blogan
Posts: 22 +0
I have an HP laptop computer with Win64/Sirefef.Y. Every time it boots, Microsoft Security Essentials finds the threat but a "You are about to be logged off" message appears and reboots the laptop prior to me being able to remove the threat with MSE.
Scan results are:
Scan result of Farbar Recovery Scan Tool Version: 13-06-2012 03
Ran by SYSTEM at 14-06-2012 18:43:04
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2281256 2011-01-09] (Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323072 2009-08-17] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [611896 2010-01-20] ()
HKLM\...\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [451072 2010-01-18] (Hewlett-Packard Company)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2009-12-16] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-09-15] (IDT, Inc.)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-08-25] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [288080 2009-07-17] (Microsoft Corporation)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [401192 2009-12-08] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201512 2009-12-08] (Egis Technology Inc.)
HKLM-x32\...\Run: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run [379248 2010-02-04] (Egis Technology Inc. )
HKLM-x32\...\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED [3331944 2009-12-03] (Symantec Corporation)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-11-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Default User\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 184.16.33.54
Lsa: [Notification Packages] EgisPwdFilter
EgisDSPwdFilter
==================== Services (Whitelisted) ======
2 CinemaNow Service; C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [127984 2010-02-26] (CinemaNow, Inc.)
2 DvmMDES; "C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe" [338168 2010-03-31] (DeviceVM, Inc.)
2 EgisTec Service; "C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe" [689008 2010-02-04] (Egis Technology Inc. )
2 HP Support Assistant Service; "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [86072 2011-09-09] (Hewlett-Packard Company)
2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [20480 2010-01-18] ()
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2009-09-30] (Intel Corporation)
2 vcsFPService; C:\Windows\system32\vcsFPService.exe [2192176 2010-02-23] (Validity Sensors, Inc.)
2 vcsFPService; C:\Windows\SysWow64\vcsFPService.exe [1799472 2010-02-23] (Validity Sensors, Inc.)
2 WDFME; "C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe" [1066896 2011-03-09] ()
2 WDSC; "C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe" [491920 2011-03-09] ()
========================== Drivers (Whitelisted) =============
1 DVMIO; C:\Windows\System32\Drivers\DVMIO.sys [20056 2009-11-11] (DeviceVM, Inc.)
3 hitmanpro35; \??\C:\Windows\system32\drivers\hitmanpro36.sys [30496 2012-06-13] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-14 18:39 - 2012-06-14 18:43 - 00000000 ____D C:\FRST
2012-06-14 11:20 - 2012-06-14 11:20 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-14 11:19 - 2012-06-14 11:19 - 00744030 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 11:18 - 2012-06-14 11:18 - 12621696 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall (1).exe
2012-06-14 11:18 - 2012-06-14 11:18 - 10288512 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-06-14 11:14 - 2012-06-14 11:14 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-13 22:06 - 2012-06-13 22:06 - 00003215 ____A C:\Users\Melissa\Desktop\Sophos Virus Removal Tool.lnk
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Users\All Users\Sophos
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Program Files (x86)\Sophos
2012-06-13 22:04 - 2012-06-13 22:05 - 76681248 ____A (Sophos Limited) C:\Users\Melissa\Downloads\Sophos Virus Removal Tool.exe
2012-06-13 22:01 - 2012-06-13 22:01 - 00002594 ____A C:\Windows\System32\.crusader
2012-06-13 21:55 - 2012-06-13 22:02 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-13 21:54 - 2012-06-13 22:00 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-13 21:53 - 2012-06-13 21:54 - 08298672 ____A (SurfRight B.V.) C:\Users\Melissa\Downloads\HitmanPro36_x64.exe
2012-06-13 20:36 - 2012-06-13 20:36 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Melissa\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-13 20:33 - 2012-06-13 20:33 - 00000361 ____A C:\rkill.log
2012-06-13 20:32 - 2012-06-13 20:32 - 01012656 ____A C:\Users\Melissa\Downloads\iExplore.exe
2012-06-13 20:31 - 2012-06-13 20:31 - 00001205 ____A C:\Users\Melissa\Downloads\registryfix.reg
2012-06-13 17:28 - 2012-06-13 20:37 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-13 17:18 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-13 17:18 - 2010-12-20 17:09 - 00038224 ____A (Malwarebytes Corporation) C:\Windows\SysWOW64\Drivers\mbamswissarmy.sys
2012-06-13 17:10 - 2012-06-14 16:53 - 00859020 ____A C:\Windows\ntbtlog.txt
2012-06-13 14:48 - 2012-06-13 14:48 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-12 21:30 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 21:30 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 21:30 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 21:30 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 21:30 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 21:30 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 21:30 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 21:30 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 21:30 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 21:30 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 21:30 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 21:30 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 21:30 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 21:30 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 21:30 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 21:30 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 21:30 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 21:30 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 21:30 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 21:30 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 21:30 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 21:30 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 21:30 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 21:30 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 21:30 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 21:30 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 21:30 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 21:30 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 13:00 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 13:00 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 13:00 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 13:00 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 13:00 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 13:00 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 13:00 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 13:00 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 13:00 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 13:00 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 13:00 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 13:00 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 13:00 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 13:00 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 12:59 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 12:59 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 12:59 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 11:33 - 2012-06-12 11:33 - 00000000 ____D C:\Users\Melissa\AppData\Local\{88D92D88-BF91-4C61-A40E-EAEAA9659A75}
2012-06-09 10:32 - 2012-06-09 10:32 - 00000000 ____D C:\Users\Melissa\AppData\Local\{F418CBDF-2460-4867-894A-2212B25A3F3A}
2012-06-07 06:07 - 2012-06-07 06:08 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC355571-59A6-43BB-9169-87159AB0C6C7}
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5D56FD0E-DC47-4C65-9780-E2323AA5E958}
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{4E2EC11D-84BE-4F63-98C7-7568967829FC}
2012-06-05 13:23 - 2012-06-05 13:23 - 00000000 ____D C:\Users\Melissa\AppData\Local\{E2E5347F-FFA8-400B-9E8E-6C5139A178F8}
2012-06-03 09:55 - 2012-06-03 09:55 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC9E5A7C-7439-44B1-A656-7F5B7D704AFD}
2012-05-29 10:27 - 2012-05-29 10:27 - 00000000 ____D C:\Users\Melissa\AppData\Local\{D632D5FD-6527-4643-BA4B-ED74956B2E04}
2012-05-27 16:41 - 2012-05-27 16:41 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5DBE9B7B-E138-4974-906C-34AD481F8900}
2012-05-24 20:16 - 2012-05-24 20:16 - 00117568 ____A C:\Users\Melissa\Documents\hairstyles.docx
2012-05-20 14:43 - 2012-05-20 16:46 - 00016283 ____A C:\Users\Melissa\Documents\Summer 2012.docx
2012-05-19 12:29 - 2012-05-19 12:29 - 00000000 ____D C:\Users\Melissa\AppData\Local\{65E1FA49-4831-4FC3-9B71-978799686524}
============ 3 Months Modified Files and Folders =============
2012-06-14 18:43 - 2012-06-14 18:39 - 00000000 ____D C:\FRST
2012-06-14 17:33 - 2012-01-11 11:36 - 00000000 __SHD C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}
2012-06-14 17:32 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-14 17:32 - 2009-07-13 20:51 - 00101391 ____A C:\Windows\setupact.log
2012-06-14 17:10 - 2010-07-29 03:11 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-14 16:57 - 2010-07-29 03:11 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-14 16:53 - 2012-06-13 17:10 - 00859020 ____A C:\Windows\ntbtlog.txt
2012-06-14 15:09 - 2009-07-13 21:08 - 00032534 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-14 11:51 - 2010-07-14 22:50 - 00000000 ____D C:\Program Files (x86)\McAfee
2012-06-14 11:51 - 2010-07-14 22:43 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-14 11:49 - 2010-05-13 17:27 - 00235818 ____A C:\Windows\PFRO.log
2012-06-14 11:47 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-14 11:47 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-14 11:44 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-14 11:36 - 2010-05-13 17:20 - 01407275 ____A C:\Windows\WindowsUpdate.log
2012-06-14 11:20 - 2012-06-14 11:20 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-14 11:19 - 2012-06-14 11:19 - 00744030 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 11:18 - 2012-06-14 11:18 - 12621696 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall (1).exe
2012-06-14 11:18 - 2012-06-14 11:18 - 10288512 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-06-14 11:14 - 2012-06-14 11:14 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-14 11:14 - 2010-07-14 23:14 - 00472840 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-06-14 10:55 - 2009-09-06 16:40 - 00000000 ____D C:\SwSetup
2012-06-13 22:06 - 2012-06-13 22:06 - 00003215 ____A C:\Users\Melissa\Desktop\Sophos Virus Removal Tool.lnk
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Users\All Users\Sophos
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Program Files (x86)\Sophos
2012-06-13 22:05 - 2012-06-13 22:04 - 76681248 ____A (Sophos Limited) C:\Users\Melissa\Downloads\Sophos Virus Removal Tool.exe
2012-06-13 22:02 - 2012-06-13 21:55 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-13 22:01 - 2012-06-13 22:01 - 00002594 ____A C:\Windows\System32\.crusader
2012-06-13 22:00 - 2012-06-13 21:54 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-13 21:54 - 2012-06-13 21:53 - 08298672 ____A (SurfRight B.V.) C:\Users\Melissa\Downloads\HitmanPro36_x64.exe
2012-06-13 20:37 - 2012-06-13 17:28 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-13 20:37 - 2011-01-08 22:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-13 20:36 - 2012-06-13 20:36 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Melissa\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-13 20:33 - 2012-06-13 20:33 - 00000361 ____A C:\rkill.log
2012-06-13 20:32 - 2012-06-13 20:32 - 01012656 ____A C:\Users\Melissa\Downloads\iExplore.exe
2012-06-13 20:31 - 2012-06-13 20:31 - 00001205 ____A C:\Users\Melissa\Downloads\registryfix.reg
2012-06-13 14:48 - 2012-06-13 14:48 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-13 14:41 - 2011-11-02 15:50 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-06-13 14:41 - 2010-07-19 05:41 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-13 09:45 - 2010-07-15 02:52 - 00000000 ____D C:\Users\Melissa\Tracing
2012-06-13 09:44 - 2009-07-13 20:45 - 00385952 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 22:25 - 2010-04-21 11:43 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-12 22:20 - 2010-09-06 18:42 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-12 11:33 - 2012-06-12 11:33 - 00000000 ____D C:\Users\Melissa\AppData\Local\{88D92D88-BF91-4C61-A40E-EAEAA9659A75}
2012-06-11 19:16 - 2011-10-23 11:33 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-09 10:32 - 2012-06-09 10:32 - 00000000 ____D C:\Users\Melissa\AppData\Local\{F418CBDF-2460-4867-894A-2212B25A3F3A}
2012-06-07 06:08 - 2012-06-07 06:07 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC355571-59A6-43BB-9169-87159AB0C6C7}
2012-06-07 06:07 - 2012-01-25 12:15 - 00000340 ____A C:\Windows\Tasks\HPCeeScheduleForMelissa.job
2012-06-06 11:34 - 2010-07-14 22:20 - 00000000 ____D C:\users\Melissa
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5D56FD0E-DC47-4C65-9780-E2323AA5E958}
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{4E2EC11D-84BE-4F63-98C7-7568967829FC}
2012-06-05 13:23 - 2012-06-05 13:23 - 00000000 ____D C:\Users\Melissa\AppData\Local\{E2E5347F-FFA8-400B-9E8E-6C5139A178F8}
2012-06-03 09:55 - 2012-06-03 09:55 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC9E5A7C-7439-44B1-A656-7F5B7D704AFD}
2012-05-29 10:27 - 2012-05-29 10:27 - 00000000 ____D C:\Users\Melissa\AppData\Local\{D632D5FD-6527-4643-BA4B-ED74956B2E04}
2012-05-28 11:42 - 2011-03-17 18:35 - 00009216 ____A C:\Users\Melissa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-27 16:41 - 2012-05-27 16:41 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5DBE9B7B-E138-4974-906C-34AD481F8900}
2012-05-27 16:36 - 2010-07-29 03:11 - 00000000 ____D C:\Users\Melissa\AppData\Roaming\Skype
2012-05-24 20:16 - 2012-05-24 20:16 - 00117568 ____A C:\Users\Melissa\Documents\hairstyles.docx
2012-05-20 16:46 - 2012-05-20 14:43 - 00016283 ____A C:\Users\Melissa\Documents\Summer 2012.docx
2012-05-19 12:29 - 2012-05-19 12:29 - 00000000 ____D C:\Users\Melissa\AppData\Local\{65E1FA49-4831-4FC3-9B71-978799686524}
2012-05-17 18:47 - 2012-06-12 21:30 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 21:30 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 21:30 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 21:30 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 21:30 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 21:30 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 21:30 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 21:30 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 21:30 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 21:30 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 21:30 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 21:30 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 21:30 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 21:30 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 21:30 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 21:30 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 21:30 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 21:30 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 21:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 21:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 21:30 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 21:30 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 21:30 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 21:30 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 21:30 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 21:30 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 21:30 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 21:30 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-12 13:00 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 09:35 - 2010-04-21 12:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 09:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\config\TxR
2012-05-04 03:06 - 2012-06-12 13:00 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 13:00 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 13:00 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-12 13:00 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 21:08 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-04-27 19:55 - 2012-06-12 12:59 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 13:00 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 13:00 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 13:00 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 13:00 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 13:00 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 13:00 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 13:00 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 13:00 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 13:00 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 18:58 - 2012-04-18 18:58 - 00000000 ____D C:\Users\Melissa\AppData\Local\{C16EADE6-2066-4177-93D6-362000851407}
2012-04-15 12:19 - 2010-08-02 20:46 - 00008302 ____A C:\Users\Melissa\AppData\Roaming\wklnhst.dat
2012-04-12 18:24 - 2012-04-12 18:24 - 00000000 ____D C:\Users\Melissa\AppData\Local\{9DAF6A0F-7C0A-4A81-A910-FC72A7A14587}
2012-04-12 18:24 - 2012-04-12 18:24 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7FBBB09B-040A-49ED-B842-052EEE9DC6D8}
2012-04-11 19:07 - 2012-04-11 19:07 - 00000000 ____D C:\Users\Melissa\AppData\Local\{B4E69451-CD9E-435F-BA68-E71471844F20}
2012-04-11 09:33 - 2012-04-11 09:33 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5BBB1075-8873-442D-BEE4-ECBF847E8290}
2012-04-10 16:44 - 2012-04-10 16:44 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7658F947-0B09-4B86-A455-4A4142244CD3}
2012-04-07 04:31 - 2012-06-12 12:59 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 12:59 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 14:56 - 2012-06-13 17:18 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-30 03:35 - 2012-05-09 19:15 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 21:24 - 2010-07-19 06:39 - 00000000 ____D C:\Users\Melissa\Desktop\Picasa3
2012-03-27 15:43 - 2012-03-27 15:43 - 00000000 ____D C:\Users\Melissa\AppData\Local\{AAF2046D-9396-49E9-909C-1B6AE16A719D}
2012-03-25 20:03 - 2011-04-11 15:01 - 00000000 ____D C:\Users\Melissa\Documents\Scholarship Essays
2012-03-22 11:12 - 2012-03-22 11:12 - 04435968 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2012-03-20 19:44 - 2012-03-20 19:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 19:44 - 2012-03-20 19:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-18 11:33 - 2010-07-29 03:11 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-03-18 11:33 - 2010-07-29 03:11 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-03-18 11:33 - 2010-07-29 03:11 - 00000000 ____D C:\Users\All Users\Skype
2012-03-18 08:47 - 2012-03-18 08:47 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5BDBAD83-4582-41AD-828E-0A93CD5A9D9C}
2012-03-18 08:47 - 2012-03-18 08:46 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7B3B6B04-6B9D-4756-88F4-89A67B853F85}
2012-03-18 00:15 - 2012-03-18 00:15 - 00000000 ____D C:\Users\Melissa\AppData\Local\{EB31119E-C18A-4917-BCD5-99CFE4FCE1C4}
2012-03-18 00:15 - 2012-03-18 00:15 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7344570A-3ED1-4D7F-9926-11CAAEAB6FF7}
ZeroAccess:
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\@
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\L
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\n
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\U
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\U\80000000.@
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\U\800000cb.@
ZeroAccess:
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}\L
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}\n
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3893.86 MB
Available physical RAM: 3177.71 MB
Total Pagefile: 3892.01 MB
Available Pagefile: 3164.72 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:447.54 GB) (Free:274.68 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:17.92 GB) (Free:2.6 GB) NTFS
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: () (Removable) (Total:0.12 GB) (Free:0.12 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 121 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 447 GB 200 MB
Partition 3 Primary 17 GB 447 GB
Partition 4 Primary 103 MB 465 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 447 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 17 GB Healthy
======================================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 103 MB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 121 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT Removable 121 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-01 14:13
======================= End Of Log ==========================
Thank you for your help.
Scan results are:
Scan result of Farbar Recovery Scan Tool Version: 13-06-2012 03
Ran by SYSTEM at 14-06-2012 18:43:04
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2281256 2011-01-09] (Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323072 2009-08-17] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [611896 2010-01-20] ()
HKLM\...\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [451072 2010-01-18] (Hewlett-Packard Company)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2009-12-16] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-09-15] (IDT, Inc.)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-08-25] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [288080 2009-07-17] (Microsoft Corporation)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [401192 2009-12-08] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201512 2009-12-08] (Egis Technology Inc.)
HKLM-x32\...\Run: [VitaKeyTSR] C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisTSR.exe /run [379248 2010-02-04] (Egis Technology Inc. )
HKLM-x32\...\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED [3331944 2009-12-03] (Symantec Corporation)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-11-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Default User\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 184.16.33.54
Lsa: [Notification Packages] EgisPwdFilter
EgisDSPwdFilter
==================== Services (Whitelisted) ======
2 CinemaNow Service; C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [127984 2010-02-26] (CinemaNow, Inc.)
2 DvmMDES; "C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe" [338168 2010-03-31] (DeviceVM, Inc.)
2 EgisTec Service; "C:\Program Files (x86)\Hewlett-Packard\HP SimplePass Identity Protection\EgisService.exe" [689008 2010-02-04] (Egis Technology Inc. )
2 HP Support Assistant Service; "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [86072 2011-09-09] (Hewlett-Packard Company)
2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [20480 2010-01-18] ()
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2009-09-30] (Intel Corporation)
2 vcsFPService; C:\Windows\system32\vcsFPService.exe [2192176 2010-02-23] (Validity Sensors, Inc.)
2 vcsFPService; C:\Windows\SysWow64\vcsFPService.exe [1799472 2010-02-23] (Validity Sensors, Inc.)
2 WDFME; "C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe" [1066896 2011-03-09] ()
2 WDSC; "C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe" [491920 2011-03-09] ()
========================== Drivers (Whitelisted) =============
1 DVMIO; C:\Windows\System32\Drivers\DVMIO.sys [20056 2009-11-11] (DeviceVM, Inc.)
3 hitmanpro35; \??\C:\Windows\system32\drivers\hitmanpro36.sys [30496 2012-06-13] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-14 18:39 - 2012-06-14 18:43 - 00000000 ____D C:\FRST
2012-06-14 11:20 - 2012-06-14 11:20 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-14 11:19 - 2012-06-14 11:19 - 00744030 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 11:18 - 2012-06-14 11:18 - 12621696 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall (1).exe
2012-06-14 11:18 - 2012-06-14 11:18 - 10288512 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-06-14 11:14 - 2012-06-14 11:14 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-13 22:06 - 2012-06-13 22:06 - 00003215 ____A C:\Users\Melissa\Desktop\Sophos Virus Removal Tool.lnk
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Users\All Users\Sophos
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Program Files (x86)\Sophos
2012-06-13 22:04 - 2012-06-13 22:05 - 76681248 ____A (Sophos Limited) C:\Users\Melissa\Downloads\Sophos Virus Removal Tool.exe
2012-06-13 22:01 - 2012-06-13 22:01 - 00002594 ____A C:\Windows\System32\.crusader
2012-06-13 21:55 - 2012-06-13 22:02 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-13 21:54 - 2012-06-13 22:00 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-13 21:53 - 2012-06-13 21:54 - 08298672 ____A (SurfRight B.V.) C:\Users\Melissa\Downloads\HitmanPro36_x64.exe
2012-06-13 20:36 - 2012-06-13 20:36 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Melissa\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-13 20:33 - 2012-06-13 20:33 - 00000361 ____A C:\rkill.log
2012-06-13 20:32 - 2012-06-13 20:32 - 01012656 ____A C:\Users\Melissa\Downloads\iExplore.exe
2012-06-13 20:31 - 2012-06-13 20:31 - 00001205 ____A C:\Users\Melissa\Downloads\registryfix.reg
2012-06-13 17:28 - 2012-06-13 20:37 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-13 17:18 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-13 17:18 - 2010-12-20 17:09 - 00038224 ____A (Malwarebytes Corporation) C:\Windows\SysWOW64\Drivers\mbamswissarmy.sys
2012-06-13 17:10 - 2012-06-14 16:53 - 00859020 ____A C:\Windows\ntbtlog.txt
2012-06-13 14:48 - 2012-06-13 14:48 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-12 21:30 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 21:30 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 21:30 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 21:30 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 21:30 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 21:30 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 21:30 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 21:30 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 21:30 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 21:30 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 21:30 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 21:30 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 21:30 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 21:30 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 21:30 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 21:30 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 21:30 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 21:30 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 21:30 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 21:30 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 21:30 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 21:30 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 21:30 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 21:30 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 21:30 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 21:30 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 21:30 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 21:30 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 13:00 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 13:00 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 13:00 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 13:00 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 13:00 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 13:00 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 13:00 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 13:00 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 13:00 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 13:00 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 13:00 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 13:00 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 13:00 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 13:00 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 12:59 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 12:59 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 12:59 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 11:33 - 2012-06-12 11:33 - 00000000 ____D C:\Users\Melissa\AppData\Local\{88D92D88-BF91-4C61-A40E-EAEAA9659A75}
2012-06-09 10:32 - 2012-06-09 10:32 - 00000000 ____D C:\Users\Melissa\AppData\Local\{F418CBDF-2460-4867-894A-2212B25A3F3A}
2012-06-07 06:07 - 2012-06-07 06:08 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC355571-59A6-43BB-9169-87159AB0C6C7}
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5D56FD0E-DC47-4C65-9780-E2323AA5E958}
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{4E2EC11D-84BE-4F63-98C7-7568967829FC}
2012-06-05 13:23 - 2012-06-05 13:23 - 00000000 ____D C:\Users\Melissa\AppData\Local\{E2E5347F-FFA8-400B-9E8E-6C5139A178F8}
2012-06-03 09:55 - 2012-06-03 09:55 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC9E5A7C-7439-44B1-A656-7F5B7D704AFD}
2012-05-29 10:27 - 2012-05-29 10:27 - 00000000 ____D C:\Users\Melissa\AppData\Local\{D632D5FD-6527-4643-BA4B-ED74956B2E04}
2012-05-27 16:41 - 2012-05-27 16:41 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5DBE9B7B-E138-4974-906C-34AD481F8900}
2012-05-24 20:16 - 2012-05-24 20:16 - 00117568 ____A C:\Users\Melissa\Documents\hairstyles.docx
2012-05-20 14:43 - 2012-05-20 16:46 - 00016283 ____A C:\Users\Melissa\Documents\Summer 2012.docx
2012-05-19 12:29 - 2012-05-19 12:29 - 00000000 ____D C:\Users\Melissa\AppData\Local\{65E1FA49-4831-4FC3-9B71-978799686524}
============ 3 Months Modified Files and Folders =============
2012-06-14 18:43 - 2012-06-14 18:39 - 00000000 ____D C:\FRST
2012-06-14 17:33 - 2012-01-11 11:36 - 00000000 __SHD C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}
2012-06-14 17:32 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-14 17:32 - 2009-07-13 20:51 - 00101391 ____A C:\Windows\setupact.log
2012-06-14 17:10 - 2010-07-29 03:11 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-14 16:57 - 2010-07-29 03:11 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-14 16:53 - 2012-06-13 17:10 - 00859020 ____A C:\Windows\ntbtlog.txt
2012-06-14 15:09 - 2009-07-13 21:08 - 00032534 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-14 11:51 - 2010-07-14 22:50 - 00000000 ____D C:\Program Files (x86)\McAfee
2012-06-14 11:51 - 2010-07-14 22:43 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-14 11:49 - 2010-05-13 17:27 - 00235818 ____A C:\Windows\PFRO.log
2012-06-14 11:47 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-14 11:47 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-14 11:44 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-14 11:36 - 2010-05-13 17:20 - 01407275 ____A C:\Windows\WindowsUpdate.log
2012-06-14 11:20 - 2012-06-14 11:20 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-14 11:19 - 2012-06-14 11:19 - 00744030 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 11:19 - 2012-06-14 11:19 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 11:18 - 2012-06-14 11:18 - 12621696 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall (1).exe
2012-06-14 11:18 - 2012-06-14 11:18 - 10288512 ____A (Microsoft Corporation) C:\Users\Melissa\Downloads\mseinstall.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-06-14 11:14 - 2012-06-14 11:14 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-14 11:14 - 2012-06-14 11:14 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-14 11:14 - 2010-07-14 23:14 - 00472840 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-06-14 10:55 - 2009-09-06 16:40 - 00000000 ____D C:\SwSetup
2012-06-13 22:06 - 2012-06-13 22:06 - 00003215 ____A C:\Users\Melissa\Desktop\Sophos Virus Removal Tool.lnk
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Users\All Users\Sophos
2012-06-13 22:06 - 2012-06-13 22:06 - 00000000 ____D C:\Program Files (x86)\Sophos
2012-06-13 22:05 - 2012-06-13 22:04 - 76681248 ____A (Sophos Limited) C:\Users\Melissa\Downloads\Sophos Virus Removal Tool.exe
2012-06-13 22:02 - 2012-06-13 21:55 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-13 22:01 - 2012-06-13 22:01 - 00002594 ____A C:\Windows\System32\.crusader
2012-06-13 22:00 - 2012-06-13 21:54 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-13 21:54 - 2012-06-13 21:53 - 08298672 ____A (SurfRight B.V.) C:\Users\Melissa\Downloads\HitmanPro36_x64.exe
2012-06-13 20:37 - 2012-06-13 17:28 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-13 20:37 - 2011-01-08 22:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-13 20:36 - 2012-06-13 20:36 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Melissa\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-13 20:33 - 2012-06-13 20:33 - 00000361 ____A C:\rkill.log
2012-06-13 20:32 - 2012-06-13 20:32 - 01012656 ____A C:\Users\Melissa\Downloads\iExplore.exe
2012-06-13 20:31 - 2012-06-13 20:31 - 00001205 ____A C:\Users\Melissa\Downloads\registryfix.reg
2012-06-13 14:48 - 2012-06-13 14:48 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-13 14:41 - 2011-11-02 15:50 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-06-13 14:41 - 2010-07-19 05:41 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-13 09:45 - 2010-07-15 02:52 - 00000000 ____D C:\Users\Melissa\Tracing
2012-06-13 09:44 - 2009-07-13 20:45 - 00385952 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 22:25 - 2010-04-21 11:43 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-12 22:20 - 2010-09-06 18:42 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-12 11:33 - 2012-06-12 11:33 - 00000000 ____D C:\Users\Melissa\AppData\Local\{88D92D88-BF91-4C61-A40E-EAEAA9659A75}
2012-06-11 19:16 - 2011-10-23 11:33 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-09 10:32 - 2012-06-09 10:32 - 00000000 ____D C:\Users\Melissa\AppData\Local\{F418CBDF-2460-4867-894A-2212B25A3F3A}
2012-06-07 06:08 - 2012-06-07 06:07 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC355571-59A6-43BB-9169-87159AB0C6C7}
2012-06-07 06:07 - 2012-01-25 12:15 - 00000340 ____A C:\Windows\Tasks\HPCeeScheduleForMelissa.job
2012-06-06 11:34 - 2010-07-14 22:20 - 00000000 ____D C:\users\Melissa
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5D56FD0E-DC47-4C65-9780-E2323AA5E958}
2012-06-06 11:22 - 2012-06-06 11:22 - 00000000 ____D C:\Users\Melissa\AppData\Local\{4E2EC11D-84BE-4F63-98C7-7568967829FC}
2012-06-05 13:23 - 2012-06-05 13:23 - 00000000 ____D C:\Users\Melissa\AppData\Local\{E2E5347F-FFA8-400B-9E8E-6C5139A178F8}
2012-06-03 09:55 - 2012-06-03 09:55 - 00000000 ____D C:\Users\Melissa\AppData\Local\{CC9E5A7C-7439-44B1-A656-7F5B7D704AFD}
2012-05-29 10:27 - 2012-05-29 10:27 - 00000000 ____D C:\Users\Melissa\AppData\Local\{D632D5FD-6527-4643-BA4B-ED74956B2E04}
2012-05-28 11:42 - 2011-03-17 18:35 - 00009216 ____A C:\Users\Melissa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-27 16:41 - 2012-05-27 16:41 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5DBE9B7B-E138-4974-906C-34AD481F8900}
2012-05-27 16:36 - 2010-07-29 03:11 - 00000000 ____D C:\Users\Melissa\AppData\Roaming\Skype
2012-05-24 20:16 - 2012-05-24 20:16 - 00117568 ____A C:\Users\Melissa\Documents\hairstyles.docx
2012-05-20 16:46 - 2012-05-20 14:43 - 00016283 ____A C:\Users\Melissa\Documents\Summer 2012.docx
2012-05-19 12:29 - 2012-05-19 12:29 - 00000000 ____D C:\Users\Melissa\AppData\Local\{65E1FA49-4831-4FC3-9B71-978799686524}
2012-05-17 18:47 - 2012-06-12 21:30 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 21:30 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 21:30 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 21:30 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 21:30 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 21:30 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 21:30 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 21:30 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 21:30 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 21:30 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 21:30 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 21:30 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 21:30 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 21:30 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 21:30 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 21:30 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 21:30 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 21:30 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 21:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 21:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 21:30 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 21:30 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 21:30 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 21:30 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 21:30 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 21:30 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 21:30 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 21:30 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-12 13:00 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 09:35 - 2010-04-21 12:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 09:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\config\TxR
2012-05-04 03:06 - 2012-06-12 13:00 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 13:00 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 13:00 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-12 13:00 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 21:08 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-04-27 19:55 - 2012-06-12 12:59 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 13:00 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 13:00 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 13:00 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 13:00 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 13:00 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 13:00 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 13:00 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 13:00 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 13:00 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 18:58 - 2012-04-18 18:58 - 00000000 ____D C:\Users\Melissa\AppData\Local\{C16EADE6-2066-4177-93D6-362000851407}
2012-04-15 12:19 - 2010-08-02 20:46 - 00008302 ____A C:\Users\Melissa\AppData\Roaming\wklnhst.dat
2012-04-12 18:24 - 2012-04-12 18:24 - 00000000 ____D C:\Users\Melissa\AppData\Local\{9DAF6A0F-7C0A-4A81-A910-FC72A7A14587}
2012-04-12 18:24 - 2012-04-12 18:24 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7FBBB09B-040A-49ED-B842-052EEE9DC6D8}
2012-04-11 19:07 - 2012-04-11 19:07 - 00000000 ____D C:\Users\Melissa\AppData\Local\{B4E69451-CD9E-435F-BA68-E71471844F20}
2012-04-11 09:33 - 2012-04-11 09:33 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5BBB1075-8873-442D-BEE4-ECBF847E8290}
2012-04-10 16:44 - 2012-04-10 16:44 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7658F947-0B09-4B86-A455-4A4142244CD3}
2012-04-07 04:31 - 2012-06-12 12:59 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 12:59 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 14:56 - 2012-06-13 17:18 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-30 03:35 - 2012-05-09 19:15 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 21:24 - 2010-07-19 06:39 - 00000000 ____D C:\Users\Melissa\Desktop\Picasa3
2012-03-27 15:43 - 2012-03-27 15:43 - 00000000 ____D C:\Users\Melissa\AppData\Local\{AAF2046D-9396-49E9-909C-1B6AE16A719D}
2012-03-25 20:03 - 2011-04-11 15:01 - 00000000 ____D C:\Users\Melissa\Documents\Scholarship Essays
2012-03-22 11:12 - 2012-03-22 11:12 - 04435968 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2012-03-20 19:44 - 2012-03-20 19:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 19:44 - 2012-03-20 19:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-18 11:33 - 2010-07-29 03:11 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-03-18 11:33 - 2010-07-29 03:11 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-03-18 11:33 - 2010-07-29 03:11 - 00000000 ____D C:\Users\All Users\Skype
2012-03-18 08:47 - 2012-03-18 08:47 - 00000000 ____D C:\Users\Melissa\AppData\Local\{5BDBAD83-4582-41AD-828E-0A93CD5A9D9C}
2012-03-18 08:47 - 2012-03-18 08:46 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7B3B6B04-6B9D-4756-88F4-89A67B853F85}
2012-03-18 00:15 - 2012-03-18 00:15 - 00000000 ____D C:\Users\Melissa\AppData\Local\{EB31119E-C18A-4917-BCD5-99CFE4FCE1C4}
2012-03-18 00:15 - 2012-03-18 00:15 - 00000000 ____D C:\Users\Melissa\AppData\Local\{7344570A-3ED1-4D7F-9926-11CAAEAB6FF7}
ZeroAccess:
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\@
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\L
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\n
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\U
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\U\80000000.@
C:\Windows\Installer\{945a142a-35f2-1738-72f4-953050c7916d}\U\800000cb.@
ZeroAccess:
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}\L
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}\n
C:\Users\Melissa\AppData\Local\{945a142a-35f2-1738-72f4-953050c7916d}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3893.86 MB
Available physical RAM: 3177.71 MB
Total Pagefile: 3892.01 MB
Available Pagefile: 3164.72 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:447.54 GB) (Free:274.68 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:17.92 GB) (Free:2.6 GB) NTFS
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: () (Removable) (Total:0.12 GB) (Free:0.12 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 121 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 447 GB 200 MB
Partition 3 Primary 17 GB 447 GB
Partition 4 Primary 103 MB 465 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 447 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 17 GB Healthy
======================================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 103 MB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 121 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT Removable 121 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-01 14:13
======================= End Of Log ==========================
Thank you for your help.