TechSpot

[Closed] Sirefef problem...Here is my FRST64 log please help

By TonyStocker
Jun 13, 2012
  1. Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
    Ran by SYSTEM at 13-06-2012 15:51:15
    Running from F:\
    Windows 7 Home Premium (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ========================== Registry (Whitelisted) =============

    HKLM\...\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL [x]
    HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL [x]
    HKLM-x32\...\Run: [CTHelper] CTHELPER.EXE [x]
    HKLM-x32\...\Run: [CTxfiHlp] CTXFIHLP.EXE [x]
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641664 2012-04-06] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
    HKU\Gamer\...\Run: [Akamai NetSession Interface] "C:\Users\Gamer\AppData\Local\Akamai\netsession_win.exe" [3331872 2012-05-07] (Akamai Technologies, Inc)
    HKU\Gamer\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3672384 2012-04-11] (DT Soft Ltd)
    HKU\Gamer\...\Run: [Desktop Software] "C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files (x86)\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden [1025320 2009-04-24] (SupportSoft, Inc.)
    Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
    Startup: C:\Users\Gamer\Start Menu\Programs\Startup\speedfan.lnk
    ShortcutTarget: speedfan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))

    ==================== Services (Whitelisted) ======

    2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-06-15] (Microsoft Corporation)
    3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [151296 2007-04-12] (Creative Technology Ltd)
    3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [252712 2007-04-10] (Creative Technology Ltd.)
    3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [700200 2007-04-10] (Creative Technology Ltd)
    3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [219432 2007-04-10] (Creative Technology Ltd)
    3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [321832 2007-04-10] (Creative Technology Ltd)
    3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [190248 2007-04-10] (Creative Technology Ltd)
    3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [363304 2007-04-10] (Creative Technology Ltd)
    3 CTERFXFX.DLL; C:\Windows\System32\CTERFXFX.DLL [142120 2007-04-10] (Creative Technology Ltd)
    3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1571112 2007-04-10] (Creative Technology Ltd.)
    3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [123688 2007-04-10] (Creative Technology Ltd.)
    3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [681256 2007-04-10] (Creative Technology Ltd)
    2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
    3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
    3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]

    ========================== Drivers (Whitelisted) =============

    1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-04-17] (DT Soft Ltd)
    3 ha10kx2k; C:\Windows\System32\Drivers\ha10kx2k.sys [1359144 2007-04-10] (Creative Technology Ltd)
    3 hap16v2k; C:\Windows\System32\Drivers\hap16v2k.sys [259880 2007-04-10] (Creative Technology Ltd)
    3 hap17v2k; C:\Windows\System32\Drivers\hap17v2k.sys [295208 2007-04-10] (Creative Technology Ltd)
    0 speedfan; C:\Windows\SysWow64\speedfan.sys [29592 2011-03-18] (Almico Software)
    3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============

    2012-06-13 15:51 - 2012-06-13 15:51 - 00000000 ____D C:\FRST
    2012-06-13 13:47 - 2012-06-13 13:47 - 00063898 ____A C:\Windows\ntbtlog.txt
    2012-06-13 13:28 - 2012-06-13 13:28 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-06-13 13:28 - 2012-06-13 13:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-06-13 13:27 - 2012-06-13 13:27 - 12621696 ____A (Microsoft Corporation) C:\Users\Gamer\Downloads\mseinstall.exe
    2012-06-12 19:06 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-06-12 19:06 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-06-12 18:41 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-12 18:41 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-12 18:41 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-12 18:41 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-12 18:41 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-12 18:41 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-12 18:41 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-12 18:41 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-12 18:41 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-12 18:41 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-12 18:41 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-12 18:41 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-12 18:41 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-12 18:41 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-12 18:41 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-12 18:41 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-12 18:41 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-12 18:41 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-12 18:41 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-12 18:41 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-12 18:41 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-12 18:41 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-12 18:41 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-12 18:41 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-12 18:41 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-12 18:41 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-12 18:41 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-12 18:41 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-12 17:19 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-12 17:19 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-06-12 17:19 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-06-12 17:19 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-06-12 17:19 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-06-12 17:19 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-06-12 17:19 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-06-12 17:19 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-06-12 17:19 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-06-12 17:19 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-06-12 17:19 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-06-12 17:19 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-06-12 17:19 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-06-12 17:19 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-06-12 17:19 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2012-06-12 17:19 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-06-12 17:19 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-06-08 09:14 - 2012-06-08 09:14 - 00003584 ____A C:\Users\Gamer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-06-07 11:15 - 2012-06-07 11:15 - 02135728 ____A C:\Users\Gamer\Downloads\installspeedfan446.exe
    2012-06-05 22:24 - 2012-06-05 22:24 - 00000000 ____D C:\Users\Gamer\Documents\RobotSoft
    2012-06-05 22:24 - 2012-06-05 22:24 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\RobotSoft
    2012-06-05 22:24 - 2012-06-05 22:24 - 00000000 ____D C:\Program Files (x86)\RobotSoft
    2012-06-05 22:20 - 2012-06-05 22:27 - 00000000 ____D C:\Users\Gamer\Downloads\Automatic Mouse and Keyboard 3.3.0.6 Software + Keygen
    2012-06-05 22:09 - 2012-06-05 22:09 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-06-05 20:13 - 2012-06-05 20:13 - 00001352 ____A C:\Users\Gamer\Documents\AutoHotkey.ahk
    2012-06-04 22:32 - 2012-06-04 22:32 - 00274408 ____A C:\Windows\Minidump\060412-18906-01.dmp
    2012-06-03 17:58 - 2012-06-03 17:58 - 00000412 ____A C:\Users\Gamer\AppData\Roaming\All CPU Meter_Settings.ini
    2012-05-31 19:11 - 2012-05-31 19:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2012-05-31 19:11 - 2012-05-31 19:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2012-05-31 19:09 - 2011-02-19 04:05 - 01139200 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
    2012-05-31 19:09 - 2011-02-19 04:04 - 00902656 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
    2012-05-31 19:09 - 2011-02-18 22:30 - 00739840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
    2012-05-31 18:06 - 2012-05-31 18:06 - 00274408 ____A C:\Windows\Minidump\053112-15953-01.dmp
    2012-05-31 11:12 - 2012-05-31 11:12 - 00000000 ____D C:\Users\Gamer\Documents\john fiebig
    2012-05-23 15:51 - 2012-05-23 15:51 - 00274408 ____A C:\Windows\Minidump\052312-15328-01.dmp
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Users\All Users\ATI
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files (x86)\AMD AVT
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files (x86)\AMD APP
    2012-05-20 23:41 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files\ATI Technologies
    2012-05-20 22:45 - 2012-05-20 22:45 - 00000000 ____D C:\Users\Gamer\Documents\Diablo III
    2012-05-20 22:16 - 2012-06-12 12:31 - 00000000 ____D C:\Program Files (x86)\Diablo III
    2012-05-20 22:16 - 2012-05-20 22:32 - 00000000 ____D C:\Users\All Users\Blizzard Entertainment
    2012-05-20 22:15 - 2012-05-20 22:15 - 00000000 ____D C:\Users\All Users\Battle.net
    2012-05-19 10:50 - 2012-05-19 10:50 - 00274408 ____A C:\Windows\Minidump\051912-14000-01.dmp

    ============ 3 Months Modified Files and Folders =============

    2012-06-13 15:51 - 2012-06-13 15:51 - 00000000 ____D C:\FRST
    2012-06-13 13:51 - 2012-04-03 19:28 - 00000000 __SHD C:\Users\Gamer\AppData\Local\{22e2e2b4-0781-8315-e72c-72d7455bfc46}
    2012-06-13 13:50 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-06-13 13:50 - 2009-07-13 20:51 - 00027101 ____A C:\Windows\setupact.log
    2012-06-13 13:47 - 2012-06-13 13:47 - 00063898 ____A C:\Windows\ntbtlog.txt
    2012-06-13 13:40 - 2012-04-08 20:16 - 00010140 ____A C:\Windows\PFRO.log
    2012-06-13 13:33 - 2012-03-31 15:11 - 01243937 ____A C:\Windows\WindowsUpdate.log
    2012-06-13 13:32 - 2012-04-05 14:33 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-06-13 13:32 - 2012-04-03 20:14 - 00001945 ____A C:\Windows\epplauncher.mif
    2012-06-13 13:32 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
    2012-06-13 13:31 - 2012-05-13 22:08 - 00000000 ____D C:\Users\Gamer\AppData\Local\ElevatedDiagnostics
    2012-06-13 13:31 - 2009-07-13 20:45 - 00016304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-06-13 13:31 - 2009-07-13 20:45 - 00016304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-06-13 13:28 - 2012-06-13 13:28 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-06-13 13:28 - 2012-06-13 13:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-06-13 13:28 - 2012-04-03 20:11 - 00773580 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-06-13 13:28 - 2009-07-13 21:13 - 00756486 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-06-13 13:27 - 2012-06-13 13:27 - 12621696 ____A (Microsoft Corporation) C:\Users\Gamer\Downloads\mseinstall.exe
    2012-06-12 19:39 - 2012-04-08 20:56 - 00000000 ____D C:\Program Files (x86)\SpeedFan
    2012-06-12 18:53 - 2009-07-13 20:45 - 00274320 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-06-12 18:46 - 2012-04-13 00:59 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-06-12 12:31 - 2012-05-20 22:16 - 00000000 ____D C:\Program Files (x86)\Diablo III
    2012-06-08 09:28 - 2012-04-26 10:19 - 00000000 ____D C:\Users\Gamer\AppData\Local\WMTools Downloaded Files
    2012-06-08 09:22 - 2012-04-26 10:12 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\NCH Software
    2012-06-08 09:14 - 2012-06-08 09:14 - 00003584 ____A C:\Users\Gamer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-06-07 11:15 - 2012-06-07 11:15 - 02135728 ____A C:\Users\Gamer\Downloads\installspeedfan446.exe
    2012-06-07 11:15 - 2012-04-08 20:56 - 00000045 ____A C:\Windows\SysWOW64\initdebug.nfo
    2012-06-06 22:42 - 2012-05-04 18:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2012-06-06 10:03 - 2012-04-04 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2012-06-05 22:27 - 2012-06-05 22:20 - 00000000 ____D C:\Users\Gamer\Downloads\Automatic Mouse and Keyboard 3.3.0.6 Software + Keygen
    2012-06-05 22:24 - 2012-06-05 22:24 - 00000000 ____D C:\Users\Gamer\Documents\RobotSoft
    2012-06-05 22:24 - 2012-06-05 22:24 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\RobotSoft
    2012-06-05 22:24 - 2012-06-05 22:24 - 00000000 ____D C:\Program Files (x86)\RobotSoft
    2012-06-05 22:23 - 2012-04-13 21:09 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\BitTorrent
    2012-06-05 22:16 - 2012-04-13 21:10 - 00000000 ____D C:\Program Files (x86)\BitTorrent
    2012-06-05 22:09 - 2012-06-05 22:09 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-06-05 22:05 - 2012-04-05 14:33 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-06-05 22:05 - 2012-04-05 14:33 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-06-05 20:15 - 2009-07-13 23:45 - 00000000 ____D C:\Windows\ShellNew
    2012-06-05 20:13 - 2012-06-05 20:13 - 00001352 ____A C:\Users\Gamer\Documents\AutoHotkey.ahk
    2012-06-05 14:57 - 2012-04-04 23:07 - 00000000 ____D C:\Users\Gamer\AppData\Local\PMB Files
    2012-06-04 22:32 - 2012-06-04 22:32 - 00274408 ____A C:\Windows\Minidump\060412-18906-01.dmp
    2012-06-04 22:32 - 2012-04-05 01:20 - 339636325 ____A C:\Windows\MEMORY.DMP
    2012-06-04 22:32 - 2012-04-05 01:20 - 00000000 ____D C:\Windows\Minidump
    2012-06-03 17:58 - 2012-06-03 17:58 - 00000412 ____A C:\Users\Gamer\AppData\Roaming\All CPU Meter_Settings.ini
    2012-05-31 19:11 - 2012-05-31 19:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2012-05-31 19:11 - 2012-05-31 19:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2012-05-31 19:03 - 2012-04-04 17:20 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2012-05-31 19:03 - 2012-04-04 17:20 - 00000000 ____D C:\Program Files (x86)\Realtek
    2012-05-31 18:06 - 2012-05-31 18:06 - 00274408 ____A C:\Windows\Minidump\053112-15953-01.dmp
    2012-05-31 11:12 - 2012-05-31 11:12 - 00000000 ____D C:\Users\Gamer\Documents\john fiebig
    2012-05-31 11:09 - 2012-04-05 00:52 - 00000000 ____D C:\Users\Gamer\AppData\Local\ApplicationHistory
    2012-05-23 15:51 - 2012-05-23 15:51 - 00274408 ____A C:\Windows\Minidump\052312-15328-01.dmp
    2012-05-22 02:00 - 2012-04-03 21:57 - 00000000 ____D C:\Users\Gamer\AppData\Local\Akamai
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Users\All Users\ATI
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files (x86)\AMD AVT
    2012-05-20 23:43 - 2012-05-20 23:43 - 00000000 ____D C:\Program Files (x86)\AMD APP
    2012-05-20 23:43 - 2012-05-20 23:41 - 00000000 ____D C:\Program Files\ATI Technologies
    2012-05-20 23:43 - 2012-05-13 23:25 - 00000000 ____D C:\Users\All Users\AMD
    2012-05-20 22:45 - 2012-05-20 22:45 - 00000000 ____D C:\Users\Gamer\Documents\Diablo III
    2012-05-20 22:32 - 2012-05-20 22:16 - 00000000 ____D C:\Users\All Users\Blizzard Entertainment
    2012-05-20 22:15 - 2012-05-20 22:15 - 00000000 ____D C:\Users\All Users\Battle.net
    2012-05-19 10:50 - 2012-05-19 10:50 - 00274408 ____A C:\Windows\Minidump\051912-14000-01.dmp
    2012-05-17 18:47 - 2012-06-12 18:41 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-05-17 18:16 - 2012-06-12 18:41 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-05-17 18:06 - 2012-06-12 18:41 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-05-17 17:59 - 2012-06-12 18:41 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-05-17 17:59 - 2012-06-12 18:41 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-05-17 17:58 - 2012-06-12 18:41 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-05-17 17:58 - 2012-06-12 18:41 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-05-17 17:56 - 2012-06-12 18:41 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-05-17 17:55 - 2012-06-12 18:41 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-05-17 17:55 - 2012-06-12 18:41 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-05-17 17:54 - 2012-06-12 18:41 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-05-17 17:51 - 2012-06-12 18:41 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-05-17 17:51 - 2012-06-12 18:41 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-05-17 17:47 - 2012-06-12 18:41 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-05-17 15:11 - 2012-06-12 18:41 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-05-17 14:48 - 2012-06-12 18:41 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-05-17 14:45 - 2012-06-12 18:41 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-05-17 14:36 - 2012-06-12 18:41 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-05-17 14:35 - 2012-06-12 18:41 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-05-17 14:35 - 2012-06-12 18:41 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-05-17 14:33 - 2012-06-12 18:41 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-05-17 14:31 - 2012-06-12 18:41 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-05-17 14:29 - 2012-06-12 18:41 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-05-17 14:29 - 2012-06-12 18:41 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-05-17 14:27 - 2012-06-12 18:41 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-05-17 14:25 - 2012-06-12 18:41 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-05-17 14:24 - 2012-06-12 18:41 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-05-17 14:20 - 2012-06-12 18:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-05-14 17:32 - 2012-06-12 17:19 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-05-13 23:25 - 2012-05-13 23:25 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\ATI
    2012-05-13 23:25 - 2012-05-13 23:25 - 00000000 ____D C:\Users\Gamer\AppData\Local\ATI
    2012-05-13 23:23 - 2012-05-13 23:23 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
    2012-05-13 23:22 - 2012-05-13 23:22 - 00000000 ____D C:\Program Files\ATI
    2012-05-13 23:22 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2012-05-13 23:21 - 2012-05-13 23:21 - 00000000 ____D C:\AMD
    2012-05-13 23:09 - 2012-05-13 23:09 - 00000118 ____A C:\Windows\SysWOW64\mon.txt
    2012-05-13 21:56 - 2012-04-05 01:00 - 00000000 ____D C:\Users\Gamer\Documents\Dungeons and Dragons Online
    2012-05-13 21:47 - 2012-04-05 01:04 - 00000000 ____D C:\Windows\SysWOW64\directx
    2012-05-13 21:47 - 2012-04-03 19:43 - 00000000 ___HD C:\Windows\msdownld.tmp
    2012-05-13 21:36 - 2012-04-05 00:54 - 00000000 ____D C:\Users\Gamer\AppData\Local\Turbine
    2012-05-13 01:34 - 2009-07-13 23:45 - 00000000 ____D C:\Program Files\Windows Journal
    2012-05-11 14:36 - 2012-05-11 14:36 - 00000000 ____D C:\Users\Gamer\AppData\Local\SupportSoft
    2012-05-11 14:36 - 2012-05-11 14:36 - 00000000 ____D C:\Program Files (x86)\ComcastUI
    2012-05-04 18:23 - 2012-05-04 18:23 - 00000000 ____D C:\Users\All Users\Mozilla
    2012-05-04 12:32 - 2012-04-13 19:32 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
     
  2. TonyStocker

    TonyStocker TS Rookie Topic Starter Posts: 24

    2012-05-04 03:06 - 2012-06-12 17:19 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-05-04 03:00 - 2012-06-12 19:06 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-05-04 02:03 - 2012-06-12 17:19 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2012-05-04 02:03 - 2012-06-12 17:19 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2012-05-04 01:59 - 2012-06-12 19:06 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-05-03 11:36 - 2012-05-03 11:36 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\Rovio
    2012-05-03 11:35 - 2012-04-17 17:57 - 00000000 ____D C:\Users\Gamer\Documents\My Games
    2012-04-30 21:40 - 2012-06-12 17:19 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
    2012-04-27 19:55 - 2012-06-12 17:19 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-04-26 10:19 - 2012-04-26 10:19 - 00000000 ____D C:\Program Files (x86)\Movie Maker 2.6
    2012-04-26 10:12 - 2012-04-26 10:12 - 00000000 ____D C:\Users\All Users\NCH Software
    2012-04-26 10:12 - 2012-04-26 10:12 - 00000000 ____D C:\Program Files (x86)\NCH Software
    2012-04-25 21:41 - 2012-06-12 17:19 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
    2012-04-25 21:41 - 2012-06-12 17:19 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
    2012-04-25 21:34 - 2012-06-12 17:19 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
    2012-04-23 21:37 - 2012-06-12 17:19 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-04-23 21:37 - 2012-06-12 17:19 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2012-04-23 21:37 - 2012-06-12 17:19 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2012-04-23 20:36 - 2012-06-12 17:19 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2012-04-23 20:36 - 2012-06-12 17:19 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2012-04-23 20:36 - 2012-06-12 17:19 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2012-04-17 17:54 - 2012-04-05 01:06 - 00034485 ____A C:\Windows\DirectX.log
    2012-04-17 17:50 - 2012-04-17 17:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
    2012-04-17 17:43 - 2012-04-17 16:50 - 00000000 ____D C:\Users\All Users\DAEMON Tools Lite
    2012-04-17 17:42 - 2012-04-17 16:53 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\DAEMON Tools Lite
    2012-04-17 16:53 - 2012-04-17 16:53 - 00283200 ____A (DT Soft Ltd) C:\Windows\System32\Drivers\dtsoftbus01.sys
    2012-04-17 16:53 - 2012-04-17 16:53 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
    2012-04-17 16:41 - 2012-04-17 16:35 - 00000000 ____D C:\Users\Gamer\Documents\Fable
    2012-04-16 12:00 - 2012-04-16 11:57 - 00000000 ____D C:\Users\All Users\Adobe
    2012-04-16 11:59 - 2012-04-16 11:59 - 00000000 ____D C:\Users\Gamer\AppData\Local\Adobe
    2012-04-16 11:59 - 2012-04-05 14:33 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\Adobe
    2012-04-16 11:59 - 2012-03-31 15:15 - 00000000 ____D C:\Users\Gamer\AppData\LocalLow
    2012-04-16 11:58 - 2012-04-16 11:58 - 00000000 ____D C:\Program Files (x86)\Adobe
    2012-04-13 20:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
    2012-04-13 14:05 - 2012-04-13 14:05 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
    2012-04-13 14:04 - 2012-04-13 14:04 - 00000000 ____D C:\Program Files (x86)\LG Electronics
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Sidebar
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Defender
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\DVD Maker
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
    2012-04-13 01:33 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\sppui
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\manifeststore
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\es-ES
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\da-DK
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\cs-CZ
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sppui
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\Setup
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\oobe
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\migwiz
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\manifeststore
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\es-ES
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\Dism
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\da-DK
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\cs-CZ
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\config\TxR
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\AdvancedInstallers
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\servicing
    2012-04-13 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\System
    2012-04-13 01:26 - 2009-07-13 18:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
    2012-04-13 01:26 - 2009-07-13 18:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
    2012-04-13 01:01 - 2012-04-13 01:01 - 00000000 ____D C:\Windows\System32\SPReview
    2012-04-13 01:01 - 2012-04-13 01:01 - 00000000 ____D C:\Windows\System32\EventProviders
    2012-04-08 20:04 - 2012-04-08 20:04 - 00000000 ____D C:\Users\All Users\IObit
    2012-04-08 20:04 - 2012-04-08 20:04 - 00000000 ____D C:\Program Files (x86)\IObit
    2012-04-07 04:31 - 2012-06-12 17:19 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
    2012-04-07 03:26 - 2012-06-12 17:19 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2012-04-05 21:34 - 2012-04-05 21:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
    2012-04-05 21:34 - 2012-04-05 21:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
    2012-04-05 21:34 - 2012-04-05 21:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
    2012-04-05 21:33 - 2012-04-05 21:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
    2012-04-05 21:33 - 2012-04-05 21:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
    2012-04-05 21:33 - 2012-04-05 21:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
    2012-04-05 21:32 - 2012-04-05 21:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
    2012-04-05 21:32 - 2012-04-05 21:32 - 00054784 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-04-05 21:32 - 2012-04-05 21:32 - 00050176 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2012-04-05 18:23 - 2012-04-05 18:23 - 00245896 ____A C:\Windows\SysWOW64\atiapfxx.blb
    2012-04-05 17:29 - 2012-04-05 17:29 - 00204952 ____A C:\Windows\SysWOW64\ativvsvl.dat
    2012-04-05 17:29 - 2012-04-05 17:29 - 00204952 ____A C:\Windows\System32\ativvsvl.dat
    2012-04-05 17:29 - 2012-04-05 17:29 - 00157144 ____A C:\Windows\SysWOW64\ativvsva.dat
    2012-04-05 17:29 - 2012-04-05 17:29 - 00157144 ____A C:\Windows\System32\ativvsva.dat
    2012-04-05 14:33 - 2012-04-05 14:33 - 00000000 ____D C:\Windows\SysWOW64\Macromed
    2012-04-05 14:33 - 2012-04-05 14:33 - 00000000 ____D C:\Windows\System32\Macromed
    2012-04-05 14:33 - 2012-04-05 14:33 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\Macromedia
    2012-04-05 01:37 - 2012-04-05 01:37 - 00000000 ____D C:\Program Files\7-Zip
    2012-04-05 01:20 - 2012-04-05 01:20 - 00274408 ____A C:\Windows\Minidump\040512-31031-01.dmp
    2012-04-05 01:19 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports
    2012-04-05 01:15 - 2012-04-04 22:54 - 00000000 ____D C:\Users\Gamer\AppData\Roaming\Mozilla
    2012-04-05 00:54 - 2012-04-05 00:54 - 00000093 ____A C:\Users\Gamer\AppData\Local\fusioncache.dat
    2012-04-05 00:51 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\Registration
    2012-04-05 00:50 - 2012-04-05 00:50 - 00000000 ____D C:\Windows\SysWOW64\URTTEMP
    2012-04-05 00:32 - 2012-04-05 00:32 - 00000000 ____D C:\Program Files (x86)\Turbine
    2012-04-05 00:25 - 2012-04-04 23:12 - 00000000 ____D C:\Users\Gamer\Documents\DDO High Res Install Files
    2012-04-04 23:46 - 2012-04-04 23:46 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
    2012-04-04 23:46 - 2012-04-04 23:46 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
    2012-04-04 23:46 - 2012-04-04 23:46 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
    2012-04-04 23:46 - 2012-04-04 23:46 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
    2012-04-04 23:46 - 2012-04-04 23:46 - 00000000 ____D C:\Users\All Users\Sun
    2012-04-04 23:46 - 2012-04-04 23:46 - 00000000 ____D C:\Program Files (x86)\Java
    2012-04-04 23:12 - 2012-04-04 23:07 - 00000000 ____D C:\Users\All Users\PMB Files
    2012-04-04 23:07 - 2012-04-04 23:07 - 00000000 ____D C:\Program Files (x86)\Pando Networks
    2012-04-04 22:54 - 2012-04-04 22:54 - 00000000 ____D C:\Users\Gamer\AppData\Local\Mozilla
    2012-04-04 22:43 - 2009-07-13 19:20 - 00000000 __RHD C:\Users\Public\Libraries
    2012-04-04 22:42 - 2012-04-04 22:42 - 04958588 ____A C:\Windows\{00000005-00000000-00000000-00001102-00000008-10211102}.BAK
    2012-04-04 22:42 - 2012-04-04 18:33 - 04958588 ____A C:\Windows\{00000005-00000000-00000000-00001102-00000008-10211102}.CDF
    2012-04-04 22:42 - 2012-03-31 15:15 - 00000000 ____D C:\Users\Gamer\AppData\Local\VirtualStore
    2012-04-04 18:33 - 2012-04-04 18:33 - 00431104 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
    2012-04-04 18:33 - 2012-04-04 18:33 - 00409600 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
    2012-04-04 18:33 - 2012-04-04 18:33 - 00136192 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
    2012-04-04 18:33 - 2012-04-04 18:33 - 00114688 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
    2012-04-04 18:32 - 2012-04-04 18:32 - 00000000 ____D C:\Windows\SysWOW64\data
    2012-04-04 18:32 - 2012-04-04 18:32 - 00000000 ____D C:\Windows\System32\data
    2012-04-04 17:41 - 2012-04-04 17:41 - 00000000 ____D C:\Program Files (x86)\Intel
    2012-04-04 17:41 - 2012-04-04 17:41 - 00000000 ____D C:\Intel
    2012-04-04 17:20 - 2012-04-04 17:20 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
    2012-04-04 17:20 - 2012-04-04 17:20 - 00000000 ____D C:\Program Files\Realtek
    2012-04-03 21:57 - 2012-04-03 21:57 - 00449938 ____A C:\Users\Gamer\Documents\C1CLG5.rar
    2012-04-03 20:16 - 2012-04-03 20:16 - 00057560 ____A C:\Users\Gamer\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-04-03 19:45 - 2012-04-03 19:38 - 00009061 ____A C:\Windows\IE9_main.log
    2012-04-03 19:45 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
    2012-04-03 19:42 - 2012-04-03 19:42 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
    2012-04-03 19:42 - 2012-04-03 19:42 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
    2012-04-03 19:42 - 2012-04-03 19:42 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
    2012-04-03 19:42 - 2012-04-03 19:42 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2012-04-03 19:42 - 2012-04-03 19:42 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
    2012-04-03 19:42 - 2012-04-03 19:42 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00072822 ____A C:\Windows\SysWOW64\ieuinit.inf
    2012-04-03 19:42 - 2012-04-03 19:42 - 00072822 ____A C:\Windows\System32\ieuinit.inf
    2012-04-03 19:42 - 2012-04-03 19:42 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2012-04-03 19:42 - 2012-04-03 19:42 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
    2012-04-03 19:42 - 2012-04-03 19:42 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
    2012-04-03 19:42 - 2012-04-03 19:42 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
    2012-03-31 16:07 - 2009-07-13 21:38 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG
    2012-03-31 16:07 - 2009-07-13 21:32 - 00028672 ____A C:\Windows\System32\config\BCD-Template
    2012-03-31 16:07 - 2009-07-13 20:45 - 00000000 ____D C:\Windows\Setup
    2012-03-31 15:35 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\restore
    2012-03-31 15:17 - 2012-03-31 15:15 - 00000000 ____D C:\users\Gamer
    2012-03-31 15:15 - 2012-03-31 16:07 - 00000000 ____D C:\Windows\Panther
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000020 ___SH C:\Users\Gamer\ntuser.ini
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\Templates
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\Start Menu
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\PrintHood
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\NetHood
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\My Documents
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\Documents\My Videos
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\Documents\My Pictures
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\Documents\My Music
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\AppData\Local\Temporary Internet Files
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Users\Gamer\AppData\Local\History
    2012-03-31 15:15 - 2012-03-31 15:15 - 00000000 __SHD C:\Recovery
    2012-03-31 15:12 - 2009-07-13 21:01 - 00041962 ____A C:\Windows\SysWOW64\license.rtf
    2012-03-31 15:12 - 2009-07-13 21:01 - 00041962 ____A C:\Windows\System32\license.rtf
    2012-03-31 15:11 - 2012-03-31 15:11 - 00001313 ____A C:\Windows\TSSysprep.log
    2012-03-31 15:11 - 2009-07-13 20:46 - 00001774 ____A C:\Windows\DtcInstall.log
    2012-03-31 15:11 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sysprep
    2012-03-31 15:10 - 2012-03-31 15:10 - 00000000 ____A C:\Windows\ativpsrm.bin
    2012-03-30 03:35 - 2012-05-12 09:39 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
    2012-03-20 19:44 - 2012-03-20 19:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
    2012-03-20 19:44 - 2012-03-20 19:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
    2012-03-16 23:58 - 2012-05-12 09:39 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys

    ZeroAccess:
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\@
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\L
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\n
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\U
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\U\00000001.@
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\U\80000000.@
    C:\Windows\Installer\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\U\800000cb.@

    ZeroAccess:
    C:\Users\Gamer\AppData\Local\{22e2e2b4-0781-8315-e72c-72d7455bfc46}
    C:\Users\Gamer\AppData\Local\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\@
    C:\Users\Gamer\AppData\Local\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\L
    C:\Users\Gamer\AppData\Local\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\n
    C:\Users\Gamer\AppData\Local\{22e2e2b4-0781-8315-e72c-72d7455bfc46}\U

    ========================= Known DLLs (Whitelisted) ============


    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06

    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ========================= Memory info ======================

    Percentage of memory in use: 14%
    Total physical RAM: 4095.3 MB
    Available physical RAM: 3488.25 MB
    Total Pagefile: 4093.45 MB
    Available Pagefile: 3471.7 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB

    ======================= Partitions =========================

    1 Drive c: (Main Brain) (Fixed) (Total:232.73 GB) (Free:169.51 GB) NTFS
    3 Drive f: () (Removable) (Total:3.69 GB) (Free:3.6 GB) FAT32
    4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 232 GB 0 B
    Disk 1 Online 3781 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 232 GB 101 MB

    ======================================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 Y System Rese NTFS Partition 100 MB Healthy

    ======================================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C Main Brain NTFS Partition 232 GB Healthy

    ======================================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 3777 MB 4096 KB

    ======================================================================================================

    Disk: 1
    Partition 1
    Type : 0B
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F FAT32 Removable 3777 MB Healthy

    ======================================================================================================

    ==========================================================

    Last Boot: 2012-06-08 09:48

    ======================= End Of Log ==========================
     
  3. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Please stay in your original topic.
    This topic is closed.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...