Hello
I have recently just had a problem with my laptop and after a bit of google searching I found these forums to be pretty helpful for others in similar situations.
I have an Asus Zenbook with Windows 7 home installed.
Recently I have found "Live Secuirty Platinum" which I understand is some bad malware. I have MSE installed but It has not picked it up, I have also tried a few other malware scanners like Malwarebyes. The problem I have none of the scans can complete as I get a window popup "Windows has encountered a critical problem and will restart automatically in one minute." and I Cant complete the scans.
I have also tried F8 on boot up to select "Disable automatic restart" and also start in safe mode but the problem still occurs.
I have noticed in other posts you have first asked for Farbar Recovery Scan Tool 64-Bit to be downloaded and the two scans run. Below are my results.
Any help would be fantastic!
- FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 04-08-2012
Ran by SYSTEM at 04-08-2012 11:57:21
Running from D:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-11-03] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-11-03] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-11-03] (Intel Corporation)
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] ()
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2661672 2012-02-19] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe" [48128 2011-12-11] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-21] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3058304 2012-03-12] (ASUS)
HKU\G\...\Run: [InternodeUsage] C:\PROGRA~2\INTERN~2\mum.exe [1361408 2011-02-18] (Angus Johnson)
HKU\G\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3671872 2012-04-17] (DT Soft Ltd)
HKU\G\...\Run: [Wabiofebni] C:\Users\G\AppData\Roaming\Ozeny\tuwai.exe [180224 2012-06-12] ()
HKU\GAFFiO\...\Run: [InternodeUsage] C:\PROGRA~2\INTERN~2\mum.exe [1361408 2011-02-18] (Angus Johnson)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit [1805912 2012-05-24] (Soluto)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\GAFFiO\Start Menu\Programs\Startup\Trillian.lnk
ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
==================== Services (Whitelisted) ======
2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [92800 2011-11-30] (ASUS)
2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-08-02] (Atheros)
2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [103584 2011-08-02] (Atheros Commnucations)
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-20] (Intel Corporation)
4 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-12] (The Within Network, LLC)
2 syshost32; "C:\Windows\Installer\{AFB2BB7F-872C-7FEC-63E4-602843CAE818}\syshost.exe" /service [x]
========================== Drivers (Whitelisted) =============
0 944a435ceeab1a2d; C:\Windows\System32\Drivers\944a435ceeab1a2d.sys [84408 2012-08-02] () ATTENTION =====> Rootkit?
3 AiCharger; C:\Windows\System32\Drivers\AiCharger.sys [17152 2011-12-05] (ASUSTek Computer Inc.)
3 AiCharger; C:\Windows\SysWow64\Drivers\AiCharger.sys [17152 2011-12-05] (ASUSTek Computer Inc.)
2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS)
3 AsusVBus; C:\Windows\System32\Drivers\AsusVBus.sys [35968 2011-12-21] (Windows (R) Win 7 DDK provider)
3 AsusVTouch; C:\Windows\System32\Drivers\AsusVTouch.sys [16512 2011-11-07] (Windows (R) Win 7 DDK provider)
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [36000 2011-08-02] (Atheros)
1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
3 BTATH_A2DP; C:\Windows\System32\Drivers\BTATH_A2DP.sys [330912 2011-08-02] (Atheros)
3 btath_avdt; C:\Windows\System32\Drivers\btath_avdt.sys [110240 2011-08-02] (Atheros)
3 BTATH_BUS; C:\Windows\System32\Drivers\BTATH_BUS.sys [30368 2011-08-02] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\Drivers\BTATH_HCRP.sys [167584 2011-08-02] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\Drivers\BTATH_LWFLT.sys [68256 2011-08-02] (Atheros)
3 BTATH_RCP; C:\Windows\System32\Drivers\BTATH_RCP.sys [280992 2011-08-02] (Atheros)
3 BtFilter; C:\Windows\System32\Drivers\BtFilter.sys [511136 2011-08-02] (Atheros)
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-07-31] (DT Soft Ltd)
3 FLxHCIh; C:\Windows\System32\Drivers\FLxHCIh.sys [71424 2011-12-12] (Fresco Logic)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
2 uxpatch; C:\Windows\System32\Drivers\uxpatch.sys [30568 2009-07-12] ()
3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x]
1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-03 17:48 - 2012-08-03 17:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89C13600320A37EF
2012-08-03 17:42 - 2012-08-03 17:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.333D1E267EEAEDB7
2012-08-03 17:38 - 2012-08-03 17:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8A3F188537EC031
2012-08-03 17:35 - 2012-08-03 17:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.042F52C167619136
2012-08-03 17:34 - 2012-08-03 17:34 - 00001272 ____A C:\Users\G\Desktop\noshut.lnk
2012-08-03 17:32 - 2012-08-03 17:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C39511281065875
2012-08-03 17:29 - 2012-08-03 17:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E2C6C5410D36A9C
2012-08-03 17:24 - 2012-08-03 17:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2A24B813FA4B31
2012-08-03 17:21 - 2012-08-03 17:22 - 00000203 ____A C:\spyhunter.fix
2012-08-03 17:21 - 2012-08-03 17:21 - 00002252 ____A C:\Users\G\Desktop\SpyHunter.lnk
2012-08-03 17:21 - 2010-08-05 00:31 - 00014680 ____A C:\Windows\System32\sh4native.exe
2012-08-03 17:20 - 2012-08-03 17:22 - 00000000 ____D C:\sh4ldr
2012-08-03 17:20 - 2012-08-03 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D95945C6F7DC6DF
2012-08-03 17:20 - 2012-08-03 17:20 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-08-03 17:17 - 2012-08-03 17:21 - 00000000 ____D C:\Windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-08-03 17:16 - 2012-08-03 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0776D71E4197441D
2012-08-03 17:15 - 2012-08-03 17:15 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\G\Desktop\explorer.exe
2012-08-03 17:13 - 2012-08-03 17:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9F691F0F718AD008
2012-08-03 17:09 - 2012-08-03 17:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71140A2BED1FEF9A
2012-08-03 17:05 - 2012-08-03 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29E47E623DFEA71C
2012-08-03 17:01 - 2012-08-03 17:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.852342F5DB97EA81
2012-08-03 17:01 - 2012-08-03 17:01 - 00000000 ____D C:\Users\G\AppData\Roaming\Malwarebytes
2012-08-03 17:00 - 2012-08-03 17:00 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-03 17:00 - 2012-08-03 17:00 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-03 17:00 - 2012-08-03 17:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-03 17:00 - 2012-07-02 20:16 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-03 16:59 - 2012-08-03 16:56 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\G\Desktop\mal.exe
2012-08-03 16:56 - 2012-08-03 16:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E5048CDED746C2C
2012-08-03 16:53 - 2012-08-03 16:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9AC4BF904EE4933
2012-08-03 16:49 - 2012-08-03 16:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BF7F1AC2EF60358B
2012-08-03 04:51 - 2012-08-03 04:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C0643A7F98FA1EE3
2012-08-03 04:44 - 2012-08-03 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81CB41BF025CA49
2012-08-03 04:34 - 2012-08-03 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF49F969043124C
2012-08-03 04:28 - 2012-08-03 04:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C480ECBA59153BD
2012-08-03 04:22 - 2012-08-03 04:22 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-03 04:22 - 2012-08-03 04:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-03 04:20 - 2012-08-03 04:20 - 12621696 ____A (Microsoft Corporation) C:\Users\G\Downloads\mseinstall.exe
2012-08-03 04:03 - 2012-08-03 04:03 - 00002018 ____A C:\Users\G\Desktop\Live Security Platinum.lnk
2012-08-03 04:00 - 2012-08-03 04:31 - 00062464 ____A C:\Windows\System32\Comptend64.dll
2012-08-03 04:00 - 2012-08-03 04:00 - 00056320 ___AH (FRISK Software International) C:\Windows\SysWOW64\Comptend.dll
2012-08-03 04:00 - 2012-08-03 03:59 - 00152064 ____A C:\Users\G\AppData\Roaming\csrec.dll
2012-08-02 23:23 - 2012-08-02 23:23 - 00001136 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-08-02 05:46 - 2012-08-02 05:46 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-08-02 05:36 - 2012-08-02 05:36 - 00084408 ____A C:\Windows\System32\Drivers\944a435ceeab1a2d.sys
2012-08-02 05:35 - 2012-08-02 23:19 - 00000000 ____D C:\Users\G\AppData\Roaming\Yfvix
2012-08-02 05:35 - 2012-08-02 23:19 - 00000000 ____D C:\Users\G\AppData\Roaming\Opry
2012-08-02 05:31 - 2012-08-02 05:31 - 00016286 ____A C:\Users\G\Desktop\hs_err_pid16784.log
2012-08-02 05:02 - 2012-08-03 02:04 - 00000000 ____D C:\Users\G\AppData\Roaming\Xoel
2012-08-02 05:02 - 2012-08-02 05:02 - 00000000 ____D C:\Users\G\AppData\Roaming\Ozeny
2012-08-02 05:02 - 2012-08-02 05:02 - 00000000 ____D C:\Users\G\AppData\Roaming\Isnys
2012-08-01 15:31 - 2012-08-01 15:32 - 16814136 ____A (Mozilla) C:\Users\G\Downloads\Firefox Setup 14.0.1.exe
2012-08-01 15:27 - 2012-08-01 15:27 - 13713850 ____A C:\Users\G\Downloads\Intel_RAIDAHCI_V11001032_XPWin7.zip
2012-08-01 15:26 - 2012-08-01 15:27 - 19414180 ____A C:\Users\G\Downloads\Realtek_LAN_V5790_V749_XPWin7.zip
2012-08-01 15:26 - 2012-08-01 15:26 - 05932880 ____A C:\Users\G\Downloads\Intel_USB3_V101209_Win7.zip
2012-08-01 15:25 - 2012-08-01 15:37 - 285344242 ____A C:\Users\G\Downloads\Intel_Graphics_V815102618_WinVista7.zip
2012-08-01 15:25 - 2012-08-01 15:36 - 251841943 ____A C:\Users\G\Downloads\Intel_Chipset_V9301019_P8H77-V_XPWin7.zip
2012-08-01 15:25 - 2012-08-01 15:33 - 141944149 ____A C:\Users\G\Downloads\Realtek_Audio_V51006526_V6016526_XPWin7.zip
2012-08-01 15:22 - 2012-08-01 15:25 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\G\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-08-01 15:17 - 2012-08-01 15:18 - 00001908 ____A C:\Windows\diagwrn.xml
2012-08-01 15:17 - 2012-08-01 15:18 - 00001908 ____A C:\Windows\diagerr.xml
2012-08-01 05:53 - 2012-08-01 05:53 - 00262144 ____A C:\Windows\Minidump\080112-20077-01.dmp
2012-08-01 05:53 - 2012-08-01 05:53 - 00000000 ____D C:\Windows\Minidump
2012-07-31 05:27 - 2012-07-31 05:27 - 00000000 ____D C:\Users\G\Downloads\Windows 7 Anytime Upgrade CD-Key Generator Final Activated
2012-07-31 05:26 - 2012-07-31 05:27 - 00000000 ____D C:\Users\G\Downloads\Windows 7 Home Premium (64 Bit) by (oldBen)
2012-07-31 03:54 - 2012-07-31 03:54 - 00001956 ____A C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2012-07-31 03:53 - 2012-07-31 03:53 - 00283200 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
2012-07-31 03:52 - 2012-07-31 03:54 - 00000000 ____D C:\Users\G\AppData\Roaming\DAEMON Tools Lite
2012-07-31 03:51 - 2012-07-31 03:53 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2012-07-31 03:50 - 2012-07-31 03:54 - 00000000 ____D C:\Users\All Users\DAEMON Tools Lite
2012-07-31 03:50 - 2012-07-31 03:50 - 14230160 ____A (DT Soft Ltd) C:\Users\G\Downloads\DTLite4454-0315.exe
2012-07-31 03:48 - 2012-07-31 03:49 - 00463080 ____A (CNET Download.com) C:\Users\G\Downloads\cnet2_DTLite4454-0315_exe.exe
2012-07-25 03:44 - 2012-07-29 13:39 - 00000000 ____D C:\Users\G\Downloads\Breaking Bad Season 1-3
2012-07-22 14:12 - 2012-07-22 14:13 - 00000000 ____D C:\Users\G\Desktop\rave
2012-07-22 13:56 - 2012-07-31 04:05 - 00000642 ___AH C:\os802099.bin
2012-07-22 13:41 - 2012-07-22 13:41 - 00000000 ____D C:\Windows\PreviewSoft
2012-07-22 13:40 - 2012-07-22 13:40 - 00001477 ____A C:\Users\G\Desktop\Resume ACDSee_Classic Download2.LNK
2012-07-22 13:40 - 2012-07-22 13:40 - 00001340 ____A C:\Users\G\Desktop\Launch ACDSee_Classic 2.44.LNK
2012-07-22 13:37 - 2012-07-24 04:46 - 00000000 ____D C:\Users\G\Desktop\KEEP
2012-07-22 03:53 - 2012-07-22 03:53 - 00000000 ____D C:\Users\G\AppData\Local\Adobe
2012-07-19 18:03 - 2012-07-19 18:03 - 00002015 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-07-19 18:03 - 2012-07-19 18:03 - 00000000 ____D C:\Windows\System32\STRING
2012-07-19 18:03 - 2012-07-19 18:03 - 00000000 ____D C:\Users\All Users\Canon IJ Network Tool
2012-07-19 18:03 - 2012-07-19 18:03 - 00000000 ____D C:\Program Files (x86)\Canon
2012-07-19 18:03 - 2010-03-18 01:55 - 00307200 ____A (CANON INC.) C:\Windows\SysWOW64\CNC495L.dll
2012-07-19 18:03 - 2010-03-17 23:41 - 00106496 ____A (CANON INC.) C:\Windows\SysWOW64\CNC495U.dll
2012-07-19 18:03 - 2010-02-04 17:07 - 00340992 ____A (CANON INC.) C:\Windows\SysWOW64\CNMNPPM.DLL
2012-07-19 18:03 - 2010-02-04 17:07 - 00327680 ____A (CANON INC.) C:\Windows\System32\CNMN6PPM.DLL
2012-07-19 18:03 - 2010-02-04 17:07 - 00037376 ____A (CANON INC.) C:\Windows\System32\CNMN6UI.DLL
2012-07-19 18:03 - 2009-11-12 21:05 - 00012800 ____A C:\Windows\SysWOW64\CNC1747D.TBL
2012-07-19 18:03 - 2008-08-25 00:32 - 00015872 ____A (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2012-07-19 18:02 - 2012-07-19 18:02 - 00000000 ___HD C:\Windows\System32\CanonIJ Uninstaller Information
2012-07-19 18:02 - 2012-07-19 18:02 - 00000000 ___HD C:\Users\All Users\CanonBJ
2012-07-19 18:01 - 2012-07-19 18:01 - 00000000 ___HD C:\Program Files\CanonBJ
2012-07-19 18:01 - 2010-08-24 11:30 - 00361472 ____A (CANON INC.) C:\Windows\System32\CNMLMA9.DLL
2012-07-19 18:01 - 2010-03-10 15:27 - 00248320 ____A (CANON INC.) C:\Windows\System32\CNMIUA9.DLL
2012-07-19 17:47 - 2012-07-19 17:47 - 00043894 ____A C:\Users\G\Downloads\SimpleCoords-1.94.zip
2012-07-19 17:44 - 2012-07-19 17:44 - 00509464 ____A C:\Users\G\Downloads\MageNuggets-2.34.zip
2012-07-19 03:20 - 2012-07-19 03:20 - 00000163 ____A C:\Users\G\Desktop\Mysterious Fortune Card.url
2012-07-18 04:36 - 2012-08-03 17:06 - 00000000 ____D C:\Users\G\AppData\Local\Gabest
2012-07-18 04:36 - 2012-07-18 04:36 - 00000000 ____D C:\Windows\Sun
2012-07-18 04:31 - 2012-07-18 04:31 - 00001898 ____A C:\Users\G\Desktop\PS3 Media Server.lnk
2012-07-18 04:27 - 2012-07-18 04:27 - 00000000 ____D C:\Windows\pss
2012-07-11 23:30 - 2012-07-11 23:30 - 00000000 ____D C:\Program Files (x86)\Belkin
2012-07-11 18:51 - 2012-07-11 18:51 - 00001118 ____A C:\Users\G\Desktop\Launcher.exe - Shortcut.lnk
2012-07-11 15:43 - 2012-07-11 15:43 - 00665466 ____A C:\Users\G\Desktop\scan.rrs
2012-07-11 09:35 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 09:31 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 09:31 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 09:31 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 09:31 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 09:30 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 09:30 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 09:30 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 09:30 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 09:30 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 09:30 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 09:30 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 09:30 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 09:30 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 09:30 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 09:30 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 09:30 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 09:30 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 09:30 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 09:30 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 09:30 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 09:30 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 09:30 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 09:30 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 09:30 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 09:30 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 09:30 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 09:30 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 09:30 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 02:53 - 2012-07-11 15:42 - 00000000 ____D C:\Program Files (x86)\PowerDataRecovery
2012-07-11 02:53 - 2012-07-11 02:53 - 00001039 ____A C:\Users\Public\Desktop\Power Data Recovery.lnk
2012-07-11 02:52 - 2012-07-11 02:52 - 00000000 ____D C:\Users\G\Documents\Power Data Recovery Pro v4.1.1
2012-07-11 02:50 - 2012-07-11 02:51 - 15861760 ____A C:\Users\G\Documents\Stellar.Phoenix.Windows.Data.Recovery.v3.0.0.With Crack By Faraz 101% Clean From VIRUS.zip
2012-07-10 23:02 - 2012-07-10 23:02 - 00000000 ____D C:\Users\G\Desktop\New folder
2012-07-10 22:18 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 22:18 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 22:18 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 22:18 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 22:18 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 22:18 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 22:17 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 22:17 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 22:17 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 22:17 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 22:17 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 22:17 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 22:17 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 22:17 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 22:17 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 22:17 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 22:17 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 22:17 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 22:17 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-05 05:52 - 2012-07-05 05:54 - 109168195 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_audio_realtek_azalia.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 03364486 ____A C:\Users\G\Documents\motherboard_driver_lan_realtek_8111.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 01246890 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_chipset_intel.exe
2012-07-05 04:11 - 2012-07-22 14:50 - 00000000 ____D C:\Users\G\AppData\Roaming\vlc
============ 3 Months Modified Files ========================
2012-08-04 11:28 - 2011-10-17 19:58 - 00008446 ____A C:\Windows\AsRecoveryHD.log
2012-08-04 11:27 - 2011-10-17 19:57 - 00039853 ____A C:\Windows\AsFac.log
2012-08-03 18:20 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-03 18:20 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-03 18:02 - 2009-07-13 21:13 - 00797650 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-03 17:59 - 2012-06-11 04:37 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-03 17:58 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-03 17:58 - 2009-07-13 20:51 - 00002068 ____A C:\Windows\setupact.log
2012-08-03 17:48 - 2012-08-03 17:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89C13600320A37EF
2012-08-03 17:42 - 2012-08-03 17:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.333D1E267EEAEDB7
2012-08-03 17:38 - 2012-08-03 17:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8A3F188537EC031
2012-08-03 17:35 - 2012-08-03 17:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.042F52C167619136
2012-08-03 17:34 - 2012-08-03 17:34 - 00001272 ____A C:\Users\G\Desktop\noshut.lnk
2012-08-03 17:32 - 2012-08-03 17:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C39511281065875
2012-08-03 17:29 - 2012-08-03 17:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E2C6C5410D36A9C
2012-08-03 17:24 - 2012-08-03 17:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2A24B813FA4B31
2012-08-03 17:22 - 2012-08-03 17:21 - 00000203 ____A C:\spyhunter.fix
2012-08-03 17:21 - 2012-08-03 17:21 - 00002252 ____A C:\Users\G\Desktop\SpyHunter.lnk
2012-08-03 17:20 - 2012-08-03 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D95945C6F7DC6DF
2012-08-03 17:16 - 2012-08-03 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0776D71E4197441D
2012-08-03 17:15 - 2012-08-03 17:15 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\G\Desktop\explorer.exe
2012-08-03 17:13 - 2012-08-03 17:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9F691F0F718AD008
2012-08-03 17:09 - 2012-08-03 17:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71140A2BED1FEF9A
2012-08-03 17:06 - 2011-10-17 19:58 - 00327852 ____A C:\Windows\PFRO.log
2012-08-03 17:05 - 2012-08-03 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29E47E623DFEA71C
2012-08-03 17:01 - 2012-08-03 17:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.852342F5DB97EA81
2012-08-03 17:00 - 2012-08-03 17:00 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-03 16:56 - 2012-08-03 16:59 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\G\Desktop\mal.exe
2012-08-03 16:56 - 2012-08-03 16:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E5048CDED746C2C
2012-08-03 16:53 - 2012-08-03 16:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9AC4BF904EE4933
2012-08-03 16:49 - 2012-08-03 16:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BF7F1AC2EF60358B
2012-08-03 04:51 - 2012-08-03 04:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C0643A7F98FA1EE3
2012-08-03 04:44 - 2012-08-03 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81CB41BF025CA49
2012-08-03 04:36 - 2012-03-12 18:08 - 01169433 ____A C:\Windows\WindowsUpdate.log
2012-08-03 04:34 - 2012-08-03 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF49F969043124C
2012-08-03 04:31 - 2012-08-03 04:00 - 00062464 ____A C:\Windows\System32\Comptend64.dll
2012-08-03 04:28 - 2012-08-03 04:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C480ECBA59153BD
2012-08-03 04:22 - 2012-06-11 04:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-03 04:22 - 2011-10-17 20:17 - 00803496 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-03 04:20 - 2012-08-03 04:20 - 12621696 ____A (Microsoft Corporation) C:\Users\G\Downloads\mseinstall.exe
2012-08-03 04:03 - 2012-08-03 04:03 - 00002018 ____A C:\Users\G\Desktop\Live Security Platinum.lnk
2012-08-03 04:00 - 2012-08-03 04:00 - 00056320 ___AH (FRISK Software International) C:\Windows\SysWOW64\Comptend.dll
2012-08-03 03:59 - 2012-08-03 04:00 - 00152064 ____A C:\Users\G\AppData\Roaming\csrec.dll
2012-08-02 23:23 - 2012-08-02 23:23 - 00001136 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-08-02 05:36 - 2012-08-02 05:36 - 00084408 ____A C:\Windows\System32\Drivers\944a435ceeab1a2d.sys
2012-08-02 05:31 - 2012-08-02 05:31 - 00016286 ____A C:\Users\G\Desktop\hs_err_pid16784.log
2012-08-01 15:37 - 2012-08-01 15:25 - 285344242 ____A C:\Users\G\Downloads\Intel_Graphics_V815102618_WinVista7.zip
2012-08-01 15:36 - 2012-08-01 15:25 - 251841943 ____A C:\Users\G\Downloads\Intel_Chipset_V9301019_P8H77-V_XPWin7.zip
2012-08-01 15:33 - 2012-08-01 15:25 - 141944149 ____A C:\Users\G\Downloads\Realtek_Audio_V51006526_V6016526_XPWin7.zip
2012-08-01 15:32 - 2012-08-01 15:31 - 16814136 ____A (Mozilla) C:\Users\G\Downloads\Firefox Setup 14.0.1.exe
2012-08-01 15:27 - 2012-08-01 15:27 - 13713850 ____A C:\Users\G\Downloads\Intel_RAIDAHCI_V11001032_XPWin7.zip
2012-08-01 15:27 - 2012-08-01 15:26 - 19414180 ____A C:\Users\G\Downloads\Realtek_LAN_V5790_V749_XPWin7.zip
2012-08-01 15:26 - 2012-08-01 15:26 - 05932880 ____A C:\Users\G\Downloads\Intel_USB3_V101209_Win7.zip
2012-08-01 15:25 - 2012-08-01 15:22 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\G\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-08-01 15:18 - 2012-08-01 15:17 - 00001908 ____A C:\Windows\diagwrn.xml
2012-08-01 15:18 - 2012-08-01 15:17 - 00001908 ____A C:\Windows\diagerr.xml
2012-08-01 15:17 - 2009-07-13 20:51 - 00000000 ____A C:\Windows\setuperr.log
2012-08-01 05:53 - 2012-08-01 05:53 - 00262144 ____A C:\Windows\Minidump\080112-20077-01.dmp
2012-07-31 04:05 - 2012-07-22 13:56 - 00000642 ___AH C:\os802099.bin
2012-07-31 03:54 - 2012-07-31 03:54 - 00001956 ____A C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2012-07-31 03:53 - 2012-07-31 03:53 - 00283200 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
2012-07-31 03:50 - 2012-07-31 03:50 - 14230160 ____A (DT Soft Ltd) C:\Users\G\Downloads\DTLite4454-0315.exe
2012-07-31 03:49 - 2012-07-31 03:48 - 00463080 ____A (CNET Download.com) C:\Users\G\Downloads\cnet2_DTLite4454-0315_exe.exe
2012-07-22 13:40 - 2012-07-22 13:40 - 00001477 ____A C:\Users\G\Desktop\Resume ACDSee_Classic Download2.LNK
2012-07-22 13:40 - 2012-07-22 13:40 - 00001340 ____A C:\Users\G\Desktop\Launch ACDSee_Classic 2.44.LNK
2012-07-19 18:03 - 2012-07-19 18:03 - 00002015 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-07-19 17:47 - 2012-07-19 17:47 - 00043894 ____A C:\Users\G\Downloads\SimpleCoords-1.94.zip
2012-07-19 17:44 - 2012-07-19 17:44 - 00509464 ____A C:\Users\G\Downloads\MageNuggets-2.34.zip
2012-07-19 03:20 - 2012-07-19 03:20 - 00000163 ____A C:\Users\G\Desktop\Mysterious Fortune Card.url
2012-07-18 04:31 - 2012-07-18 04:31 - 00001898 ____A C:\Users\G\Desktop\PS3 Media Server.lnk
2012-07-11 18:51 - 2012-07-11 18:51 - 00001118 ____A C:\Users\G\Desktop\Launcher.exe - Shortcut.lnk
2012-07-11 15:43 - 2012-07-11 15:43 - 00665466 ____A C:\Users\G\Desktop\scan.rrs
2012-07-11 09:53 - 2009-07-13 20:45 - 00274320 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 09:32 - 2012-06-04 03:27 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 02:53 - 2012-07-11 02:53 - 00001039 ____A C:\Users\Public\Desktop\Power Data Recovery.lnk
2012-07-11 02:51 - 2012-07-11 02:50 - 15861760 ____A C:\Users\G\Documents\Stellar.Phoenix.Windows.Data.Recovery.v3.0.0.With Crack By Faraz 101% Clean From VIRUS.zip
2012-07-05 05:54 - 2012-07-05 05:52 - 109168195 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_audio_realtek_azalia.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 03364486 ____A C:\Users\G\Documents\motherboard_driver_lan_realtek_8111.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 01246890 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_chipset_intel.exe
2012-07-03 02:29 - 2012-07-03 02:29 - 00067371 ____A C:\Users\G\Downloads\SwindlerPreventer_4-3-3.zip
2012-07-03 02:27 - 2012-07-03 02:27 - 00378804 ____A C:\Users\G\Downloads\Recount-v4.3.0d_release.zip
2012-07-03 02:24 - 2012-07-03 02:24 - 00397722 ____A C:\Users\G\Downloads\Quartz-3.0.8.zip
2012-07-03 02:21 - 2012-07-03 02:20 - 00797377 ____A C:\Users\G\Downloads\Overachiever-v0.65.zip
2012-07-03 02:17 - 2012-07-03 02:17 - 00270569 ____A C:\Users\G\Downloads\GatherMate2_Data-v10.5.zip
2012-07-03 02:16 - 2012-07-03 02:16 - 00846388 ____A C:\Users\G\Downloads\GatherMate2-1.16.2.zip
2012-07-03 02:15 - 2012-07-03 02:14 - 00465193 ____A C:\Users\G\Downloads\Decursive-2.7.0.5.zip
2012-07-03 02:10 - 2012-07-03 02:10 - 01124103 ____A C:\Users\G\Downloads\DBM-4.10.12-r7536-Core-and-Cataclysm-Mods.zip
2012-07-03 02:07 - 2012-07-03 02:07 - 00333196 ____A C:\Users\G\Downloads\Chatter-v.1.3.3.zip
2012-07-03 02:02 - 2012-07-03 02:02 - 00279513 ____A C:\Users\G\Downloads\Bartender4-4.4.20.1.zip
2012-07-02 20:16 - 2012-08-03 17:00 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-30 01:06 - 2012-06-30 01:06 - 26576272 ____A C:\Users\G\Documents\mp495swin102ea24.exe
2012-06-19 04:16 - 2012-03-12 18:10 - 00015470 ____A C:\Windows\DPINST.LOG
2012-06-19 04:11 - 2012-06-19 03:50 - 150138003 ____A C:\Users\G\Documents\Touchpad_Elantech_Win7_64_Z10590.zip
2012-06-19 03:54 - 2012-06-19 03:51 - 16576878 ____A C:\Users\G\Documents\WLAN_Atheros_Win7_64_Z921470.zip
2012-06-17 02:58 - 2012-06-17 02:58 - 00057560 ____A C:\Users\natlie\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-12 04:54 - 2012-06-03 18:08 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe
2012-06-12 04:39 - 2012-06-11 04:06 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-06-12 04:36 - 2012-06-12 04:36 - 00002585 ____A C:\Users\GAFFiO\Desktop\Power4Gear Hybrid.lnk
2012-06-12 02:31 - 2012-06-12 02:31 - 00290334 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-06-12 02:31 - 2012-06-12 02:31 - 00286962 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-06-11 19:08 - 2012-07-11 09:35 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 06:49 - 2012-06-11 06:49 - 00057560 ____A C:\Users\GAFFiO\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-11 06:47 - 2012-06-11 06:47 - 00000020 ___SH C:\Users\GAFFiO\ntuser.ini
2012-06-11 04:40 - 2012-06-11 04:40 - 00001038 ____A C:\Users\G\Desktop\Dropbox.lnk
2012-06-11 04:37 - 2012-06-06 15:00 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-11 04:37 - 2012-06-06 15:00 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-11 04:31 - 2012-06-11 04:31 - 00001899 ____A C:\Users\GAFFiO\Desktop\Soluto.lnk
2012-06-11 04:31 - 2012-06-11 04:31 - 00000098 ____A C:\Users\All Users\Microsoft.SqlServer.Compact.351.64.bc
2012-06-11 04:27 - 2012-06-11 04:27 - 00001694 ____A C:\Users\G\Desktop\Ultimate Windows Tweaker.exe - Shortcut.lnk
2012-06-11 04:20 - 2012-06-11 04:19 - 02079657 ____A C:\Users\G\Documents\mplayerc_20100214.zip
2012-06-11 04:19 - 2012-06-11 04:19 - 01580080 ____A (Soluto Inc) C:\Users\G\Documents\solutoinstaller-Hq8k5BSo1a.exe
2012-06-11 04:16 - 2012-06-11 04:16 - 00001917 ____A C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2012-06-11 04:15 - 2012-06-11 04:15 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-06-11 04:07 - 2012-06-11 04:07 - 00001085 ____A C:\Users\Public\Desktop\Trillian.lnk
2012-06-11 04:06 - 2012-06-11 04:06 - 00142646 ____A C:\Users\G\Documents\UWT2.1.zip
2012-06-11 03:58 - 2012-06-11 03:58 - 00254152 ____A (Secure By Design Inc.) C:\Users\G\Documents\Ninite AdAware Dropbox Essentials Firefox Flash Installer.exe
2012-06-08 21:43 - 2012-07-10 22:17 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 22:17 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 04:19 - 2012-06-07 04:19 - 00034814 ____A C:\Users\natlie\AppData\Local\dt.dat
2012-06-07 03:33 - 2012-06-07 03:33 - 00107026 ____A C:\Users\G\Documents\Control_System.zip
2012-06-05 22:06 - 2012-07-10 22:18 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 22:18 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 22:17 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 22:18 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 22:18 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 22:17 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-04 05:08 - 2012-06-11 04:02 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-04 05:08 - 2012-06-11 04:02 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-04 05:06 - 2012-06-04 05:06 - 00892360 ____A (Oracle Corporation) C:\Users\G\Documents\jxpiinstall.exe
2012-06-04 03:54 - 2012-06-04 03:36 - 00004408 ____A C:\Windows\System32\TmInstall.log
2012-06-04 03:36 - 2012-06-04 03:36 - 00004280 ____A C:\Windows\SysWOW64\TmInstall.log
2012-06-04 03:28 - 2012-06-04 03:28 - 18002040 ____A (Dropbox, Inc.) C:\Users\G\Documents\Dropbox 1.4.7.exe
2012-06-04 03:28 - 2012-06-04 03:28 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-06-04 03:22 - 2012-06-04 03:22 - 16474544 ____A (Nullsoft, Inc.) C:\Users\G\Documents\winamp5623_full_emusic-7plus_all.exe
2012-06-04 03:21 - 2012-06-04 03:21 - 01639789 ____A C:\Users\G\Documents\winrar-x64-411.exe
2012-06-04 03:17 - 2012-06-04 03:17 - 02941072 ____A (Code Sector ) C:\Users\G\Documents\teracopy.exe
2012-06-04 02:51 - 2012-06-04 02:51 - 03879712 ____A (AVG Technologies) C:\Users\G\Documents\avg_free_stb_all_2012_2178_cnet.exe
2012-06-04 02:46 - 2012-06-04 02:46 - 04849631 ____A (Preview Systems) C:\Users\G\Documents\acdseeclassic.exe
2012-06-04 02:44 - 2012-06-04 02:44 - 00880528 ____A (BitTorrent, Inc.) C:\Users\G\Documents\uTorrent.exe
2012-06-04 02:43 - 2012-06-04 02:42 - 30791231 ____A C:\Users\G\Documents\pms-setup-windows-1.52.1.exe
2012-06-04 02:35 - 2012-06-04 02:35 - 01099435 ____A ( ) C:\Users\G\Documents\mum_setup_8.exe
2012-06-04 01:31 - 2012-06-04 01:31 - 00000020 ___SH C:\Users\natlie\ntuser.ini
2012-06-03 18:31 - 2012-06-03 18:27 - 2797840384 ____A C:\CD2.iso
2012-06-03 18:27 - 2012-06-03 18:21 - 4057518080 ____A C:\CD1.iso
2012-06-03 18:08 - 2012-06-03 18:08 - 00057560 ____A C:\Users\G\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-03 18:08 - 2012-06-03 18:08 - 00000192 ____A C:\Windows\FixPatch.log
2012-06-03 18:08 - 2012-06-03 18:08 - 00000020 ___SH C:\Users\G\ntuser.ini
2012-06-03 18:08 - 2011-10-17 20:18 - 02862550 ____A C:\Windows\AsDebug.log
2012-06-03 18:08 - 2011-10-17 20:10 - 00002483 ____A C:\Windows\PQArecord.log
2012-06-03 18:08 - 2011-02-18 12:12 - 00288010 ____A C:\Windows\AsCDProc.log
2012-06-02 14:19 - 2012-06-22 04:10 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 04:10 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 04:10 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 04:10 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 04:10 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 04:10 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 04:10 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 04:49 - 2012-07-11 09:30 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 09:30 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 09:30 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 09:30 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 09:30 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 09:30 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 09:30 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 09:30 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 09:30 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 09:30 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 09:30 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 09:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 09:31 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 09:30 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 09:30 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 09:30 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 09:30 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 09:30 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 09:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 09:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 09:30 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 09:30 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 09:30 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 09:30 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 09:30 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 09:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 09:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 09:30 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 22:17 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:49 - 2012-06-22 04:09 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 21:48 - 2012-07-10 22:17 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 22:17 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 22:17 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:45 - 2012-06-22 04:09 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 21:44 - 2012-07-10 22:17 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 22:17 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 22:17 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 22:17 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 22:17 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-23 23:57 - 2012-06-11 04:31 - 00054728 ____A (Soluto LTD.) C:\Windows\System32\Drivers\Soluto.sys
ZeroAccess:
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\L
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\n
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\L\00000004.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\L\201d3dde
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\00000004.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\00000008.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\000000cb.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\80000000.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\80000032.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\80000064.@
ZeroAccess:
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\@
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\L
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\n
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3998.64 MB
Available physical RAM: 3377.01 MB
Total Pagefile: 3996.79 MB
Available Pagefile: 3377.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:111.24 GB) (Free:0.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: () (Removable) (Total:7.46 GB) (Free:3.01 GB) NTFS
3 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 119 GB 0 B
Disk 1 Online 7636 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 111 GB 1024 KB
Partition 2 Primary 8 GB 111 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 C OS NTFS Partition 111 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7635 MB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D NTFS Removable 7635 MB Healthy
==================================================================================
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
==========================================================
Last Boot: 2012-07-27 07:23
======================= End Of Log ==========================
- Search.txt
Farbar Recovery Scan Tool Version: 04-08-2012
Ran by SYSTEM at 2012-08-04 11:58:32
Running from D:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
I have recently just had a problem with my laptop and after a bit of google searching I found these forums to be pretty helpful for others in similar situations.
I have an Asus Zenbook with Windows 7 home installed.
Recently I have found "Live Secuirty Platinum" which I understand is some bad malware. I have MSE installed but It has not picked it up, I have also tried a few other malware scanners like Malwarebyes. The problem I have none of the scans can complete as I get a window popup "Windows has encountered a critical problem and will restart automatically in one minute." and I Cant complete the scans.
I have also tried F8 on boot up to select "Disable automatic restart" and also start in safe mode but the problem still occurs.
I have noticed in other posts you have first asked for Farbar Recovery Scan Tool 64-Bit to be downloaded and the two scans run. Below are my results.
Any help would be fantastic!
- FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 04-08-2012
Ran by SYSTEM at 04-08-2012 11:57:21
Running from D:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-11-03] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-11-03] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-11-03] (Intel Corporation)
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] ()
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2661672 2012-02-19] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe" [48128 2011-12-11] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-21] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3058304 2012-03-12] (ASUS)
HKU\G\...\Run: [InternodeUsage] C:\PROGRA~2\INTERN~2\mum.exe [1361408 2011-02-18] (Angus Johnson)
HKU\G\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3671872 2012-04-17] (DT Soft Ltd)
HKU\G\...\Run: [Wabiofebni] C:\Users\G\AppData\Roaming\Ozeny\tuwai.exe [180224 2012-06-12] ()
HKU\GAFFiO\...\Run: [InternodeUsage] C:\PROGRA~2\INTERN~2\mum.exe [1361408 2011-02-18] (Angus Johnson)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit [1805912 2012-05-24] (Soluto)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\GAFFiO\Start Menu\Programs\Startup\Trillian.lnk
ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
==================== Services (Whitelisted) ======
2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [92800 2011-11-30] (ASUS)
2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-08-02] (Atheros)
2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [103584 2011-08-02] (Atheros Commnucations)
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-20] (Intel Corporation)
4 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-12] (The Within Network, LLC)
2 syshost32; "C:\Windows\Installer\{AFB2BB7F-872C-7FEC-63E4-602843CAE818}\syshost.exe" /service [x]
========================== Drivers (Whitelisted) =============
0 944a435ceeab1a2d; C:\Windows\System32\Drivers\944a435ceeab1a2d.sys [84408 2012-08-02] () ATTENTION =====> Rootkit?
3 AiCharger; C:\Windows\System32\Drivers\AiCharger.sys [17152 2011-12-05] (ASUSTek Computer Inc.)
3 AiCharger; C:\Windows\SysWow64\Drivers\AiCharger.sys [17152 2011-12-05] (ASUSTek Computer Inc.)
2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS)
3 AsusVBus; C:\Windows\System32\Drivers\AsusVBus.sys [35968 2011-12-21] (Windows (R) Win 7 DDK provider)
3 AsusVTouch; C:\Windows\System32\Drivers\AsusVTouch.sys [16512 2011-11-07] (Windows (R) Win 7 DDK provider)
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [36000 2011-08-02] (Atheros)
1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
3 BTATH_A2DP; C:\Windows\System32\Drivers\BTATH_A2DP.sys [330912 2011-08-02] (Atheros)
3 btath_avdt; C:\Windows\System32\Drivers\btath_avdt.sys [110240 2011-08-02] (Atheros)
3 BTATH_BUS; C:\Windows\System32\Drivers\BTATH_BUS.sys [30368 2011-08-02] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\Drivers\BTATH_HCRP.sys [167584 2011-08-02] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\Drivers\BTATH_LWFLT.sys [68256 2011-08-02] (Atheros)
3 BTATH_RCP; C:\Windows\System32\Drivers\BTATH_RCP.sys [280992 2011-08-02] (Atheros)
3 BtFilter; C:\Windows\System32\Drivers\BtFilter.sys [511136 2011-08-02] (Atheros)
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-07-31] (DT Soft Ltd)
3 FLxHCIh; C:\Windows\System32\Drivers\FLxHCIh.sys [71424 2011-12-12] (Fresco Logic)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
2 uxpatch; C:\Windows\System32\Drivers\uxpatch.sys [30568 2009-07-12] ()
3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x]
1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-03 17:48 - 2012-08-03 17:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89C13600320A37EF
2012-08-03 17:42 - 2012-08-03 17:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.333D1E267EEAEDB7
2012-08-03 17:38 - 2012-08-03 17:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8A3F188537EC031
2012-08-03 17:35 - 2012-08-03 17:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.042F52C167619136
2012-08-03 17:34 - 2012-08-03 17:34 - 00001272 ____A C:\Users\G\Desktop\noshut.lnk
2012-08-03 17:32 - 2012-08-03 17:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C39511281065875
2012-08-03 17:29 - 2012-08-03 17:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E2C6C5410D36A9C
2012-08-03 17:24 - 2012-08-03 17:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2A24B813FA4B31
2012-08-03 17:21 - 2012-08-03 17:22 - 00000203 ____A C:\spyhunter.fix
2012-08-03 17:21 - 2012-08-03 17:21 - 00002252 ____A C:\Users\G\Desktop\SpyHunter.lnk
2012-08-03 17:21 - 2010-08-05 00:31 - 00014680 ____A C:\Windows\System32\sh4native.exe
2012-08-03 17:20 - 2012-08-03 17:22 - 00000000 ____D C:\sh4ldr
2012-08-03 17:20 - 2012-08-03 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D95945C6F7DC6DF
2012-08-03 17:20 - 2012-08-03 17:20 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-08-03 17:17 - 2012-08-03 17:21 - 00000000 ____D C:\Windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-08-03 17:16 - 2012-08-03 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0776D71E4197441D
2012-08-03 17:15 - 2012-08-03 17:15 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\G\Desktop\explorer.exe
2012-08-03 17:13 - 2012-08-03 17:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9F691F0F718AD008
2012-08-03 17:09 - 2012-08-03 17:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71140A2BED1FEF9A
2012-08-03 17:05 - 2012-08-03 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29E47E623DFEA71C
2012-08-03 17:01 - 2012-08-03 17:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.852342F5DB97EA81
2012-08-03 17:01 - 2012-08-03 17:01 - 00000000 ____D C:\Users\G\AppData\Roaming\Malwarebytes
2012-08-03 17:00 - 2012-08-03 17:00 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-03 17:00 - 2012-08-03 17:00 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-03 17:00 - 2012-08-03 17:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-03 17:00 - 2012-07-02 20:16 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-03 16:59 - 2012-08-03 16:56 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\G\Desktop\mal.exe
2012-08-03 16:56 - 2012-08-03 16:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E5048CDED746C2C
2012-08-03 16:53 - 2012-08-03 16:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9AC4BF904EE4933
2012-08-03 16:49 - 2012-08-03 16:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BF7F1AC2EF60358B
2012-08-03 04:51 - 2012-08-03 04:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C0643A7F98FA1EE3
2012-08-03 04:44 - 2012-08-03 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81CB41BF025CA49
2012-08-03 04:34 - 2012-08-03 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF49F969043124C
2012-08-03 04:28 - 2012-08-03 04:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C480ECBA59153BD
2012-08-03 04:22 - 2012-08-03 04:22 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-03 04:22 - 2012-08-03 04:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-03 04:20 - 2012-08-03 04:20 - 12621696 ____A (Microsoft Corporation) C:\Users\G\Downloads\mseinstall.exe
2012-08-03 04:03 - 2012-08-03 04:03 - 00002018 ____A C:\Users\G\Desktop\Live Security Platinum.lnk
2012-08-03 04:00 - 2012-08-03 04:31 - 00062464 ____A C:\Windows\System32\Comptend64.dll
2012-08-03 04:00 - 2012-08-03 04:00 - 00056320 ___AH (FRISK Software International) C:\Windows\SysWOW64\Comptend.dll
2012-08-03 04:00 - 2012-08-03 03:59 - 00152064 ____A C:\Users\G\AppData\Roaming\csrec.dll
2012-08-02 23:23 - 2012-08-02 23:23 - 00001136 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-08-02 05:46 - 2012-08-02 05:46 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-08-02 05:36 - 2012-08-02 05:36 - 00084408 ____A C:\Windows\System32\Drivers\944a435ceeab1a2d.sys
2012-08-02 05:35 - 2012-08-02 23:19 - 00000000 ____D C:\Users\G\AppData\Roaming\Yfvix
2012-08-02 05:35 - 2012-08-02 23:19 - 00000000 ____D C:\Users\G\AppData\Roaming\Opry
2012-08-02 05:31 - 2012-08-02 05:31 - 00016286 ____A C:\Users\G\Desktop\hs_err_pid16784.log
2012-08-02 05:02 - 2012-08-03 02:04 - 00000000 ____D C:\Users\G\AppData\Roaming\Xoel
2012-08-02 05:02 - 2012-08-02 05:02 - 00000000 ____D C:\Users\G\AppData\Roaming\Ozeny
2012-08-02 05:02 - 2012-08-02 05:02 - 00000000 ____D C:\Users\G\AppData\Roaming\Isnys
2012-08-01 15:31 - 2012-08-01 15:32 - 16814136 ____A (Mozilla) C:\Users\G\Downloads\Firefox Setup 14.0.1.exe
2012-08-01 15:27 - 2012-08-01 15:27 - 13713850 ____A C:\Users\G\Downloads\Intel_RAIDAHCI_V11001032_XPWin7.zip
2012-08-01 15:26 - 2012-08-01 15:27 - 19414180 ____A C:\Users\G\Downloads\Realtek_LAN_V5790_V749_XPWin7.zip
2012-08-01 15:26 - 2012-08-01 15:26 - 05932880 ____A C:\Users\G\Downloads\Intel_USB3_V101209_Win7.zip
2012-08-01 15:25 - 2012-08-01 15:37 - 285344242 ____A C:\Users\G\Downloads\Intel_Graphics_V815102618_WinVista7.zip
2012-08-01 15:25 - 2012-08-01 15:36 - 251841943 ____A C:\Users\G\Downloads\Intel_Chipset_V9301019_P8H77-V_XPWin7.zip
2012-08-01 15:25 - 2012-08-01 15:33 - 141944149 ____A C:\Users\G\Downloads\Realtek_Audio_V51006526_V6016526_XPWin7.zip
2012-08-01 15:22 - 2012-08-01 15:25 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\G\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-08-01 15:17 - 2012-08-01 15:18 - 00001908 ____A C:\Windows\diagwrn.xml
2012-08-01 15:17 - 2012-08-01 15:18 - 00001908 ____A C:\Windows\diagerr.xml
2012-08-01 05:53 - 2012-08-01 05:53 - 00262144 ____A C:\Windows\Minidump\080112-20077-01.dmp
2012-08-01 05:53 - 2012-08-01 05:53 - 00000000 ____D C:\Windows\Minidump
2012-07-31 05:27 - 2012-07-31 05:27 - 00000000 ____D C:\Users\G\Downloads\Windows 7 Anytime Upgrade CD-Key Generator Final Activated
2012-07-31 05:26 - 2012-07-31 05:27 - 00000000 ____D C:\Users\G\Downloads\Windows 7 Home Premium (64 Bit) by (oldBen)
2012-07-31 03:54 - 2012-07-31 03:54 - 00001956 ____A C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2012-07-31 03:53 - 2012-07-31 03:53 - 00283200 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
2012-07-31 03:52 - 2012-07-31 03:54 - 00000000 ____D C:\Users\G\AppData\Roaming\DAEMON Tools Lite
2012-07-31 03:51 - 2012-07-31 03:53 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2012-07-31 03:50 - 2012-07-31 03:54 - 00000000 ____D C:\Users\All Users\DAEMON Tools Lite
2012-07-31 03:50 - 2012-07-31 03:50 - 14230160 ____A (DT Soft Ltd) C:\Users\G\Downloads\DTLite4454-0315.exe
2012-07-31 03:48 - 2012-07-31 03:49 - 00463080 ____A (CNET Download.com) C:\Users\G\Downloads\cnet2_DTLite4454-0315_exe.exe
2012-07-25 03:44 - 2012-07-29 13:39 - 00000000 ____D C:\Users\G\Downloads\Breaking Bad Season 1-3
2012-07-22 14:12 - 2012-07-22 14:13 - 00000000 ____D C:\Users\G\Desktop\rave
2012-07-22 13:56 - 2012-07-31 04:05 - 00000642 ___AH C:\os802099.bin
2012-07-22 13:41 - 2012-07-22 13:41 - 00000000 ____D C:\Windows\PreviewSoft
2012-07-22 13:40 - 2012-07-22 13:40 - 00001477 ____A C:\Users\G\Desktop\Resume ACDSee_Classic Download2.LNK
2012-07-22 13:40 - 2012-07-22 13:40 - 00001340 ____A C:\Users\G\Desktop\Launch ACDSee_Classic 2.44.LNK
2012-07-22 13:37 - 2012-07-24 04:46 - 00000000 ____D C:\Users\G\Desktop\KEEP
2012-07-22 03:53 - 2012-07-22 03:53 - 00000000 ____D C:\Users\G\AppData\Local\Adobe
2012-07-19 18:03 - 2012-07-19 18:03 - 00002015 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-07-19 18:03 - 2012-07-19 18:03 - 00000000 ____D C:\Windows\System32\STRING
2012-07-19 18:03 - 2012-07-19 18:03 - 00000000 ____D C:\Users\All Users\Canon IJ Network Tool
2012-07-19 18:03 - 2012-07-19 18:03 - 00000000 ____D C:\Program Files (x86)\Canon
2012-07-19 18:03 - 2010-03-18 01:55 - 00307200 ____A (CANON INC.) C:\Windows\SysWOW64\CNC495L.dll
2012-07-19 18:03 - 2010-03-17 23:41 - 00106496 ____A (CANON INC.) C:\Windows\SysWOW64\CNC495U.dll
2012-07-19 18:03 - 2010-02-04 17:07 - 00340992 ____A (CANON INC.) C:\Windows\SysWOW64\CNMNPPM.DLL
2012-07-19 18:03 - 2010-02-04 17:07 - 00327680 ____A (CANON INC.) C:\Windows\System32\CNMN6PPM.DLL
2012-07-19 18:03 - 2010-02-04 17:07 - 00037376 ____A (CANON INC.) C:\Windows\System32\CNMN6UI.DLL
2012-07-19 18:03 - 2009-11-12 21:05 - 00012800 ____A C:\Windows\SysWOW64\CNC1747D.TBL
2012-07-19 18:03 - 2008-08-25 00:32 - 00015872 ____A (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2012-07-19 18:02 - 2012-07-19 18:02 - 00000000 ___HD C:\Windows\System32\CanonIJ Uninstaller Information
2012-07-19 18:02 - 2012-07-19 18:02 - 00000000 ___HD C:\Users\All Users\CanonBJ
2012-07-19 18:01 - 2012-07-19 18:01 - 00000000 ___HD C:\Program Files\CanonBJ
2012-07-19 18:01 - 2010-08-24 11:30 - 00361472 ____A (CANON INC.) C:\Windows\System32\CNMLMA9.DLL
2012-07-19 18:01 - 2010-03-10 15:27 - 00248320 ____A (CANON INC.) C:\Windows\System32\CNMIUA9.DLL
2012-07-19 17:47 - 2012-07-19 17:47 - 00043894 ____A C:\Users\G\Downloads\SimpleCoords-1.94.zip
2012-07-19 17:44 - 2012-07-19 17:44 - 00509464 ____A C:\Users\G\Downloads\MageNuggets-2.34.zip
2012-07-19 03:20 - 2012-07-19 03:20 - 00000163 ____A C:\Users\G\Desktop\Mysterious Fortune Card.url
2012-07-18 04:36 - 2012-08-03 17:06 - 00000000 ____D C:\Users\G\AppData\Local\Gabest
2012-07-18 04:36 - 2012-07-18 04:36 - 00000000 ____D C:\Windows\Sun
2012-07-18 04:31 - 2012-07-18 04:31 - 00001898 ____A C:\Users\G\Desktop\PS3 Media Server.lnk
2012-07-18 04:27 - 2012-07-18 04:27 - 00000000 ____D C:\Windows\pss
2012-07-11 23:30 - 2012-07-11 23:30 - 00000000 ____D C:\Program Files (x86)\Belkin
2012-07-11 18:51 - 2012-07-11 18:51 - 00001118 ____A C:\Users\G\Desktop\Launcher.exe - Shortcut.lnk
2012-07-11 15:43 - 2012-07-11 15:43 - 00665466 ____A C:\Users\G\Desktop\scan.rrs
2012-07-11 09:35 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 09:31 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 09:31 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 09:31 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 09:31 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 09:30 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 09:30 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 09:30 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 09:30 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 09:30 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 09:30 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 09:30 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 09:30 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 09:30 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 09:30 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 09:30 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 09:30 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 09:30 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 09:30 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 09:30 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 09:30 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 09:30 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 09:30 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 09:30 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 09:30 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 09:30 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 09:30 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 09:30 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 09:30 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 02:53 - 2012-07-11 15:42 - 00000000 ____D C:\Program Files (x86)\PowerDataRecovery
2012-07-11 02:53 - 2012-07-11 02:53 - 00001039 ____A C:\Users\Public\Desktop\Power Data Recovery.lnk
2012-07-11 02:52 - 2012-07-11 02:52 - 00000000 ____D C:\Users\G\Documents\Power Data Recovery Pro v4.1.1
2012-07-11 02:50 - 2012-07-11 02:51 - 15861760 ____A C:\Users\G\Documents\Stellar.Phoenix.Windows.Data.Recovery.v3.0.0.With Crack By Faraz 101% Clean From VIRUS.zip
2012-07-10 23:02 - 2012-07-10 23:02 - 00000000 ____D C:\Users\G\Desktop\New folder
2012-07-10 22:18 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 22:18 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 22:18 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 22:18 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 22:18 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 22:18 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 22:17 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 22:17 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 22:17 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 22:17 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 22:17 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 22:17 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 22:17 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 22:17 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 22:17 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 22:17 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 22:17 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 22:17 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 22:17 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-05 05:52 - 2012-07-05 05:54 - 109168195 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_audio_realtek_azalia.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 03364486 ____A C:\Users\G\Documents\motherboard_driver_lan_realtek_8111.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 01246890 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_chipset_intel.exe
2012-07-05 04:11 - 2012-07-22 14:50 - 00000000 ____D C:\Users\G\AppData\Roaming\vlc
============ 3 Months Modified Files ========================
2012-08-04 11:28 - 2011-10-17 19:58 - 00008446 ____A C:\Windows\AsRecoveryHD.log
2012-08-04 11:27 - 2011-10-17 19:57 - 00039853 ____A C:\Windows\AsFac.log
2012-08-03 18:20 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-03 18:20 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-03 18:02 - 2009-07-13 21:13 - 00797650 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-03 17:59 - 2012-06-11 04:37 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-03 17:58 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-03 17:58 - 2009-07-13 20:51 - 00002068 ____A C:\Windows\setupact.log
2012-08-03 17:48 - 2012-08-03 17:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89C13600320A37EF
2012-08-03 17:42 - 2012-08-03 17:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.333D1E267EEAEDB7
2012-08-03 17:38 - 2012-08-03 17:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E8A3F188537EC031
2012-08-03 17:35 - 2012-08-03 17:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.042F52C167619136
2012-08-03 17:34 - 2012-08-03 17:34 - 00001272 ____A C:\Users\G\Desktop\noshut.lnk
2012-08-03 17:32 - 2012-08-03 17:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C39511281065875
2012-08-03 17:29 - 2012-08-03 17:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E2C6C5410D36A9C
2012-08-03 17:24 - 2012-08-03 17:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2A24B813FA4B31
2012-08-03 17:22 - 2012-08-03 17:21 - 00000203 ____A C:\spyhunter.fix
2012-08-03 17:21 - 2012-08-03 17:21 - 00002252 ____A C:\Users\G\Desktop\SpyHunter.lnk
2012-08-03 17:20 - 2012-08-03 17:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D95945C6F7DC6DF
2012-08-03 17:16 - 2012-08-03 17:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0776D71E4197441D
2012-08-03 17:15 - 2012-08-03 17:15 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\G\Desktop\explorer.exe
2012-08-03 17:13 - 2012-08-03 17:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9F691F0F718AD008
2012-08-03 17:09 - 2012-08-03 17:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71140A2BED1FEF9A
2012-08-03 17:06 - 2011-10-17 19:58 - 00327852 ____A C:\Windows\PFRO.log
2012-08-03 17:05 - 2012-08-03 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29E47E623DFEA71C
2012-08-03 17:01 - 2012-08-03 17:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.852342F5DB97EA81
2012-08-03 17:00 - 2012-08-03 17:00 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-03 16:56 - 2012-08-03 16:59 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\G\Desktop\mal.exe
2012-08-03 16:56 - 2012-08-03 16:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E5048CDED746C2C
2012-08-03 16:53 - 2012-08-03 16:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D9AC4BF904EE4933
2012-08-03 16:49 - 2012-08-03 16:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BF7F1AC2EF60358B
2012-08-03 04:51 - 2012-08-03 04:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C0643A7F98FA1EE3
2012-08-03 04:44 - 2012-08-03 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81CB41BF025CA49
2012-08-03 04:36 - 2012-03-12 18:08 - 01169433 ____A C:\Windows\WindowsUpdate.log
2012-08-03 04:34 - 2012-08-03 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECF49F969043124C
2012-08-03 04:31 - 2012-08-03 04:00 - 00062464 ____A C:\Windows\System32\Comptend64.dll
2012-08-03 04:28 - 2012-08-03 04:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4C480ECBA59153BD
2012-08-03 04:22 - 2012-06-11 04:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-03 04:22 - 2011-10-17 20:17 - 00803496 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-03 04:20 - 2012-08-03 04:20 - 12621696 ____A (Microsoft Corporation) C:\Users\G\Downloads\mseinstall.exe
2012-08-03 04:03 - 2012-08-03 04:03 - 00002018 ____A C:\Users\G\Desktop\Live Security Platinum.lnk
2012-08-03 04:00 - 2012-08-03 04:00 - 00056320 ___AH (FRISK Software International) C:\Windows\SysWOW64\Comptend.dll
2012-08-03 03:59 - 2012-08-03 04:00 - 00152064 ____A C:\Users\G\AppData\Roaming\csrec.dll
2012-08-02 23:23 - 2012-08-02 23:23 - 00001136 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-08-02 05:36 - 2012-08-02 05:36 - 00084408 ____A C:\Windows\System32\Drivers\944a435ceeab1a2d.sys
2012-08-02 05:31 - 2012-08-02 05:31 - 00016286 ____A C:\Users\G\Desktop\hs_err_pid16784.log
2012-08-01 15:37 - 2012-08-01 15:25 - 285344242 ____A C:\Users\G\Downloads\Intel_Graphics_V815102618_WinVista7.zip
2012-08-01 15:36 - 2012-08-01 15:25 - 251841943 ____A C:\Users\G\Downloads\Intel_Chipset_V9301019_P8H77-V_XPWin7.zip
2012-08-01 15:33 - 2012-08-01 15:25 - 141944149 ____A C:\Users\G\Downloads\Realtek_Audio_V51006526_V6016526_XPWin7.zip
2012-08-01 15:32 - 2012-08-01 15:31 - 16814136 ____A (Mozilla) C:\Users\G\Downloads\Firefox Setup 14.0.1.exe
2012-08-01 15:27 - 2012-08-01 15:27 - 13713850 ____A C:\Users\G\Downloads\Intel_RAIDAHCI_V11001032_XPWin7.zip
2012-08-01 15:27 - 2012-08-01 15:26 - 19414180 ____A C:\Users\G\Downloads\Realtek_LAN_V5790_V749_XPWin7.zip
2012-08-01 15:26 - 2012-08-01 15:26 - 05932880 ____A C:\Users\G\Downloads\Intel_USB3_V101209_Win7.zip
2012-08-01 15:25 - 2012-08-01 15:22 - 158124424 ____A (Advanced Micro Devices, Inc.) C:\Users\G\Downloads\12-6_vista_win7_64_dd_ccc.exe
2012-08-01 15:18 - 2012-08-01 15:17 - 00001908 ____A C:\Windows\diagwrn.xml
2012-08-01 15:18 - 2012-08-01 15:17 - 00001908 ____A C:\Windows\diagerr.xml
2012-08-01 15:17 - 2009-07-13 20:51 - 00000000 ____A C:\Windows\setuperr.log
2012-08-01 05:53 - 2012-08-01 05:53 - 00262144 ____A C:\Windows\Minidump\080112-20077-01.dmp
2012-07-31 04:05 - 2012-07-22 13:56 - 00000642 ___AH C:\os802099.bin
2012-07-31 03:54 - 2012-07-31 03:54 - 00001956 ____A C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2012-07-31 03:53 - 2012-07-31 03:53 - 00283200 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
2012-07-31 03:50 - 2012-07-31 03:50 - 14230160 ____A (DT Soft Ltd) C:\Users\G\Downloads\DTLite4454-0315.exe
2012-07-31 03:49 - 2012-07-31 03:48 - 00463080 ____A (CNET Download.com) C:\Users\G\Downloads\cnet2_DTLite4454-0315_exe.exe
2012-07-22 13:40 - 2012-07-22 13:40 - 00001477 ____A C:\Users\G\Desktop\Resume ACDSee_Classic Download2.LNK
2012-07-22 13:40 - 2012-07-22 13:40 - 00001340 ____A C:\Users\G\Desktop\Launch ACDSee_Classic 2.44.LNK
2012-07-19 18:03 - 2012-07-19 18:03 - 00002015 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-07-19 17:47 - 2012-07-19 17:47 - 00043894 ____A C:\Users\G\Downloads\SimpleCoords-1.94.zip
2012-07-19 17:44 - 2012-07-19 17:44 - 00509464 ____A C:\Users\G\Downloads\MageNuggets-2.34.zip
2012-07-19 03:20 - 2012-07-19 03:20 - 00000163 ____A C:\Users\G\Desktop\Mysterious Fortune Card.url
2012-07-18 04:31 - 2012-07-18 04:31 - 00001898 ____A C:\Users\G\Desktop\PS3 Media Server.lnk
2012-07-11 18:51 - 2012-07-11 18:51 - 00001118 ____A C:\Users\G\Desktop\Launcher.exe - Shortcut.lnk
2012-07-11 15:43 - 2012-07-11 15:43 - 00665466 ____A C:\Users\G\Desktop\scan.rrs
2012-07-11 09:53 - 2009-07-13 20:45 - 00274320 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 09:32 - 2012-06-04 03:27 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 02:53 - 2012-07-11 02:53 - 00001039 ____A C:\Users\Public\Desktop\Power Data Recovery.lnk
2012-07-11 02:51 - 2012-07-11 02:50 - 15861760 ____A C:\Users\G\Documents\Stellar.Phoenix.Windows.Data.Recovery.v3.0.0.With Crack By Faraz 101% Clean From VIRUS.zip
2012-07-05 05:54 - 2012-07-05 05:52 - 109168195 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_audio_realtek_azalia.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 03364486 ____A C:\Users\G\Documents\motherboard_driver_lan_realtek_8111.exe
2012-07-05 05:52 - 2012-07-05 05:52 - 01246890 ____A (Igor Pavlov) C:\Users\G\Documents\mb_driver_chipset_intel.exe
2012-07-03 02:29 - 2012-07-03 02:29 - 00067371 ____A C:\Users\G\Downloads\SwindlerPreventer_4-3-3.zip
2012-07-03 02:27 - 2012-07-03 02:27 - 00378804 ____A C:\Users\G\Downloads\Recount-v4.3.0d_release.zip
2012-07-03 02:24 - 2012-07-03 02:24 - 00397722 ____A C:\Users\G\Downloads\Quartz-3.0.8.zip
2012-07-03 02:21 - 2012-07-03 02:20 - 00797377 ____A C:\Users\G\Downloads\Overachiever-v0.65.zip
2012-07-03 02:17 - 2012-07-03 02:17 - 00270569 ____A C:\Users\G\Downloads\GatherMate2_Data-v10.5.zip
2012-07-03 02:16 - 2012-07-03 02:16 - 00846388 ____A C:\Users\G\Downloads\GatherMate2-1.16.2.zip
2012-07-03 02:15 - 2012-07-03 02:14 - 00465193 ____A C:\Users\G\Downloads\Decursive-2.7.0.5.zip
2012-07-03 02:10 - 2012-07-03 02:10 - 01124103 ____A C:\Users\G\Downloads\DBM-4.10.12-r7536-Core-and-Cataclysm-Mods.zip
2012-07-03 02:07 - 2012-07-03 02:07 - 00333196 ____A C:\Users\G\Downloads\Chatter-v.1.3.3.zip
2012-07-03 02:02 - 2012-07-03 02:02 - 00279513 ____A C:\Users\G\Downloads\Bartender4-4.4.20.1.zip
2012-07-02 20:16 - 2012-08-03 17:00 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-30 01:06 - 2012-06-30 01:06 - 26576272 ____A C:\Users\G\Documents\mp495swin102ea24.exe
2012-06-19 04:16 - 2012-03-12 18:10 - 00015470 ____A C:\Windows\DPINST.LOG
2012-06-19 04:11 - 2012-06-19 03:50 - 150138003 ____A C:\Users\G\Documents\Touchpad_Elantech_Win7_64_Z10590.zip
2012-06-19 03:54 - 2012-06-19 03:51 - 16576878 ____A C:\Users\G\Documents\WLAN_Atheros_Win7_64_Z921470.zip
2012-06-17 02:58 - 2012-06-17 02:58 - 00057560 ____A C:\Users\natlie\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-12 04:54 - 2012-06-03 18:08 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe
2012-06-12 04:39 - 2012-06-11 04:06 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-06-12 04:36 - 2012-06-12 04:36 - 00002585 ____A C:\Users\GAFFiO\Desktop\Power4Gear Hybrid.lnk
2012-06-12 02:31 - 2012-06-12 02:31 - 00290334 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-06-12 02:31 - 2012-06-12 02:31 - 00286962 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-06-11 19:08 - 2012-07-11 09:35 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 06:49 - 2012-06-11 06:49 - 00057560 ____A C:\Users\GAFFiO\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-11 06:47 - 2012-06-11 06:47 - 00000020 ___SH C:\Users\GAFFiO\ntuser.ini
2012-06-11 04:40 - 2012-06-11 04:40 - 00001038 ____A C:\Users\G\Desktop\Dropbox.lnk
2012-06-11 04:37 - 2012-06-06 15:00 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-11 04:37 - 2012-06-06 15:00 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-11 04:31 - 2012-06-11 04:31 - 00001899 ____A C:\Users\GAFFiO\Desktop\Soluto.lnk
2012-06-11 04:31 - 2012-06-11 04:31 - 00000098 ____A C:\Users\All Users\Microsoft.SqlServer.Compact.351.64.bc
2012-06-11 04:27 - 2012-06-11 04:27 - 00001694 ____A C:\Users\G\Desktop\Ultimate Windows Tweaker.exe - Shortcut.lnk
2012-06-11 04:20 - 2012-06-11 04:19 - 02079657 ____A C:\Users\G\Documents\mplayerc_20100214.zip
2012-06-11 04:19 - 2012-06-11 04:19 - 01580080 ____A (Soluto Inc) C:\Users\G\Documents\solutoinstaller-Hq8k5BSo1a.exe
2012-06-11 04:16 - 2012-06-11 04:16 - 00001917 ____A C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2012-06-11 04:15 - 2012-06-11 04:15 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-06-11 04:07 - 2012-06-11 04:07 - 00001085 ____A C:\Users\Public\Desktop\Trillian.lnk
2012-06-11 04:06 - 2012-06-11 04:06 - 00142646 ____A C:\Users\G\Documents\UWT2.1.zip
2012-06-11 03:58 - 2012-06-11 03:58 - 00254152 ____A (Secure By Design Inc.) C:\Users\G\Documents\Ninite AdAware Dropbox Essentials Firefox Flash Installer.exe
2012-06-08 21:43 - 2012-07-10 22:17 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 22:17 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 04:19 - 2012-06-07 04:19 - 00034814 ____A C:\Users\natlie\AppData\Local\dt.dat
2012-06-07 03:33 - 2012-06-07 03:33 - 00107026 ____A C:\Users\G\Documents\Control_System.zip
2012-06-05 22:06 - 2012-07-10 22:18 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 22:18 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 22:17 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 22:18 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 22:18 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 22:17 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-04 05:08 - 2012-06-11 04:02 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-04 05:08 - 2012-06-11 04:02 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-04 05:06 - 2012-06-04 05:06 - 00892360 ____A (Oracle Corporation) C:\Users\G\Documents\jxpiinstall.exe
2012-06-04 03:54 - 2012-06-04 03:36 - 00004408 ____A C:\Windows\System32\TmInstall.log
2012-06-04 03:36 - 2012-06-04 03:36 - 00004280 ____A C:\Windows\SysWOW64\TmInstall.log
2012-06-04 03:28 - 2012-06-04 03:28 - 18002040 ____A (Dropbox, Inc.) C:\Users\G\Documents\Dropbox 1.4.7.exe
2012-06-04 03:28 - 2012-06-04 03:28 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-06-04 03:22 - 2012-06-04 03:22 - 16474544 ____A (Nullsoft, Inc.) C:\Users\G\Documents\winamp5623_full_emusic-7plus_all.exe
2012-06-04 03:21 - 2012-06-04 03:21 - 01639789 ____A C:\Users\G\Documents\winrar-x64-411.exe
2012-06-04 03:17 - 2012-06-04 03:17 - 02941072 ____A (Code Sector ) C:\Users\G\Documents\teracopy.exe
2012-06-04 02:51 - 2012-06-04 02:51 - 03879712 ____A (AVG Technologies) C:\Users\G\Documents\avg_free_stb_all_2012_2178_cnet.exe
2012-06-04 02:46 - 2012-06-04 02:46 - 04849631 ____A (Preview Systems) C:\Users\G\Documents\acdseeclassic.exe
2012-06-04 02:44 - 2012-06-04 02:44 - 00880528 ____A (BitTorrent, Inc.) C:\Users\G\Documents\uTorrent.exe
2012-06-04 02:43 - 2012-06-04 02:42 - 30791231 ____A C:\Users\G\Documents\pms-setup-windows-1.52.1.exe
2012-06-04 02:35 - 2012-06-04 02:35 - 01099435 ____A ( ) C:\Users\G\Documents\mum_setup_8.exe
2012-06-04 01:31 - 2012-06-04 01:31 - 00000020 ___SH C:\Users\natlie\ntuser.ini
2012-06-03 18:31 - 2012-06-03 18:27 - 2797840384 ____A C:\CD2.iso
2012-06-03 18:27 - 2012-06-03 18:21 - 4057518080 ____A C:\CD1.iso
2012-06-03 18:08 - 2012-06-03 18:08 - 00057560 ____A C:\Users\G\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-03 18:08 - 2012-06-03 18:08 - 00000192 ____A C:\Windows\FixPatch.log
2012-06-03 18:08 - 2012-06-03 18:08 - 00000020 ___SH C:\Users\G\ntuser.ini
2012-06-03 18:08 - 2011-10-17 20:18 - 02862550 ____A C:\Windows\AsDebug.log
2012-06-03 18:08 - 2011-10-17 20:10 - 00002483 ____A C:\Windows\PQArecord.log
2012-06-03 18:08 - 2011-02-18 12:12 - 00288010 ____A C:\Windows\AsCDProc.log
2012-06-02 14:19 - 2012-06-22 04:10 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 04:10 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 04:10 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 04:10 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 04:10 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 04:10 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 04:10 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 04:49 - 2012-07-11 09:30 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 09:30 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 09:30 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 09:30 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 09:30 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 09:30 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 09:30 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 09:30 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 09:30 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 09:30 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 09:30 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 09:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 09:31 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 09:30 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 09:30 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 09:30 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 09:30 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 09:30 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 09:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 09:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 09:30 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 09:30 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 09:30 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 09:30 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 09:30 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 09:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 09:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 09:30 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 22:17 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:49 - 2012-06-22 04:09 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 21:48 - 2012-07-10 22:17 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 22:17 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 22:17 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:45 - 2012-06-22 04:09 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 21:44 - 2012-07-10 22:17 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 22:17 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 22:17 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 22:17 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 22:17 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-23 23:57 - 2012-06-11 04:31 - 00054728 ____A (Soluto LTD.) C:\Windows\System32\Drivers\Soluto.sys
ZeroAccess:
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\L
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\n
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\L\00000004.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\L\201d3dde
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\00000004.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\00000008.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\000000cb.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\80000000.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\80000032.@
C:\Windows\Installer\{f54dba68-706f-6da4-e5da-66574788c273}\U\80000064.@
ZeroAccess:
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\@
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\L
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\n
C:\Users\G\AppData\Local\{f54dba68-706f-6da4-e5da-66574788c273}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3998.64 MB
Available physical RAM: 3377.01 MB
Total Pagefile: 3996.79 MB
Available Pagefile: 3377.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:111.24 GB) (Free:0.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: () (Removable) (Total:7.46 GB) (Free:3.01 GB) NTFS
3 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 119 GB 0 B
Disk 1 Online 7636 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 111 GB 1024 KB
Partition 2 Primary 8 GB 111 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 C OS NTFS Partition 111 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7635 MB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D NTFS Removable 7635 MB Healthy
==================================================================================
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
==========================================================
Last Boot: 2012-07-27 07:23
======================= End Of Log ==========================
- Search.txt
Farbar Recovery Scan Tool Version: 04-08-2012
Ran by SYSTEM at 2012-08-04 11:58:32
Running from D:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======