726 ____A C:\Windows\PFRO.log
2012-08-12 00:00 - 2012-08-13 18:04 - 00001288 ____A C:\Windows\setupact.log
2012-08-12 00:00 - 2012-08-12 00:00 - 00000000 ____A C:\Windows\setuperr.log
2012-08-11 22:23 - 2012-08-11 22:23 - 03907920 ____A (Piriform Ltd) C:\Users\Will\Downloads\ccsetup321.exe
2012-08-11 22:15 - 2012-08-11 22:15 - 00000000 ____D C:\Users\Will\AppData\Roaming\SUPERAntiSpyware.com
2012-08-11 22:15 - 2012-08-11 22:15 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-08-11 22:15 - 2012-08-11 22:15 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-08-11 22:13 - 2012-08-11 22:14 - 19113832 ____A (SUPERAntiSpyware.com) C:\Users\Will\Downloads\SUPERAntiSpyware.exe
2012-08-07 16:40 - 2012-08-07 16:40 - 00000000 ____D C:\Users\All Users\ATI
2012-08-07 16:40 - 2012-08-07 16:40 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-08-07 16:23 - 2012-08-07 16:29 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\Will\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-07-28 09:34 - 2012-07-28 09:35 - 00000000 ____D C:\Users\Will\Documents\lifted_ultimate_guitar_songs
2012-07-16 16:28 - 2012-08-13 17:38 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001UA.job
2012-07-16 16:28 - 2012-08-13 16:38 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001Core.job
2012-07-15 09:45 - 2012-07-15 09:45 - 00000000 ____D C:\Users\Will\Downloads\Interface368
2012-07-14 17:30 - 2012-07-14 17:31 - 00000000 ____D C:\Users\Will\AppData\Roaming\TS3Client
2012-07-14 17:30 - 2012-07-14 17:30 - 00000000 ____D C:\Users\Will\AppData\Roaming\ts3overlay
2012-07-14 17:29 - 2012-07-14 17:29 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
============ 3 Months Modified Files ========================
2012-08-13 18:06 - 2012-08-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A0B6E413111EA478
2012-08-13 18:06 - 2012-08-13 18:06 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uyganlrc.sys
2012-08-13 18:04 - 2012-08-12 00:00 - 00001288 ____A C:\Windows\setupact.log
2012-08-13 18:04 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 18:02 - 2012-08-13 18:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B24BF0B1C2B09403
2012-08-13 17:58 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-13 17:55 - 2012-08-13 17:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D4E46280C8B8F45
2012-08-13 17:52 - 2012-04-07 16:10 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-13 17:50 - 2012-08-13 17:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37EFFD7460A91135
2012-08-13 17:43 - 2012-08-12 04:39 - 00000726 ____A C:\Windows\PFRO.log
2012-08-13 17:41 - 2012-08-13 17:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB7654E947CB0EFE
2012-08-13 17:38 - 2012-07-16 16:28 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001UA.job
2012-08-13 17:28 - 2012-08-13 17:24 - 00004199 ____A C:\Windows\WindowsUpdate.log
2012-08-13 17:27 - 2012-08-13 17:27 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-13 17:27 - 2010-05-24 13:31 - 00760780 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-13 17:26 - 2012-08-13 17:25 - 12621696 ____A (Microsoft Corporation) C:\Users\Will\Downloads\mseinstall.exe
2012-08-13 17:09 - 2012-08-13 17:09 - 00885448 ____A (BillP Studios) C:\Users\Will\Downloads\wpsetup.exe
2012-08-13 16:49 - 2009-07-13 20:45 - 00015344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-13 16:49 - 2009-07-13 20:45 - 00015344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-13 16:45 - 2012-08-13 16:45 - 00607260 ____A (Swearware) C:\Users\Will\Downloads\dds.com
2012-08-13 16:44 - 2012-08-13 16:44 - 00881494 ____A C:\Users\Will\Downloads\SecurityCheck.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00050477 ____A C:\Users\Will\Downloads\Defogger.exe
2012-08-13 16:41 - 2012-08-13 16:41 - 00000650 ____A C:\Users\Will\Downloads\defogger_disable.log
2012-08-13 16:41 - 2012-08-13 16:41 - 00000188 ____A C:\Users\Will\defogger_reenable
2012-08-13 16:38 - 2012-07-16 16:28 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2922222807-1611373505-41519391-1001Core.job
2012-08-13 16:31 - 2012-08-13 16:30 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Will\Downloads\tdsskiller.exe
2012-08-12 05:24 - 2012-08-12 05:24 - 00001651 ____A C:\Users\Will\Desktop\Wow - Shortcut.lnk
2012-08-12 00:00 - 2012-08-12 00:00 - 00000000 ____A C:\Windows\setuperr.log
2012-08-11 22:23 - 2012-08-11 22:23 - 03907920 ____A (Piriform Ltd) C:\Users\Will\Downloads\ccsetup321.exe
2012-08-11 22:14 - 2012-08-11 22:13 - 19113832 ____A (SUPERAntiSpyware.com) C:\Users\Will\Downloads\SUPERAntiSpyware.exe
2012-08-11 17:16 - 2009-07-13 21:13 - 00743686 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-07 16:29 - 2012-08-07 16:23 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\Will\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-08-07 13:39 - 2009-07-13 20:45 - 03303728 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-03 18:52 - 2012-04-07 16:10 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 18:52 - 2011-05-15 07:19 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-25 06:09 - 2012-01-13 19:47 - 00003158 ____A C:\Users\Will\Documents\dragon_soul_tank_guide.txt
2012-07-16 16:28 - 2010-05-21 19:59 - 00117504 ____A C:\Users\Will\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-12 16:30 - 2010-12-02 18:32 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-07-10 20:49 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-10 20:46 - 2010-05-25 22:37 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-06 18:17 - 2012-07-06 18:17 - 01287016 ____A (Microsoft Corporation) C:\Users\Will\Downloads\wlsetup-web.exe
2012-07-04 12:12 - 2012-07-04 12:12 - 00000427 ____A C:\Users\Will\Downloads\61166.torrent
2012-07-03 12:46 - 2011-11-26 11:15 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-27 20:34 - 2012-06-27 20:34 - 00061440 ____A C:\Windows\SysWOW64\nvPhotoshopUtil.dll
2012-06-27 20:34 - 2012-06-27 20:34 - 00040960 ____A C:\Windows\SysWOW64\nvISWOW64.dll
2012-06-27 20:34 - 2012-06-27 20:33 - 18518446 ____A (InstallShield Software Corporation) C:\Users\Will\Downloads\Photoshop_Plugins_x64_8.54.0625.1800.exe
2012-06-27 20:34 - 2012-06-27 20:32 - 00151552 ____A C:\Windows\SysWOW64\nvRegDev.dll
2012-06-27 20:33 - 2012-06-27 20:33 - 01815240 ____A (InstallShield Software Corporation) C:\Users\Will\Downloads\DDS_viewer.exe
2012-06-27 20:32 - 2012-06-27 20:31 - 10690888 ____A (InstallShield Software Corporation) C:\Users\Will\Downloads\DDS_Utilities_8.31.1127.1645.exe
2012-06-24 15:49 - 2012-06-24 15:49 - 00013895 ____A C:\Users\Will\Downloads\BSA_Unpacker-4804-1-0.rar
2012-06-24 09:55 - 2012-06-24 09:55 - 00000146 ____A C:\Users\Will\Desktop\Sound - Shortcut.lnk
2012-06-15 06:57 - 2012-06-15 06:57 - 00001070 ____A C:\Users\Will\Documents - Shortcut.lnk
2012-06-14 20:16 - 2012-06-14 17:49 - 3442802688 ____A C:\Users\Will\Downloads\air-nexus2.iso
2012-06-11 19:08 - 2012-07-10 20:49 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 12:50 - 2012-06-11 12:50 - 16457728 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-06-11 12:50 - 2012-06-11 12:50 - 00075264 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-06-11 12:49 - 2012-06-11 12:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-06-11 10:59 - 2012-06-11 10:59 - 10248192 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00070144 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:29 - 2011-12-05 19:18 - 24826368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:24 - 2012-06-11 09:24 - 00924160 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-06-11 09:23 - 2010-08-04 00:54 - 01090560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00532992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00239616 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 09:16 - 2012-06-11 09:16 - 06301696 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-06-11 09:01 - 2010-08-04 00:37 - 06914560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-06-11 08:51 - 2011-01-26 14:32 - 04246528 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-06-11 08:50 - 2012-06-11 08:50 - 02936864 ____A C:\Windows\System32\atiumd6a.cap
2012-06-11 08:45 - 2012-06-11 08:45 - 15703040 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 05480448 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-06-11 08:43 - 2012-06-11 08:43 - 04729344 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-06-11 08:36 - 2011-01-26 14:21 - 06605824 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-06-11 08:27 - 2011-12-05 18:13 - 00539136 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00367616 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:26 - 2011-12-05 18:12 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-06-11 08:26 - 2011-12-05 18:12 - 00017920 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00042496 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-06-11 08:25 - 2011-01-26 14:12 - 00045056 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-06-11 08:25 - 2010-04-06 17:22 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-06-10 16:38 - 2012-06-10 16:38 - 16474544 ____A (Nullsoft, Inc.) C:\Users\Will\Downloads\winamp5623_full_emusic-7plus_all.exe
2012-06-09 20:33 - 2012-06-09 20:33 - 03862112 ____A (Piriform Ltd) C:\Users\Will\Downloads\ccsetup319.exe
2012-06-08 21:43 - 2012-07-10 20:08 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 20:08 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 20:08 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 20:08 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 20:08 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 20:08 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 20:08 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 20:08 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-23 06:16 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-23 06:16 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-23 06:16 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-23 06:16 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-23 06:16 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 20:45 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 20:45 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 20:45 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 20:45 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 20:45 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 20:45 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 20:45 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 20:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 20:45 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 20:45 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 20:45 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 20:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 20:45 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 20:45 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 20:45 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 20:45 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 20:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 20:45 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 20:45 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 20:45 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 20:45 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 20:45 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 20:45 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 20:45 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 20:45 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 20:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 20:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 20:45 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 20:08 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 20:08 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 20:08 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 20:08 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 20:08 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 20:08 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 20:08 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 20:08 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 20:08 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-25 14:30 - 2012-05-25 14:30 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_lgSSQVGA_01_00_00.Wdf
2012-05-25 14:30 - 2012-05-25 14:30 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_lgSSBW_01_00_00.Wdf
2012-05-21 06:01 - 2012-05-20 13:07 - 00000290 ____A C:\Users\Will\Documents\diablo_3_barbarian_tank_setup.txt
ZeroAccess:
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\@
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\L
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U\00000001.@
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U\80000000.@
C:\Windows\Installer\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U\800000cb.@
ZeroAccess:
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\@
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\L
C:\Users\Will\AppData\Local\{fced1ba1-e047-b75d-b9a3-bc3eb4af449b}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16382.18 MB
Available physical RAM: 15175.64 MB
Total Pagefile: 16380.33 MB
Available Pagefile: 15184.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:596.07 GB) (Free:80.43 GB) NTFS
2 Drive e: (GRMCHPXFREO_EN_DVD) (CDROM) (Total:3 GB) (Free:0 GB) UDF
3 Drive f: (CORSAIR) (Removable) (Total:14.93 GB) (Free:14.93 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 596 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 596 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F CORSAIR FAT32 Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-08-07 05:30
======================= End Of Log ==========================