SyracuseTech
Posts: 11 +0
I have a computer I am fixing for a friend that has the two viruses on it. It is causing the computer to crash because of a critical error about 1 minute into getting in Windows. MSE is not able to get rid of the virus. Below is my Frst.txt file, and thank you in advance for the help with this annoying virus.
[FONT=Calibri]Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 20-07-2012 01[/FONT]
[FONT=Calibri]Ran by SYSTEM at 24-07-2012 09:31:25[/FONT]
[FONT=Calibri]Running from E:\[/FONT]
[FONT=Calibri]Windows 7 Professional Service Pack 1 (X86) OS Language: English(US) [/FONT]
[FONT=Calibri]The current controlset is ControlSet002[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================== Registry (Whitelisted) =============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [3444736 2007-12-08] (Dell Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [288040 2010-04-05] (Alps Electric Co., Ltd.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [39792 2008-01-11] (Adobe Systems Incorporated)[/FONT]
[FONT=Calibri]HKLM\...\Run: [DLCCCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16 [73728 2006-02-24] ()[/FONT]
[FONT=Calibri]HKLM\...\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [431600 2007-01-29] (Dell)[/FONT]
[FONT=Calibri]HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)[/FONT]
[FONT=Calibri]HKU\KWright\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)[/FONT]
[FONT=Calibri]Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)[/FONT]
[FONT=Calibri]Tcpip\Parameters: [DhcpNameServer] 71.243.0.12 68.237.161.12[/FONT]
[FONT=Calibri]Startup: C:\Users\KWright\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk[/FONT]
[FONT=Calibri]ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]================================ Services (Whitelisted) ==================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]2 dlcc_device; C:\Windows\system32\dlcccoms.exe -service [538096 2007-01-29] ( )[/FONT]
[FONT=Calibri]2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)[/FONT]
[FONT=Calibri]2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)[/FONT]
[FONT=Calibri]2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe" [335872 2006-10-26] (Microsoft Corporation)[/FONT]
[FONT=Calibri]2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x][/FONT]
[FONT=Calibri]3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x][/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================== Drivers (Whitelisted) =============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)[/FONT]
[FONT=Calibri]3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-07-21] ()[/FONT]
[FONT=Calibri]0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)[/FONT]
[FONT=Calibri]3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()[/FONT]
[FONT=Calibri]3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [x][/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================== NetSvcs (Whitelisted) ===========[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]============ One Month Created Files and Folders ==============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]2012-07-24 09:31 - 2012-07-24 09:31 - 00000000 ____D C:\FRST[/FONT]
[FONT=Calibri]2012-07-24 05:23 - 2012-07-24 05:23 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ihotufes.sys[/FONT]
[FONT=Calibri]2012-07-23 12:55 - 2012-07-24 08:49 - 00000000 ____D C:\Windows\Microsoft Antimalware[/FONT]
[FONT=Calibri]2012-07-23 09:18 - 2012-07-23 09:18 - 00000000 ____D C:\TDSSKiller_Quarantine[/FONT]
[FONT=Calibri]2012-07-23 02:23 - 2012-07-23 04:27 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0[/FONT]
[FONT=Calibri]2012-07-21 11:40 - 2012-07-21 11:40 - 00000000 ____D C:\Program Files\Microsoft Security Client[/FONT]
[FONT=Calibri]2012-07-21 11:39 - 2012-07-21 11:39 - 00040776 ____A C:\Windows\System32\Drivers\mbamswissarmy.sys[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-18 16:28 - 00001077 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-18 16:28 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-03 09:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys[/FONT]
[FONT=Calibri]2012-07-11 14:13 - 2012-07-11 14:13 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\xiksufkh.sys[/FONT]
[FONT=Calibri]2012-07-11 14:13 - 2012-07-11 14:13 - 00000000 ____D C:\Users\KWright\AppData\Roaming\GetRightToGo[/FONT]
[FONT=Calibri]2012-07-11 10:25 - 2012-07-24 05:22 - 00004882 ____A C:\Windows\setupact.log[/FONT]
[FONT=Calibri]2012-07-11 10:25 - 2012-07-11 10:25 - 00000000 ____A C:\Windows\setuperr.log[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll[/FONT]
[FONT=Calibri]2012-07-11 07:35 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll[/FONT]
[FONT=Calibri]2012-07-02 16:57 - 2012-07-02 16:57 - 00000000 ____D C:\Users\KWright\AppData\Roaming\Sony[/FONT]
[FONT=Calibri]2012-07-02 16:56 - 2012-07-02 16:56 - 00001903 ____A C:\Users\Public\Desktop\Photo Go 1.0.lnk[/FONT]
[FONT=Calibri]2012-07-02 16:56 - 2012-07-02 16:56 - 00000000 ____D C:\Program Files\Sony[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 11:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 11:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]============ 3 Months Modified Files ========================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]2012-07-24 05:23 - 2012-07-24 05:23 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ihotufes.sys[/FONT]
[FONT=Calibri]2012-07-24 05:23 - 2012-03-05 14:28 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job[/FONT]
[FONT=Calibri]2012-07-24 05:22 - 2012-07-11 10:25 - 00004882 ____A C:\Windows\setupact.log[/FONT]
[FONT=Calibri]2012-07-24 05:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT[/FONT]
[FONT=Calibri]2012-07-24 05:17 - 2009-07-13 20:34 - 00021504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0[/FONT]
[FONT=Calibri]2012-07-24 05:17 - 2009-07-13 20:34 - 00021504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0[/FONT]
[FONT=Calibri]2012-07-24 05:10 - 2012-02-28 15:15 - 01430456 ____A C:\Windows\WindowsUpdate.log[/FONT]
[FONT=Calibri]2012-07-21 11:41 - 2012-02-28 16:11 - 00001945 ____A C:\Windows\epplauncher.mif[/FONT]
[FONT=Calibri]2012-07-21 11:40 - 2010-11-20 13:01 - 00747538 ____A C:\Windows\System32\PerfStringBackup.INI[/FONT]
[FONT=Calibri]2012-07-21 11:39 - 2012-07-21 11:39 - 00040776 ____A C:\Windows\System32\Drivers\mbamswissarmy.sys[/FONT]
[FONT=Calibri]2012-07-21 10:44 - 2012-03-05 14:28 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-18 16:28 - 00001077 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[/FONT]
[FONT=Calibri]2012-07-14 06:25 - 2010-11-20 13:48 - 00016862 ____A C:\Windows\PFRO.log[/FONT]
[FONT=Calibri]2012-07-13 12:31 - 2009-07-13 20:33 - 00409752 ____A C:\Windows\System32\FNTCACHE.DAT[/FONT]
[FONT=Calibri]2012-07-13 09:50 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe[/FONT]
[FONT=Calibri]2012-07-11 14:13 - 2012-07-11 14:13 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\xiksufkh.sys[/FONT]
[FONT=Calibri]2012-07-11 10:25 - 2012-07-11 10:25 - 00000000 ____A C:\Windows\setuperr.log[/FONT]
[FONT=Calibri]2012-07-11 07:37 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini[/FONT]
[FONT=Calibri]2012-07-11 07:35 - 2012-02-28 13:08 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe[/FONT]
[FONT=Calibri]2012-07-03 09:46 - 2012-07-18 16:28 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys[/FONT]
[FONT=Calibri]2012-07-02 16:56 - 2012-07-02 16:56 - 00001903 ____A C:\Users\Public\Desktop\Photo Go 1.0.lnk[/FONT]
[FONT=Calibri]2012-06-27 03:14 - 2009-07-13 20:53 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT[/FONT]
[FONT=Calibri]2012-06-15 17:23 - 2012-06-15 17:23 - 00000079 ____A C:\DVDPATH.TXT[/FONT]
[FONT=Calibri]2012-06-12 20:18 - 2012-02-28 12:57 - 00008688 ____A C:\Windows\IE9_main.log[/FONT]
[FONT=Calibri]2012-06-12 17:47 - 2012-06-12 17:46 - 00005862 ____A C:\Windows\System32\commonpriv.log[/FONT]
[FONT=Calibri]2012-06-12 17:46 - 2012-06-12 17:46 - 00000000 ____A C:\Windows\System32\commonpriv.log.lock[/FONT]
[FONT=Calibri]2012-06-11 18:40 - 2012-07-11 07:35 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys[/FONT]
[FONT=Calibri]2012-06-08 20:41 - 2012-07-10 11:35 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll[/FONT]
[FONT=Calibri]2012-06-08 18:55 - 2012-06-08 18:55 - 00034764 ____A C:\Users\KWright\AppData\Local\dt.dat[/FONT]
[FONT=Calibri]2012-06-08 13:33 - 2012-06-08 13:33 - 00912860 ____A C:\Users\KWright\Desktop\Attachments_2012_06_8tourdecure.zip[/FONT]
[FONT=Calibri]2012-06-08 13:33 - 2012-06-08 12:10 - 02442050 ____A C:\Users\KWright\Desktop\Attachments_2012_06_8.zip[/FONT]
[FONT=Calibri]2012-06-05 21:05 - 2012-07-10 11:35 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll[/FONT]
[FONT=Calibri]2012-06-05 21:05 - 2012-07-10 11:35 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll[/FONT]
[FONT=Calibri]2012-06-05 21:03 - 2012-07-10 11:35 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll[/FONT]
[FONT=Calibri]2012-06-05 17:32 - 2012-06-05 17:32 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe[/FONT]
[FONT=Calibri]2012-06-05 17:32 - 2012-02-28 16:24 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl[/FONT]
[FONT=Calibri]2012-06-04 17:52 - 2012-06-04 17:52 - 05189608 ____A C:\Users\KWright\Desktop\DisneyPhotopass3565902-1.zip[/FONT]
[FONT=Calibri]2012-06-04 16:15 - 2012-06-04 16:15 - 00952631 ____A C:\Users\KWright\Desktop\Disney Photo.zip[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll[/FONT]
[FONT=Calibri]2012-06-02 14:12 - 2012-06-24 13:17 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll[/FONT]
[FONT=Calibri]2012-06-02 14:12 - 2012-06-24 13:17 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll[/FONT]
[FONT=Calibri]2012-06-02 11:19 - 2012-06-24 13:17 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll[/FONT]
[FONT=Calibri]2012-06-02 11:12 - 2012-06-24 13:17 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe[/FONT]
[FONT=Calibri]2012-06-02 01:07 - 2012-07-11 07:38 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll[/FONT]
[FONT=Calibri]2012-06-02 00:43 - 2012-07-11 07:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll[/FONT]
[FONT=Calibri]2012-06-02 00:33 - 2012-07-11 07:38 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll[/FONT]
[FONT=Calibri]2012-06-02 00:26 - 2012-07-11 07:38 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll[/FONT]
[FONT=Calibri]2012-06-02 00:25 - 2012-07-11 07:38 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl[/FONT]
[FONT=Calibri]2012-06-02 00:25 - 2012-07-11 07:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll[/FONT]
[FONT=Calibri]2012-06-02 00:23 - 2012-07-11 07:38 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll[/FONT]
[FONT=Calibri]2012-06-02 00:21 - 2012-07-11 07:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll[/FONT]
[FONT=Calibri]2012-06-02 00:20 - 2012-07-11 07:38 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe[/FONT]
[FONT=Calibri]2012-06-02 00:19 - 2012-07-11 07:38 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll[/FONT]
[FONT=Calibri]2012-06-02 00:19 - 2012-07-11 07:38 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll[/FONT]
[FONT=Calibri]2012-06-02 00:17 - 2012-07-11 07:38 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll[/FONT]
[FONT=Calibri]2012-06-02 00:16 - 2012-07-11 07:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb[/FONT]
[FONT=Calibri]2012-06-02 00:14 - 2012-07-11 07:38 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll[/FONT]
[FONT=Calibri]2012-06-01 20:45 - 2012-07-10 11:35 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys[/FONT]
[FONT=Calibri]2012-06-01 20:45 - 2012-07-10 11:35 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys[/FONT]
[FONT=Calibri]2012-06-01 20:40 - 2012-07-10 11:35 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys[/FONT]
[FONT=Calibri]2012-06-01 20:40 - 2012-07-10 11:35 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll[/FONT]
[FONT=Calibri]2012-06-01 20:39 - 2012-07-10 11:35 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll[/FONT]
[FONT=Calibri]2012-05-14 21:23 - 2012-05-14 21:23 - 00952631 ____A C:\Users\KWright\Desktop\Digital Download Entitlement 4x6 format (3503553).zip[/FONT]
[FONT=Calibri]2012-05-14 21:22 - 2012-05-14 21:22 - 00952631 ____A C:\Users\KWright\Downloads\Digital Download Entitlement 4x6 format (3503553).zip[/FONT]
[FONT=Calibri]2012-05-05 19:30 - 2012-05-05 19:30 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf[/FONT]
[FONT=Calibri]2012-04-30 20:44 - 2012-06-13 07:08 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll[/FONT]
[FONT=Calibri]2012-04-27 19:17 - 2012-06-13 07:08 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]ZeroAccess:[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\00000004.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\00000004.@.vir[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\1afb2d56[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\201d3dde[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\00000004.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\00000008.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\000000cb.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\80000000.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\80000032.@[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]ZeroAccess:[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\@[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]ZeroAccess:[/FONT]
[FONT=Calibri]C:\Windows\assembly\GAC\Desktop.ini[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================= Known DLLs (Whitelisted) ============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================= Bamital & volsnap Check ============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]C:\Windows\explorer.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\winlogon.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\wininit.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\svchost.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.[/FONT]
[FONT=Calibri]C:\Windows\System32\User32.dll => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\userinit.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================== EXE ASSOCIATION =====================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]HKLM\...\.exe: exefile => OK[/FONT]
[FONT=Calibri]HKLM\...\exefile\DefaultIcon: %1 => OK[/FONT]
[FONT=Calibri]HKLM\...\exefile\open\command: "%1" %* => OK[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================= Memory info ====================== [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Percentage of memory in use: 13%[/FONT]
[FONT=Calibri]Total physical RAM: 3062.04 MB[/FONT]
[FONT=Calibri]Available physical RAM: 2639.39 MB[/FONT]
[FONT=Calibri]Total Pagefile: 3060.33 MB[/FONT]
[FONT=Calibri]Available Pagefile: 2639.34 MB[/FONT]
[FONT=Calibri]Total Virtual: 2047.88 MB[/FONT]
[FONT=Calibri]Available Virtual: 1956.68 MB[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]======================= Partitions =========================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]1 Drive c: (New Volume) (Fixed) (Total:232.88 GB) (Free:140.16 GB) NTFS ==>[Drive with boot components (obtained from BCD)][/FONT]
[FONT=Calibri]3 Drive e: (AV) (Removable) (Total:0.96 GB) (Free:0.95 GB) FAT[/FONT]
[FONT=Calibri]4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Disk ### Status Size Free Dyn Gpt[/FONT]
[FONT=Calibri] -------- ------------- ------- ------- --- ---[/FONT]
[FONT=Calibri] Disk 0 Online 232 GB 0 B [/FONT]
[FONT=Calibri] Disk 1 Online 981 MB 0 B [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Partitions of Disk 0:[/FONT]
[FONT=Calibri]===============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Partition ### Type Size Offset[/FONT]
[FONT=Calibri] ------------- ---------------- ------- -------[/FONT]
[FONT=Calibri] Partition 1 Primary 232 GB 1024 KB[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Disk: 0[/FONT]
[FONT=Calibri]Partition 1[/FONT]
[FONT=Calibri]Type : 07[/FONT]
[FONT=Calibri]Hidden: No[/FONT]
[FONT=Calibri]Active: Yes[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Volume ### Ltr Label Fs Type Size Status Info[/FONT]
[FONT=Calibri] ---------- --- ----------- ----- ---------- ------- --------- --------[/FONT]
[FONT=Calibri]* Volume 1 C New Volume NTFS Partition 232 GB Healthy [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Partitions of Disk 1:[/FONT]
[FONT=Calibri]===============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Partition ### Type Size Offset[/FONT]
[FONT=Calibri] ------------- ---------------- ------- -------[/FONT]
[FONT=Calibri] Partition 1 Primary 980 MB 31 KB[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Disk: 1[/FONT]
[FONT=Calibri]Partition 1[/FONT]
[FONT=Calibri]Type : 06[/FONT]
[FONT=Calibri]Hidden: No[/FONT]
[FONT=Calibri]Active: Yes[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Volume ### Ltr Label Fs Type Size Status Info[/FONT]
[FONT=Calibri] ---------- --- ----------- ----- ---------- ------- --------- --------[/FONT]
[FONT=Calibri]* Volume 2 E AV FAT Removable 980 MB Healthy [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==========================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Last Boot: 2012-07-18 17:44[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]======================= End Of Log ==========================[/FONT]
[FONT=Calibri]Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 20-07-2012 01[/FONT]
[FONT=Calibri]Ran by SYSTEM at 24-07-2012 09:31:25[/FONT]
[FONT=Calibri]Running from E:\[/FONT]
[FONT=Calibri]Windows 7 Professional Service Pack 1 (X86) OS Language: English(US) [/FONT]
[FONT=Calibri]The current controlset is ControlSet002[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================== Registry (Whitelisted) =============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [3444736 2007-12-08] (Dell Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [288040 2010-04-05] (Alps Electric Co., Ltd.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [39792 2008-01-11] (Adobe Systems Incorporated)[/FONT]
[FONT=Calibri]HKLM\...\Run: [DLCCCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16 [73728 2006-02-24] ()[/FONT]
[FONT=Calibri]HKLM\...\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [431600 2007-01-29] (Dell)[/FONT]
[FONT=Calibri]HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)[/FONT]
[FONT=Calibri]HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)[/FONT]
[FONT=Calibri]HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)[/FONT]
[FONT=Calibri]HKU\KWright\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)[/FONT]
[FONT=Calibri]Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)[/FONT]
[FONT=Calibri]Tcpip\Parameters: [DhcpNameServer] 71.243.0.12 68.237.161.12[/FONT]
[FONT=Calibri]Startup: C:\Users\KWright\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk[/FONT]
[FONT=Calibri]ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]================================ Services (Whitelisted) ==================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]2 dlcc_device; C:\Windows\system32\dlcccoms.exe -service [538096 2007-01-29] ( )[/FONT]
[FONT=Calibri]2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)[/FONT]
[FONT=Calibri]2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)[/FONT]
[FONT=Calibri]2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe" [335872 2006-10-26] (Microsoft Corporation)[/FONT]
[FONT=Calibri]2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x][/FONT]
[FONT=Calibri]3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x][/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================== Drivers (Whitelisted) =============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)[/FONT]
[FONT=Calibri]3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-07-21] ()[/FONT]
[FONT=Calibri]0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)[/FONT]
[FONT=Calibri]3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()[/FONT]
[FONT=Calibri]3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [x][/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================== NetSvcs (Whitelisted) ===========[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]============ One Month Created Files and Folders ==============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]2012-07-24 09:31 - 2012-07-24 09:31 - 00000000 ____D C:\FRST[/FONT]
[FONT=Calibri]2012-07-24 05:23 - 2012-07-24 05:23 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ihotufes.sys[/FONT]
[FONT=Calibri]2012-07-23 12:55 - 2012-07-24 08:49 - 00000000 ____D C:\Windows\Microsoft Antimalware[/FONT]
[FONT=Calibri]2012-07-23 09:18 - 2012-07-23 09:18 - 00000000 ____D C:\TDSSKiller_Quarantine[/FONT]
[FONT=Calibri]2012-07-23 02:23 - 2012-07-23 04:27 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0[/FONT]
[FONT=Calibri]2012-07-21 11:40 - 2012-07-21 11:40 - 00000000 ____D C:\Program Files\Microsoft Security Client[/FONT]
[FONT=Calibri]2012-07-21 11:39 - 2012-07-21 11:39 - 00040776 ____A C:\Windows\System32\Drivers\mbamswissarmy.sys[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-18 16:28 - 00001077 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-18 16:28 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-03 09:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys[/FONT]
[FONT=Calibri]2012-07-11 14:13 - 2012-07-11 14:13 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\xiksufkh.sys[/FONT]
[FONT=Calibri]2012-07-11 14:13 - 2012-07-11 14:13 - 00000000 ____D C:\Users\KWright\AppData\Roaming\GetRightToGo[/FONT]
[FONT=Calibri]2012-07-11 10:25 - 2012-07-24 05:22 - 00004882 ____A C:\Windows\setupact.log[/FONT]
[FONT=Calibri]2012-07-11 10:25 - 2012-07-11 10:25 - 00000000 ____A C:\Windows\setuperr.log[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb[/FONT]
[FONT=Calibri]2012-07-11 07:38 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll[/FONT]
[FONT=Calibri]2012-07-11 07:35 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll[/FONT]
[FONT=Calibri]2012-07-10 11:35 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll[/FONT]
[FONT=Calibri]2012-07-02 16:57 - 2012-07-02 16:57 - 00000000 ____D C:\Users\KWright\AppData\Roaming\Sony[/FONT]
[FONT=Calibri]2012-07-02 16:56 - 2012-07-02 16:56 - 00001903 ____A C:\Users\Public\Desktop\Photo Go 1.0.lnk[/FONT]
[FONT=Calibri]2012-07-02 16:56 - 2012-07-02 16:56 - 00000000 ____D C:\Program Files\Sony[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 11:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll[/FONT]
[FONT=Calibri]2012-06-24 13:17 - 2012-06-02 11:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]============ 3 Months Modified Files ========================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]2012-07-24 05:23 - 2012-07-24 05:23 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ihotufes.sys[/FONT]
[FONT=Calibri]2012-07-24 05:23 - 2012-03-05 14:28 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job[/FONT]
[FONT=Calibri]2012-07-24 05:22 - 2012-07-11 10:25 - 00004882 ____A C:\Windows\setupact.log[/FONT]
[FONT=Calibri]2012-07-24 05:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT[/FONT]
[FONT=Calibri]2012-07-24 05:17 - 2009-07-13 20:34 - 00021504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0[/FONT]
[FONT=Calibri]2012-07-24 05:17 - 2009-07-13 20:34 - 00021504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0[/FONT]
[FONT=Calibri]2012-07-24 05:10 - 2012-02-28 15:15 - 01430456 ____A C:\Windows\WindowsUpdate.log[/FONT]
[FONT=Calibri]2012-07-21 11:41 - 2012-02-28 16:11 - 00001945 ____A C:\Windows\epplauncher.mif[/FONT]
[FONT=Calibri]2012-07-21 11:40 - 2010-11-20 13:01 - 00747538 ____A C:\Windows\System32\PerfStringBackup.INI[/FONT]
[FONT=Calibri]2012-07-21 11:39 - 2012-07-21 11:39 - 00040776 ____A C:\Windows\System32\Drivers\mbamswissarmy.sys[/FONT]
[FONT=Calibri]2012-07-21 10:44 - 2012-03-05 14:28 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job[/FONT]
[FONT=Calibri]2012-07-18 16:28 - 2012-07-18 16:28 - 00001077 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[/FONT]
[FONT=Calibri]2012-07-14 06:25 - 2010-11-20 13:48 - 00016862 ____A C:\Windows\PFRO.log[/FONT]
[FONT=Calibri]2012-07-13 12:31 - 2009-07-13 20:33 - 00409752 ____A C:\Windows\System32\FNTCACHE.DAT[/FONT]
[FONT=Calibri]2012-07-13 09:50 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe[/FONT]
[FONT=Calibri]2012-07-11 14:13 - 2012-07-11 14:13 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\xiksufkh.sys[/FONT]
[FONT=Calibri]2012-07-11 10:25 - 2012-07-11 10:25 - 00000000 ____A C:\Windows\setuperr.log[/FONT]
[FONT=Calibri]2012-07-11 07:37 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini[/FONT]
[FONT=Calibri]2012-07-11 07:35 - 2012-02-28 13:08 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe[/FONT]
[FONT=Calibri]2012-07-03 09:46 - 2012-07-18 16:28 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys[/FONT]
[FONT=Calibri]2012-07-02 16:56 - 2012-07-02 16:56 - 00001903 ____A C:\Users\Public\Desktop\Photo Go 1.0.lnk[/FONT]
[FONT=Calibri]2012-06-27 03:14 - 2009-07-13 20:53 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT[/FONT]
[FONT=Calibri]2012-06-15 17:23 - 2012-06-15 17:23 - 00000079 ____A C:\DVDPATH.TXT[/FONT]
[FONT=Calibri]2012-06-12 20:18 - 2012-02-28 12:57 - 00008688 ____A C:\Windows\IE9_main.log[/FONT]
[FONT=Calibri]2012-06-12 17:47 - 2012-06-12 17:46 - 00005862 ____A C:\Windows\System32\commonpriv.log[/FONT]
[FONT=Calibri]2012-06-12 17:46 - 2012-06-12 17:46 - 00000000 ____A C:\Windows\System32\commonpriv.log.lock[/FONT]
[FONT=Calibri]2012-06-11 18:40 - 2012-07-11 07:35 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys[/FONT]
[FONT=Calibri]2012-06-08 20:41 - 2012-07-10 11:35 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll[/FONT]
[FONT=Calibri]2012-06-08 18:55 - 2012-06-08 18:55 - 00034764 ____A C:\Users\KWright\AppData\Local\dt.dat[/FONT]
[FONT=Calibri]2012-06-08 13:33 - 2012-06-08 13:33 - 00912860 ____A C:\Users\KWright\Desktop\Attachments_2012_06_8tourdecure.zip[/FONT]
[FONT=Calibri]2012-06-08 13:33 - 2012-06-08 12:10 - 02442050 ____A C:\Users\KWright\Desktop\Attachments_2012_06_8.zip[/FONT]
[FONT=Calibri]2012-06-05 21:05 - 2012-07-10 11:35 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll[/FONT]
[FONT=Calibri]2012-06-05 21:05 - 2012-07-10 11:35 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll[/FONT]
[FONT=Calibri]2012-06-05 21:03 - 2012-07-10 11:35 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll[/FONT]
[FONT=Calibri]2012-06-05 17:32 - 2012-06-05 17:32 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe[/FONT]
[FONT=Calibri]2012-06-05 17:32 - 2012-02-28 16:24 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl[/FONT]
[FONT=Calibri]2012-06-04 17:52 - 2012-06-04 17:52 - 05189608 ____A C:\Users\KWright\Desktop\DisneyPhotopass3565902-1.zip[/FONT]
[FONT=Calibri]2012-06-04 16:15 - 2012-06-04 16:15 - 00952631 ____A C:\Users\KWright\Desktop\Disney Photo.zip[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll[/FONT]
[FONT=Calibri]2012-06-02 14:19 - 2012-06-24 13:17 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll[/FONT]
[FONT=Calibri]2012-06-02 14:12 - 2012-06-24 13:17 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll[/FONT]
[FONT=Calibri]2012-06-02 14:12 - 2012-06-24 13:17 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll[/FONT]
[FONT=Calibri]2012-06-02 11:19 - 2012-06-24 13:17 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll[/FONT]
[FONT=Calibri]2012-06-02 11:12 - 2012-06-24 13:17 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe[/FONT]
[FONT=Calibri]2012-06-02 01:07 - 2012-07-11 07:38 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll[/FONT]
[FONT=Calibri]2012-06-02 00:43 - 2012-07-11 07:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll[/FONT]
[FONT=Calibri]2012-06-02 00:33 - 2012-07-11 07:38 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll[/FONT]
[FONT=Calibri]2012-06-02 00:26 - 2012-07-11 07:38 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll[/FONT]
[FONT=Calibri]2012-06-02 00:25 - 2012-07-11 07:38 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl[/FONT]
[FONT=Calibri]2012-06-02 00:25 - 2012-07-11 07:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll[/FONT]
[FONT=Calibri]2012-06-02 00:23 - 2012-07-11 07:38 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll[/FONT]
[FONT=Calibri]2012-06-02 00:21 - 2012-07-11 07:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll[/FONT]
[FONT=Calibri]2012-06-02 00:20 - 2012-07-11 07:38 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe[/FONT]
[FONT=Calibri]2012-06-02 00:19 - 2012-07-11 07:38 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll[/FONT]
[FONT=Calibri]2012-06-02 00:19 - 2012-07-11 07:38 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll[/FONT]
[FONT=Calibri]2012-06-02 00:17 - 2012-07-11 07:38 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll[/FONT]
[FONT=Calibri]2012-06-02 00:16 - 2012-07-11 07:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb[/FONT]
[FONT=Calibri]2012-06-02 00:14 - 2012-07-11 07:38 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll[/FONT]
[FONT=Calibri]2012-06-01 20:45 - 2012-07-10 11:35 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys[/FONT]
[FONT=Calibri]2012-06-01 20:45 - 2012-07-10 11:35 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys[/FONT]
[FONT=Calibri]2012-06-01 20:40 - 2012-07-10 11:35 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys[/FONT]
[FONT=Calibri]2012-06-01 20:40 - 2012-07-10 11:35 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll[/FONT]
[FONT=Calibri]2012-06-01 20:39 - 2012-07-10 11:35 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll[/FONT]
[FONT=Calibri]2012-05-14 21:23 - 2012-05-14 21:23 - 00952631 ____A C:\Users\KWright\Desktop\Digital Download Entitlement 4x6 format (3503553).zip[/FONT]
[FONT=Calibri]2012-05-14 21:22 - 2012-05-14 21:22 - 00952631 ____A C:\Users\KWright\Downloads\Digital Download Entitlement 4x6 format (3503553).zip[/FONT]
[FONT=Calibri]2012-05-05 19:30 - 2012-05-05 19:30 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf[/FONT]
[FONT=Calibri]2012-04-30 20:44 - 2012-06-13 07:08 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll[/FONT]
[FONT=Calibri]2012-04-27 19:17 - 2012-06-13 07:08 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]ZeroAccess:[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\00000004.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\00000004.@.vir[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\1afb2d56[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L\201d3dde[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\00000004.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\00000008.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\000000cb.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\80000000.@[/FONT]
[FONT=Calibri]C:\Windows\Installer\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U\80000032.@[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]ZeroAccess:[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\@[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\L[/FONT]
[FONT=Calibri]C:\Users\KWright\AppData\Local\{58373e3b-29d5-06fe-70c4-fd025b02dadc}\U[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]ZeroAccess:[/FONT]
[FONT=Calibri]C:\Windows\assembly\GAC\Desktop.ini[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================= Known DLLs (Whitelisted) ============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================= Bamital & volsnap Check ============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]C:\Windows\explorer.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\winlogon.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\wininit.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\svchost.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.[/FONT]
[FONT=Calibri]C:\Windows\System32\User32.dll => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\userinit.exe => MD5 is legit[/FONT]
[FONT=Calibri]C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================== EXE ASSOCIATION =====================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]HKLM\...\.exe: exefile => OK[/FONT]
[FONT=Calibri]HKLM\...\exefile\DefaultIcon: %1 => OK[/FONT]
[FONT=Calibri]HKLM\...\exefile\open\command: "%1" %* => OK[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]========================= Memory info ====================== [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Percentage of memory in use: 13%[/FONT]
[FONT=Calibri]Total physical RAM: 3062.04 MB[/FONT]
[FONT=Calibri]Available physical RAM: 2639.39 MB[/FONT]
[FONT=Calibri]Total Pagefile: 3060.33 MB[/FONT]
[FONT=Calibri]Available Pagefile: 2639.34 MB[/FONT]
[FONT=Calibri]Total Virtual: 2047.88 MB[/FONT]
[FONT=Calibri]Available Virtual: 1956.68 MB[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]======================= Partitions =========================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]1 Drive c: (New Volume) (Fixed) (Total:232.88 GB) (Free:140.16 GB) NTFS ==>[Drive with boot components (obtained from BCD)][/FONT]
[FONT=Calibri]3 Drive e: (AV) (Removable) (Total:0.96 GB) (Free:0.95 GB) FAT[/FONT]
[FONT=Calibri]4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Disk ### Status Size Free Dyn Gpt[/FONT]
[FONT=Calibri] -------- ------------- ------- ------- --- ---[/FONT]
[FONT=Calibri] Disk 0 Online 232 GB 0 B [/FONT]
[FONT=Calibri] Disk 1 Online 981 MB 0 B [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Partitions of Disk 0:[/FONT]
[FONT=Calibri]===============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Partition ### Type Size Offset[/FONT]
[FONT=Calibri] ------------- ---------------- ------- -------[/FONT]
[FONT=Calibri] Partition 1 Primary 232 GB 1024 KB[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Disk: 0[/FONT]
[FONT=Calibri]Partition 1[/FONT]
[FONT=Calibri]Type : 07[/FONT]
[FONT=Calibri]Hidden: No[/FONT]
[FONT=Calibri]Active: Yes[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Volume ### Ltr Label Fs Type Size Status Info[/FONT]
[FONT=Calibri] ---------- --- ----------- ----- ---------- ------- --------- --------[/FONT]
[FONT=Calibri]* Volume 1 C New Volume NTFS Partition 232 GB Healthy [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Partitions of Disk 1:[/FONT]
[FONT=Calibri]===============[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Partition ### Type Size Offset[/FONT]
[FONT=Calibri] ------------- ---------------- ------- -------[/FONT]
[FONT=Calibri] Partition 1 Primary 980 MB 31 KB[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Disk: 1[/FONT]
[FONT=Calibri]Partition 1[/FONT]
[FONT=Calibri]Type : 06[/FONT]
[FONT=Calibri]Hidden: No[/FONT]
[FONT=Calibri]Active: Yes[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri] Volume ### Ltr Label Fs Type Size Status Info[/FONT]
[FONT=Calibri] ---------- --- ----------- ----- ---------- ------- --------- --------[/FONT]
[FONT=Calibri]* Volume 2 E AV FAT Removable 980 MB Healthy [/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==================================================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]==========================================================[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]Last Boot: 2012-07-18 17:44[/FONT]
[FONT=Calibri] [/FONT]
[FONT=Calibri]======================= End Of Log ==========================[/FONT]