asimperson
Posts: 17 +0
Hi all,
I seem to have gotten bit by this as well, despite using MSE and other tools I still haven't been able to completely get rid of the infection. I did consider doing a System Restore to a point before the infection but that doesn't seem to get recommended a whole lot so I haven't done it.
What I've done for now is run FRST, and these are the results:
Scan result of Farbar Recovery Scan Tool Version: 08-07-2012
Ran by SYSTEM at 08-07-2012 15:09:21
Running from J:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM\...\Run: [TortoiseHgOverlayIconServer] E:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe [x]
HKLM\...\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart [980368 2011-11-05] (The Eraser Project)
HKLM\...\Run: [boincmgr] "E:\Program Files\BOINC\boincmgr.exe" /a /s [x]
HKLM\...\Run: [boinctray] "E:\Program Files\BOINC\boinctray.exe" [x]
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe [271736 2010-09-14] (American Power Conversion Corporation)
HKLM-x32\...\Run: [BCSSync] "E:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [THX Audio Control Panel] "E:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r [x]
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe" [x]
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641704 2012-06-11] (Advanced Micro Devices, Inc.)
HKU\asim\...\Run: [TomTomHOME.exe] "e:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" -s [x]
HKU\asim\...\Run: [Google Update] "C:\Users\asim\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-05-30] (Google Inc.)
HKU\asim\...\Run: [ASRockXTU] [x]
HKU\asim\...\Run: [OfficeSyncProcess] "E:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [x]
HKU\asim\...\Run: [Steam] "E:\Steam\Steam.exe" -silent [x]
HKU\asim\...\Run: [Koodv] C:\Users\asim\AppData\Roaming\Ymafuw\keiq.exe [421888 2012-04-10] ()
HKU\asim\...\Run: [wseto] "C:\Windows\System32\rundll32.exe" "C:\Users\asim\AppData\Roaming\wseto.dll",TypeToAdsTypeDNWithString [375808 2012-07-07] (Dogbert)
HKU\asim\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1082440 2012-04-04] (Malwarebytes Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
Startup: C:\Users\asim\Start Menu\Programs\Startup\FreePOPs.lnk
ShortcutTarget: FreePOPs.lnk -> C:\Program Files (x86)\FreePOPs\freepopsd.exe ()
Startup: C:\Users\asim\Start Menu\Programs\Startup\pagent.lnk
ShortcutTarget: pagent.lnk -> C:\windows\system32\config\systemprofile\Desktop\sshkeys\pageant.exe (No File)
Startup: C:\Users\asim\Start Menu\Programs\Startup\Password Safe.lnk
ShortcutTarget: Password Safe.lnk -> C:\Program Files (x86)\Password Safe\pwsafe.exe (SourceForge.net)
==================== Services (Whitelisted) ======
2 APC Data Service; "C:\Program Files (x86)\APC\APC PowerChute Personal Edition\dataserv.exe" [21880 2010-09-14] (American Power Conversion Corporation)
2 APC UPS Service; "C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe" [705912 2010-09-14] (American Power Conversion Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 AdobeActiveFileMonitor9.0; C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [x]
3 Microsoft SharePoint Workspace Audit Service; "C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE" /auditservice [x]
2 TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
========================== Drivers (Whitelisted) =============
3 BazisVirtualCDBus; C:\Windows\System32\Drivers\BazisVirtualCDBus.sys [198480 2011-08-08] (SysProgs.org)
0 mv91xx; C:\Windows\System32\Drivers\mv91xx.sys [302120 2010-09-30] (Marvell Semiconductor, Inc.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-07 12:07 - 2012-07-07 12:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F8CCFB3BBDC3120
2012-07-07 12:04 - 2012-07-07 12:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.452CEDDFB472FFA5
2012-07-07 12:02 - 2012-07-07 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DBA9A7DD8E2D21F6
2012-07-07 04:59 - 2012-07-07 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28C7AFDF4A6B032F
2012-07-07 04:56 - 2012-07-07 04:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D8756818028673E
2012-07-07 04:55 - 2012-07-07 04:55 - 00000000 ____D C:\Users\asim\AppData\Roaming\SUPERAntiSpyware.com
2012-07-07 04:53 - 2012-07-07 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.210092B5F4929FD1
2012-07-07 04:50 - 2012-07-07 04:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77D8D2FCF29EF135
2012-07-07 04:50 - 2012-07-07 04:50 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-07-07 04:50 - 2012-07-07 04:50 - 00000000 ____D C:\Users\All Users\SUPERSetup
2012-07-07 04:50 - 2012-07-07 04:50 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-07-07 04:50 - 2012-07-07 04:50 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-07-07 04:49 - 2012-07-07 04:49 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\11712296.sys
2012-07-07 04:47 - 2012-07-07 04:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.538C2617149635E5
2012-07-07 04:44 - 2012-07-07 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78879EDBFCA7CE8D
2012-07-07 04:39 - 2012-07-07 04:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.835E6C898369C506
2012-07-07 04:39 - 2012-07-07 04:39 - 00176940 ____A C:\Users\asim\Downloads\BFE.reg
2012-07-07 04:38 - 2012-07-07 04:38 - 00006396 ____A C:\Users\asim\Downloads\MpsSvc.reg
2012-07-07 04:37 - 2012-07-07 04:37 - 00007586 ____A C:\Users\asim\Downloads\WinDefend.reg
2012-07-07 04:36 - 2012-07-07 04:36 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-07 04:36 - 2012-07-07 04:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-07 04:19 - 2012-07-07 04:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-07 04:19 - 2012-07-07 04:19 - 00000000 ____D C:\Users\asim\AppData\Roaming\Malwarebytes
2012-07-07 04:19 - 2012-07-07 04:19 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-07 04:19 - 2012-07-07 04:19 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-07 04:19 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-07 04:18 - 2012-07-07 04:19 - 10063024 ____A (Malwarebytes Corporation ) C:\Users\asim\Downloads\mbam-setup.exe
2012-07-07 04:13 - 2012-07-07 04:13 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-07 04:13 - 2012-07-07 04:13 - 00001238 ____A C:\Users\asim\Desktop\FixExec.txt
2012-07-07 04:13 - 2012-07-07 04:13 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-07 03:57 - 2012-07-07 03:57 - 00000000 ____D C:\Users\asim\AppData\Local\{D5C3F5E5-C82A-11E1-8270-B8AC6F996F26}
2012-07-07 03:56 - 2012-07-07 03:56 - 00375808 ____A (Dogbert) C:\Users\asim\AppData\Roaming\wseto.dll
2012-07-07 03:56 - 2012-07-07 03:56 - 00000000 ____D C:\Users\asim\AppData\Local\{D5C3BD85-C82A-11E1-8270-B8AC6F996F26}
2012-07-07 03:55 - 2012-07-07 04:28 - 00000000 ____D C:\Users\asim\AppData\Roaming\Saepy
2012-07-07 03:55 - 2012-07-07 04:24 - 00000000 ____D C:\Users\asim\AppData\Local\PlatformUserServices
2012-07-07 03:55 - 2012-07-07 03:55 - 00000000 ____D C:\Users\asim\AppData\Roaming\Ymafuw
2012-07-07 03:55 - 2012-07-07 03:55 - 00000000 ____D C:\Users\asim\AppData\Roaming\Udmex
2012-07-07 03:55 - 2012-07-07 03:55 - 00000000 ____D C:\Users\All Users\B7E858A700008F5E000369D2B4EB2331
2012-07-03 21:05 - 2012-07-03 21:05 - 00000000 ____D C:\Users\All Users\ATI
2012-07-03 21:05 - 2012-07-03 21:05 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-07-03 21:00 - 2012-07-03 21:00 - 00000000 ____D C:\AMD
2012-06-25 20:03 - 2012-06-25 20:03 - 00000000 ____D C:\Users\asim\Documents\SavedGames
2012-06-25 20:03 - 2012-06-25 20:03 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2012-06-20 20:48 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-20 20:48 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-20 20:48 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-20 20:48 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-20 20:48 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 03:59 - 2012-06-19 03:59 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-19 03:59 - 2012-06-19 03:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-18 20:33 - 2012-06-18 20:39 - 60429312 ____A C:\Users\asim\Downloads\graphviz-2.28.0.msi
2012-06-13 00:31 - 2012-06-13 00:31 - 00000000 ____D C:\Users\asim\AppData\Local\Macromedia
2012-06-12 22:48 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 22:48 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 22:48 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 22:48 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 22:48 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 22:48 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 22:48 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 22:48 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 22:48 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 22:48 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 22:48 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 22:48 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 22:48 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 22:48 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 22:48 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 22:48 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 22:48 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 22:48 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 22:48 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 22:48 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 22:48 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 22:48 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 22:48 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 22:48 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 22:48 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 22:48 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 22:48 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 22:48 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 22:48 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 22:48 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 22:48 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 22:48 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 22:48 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 22:48 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 22:47 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 22:47 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 22:47 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-06-12 22:47 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 22:47 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 22:47 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-06-12 22:47 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 22:47 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 22:47 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 22:47 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 22:47 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 22:47 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 22:47 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 23:32 - 2012-06-11 23:32 - 00001573 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 23:32 - 2012-06-11 23:32 - 00000000 ____D C:\Program Files\iTunes
2012-06-11 23:32 - 2012-06-11 23:32 - 00000000 ____D C:\Program Files\iPod
2012-06-11 12:50 - 2012-06-11 12:50 - 16457728 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-06-11 12:50 - 2012-06-11 12:50 - 00075264 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-06-11 12:49 - 2012-06-11 12:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-06-11 10:59 - 2012-06-11 10:59 - 10248192 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00070144 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:29 - 2012-06-11 10:29 - 24826368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00532992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00239616 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 08:51 - 2012-06-11 08:51 - 04246528 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-06-11 08:50 - 2012-06-11 08:50 - 02936864 ____A C:\Windows\System32\atiumd6a.cap
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-06-11 08:36 - 2012-06-11 08:36 - 06605824 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00367616 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00017920 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00045056 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
============ 3 Months Modified Files ========================
2012-07-07 12:13 - 2009-07-13 21:13 - 00782568 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-07 12:07 - 2012-07-07 12:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F8CCFB3BBDC3120
2012-07-07 12:06 - 2011-05-31 01:48 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-07 12:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-07 12:05 - 2009-07-13 20:51 - 00042333 ____A C:\Windows\setupact.log
2012-07-07 12:04 - 2012-07-07 12:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.452CEDDFB472FFA5
2012-07-07 12:02 - 2012-07-07 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DBA9A7DD8E2D21F6
2012-07-07 11:58 - 2010-11-20 19:47 - 00049286 ____A C:\Windows\PFRO.log
2012-07-07 05:02 - 2011-05-26 17:25 - 02019851 ____A C:\Windows\WindowsUpdate.log
2012-07-07 04:59 - 2012-07-07 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28C7AFDF4A6B032F
2012-07-07 04:56 - 2012-07-07 04:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D8756818028673E
2012-07-07 04:56 - 2011-05-30 20:25 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1299077805-4049216064-1238344601-1000UA.job
2012-07-07 04:53 - 2012-07-07 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.210092B5F4929FD1
2012-07-07 04:50 - 2012-07-07 04:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77D8D2FCF29EF135
2012-07-07 04:50 - 2012-07-07 04:50 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-07-07 04:49 - 2012-07-07 04:49 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\11712296.sys
2012-07-07 04:47 - 2012-07-07 04:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.538C2617149635E5
2012-07-07 04:44 - 2012-07-07 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78879EDBFCA7CE8D
2012-07-07 04:39 - 2012-07-07 04:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.835E6C898369C506
2012-07-07 04:39 - 2012-07-07 04:39 - 00176940 ____A C:\Users\asim\Downloads\BFE.reg
2012-07-07 04:38 - 2012-07-07 04:38 - 00006396 ____A C:\Users\asim\Downloads\MpsSvc.reg
2012-07-07 04:37 - 2012-07-07 04:37 - 00007586 ____A C:\Users\asim\Downloads\WinDefend.reg
2012-07-07 04:36 - 2011-05-26 20:09 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-07 04:36 - 2011-05-26 20:08 - 00798480 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-07 04:35 - 2011-05-26 20:08 - 12621696 ____A (Microsoft Corporation) C:\Users\asim\Downloads\mseinstall.exe
2012-07-07 04:35 - 2009-07-13 20:45 - 00022208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-07 04:35 - 2009-07-13 20:45 - 00022208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-07 04:19 - 2012-07-07 04:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-07 04:19 - 2012-07-07 04:18 - 10063024 ____A (Malwarebytes Corporation ) C:\Users\asim\Downloads\mbam-setup.exe
2012-07-07 04:13 - 2012-07-07 04:13 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-07 04:13 - 2012-07-07 04:13 - 00001238 ____A C:\Users\asim\Desktop\FixExec.txt
2012-07-07 03:56 - 2012-07-07 03:56 - 00375808 ____A (Dogbert) C:\Users\asim\AppData\Roaming\wseto.dll
2012-07-07 03:22 - 2011-05-27 23:49 - 00000600 ____A C:\Users\asim\AppData\Roaming\winscp.rnd
2012-07-07 03:18 - 2011-05-31 01:48 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 18:56 - 2011-05-30 20:25 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1299077805-4049216064-1238344601-1000Core.job
2012-07-03 19:19 - 2012-04-03 00:26 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-03 19:19 - 2011-05-26 23:40 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-29 19:57 - 2011-05-30 20:25 - 00002395 ____A C:\Users\asim\Desktop\Google Chrome.lnk
2012-06-26 10:55 - 2012-03-15 20:14 - 00000891 ____A C:\Users\Public\Desktop\Mass Effect 3.lnk
2012-06-26 10:55 - 2011-05-28 00:16 - 00246624 ____A C:\Windows\DirectX.log
2012-06-24 21:38 - 2011-05-30 14:08 - 00000600 ____A C:\Users\asim\AppData\Local\PUTTY.RND
2012-06-18 20:39 - 2012-06-18 20:33 - 60429312 ____A C:\Users\asim\Downloads\graphviz-2.28.0.msi
2012-06-12 23:11 - 2009-07-13 20:45 - 00424824 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 22:51 - 2011-05-26 17:56 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-11 23:32 - 2012-06-11 23:32 - 00001573 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 12:50 - 2012-06-11 12:50 - 16457728 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-06-11 12:50 - 2012-06-11 12:50 - 00075264 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-06-11 12:49 - 2012-06-11 12:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-06-11 10:59 - 2012-06-11 10:59 - 10248192 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00070144 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:29 - 2012-06-11 10:29 - 24826368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:24 - 2011-04-19 18:09 - 00924160 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-06-11 09:23 - 2011-04-19 18:07 - 01090560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00532992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00239616 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 09:16 - 2012-02-14 19:07 - 06301696 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-06-11 09:01 - 2011-04-19 17:49 - 06914560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-06-11 08:51 - 2012-06-11 08:51 - 04246528 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-06-11 08:50 - 2012-06-11 08:50 - 02936864 ____A C:\Windows\System32\atiumd6a.cap
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-06-11 08:45 - 2011-04-19 17:46 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-06-11 08:45 - 2011-04-19 17:45 - 15703040 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-06-11 08:45 - 2011-04-19 17:38 - 05480448 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-06-11 08:43 - 2011-04-19 17:30 - 04729344 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-06-11 08:36 - 2012-06-11 08:36 - 06605824 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-06-11 08:27 - 2011-07-07 18:47 - 00539136 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00367616 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00017920 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:26 - 2011-04-19 17:22 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00045056 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-06-11 08:25 - 2012-02-14 18:12 - 00042496 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-06-11 08:25 - 2011-04-19 17:21 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:24 - 2011-04-19 17:21 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 20:48 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-20 20:48 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 20:48 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-20 20:48 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-31 03:11 - 2012-05-31 03:11 - 00000794 ____A C:\Users\asim\Desktop\new text document.txt
2012-05-31 03:07 - 2012-05-31 03:07 - 03466248 ____A (TrueCrypt Foundation) C:\Users\asim\Downloads\TrueCrypt Setup 7.1a.exe
2012-05-31 03:07 - 2011-05-28 15:49 - 00231376 ____A (TrueCrypt Foundation) C:\Windows\System32\Drivers\truecrypt.sys
2012-05-21 11:55 - 2012-05-21 11:55 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-20 21:43 - 2012-05-20 21:43 - 00000218 ____A C:\Users\asim\.recently-used.xbel
2012-05-20 19:04 - 2012-05-20 19:04 - 00000932 ____A C:\Users\asim\asoiaf_2012-05-20.gpkg
2012-05-17 18:47 - 2012-06-12 22:48 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 22:48 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 22:48 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 22:48 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 22:48 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 22:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 22:48 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 22:48 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 22:48 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 22:48 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 22:48 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 22:48 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 22:48 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 22:48 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 22:48 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 22:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 22:48 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 22:48 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 22:48 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 22:48 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 22:48 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 22:48 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 22:48 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 22:48 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 22:48 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 22:48 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 22:48 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-16 02:07 - 2012-05-16 02:07 - 02427820 ____A (Ilan Shemes ) C:\Users\asim\Downloads\GrabIt172b6.exe
2012-05-14 17:32 - 2012-06-12 22:47 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 01:41 - 2012-05-11 01:41 - 00000779 ____A C:\Users\Public\Desktop\OpenNX.lnk
2012-05-11 01:39 - 2012-05-11 01:39 - 14299990 ____A (The OpenNX Team ) C:\Users\asim\Downloads\OpenNX-0.16.0.708-Setup.exe
2012-05-11 01:37 - 2012-01-31 03:35 - 00000150 ____A C:\Users\asim\.Xauthority
2012-05-10 02:02 - 2011-05-30 22:12 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-05-10 02:02 - 2011-05-30 22:12 - 00000831 ____A C:\Windows\LkmdfCoInst.log
2012-05-10 02:02 - 2011-05-30 22:11 - 00016392 ____A C:\Windows\LDPINST.LOG
2012-05-10 02:01 - 2012-05-10 02:01 - 27941800 ____A (Logitech Inc.) C:\Users\asim\Downloads\setpoint632_x64.exe
2012-05-09 01:05 - 2012-05-09 01:05 - 00000523 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
2012-05-09 01:02 - 2011-07-19 19:59 - 00705053 ____A C:\Users\asim\Downloads\setup.exe
2012-05-08 22:27 - 2012-05-08 22:26 - 160889384 ____A (Advanced Micro Devices, Inc.) C:\Users\asim\Downloads\12-4_vista_win7_64_dd_ccc.exe
2012-05-05 22:46 - 2011-06-09 01:08 - 00000947 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-04 03:06 - 2012-06-12 22:47 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-12 22:47 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-12 22:47 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 22:47 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-12 22:47 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-12 22:47 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-12 22:47 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 23:50 - 2012-04-26 23:50 - 00275008 ____A C:\Windows\Minidump\042712-25022-01.dmp
2012-04-26 23:48 - 2012-04-26 23:48 - 00831496 ____A (SysProgs.org) C:\Users\asim\Downloads\WinCDEmu-3.6.exe
2012-04-26 01:02 - 2012-04-06 03:14 - 00000735 ____A C:\Users\asim\Desktop\may-june2012 flights.txt
2012-04-25 21:41 - 2012-06-12 22:47 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 22:47 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 22:47 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 22:48 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 22:48 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 22:48 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 22:48 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 22:48 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 22:48 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 19:56 - 2012-04-18 19:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 19:56 - 2012-04-18 19:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-15 15:46 - 2011-05-26 17:57 - 00002009 ____A C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2012-04-15 15:45 - 2012-04-15 15:45 - 17597976 ____A (Mozilla) C:\Users\asim\Desktop\Thunderbird Setup 12.0b4.exe
2012-04-14 16:57 - 2012-04-14 16:57 - 09267640 ____A (Space Sciences Laboratory, U.C. Berkeley) C:\Users\asim\Desktop\boinc_7.0.25_windows_x86_64.exe
2012-04-12 11:30 - 2012-04-12 11:30 - 00637743 ____A C:\Windows\System32\atiicdxx.dat
ZeroAccess:
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}\7
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}\@
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}\L
ZeroAccess:
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}\@
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}\L
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16366.62 MB
Available physical RAM: 15165.38 MB
Total Pagefile: 16364.82 MB
Available Pagefile: 15163.05 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.69 GB) (Free:10.15 GB) NTFS
2 Drive d: (Backup) (Fixed) (Total:223 GB) (Free:57.45 GB) NTFS
3 Drive e: (stuff) (Fixed) (Total:857.47 GB) (Free:684.25 GB) NTFS
4 Drive f: (media) (Fixed) (Total:857.47 GB) (Free:284.79 GB) NTFS
5 Drive g: (stuff2) (Fixed) (Total:856.46 GB) (Free:434.56 GB) NTFS
6 Drive I: (MassEffect2) (CDROM) (Total:2.68 GB) (Free:0 GB) UDF
7 Drive j: (USBSTICK) (Removable) (Total:0.12 GB) (Free:0.09 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 2794 GB 1024 KB *
Disk 2 Online 124 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 111 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 111 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Reserved 128 MB 17 KB
Partition 2 Primary 223 GB 129 MB
Partition 3 Primary 857 GB 223 GB
Partition 4 Primary 857 GB 1080 GB
Partition 5 Primary 856 GB 1938 GB
==================================================================================
Disk: 1
Partition 1
Type : e3c9e316-0b5c-4db8-817d-f92df00215ae
Hidden : Yes
Required: No
Attrib : 0000000000000000
There is no volume associated with this partition.
==================================================================================
Disk: 1
Partition 2
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Backup NTFS Partition 223 GB Healthy
==================================================================================
Disk: 1
Partition 3
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E stuff NTFS Partition 857 GB Healthy
==================================================================================
Disk: 1
Partition 4
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 F media NTFS Partition 857 GB Healthy
==================================================================================
Disk: 1
Partition 5
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 G stuff2 NTFS Partition 856 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 123 MB 64 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J USBSTICK FAT Removable 123 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 04:31
======================= End Of Log ==========================
I seem to have gotten bit by this as well, despite using MSE and other tools I still haven't been able to completely get rid of the infection. I did consider doing a System Restore to a point before the infection but that doesn't seem to get recommended a whole lot so I haven't done it.
What I've done for now is run FRST, and these are the results:
Scan result of Farbar Recovery Scan Tool Version: 08-07-2012
Ran by SYSTEM at 08-07-2012 15:09:21
Running from J:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [497648 2010-07-29] (Adobe Systems Incorporated)
HKLM\...\Run: [TortoiseHgOverlayIconServer] E:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe [x]
HKLM\...\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart [980368 2011-11-05] (The Eraser Project)
HKLM\...\Run: [boincmgr] "E:\Program Files\BOINC\boincmgr.exe" /a /s [x]
HKLM\...\Run: [boinctray] "E:\Program Files\BOINC\boinctray.exe" [x]
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe [271736 2010-09-14] (American Power Conversion Corporation)
HKLM-x32\...\Run: [BCSSync] "E:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [THX Audio Control Panel] "E:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r [x]
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe" [x]
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641704 2012-06-11] (Advanced Micro Devices, Inc.)
HKU\asim\...\Run: [TomTomHOME.exe] "e:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" -s [x]
HKU\asim\...\Run: [Google Update] "C:\Users\asim\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-05-30] (Google Inc.)
HKU\asim\...\Run: [ASRockXTU] [x]
HKU\asim\...\Run: [OfficeSyncProcess] "E:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [x]
HKU\asim\...\Run: [Steam] "E:\Steam\Steam.exe" -silent [x]
HKU\asim\...\Run: [Koodv] C:\Users\asim\AppData\Roaming\Ymafuw\keiq.exe [421888 2012-04-10] ()
HKU\asim\...\Run: [wseto] "C:\Windows\System32\rundll32.exe" "C:\Users\asim\AppData\Roaming\wseto.dll",TypeToAdsTypeDNWithString [375808 2012-07-07] (Dogbert)
HKU\asim\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1082440 2012-04-04] (Malwarebytes Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
Startup: C:\Users\asim\Start Menu\Programs\Startup\FreePOPs.lnk
ShortcutTarget: FreePOPs.lnk -> C:\Program Files (x86)\FreePOPs\freepopsd.exe ()
Startup: C:\Users\asim\Start Menu\Programs\Startup\pagent.lnk
ShortcutTarget: pagent.lnk -> C:\windows\system32\config\systemprofile\Desktop\sshkeys\pageant.exe (No File)
Startup: C:\Users\asim\Start Menu\Programs\Startup\Password Safe.lnk
ShortcutTarget: Password Safe.lnk -> C:\Program Files (x86)\Password Safe\pwsafe.exe (SourceForge.net)
==================== Services (Whitelisted) ======
2 APC Data Service; "C:\Program Files (x86)\APC\APC PowerChute Personal Edition\dataserv.exe" [21880 2010-09-14] (American Power Conversion Corporation)
2 APC UPS Service; "C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe" [705912 2010-09-14] (American Power Conversion Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 AdobeActiveFileMonitor9.0; C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [x]
3 Microsoft SharePoint Workspace Audit Service; "C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE" /auditservice [x]
2 TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
========================== Drivers (Whitelisted) =============
3 BazisVirtualCDBus; C:\Windows\System32\Drivers\BazisVirtualCDBus.sys [198480 2011-08-08] (SysProgs.org)
0 mv91xx; C:\Windows\System32\Drivers\mv91xx.sys [302120 2010-09-30] (Marvell Semiconductor, Inc.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-07 12:07 - 2012-07-07 12:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F8CCFB3BBDC3120
2012-07-07 12:04 - 2012-07-07 12:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.452CEDDFB472FFA5
2012-07-07 12:02 - 2012-07-07 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DBA9A7DD8E2D21F6
2012-07-07 04:59 - 2012-07-07 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28C7AFDF4A6B032F
2012-07-07 04:56 - 2012-07-07 04:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D8756818028673E
2012-07-07 04:55 - 2012-07-07 04:55 - 00000000 ____D C:\Users\asim\AppData\Roaming\SUPERAntiSpyware.com
2012-07-07 04:53 - 2012-07-07 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.210092B5F4929FD1
2012-07-07 04:50 - 2012-07-07 04:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77D8D2FCF29EF135
2012-07-07 04:50 - 2012-07-07 04:50 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-07-07 04:50 - 2012-07-07 04:50 - 00000000 ____D C:\Users\All Users\SUPERSetup
2012-07-07 04:50 - 2012-07-07 04:50 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-07-07 04:50 - 2012-07-07 04:50 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-07-07 04:49 - 2012-07-07 04:49 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\11712296.sys
2012-07-07 04:47 - 2012-07-07 04:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.538C2617149635E5
2012-07-07 04:44 - 2012-07-07 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78879EDBFCA7CE8D
2012-07-07 04:39 - 2012-07-07 04:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.835E6C898369C506
2012-07-07 04:39 - 2012-07-07 04:39 - 00176940 ____A C:\Users\asim\Downloads\BFE.reg
2012-07-07 04:38 - 2012-07-07 04:38 - 00006396 ____A C:\Users\asim\Downloads\MpsSvc.reg
2012-07-07 04:37 - 2012-07-07 04:37 - 00007586 ____A C:\Users\asim\Downloads\WinDefend.reg
2012-07-07 04:36 - 2012-07-07 04:36 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-07 04:36 - 2012-07-07 04:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-07 04:19 - 2012-07-07 04:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-07 04:19 - 2012-07-07 04:19 - 00000000 ____D C:\Users\asim\AppData\Roaming\Malwarebytes
2012-07-07 04:19 - 2012-07-07 04:19 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-07 04:19 - 2012-07-07 04:19 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-07 04:19 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-07 04:18 - 2012-07-07 04:19 - 10063024 ____A (Malwarebytes Corporation ) C:\Users\asim\Downloads\mbam-setup.exe
2012-07-07 04:13 - 2012-07-07 04:13 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-07 04:13 - 2012-07-07 04:13 - 00001238 ____A C:\Users\asim\Desktop\FixExec.txt
2012-07-07 04:13 - 2012-07-07 04:13 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-07 03:57 - 2012-07-07 03:57 - 00000000 ____D C:\Users\asim\AppData\Local\{D5C3F5E5-C82A-11E1-8270-B8AC6F996F26}
2012-07-07 03:56 - 2012-07-07 03:56 - 00375808 ____A (Dogbert) C:\Users\asim\AppData\Roaming\wseto.dll
2012-07-07 03:56 - 2012-07-07 03:56 - 00000000 ____D C:\Users\asim\AppData\Local\{D5C3BD85-C82A-11E1-8270-B8AC6F996F26}
2012-07-07 03:55 - 2012-07-07 04:28 - 00000000 ____D C:\Users\asim\AppData\Roaming\Saepy
2012-07-07 03:55 - 2012-07-07 04:24 - 00000000 ____D C:\Users\asim\AppData\Local\PlatformUserServices
2012-07-07 03:55 - 2012-07-07 03:55 - 00000000 ____D C:\Users\asim\AppData\Roaming\Ymafuw
2012-07-07 03:55 - 2012-07-07 03:55 - 00000000 ____D C:\Users\asim\AppData\Roaming\Udmex
2012-07-07 03:55 - 2012-07-07 03:55 - 00000000 ____D C:\Users\All Users\B7E858A700008F5E000369D2B4EB2331
2012-07-03 21:05 - 2012-07-03 21:05 - 00000000 ____D C:\Users\All Users\ATI
2012-07-03 21:05 - 2012-07-03 21:05 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-07-03 21:00 - 2012-07-03 21:00 - 00000000 ____D C:\AMD
2012-06-25 20:03 - 2012-06-25 20:03 - 00000000 ____D C:\Users\asim\Documents\SavedGames
2012-06-25 20:03 - 2012-06-25 20:03 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2012-06-20 20:48 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-20 20:48 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-20 20:48 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-20 20:48 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-20 20:48 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-20 20:48 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 03:59 - 2012-06-19 03:59 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-19 03:59 - 2012-06-19 03:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-18 20:33 - 2012-06-18 20:39 - 60429312 ____A C:\Users\asim\Downloads\graphviz-2.28.0.msi
2012-06-13 00:31 - 2012-06-13 00:31 - 00000000 ____D C:\Users\asim\AppData\Local\Macromedia
2012-06-12 22:48 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 22:48 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 22:48 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 22:48 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 22:48 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 22:48 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 22:48 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 22:48 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 22:48 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 22:48 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 22:48 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 22:48 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 22:48 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 22:48 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 22:48 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 22:48 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 22:48 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 22:48 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 22:48 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 22:48 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 22:48 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 22:48 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 22:48 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 22:48 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 22:48 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 22:48 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 22:48 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 22:48 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 22:48 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 22:48 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 22:48 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 22:48 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 22:48 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 22:48 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 22:47 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 22:47 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 22:47 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-06-12 22:47 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 22:47 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 22:47 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-06-12 22:47 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 22:47 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 22:47 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 22:47 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 22:47 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 22:47 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 22:47 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 23:32 - 2012-06-11 23:32 - 00001573 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 23:32 - 2012-06-11 23:32 - 00000000 ____D C:\Program Files\iTunes
2012-06-11 23:32 - 2012-06-11 23:32 - 00000000 ____D C:\Program Files\iPod
2012-06-11 12:50 - 2012-06-11 12:50 - 16457728 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-06-11 12:50 - 2012-06-11 12:50 - 00075264 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-06-11 12:49 - 2012-06-11 12:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-06-11 10:59 - 2012-06-11 10:59 - 10248192 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00070144 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:29 - 2012-06-11 10:29 - 24826368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00532992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00239616 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 08:51 - 2012-06-11 08:51 - 04246528 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-06-11 08:50 - 2012-06-11 08:50 - 02936864 ____A C:\Windows\System32\atiumd6a.cap
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-06-11 08:36 - 2012-06-11 08:36 - 06605824 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00367616 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00017920 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00045056 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
============ 3 Months Modified Files ========================
2012-07-07 12:13 - 2009-07-13 21:13 - 00782568 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-07 12:07 - 2012-07-07 12:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F8CCFB3BBDC3120
2012-07-07 12:06 - 2011-05-31 01:48 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-07 12:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-07 12:05 - 2009-07-13 20:51 - 00042333 ____A C:\Windows\setupact.log
2012-07-07 12:04 - 2012-07-07 12:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.452CEDDFB472FFA5
2012-07-07 12:02 - 2012-07-07 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DBA9A7DD8E2D21F6
2012-07-07 11:58 - 2010-11-20 19:47 - 00049286 ____A C:\Windows\PFRO.log
2012-07-07 05:02 - 2011-05-26 17:25 - 02019851 ____A C:\Windows\WindowsUpdate.log
2012-07-07 04:59 - 2012-07-07 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28C7AFDF4A6B032F
2012-07-07 04:56 - 2012-07-07 04:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D8756818028673E
2012-07-07 04:56 - 2011-05-30 20:25 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1299077805-4049216064-1238344601-1000UA.job
2012-07-07 04:53 - 2012-07-07 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.210092B5F4929FD1
2012-07-07 04:50 - 2012-07-07 04:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77D8D2FCF29EF135
2012-07-07 04:50 - 2012-07-07 04:50 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-07-07 04:49 - 2012-07-07 04:49 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\11712296.sys
2012-07-07 04:47 - 2012-07-07 04:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.538C2617149635E5
2012-07-07 04:44 - 2012-07-07 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78879EDBFCA7CE8D
2012-07-07 04:39 - 2012-07-07 04:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.835E6C898369C506
2012-07-07 04:39 - 2012-07-07 04:39 - 00176940 ____A C:\Users\asim\Downloads\BFE.reg
2012-07-07 04:38 - 2012-07-07 04:38 - 00006396 ____A C:\Users\asim\Downloads\MpsSvc.reg
2012-07-07 04:37 - 2012-07-07 04:37 - 00007586 ____A C:\Users\asim\Downloads\WinDefend.reg
2012-07-07 04:36 - 2011-05-26 20:09 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-07 04:36 - 2011-05-26 20:08 - 00798480 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-07 04:35 - 2011-05-26 20:08 - 12621696 ____A (Microsoft Corporation) C:\Users\asim\Downloads\mseinstall.exe
2012-07-07 04:35 - 2009-07-13 20:45 - 00022208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-07 04:35 - 2009-07-13 20:45 - 00022208 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-07 04:19 - 2012-07-07 04:19 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-07 04:19 - 2012-07-07 04:18 - 10063024 ____A (Malwarebytes Corporation ) C:\Users\asim\Downloads\mbam-setup.exe
2012-07-07 04:13 - 2012-07-07 04:13 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-07 04:13 - 2012-07-07 04:13 - 00001238 ____A C:\Users\asim\Desktop\FixExec.txt
2012-07-07 03:56 - 2012-07-07 03:56 - 00375808 ____A (Dogbert) C:\Users\asim\AppData\Roaming\wseto.dll
2012-07-07 03:22 - 2011-05-27 23:49 - 00000600 ____A C:\Users\asim\AppData\Roaming\winscp.rnd
2012-07-07 03:18 - 2011-05-31 01:48 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 18:56 - 2011-05-30 20:25 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1299077805-4049216064-1238344601-1000Core.job
2012-07-03 19:19 - 2012-04-03 00:26 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-03 19:19 - 2011-05-26 23:40 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-29 19:57 - 2011-05-30 20:25 - 00002395 ____A C:\Users\asim\Desktop\Google Chrome.lnk
2012-06-26 10:55 - 2012-03-15 20:14 - 00000891 ____A C:\Users\Public\Desktop\Mass Effect 3.lnk
2012-06-26 10:55 - 2011-05-28 00:16 - 00246624 ____A C:\Windows\DirectX.log
2012-06-24 21:38 - 2011-05-30 14:08 - 00000600 ____A C:\Users\asim\AppData\Local\PUTTY.RND
2012-06-18 20:39 - 2012-06-18 20:33 - 60429312 ____A C:\Users\asim\Downloads\graphviz-2.28.0.msi
2012-06-12 23:11 - 2009-07-13 20:45 - 00424824 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 22:51 - 2011-05-26 17:56 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-11 23:32 - 2012-06-11 23:32 - 00001573 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 12:50 - 2012-06-11 12:50 - 16457728 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-06-11 12:50 - 2012-06-11 12:50 - 00075264 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-06-11 12:50 - 2012-06-11 12:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-06-11 12:49 - 2012-06-11 12:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-06-11 10:59 - 2012-06-11 10:59 - 10248192 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00070144 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:29 - 2012-06-11 10:29 - 24826368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:24 - 2011-04-19 18:09 - 00924160 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-06-11 09:23 - 2011-04-19 18:07 - 01090560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00532992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00239616 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 09:16 - 2012-02-14 19:07 - 06301696 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-06-11 09:01 - 2011-04-19 17:49 - 06914560 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-06-11 08:51 - 2012-06-11 08:51 - 04246528 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-06-11 08:50 - 2012-06-11 08:50 - 02936864 ____A C:\Windows\System32\atiumd6a.cap
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-06-11 08:45 - 2011-04-19 17:46 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-06-11 08:45 - 2011-04-19 17:45 - 15703040 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-06-11 08:45 - 2011-04-19 17:38 - 05480448 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-06-11 08:43 - 2011-04-19 17:30 - 04729344 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-06-11 08:36 - 2012-06-11 08:36 - 06605824 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-06-11 08:27 - 2011-07-07 18:47 - 00539136 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00367616 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00017920 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:26 - 2011-04-19 17:22 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00045056 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-06-11 08:25 - 2012-02-14 18:12 - 00042496 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-06-11 08:25 - 2011-04-19 17:21 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:24 - 2011-04-19 17:21 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 20:48 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 20:48 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-20 20:48 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 20:48 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-20 20:48 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-31 03:11 - 2012-05-31 03:11 - 00000794 ____A C:\Users\asim\Desktop\new text document.txt
2012-05-31 03:07 - 2012-05-31 03:07 - 03466248 ____A (TrueCrypt Foundation) C:\Users\asim\Downloads\TrueCrypt Setup 7.1a.exe
2012-05-31 03:07 - 2011-05-28 15:49 - 00231376 ____A (TrueCrypt Foundation) C:\Windows\System32\Drivers\truecrypt.sys
2012-05-21 11:55 - 2012-05-21 11:55 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-20 21:43 - 2012-05-20 21:43 - 00000218 ____A C:\Users\asim\.recently-used.xbel
2012-05-20 19:04 - 2012-05-20 19:04 - 00000932 ____A C:\Users\asim\asoiaf_2012-05-20.gpkg
2012-05-17 18:47 - 2012-06-12 22:48 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 22:48 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 22:48 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 22:48 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 22:48 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 22:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 22:48 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 22:48 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 22:48 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 22:48 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 22:48 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 22:48 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 22:48 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 22:48 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 22:48 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 22:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 22:48 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 22:48 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 22:48 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 22:48 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 22:48 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 22:48 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 22:48 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 22:48 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 22:48 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 22:48 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 22:48 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-16 02:07 - 2012-05-16 02:07 - 02427820 ____A (Ilan Shemes ) C:\Users\asim\Downloads\GrabIt172b6.exe
2012-05-14 17:32 - 2012-06-12 22:47 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 01:41 - 2012-05-11 01:41 - 00000779 ____A C:\Users\Public\Desktop\OpenNX.lnk
2012-05-11 01:39 - 2012-05-11 01:39 - 14299990 ____A (The OpenNX Team ) C:\Users\asim\Downloads\OpenNX-0.16.0.708-Setup.exe
2012-05-11 01:37 - 2012-01-31 03:35 - 00000150 ____A C:\Users\asim\.Xauthority
2012-05-10 02:02 - 2011-05-30 22:12 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-05-10 02:02 - 2011-05-30 22:12 - 00000831 ____A C:\Windows\LkmdfCoInst.log
2012-05-10 02:02 - 2011-05-30 22:11 - 00016392 ____A C:\Windows\LDPINST.LOG
2012-05-10 02:01 - 2012-05-10 02:01 - 27941800 ____A (Logitech Inc.) C:\Users\asim\Downloads\setpoint632_x64.exe
2012-05-09 01:05 - 2012-05-09 01:05 - 00000523 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
2012-05-09 01:02 - 2011-07-19 19:59 - 00705053 ____A C:\Users\asim\Downloads\setup.exe
2012-05-08 22:27 - 2012-05-08 22:26 - 160889384 ____A (Advanced Micro Devices, Inc.) C:\Users\asim\Downloads\12-4_vista_win7_64_dd_ccc.exe
2012-05-05 22:46 - 2011-06-09 01:08 - 00000947 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-04 03:06 - 2012-06-12 22:47 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-12 22:47 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-12 22:47 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 22:47 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-12 22:47 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-12 22:47 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-12 22:47 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 23:50 - 2012-04-26 23:50 - 00275008 ____A C:\Windows\Minidump\042712-25022-01.dmp
2012-04-26 23:48 - 2012-04-26 23:48 - 00831496 ____A (SysProgs.org) C:\Users\asim\Downloads\WinCDEmu-3.6.exe
2012-04-26 01:02 - 2012-04-06 03:14 - 00000735 ____A C:\Users\asim\Desktop\may-june2012 flights.txt
2012-04-25 21:41 - 2012-06-12 22:47 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 22:47 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 22:47 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 22:48 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 22:48 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 22:48 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 22:48 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 22:48 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 22:48 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 19:56 - 2012-04-18 19:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 19:56 - 2012-04-18 19:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-15 15:46 - 2011-05-26 17:57 - 00002009 ____A C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2012-04-15 15:45 - 2012-04-15 15:45 - 17597976 ____A (Mozilla) C:\Users\asim\Desktop\Thunderbird Setup 12.0b4.exe
2012-04-14 16:57 - 2012-04-14 16:57 - 09267640 ____A (Space Sciences Laboratory, U.C. Berkeley) C:\Users\asim\Desktop\boinc_7.0.25_windows_x86_64.exe
2012-04-12 11:30 - 2012-04-12 11:30 - 00637743 ____A C:\Windows\System32\atiicdxx.dat
ZeroAccess:
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}\7
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}\@
C:\Windows\Installer\{b403175c-6a0a-aa8f-bd99-9defd15943df}\L
ZeroAccess:
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}\@
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}\L
C:\Users\asim\AppData\Local\{b403175c-6a0a-aa8f-bd99-9defd15943df}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16366.62 MB
Available physical RAM: 15165.38 MB
Total Pagefile: 16364.82 MB
Available Pagefile: 15163.05 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.69 GB) (Free:10.15 GB) NTFS
2 Drive d: (Backup) (Fixed) (Total:223 GB) (Free:57.45 GB) NTFS
3 Drive e: (stuff) (Fixed) (Total:857.47 GB) (Free:684.25 GB) NTFS
4 Drive f: (media) (Fixed) (Total:857.47 GB) (Free:284.79 GB) NTFS
5 Drive g: (stuff2) (Fixed) (Total:856.46 GB) (Free:434.56 GB) NTFS
6 Drive I: (MassEffect2) (CDROM) (Total:2.68 GB) (Free:0 GB) UDF
7 Drive j: (USBSTICK) (Removable) (Total:0.12 GB) (Free:0.09 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 2794 GB 1024 KB *
Disk 2 Online 124 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 111 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 111 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Reserved 128 MB 17 KB
Partition 2 Primary 223 GB 129 MB
Partition 3 Primary 857 GB 223 GB
Partition 4 Primary 857 GB 1080 GB
Partition 5 Primary 856 GB 1938 GB
==================================================================================
Disk: 1
Partition 1
Type : e3c9e316-0b5c-4db8-817d-f92df00215ae
Hidden : Yes
Required: No
Attrib : 0000000000000000
There is no volume associated with this partition.
==================================================================================
Disk: 1
Partition 2
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Backup NTFS Partition 223 GB Healthy
==================================================================================
Disk: 1
Partition 3
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E stuff NTFS Partition 857 GB Healthy
==================================================================================
Disk: 1
Partition 4
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 F media NTFS Partition 857 GB Healthy
==================================================================================
Disk: 1
Partition 5
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 G stuff2 NTFS Partition 856 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 123 MB 64 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J USBSTICK FAT Removable 123 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 04:31
======================= End Of Log ==========================