FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-12-2012
Ran by SYSTEM at 10-12-2012 10:00:11
Running from E:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2122536 2010-05-07] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10144288 2010-04-13] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey [x]
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [498160 2009-10-15] ()
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [409744 2009-06-24] (Creative Technology Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254896 2012-09-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Sendori Tray] "C:\Program Files (x86)\Sendori\SendoriTray.exe" [82792 2012-11-26] (Sendori, Inc.)
HKU\jah\...\Run: [Novatel Wireless] Rundll32.exe "C:\Users\jah\AppData\Local\Novatel Wireless\kwnlrzdh.dll",ompd_free_thread_info [760320 2012-12-04] ()
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Tcpip\..\Interfaces\{00DB6E6E-F3AB-4C9D-8D23-EDB53E8402C6}: [NameServer]192.168.9.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Jungle Disk Desktop.lnk
ShortcutTarget: Jungle Disk Desktop.lnk -> C:\Program Files\Jungle Disk Desktop\JungleDiskMonitor.exe (Jungle Disk, Inc.)
Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\jah\Start Menu\Programs\Startup\PdaNet Desktop.lnk
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
==================== Services (Whitelisted) ===================
2 Application Sendori; C:\Program Files (x86)\Sendori\SendoriSvc.exe [118632 2012-11-26] (Sendori, Inc.)
2 JungleDiskService; "C:\Program Files\Jungle Disk Desktop\JungleDiskMonitor.exe" --service [9761096 2011-05-17] (Jungle Disk, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
2 Service Sendori; C:\Program Files (x86)\Sendori\Sendori.Service.exe [14696 2012-11-26] (sendori)
2 sndappv2; C:\Program Files (x86)\Sendori\sndappv2.exe [3569512 2012-11-26] (Sendori)
==================== Drivers (Whitelisted) =====================
1 cbfs3; C:\Windows\System32\Drivers\cbfs3.sys [321424 2010-11-30] (EldoS Corporation)
0 mbamchameleon; C:\Windows\System32\Drivers\mbamchameleon.sys [36680 2012-11-23] ()
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
0 mbamswissarmy; C:\Windows\System32\drivers\mbamswissarmy.sys [x]
3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-12-08 11:00 - 2011-10-04 04:22 - 00203320 ____A (DEVGURU Co., LTD.(
www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys
2012-12-08 11:00 - 2011-10-04 04:22 - 00095544 ____A (DEVGURU Co., LTD.(
www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys
2012-12-08 10:59 - 2012-12-08 10:59 - 00000000 ____D C:\Program Files\SAMSUNG
2012-12-08 10:58 - 2012-12-08 10:58 - 00000000 ____D C:\Users\All Users\Samsung
2012-12-08 10:58 - 2012-12-08 10:58 - 00000000 ____D C:\Users\All Users\Application Data\Samsung
2012-12-08 10:57 - 2012-12-08 10:58 - 00000000 ____D C:\Samsung Galaxy S3 QCom ToolKit
2012-12-08 10:57 - 2012-12-08 10:57 - 00001651 ____A C:\Users\jah\Desktop\Samsung GS3 QCom ToolKit.lnk
2012-12-08 10:26 - 2012-12-08 10:26 - 07444480 ____A C:\Users\jah\Desktop\recovery-clockwork-touch-6.0.1.2-d2spr.tar
2012-12-08 10:25 - 2012-12-08 10:25 - 06410240 ____A C:\Users\jah\Desktop\Sprint_Stock_Recovery.tar
2012-12-08 09:45 - 2012-12-08 09:45 - 00000000 ____D C:\Users\jah\Desktop\Odin3-v1.85
2012-12-08 09:42 - 2012-12-08 09:42 - 01461029 ____A (Farbar) C:\Users\jah\Desktop\FRST64(1).exe
2012-12-07 14:09 - 2012-12-07 14:09 - 00683568 ____A C:\Windows\Minidump\120712-18876-01.dmp
2012-12-06 18:06 - 2012-12-06 18:07 - 00000030 ____A C:\Users\jah\Desktop\New Text Document.txt
2012-12-06 14:06 - 2012-12-06 14:07 - 00683568 ____A C:\Windows\Minidump\120612-17799-01.dmp
2012-12-04 18:15 - 2012-12-04 18:15 - 00000000 ____D C:\Program Files (x86)\ESET
2012-12-04 18:14 - 2012-12-04 18:14 - 02322184 ____A (ESET) C:\Users\jah\Downloads\esetsmartinstaller_enu.exe
2012-12-04 18:02 - 2012-12-04 18:02 - 00448512 ____A (OldTimer Tools) C:\Users\jah\Desktop\TFC.exe
2012-12-04 18:01 - 2012-12-04 18:02 - 00696153 ____A (Farbar) C:\Users\jah\Desktop\FSS.exe
2012-12-04 18:01 - 2012-12-04 18:01 - 00856731 ____A C:\Users\jah\Desktop\SecurityCheck.exe
2012-12-04 17:53 - 2012-12-04 17:53 - 00000000 ____D C:\_OTL
2012-12-04 17:51 - 2012-12-04 17:52 - 00602112 ____A (OldTimer Tools) C:\Users\jah\Desktop\OTL.exe
2012-11-27 14:54 - 2012-12-04 17:58 - 00000000 ____D C:\Users\jah\Local Settings\Novatel Wireless
2012-11-27 14:54 - 2012-12-04 17:58 - 00000000 ____D C:\Users\jah\Local Settings\Application Data\Novatel Wireless
2012-11-27 14:54 - 2012-12-04 17:58 - 00000000 ____D C:\Users\jah\AppData\Local\Novatel Wireless
2012-11-27 09:34 - 2012-11-27 09:34 - 00000000 ____D C:\Users\All Users\PDF Architect
2012-11-27 09:34 - 2012-11-27 09:34 - 00000000 ____D C:\Users\All Users\Application Data\PDF Architect
2012-11-26 19:36 - 2012-11-26 19:36 - 00069384 ____A C:\Users\JMS\Downloads\TS010169559.dotx
2012-11-26 19:32 - 2012-11-26 19:32 - 00000000 ____D C:\Users\JMS\Application Data\PDF Architect
2012-11-26 19:32 - 2012-11-26 19:32 - 00000000 ____D C:\Users\JMS\AppData\Roaming\PDF Architect
2012-11-26 19:28 - 2012-11-29 21:05 - 00000000 ____D C:\Users\All Users\Sendori
2012-11-26 19:28 - 2012-11-29 21:05 - 00000000 ____D C:\Users\All Users\Application Data\Sendori
2012-11-26 19:28 - 2012-11-26 19:28 - 00000000 ____D C:\Users\JMS\Application Data\APP_NAME_NON_STRING
2012-11-26 19:28 - 2012-11-26 19:28 - 00000000 ____D C:\Users\JMS\AppData\Roaming\APP_NAME_NON_STRING
2012-11-26 19:28 - 2012-11-26 13:12 - 00321384 ____A (Sendori) C:\Windows\SysWOW64\Sendori.dll
2012-11-26 19:27 - 2012-11-29 21:06 - 00000000 ____D C:\Program Files (x86)\Sendori
2012-11-26 19:27 - 2012-11-26 19:28 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\Application Data\pdfforge
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\Application Data\OpenCandy
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\AppData\Roaming\pdfforge
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\AppData\Roaming\OpenCandy
2012-11-26 19:27 - 2012-10-28 17:32 - 00103936 ____A (pdfforge GbR) C:\Windows\System32\pdfcmon.dll
2012-11-26 19:27 - 2012-05-05 09:54 - 01071088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2012-11-26 19:27 - 2012-05-05 09:54 - 00662288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX
2012-11-26 19:27 - 2012-05-05 09:54 - 00137000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2012-11-26 19:27 - 2012-05-05 09:54 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL
2012-11-26 19:21 - 2012-11-26 19:21 - 00457048 ____A (pdfforge GbR ) C:\Users\JMS\Downloads\PDFCreatorWebSetup.exe
2012-11-26 19:17 - 2012-11-26 20:04 - 00000000 ____D C:\Users\JMS\Application Data\SoftGrid Client
2012-11-26 19:17 - 2012-11-26 20:04 - 00000000 ____D C:\Users\JMS\AppData\Roaming\SoftGrid Client
2012-11-26 19:17 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\Local Settings\SoftGrid Client
2012-11-26 19:17 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\Local Settings\Application Data\SoftGrid Client
2012-11-26 19:17 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\AppData\Local\SoftGrid Client
2012-11-23 18:09 - 2012-11-23 18:18 - 00000000 ____D C:\Qoobox
2012-11-23 18:09 - 2012-11-23 18:16 - 00000000 ____D C:\Windows\erdnt
2012-11-23 18:09 - 2011-06-26 00:45 - 00256000 ____A C:\Windows\PEV.exe
2012-11-23 18:09 - 2010-11-07 11:20 - 00208896 ____A C:\Windows\MBR.exe
2012-11-23 18:09 - 2009-04-19 22:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-11-23 18:09 - 2000-08-30 18:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-11-23 18:09 - 2000-08-30 18:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-11-23 18:09 - 2000-08-30 18:00 - 00098816 ____A C:\Windows\sed.exe
2012-11-23 18:09 - 2000-08-30 18:00 - 00080412 ____A C:\Windows\grep.exe
2012-11-23 18:09 - 2000-08-30 18:00 - 00068096 ____A C:\Windows\zip.exe
2012-11-23 15:18 - 2012-11-23 15:18 - 00279088 ____A C:\Windows\Minidump\112312-19936-01.dmp
2012-11-23 13:34 - 2012-11-23 13:34 - 00000317 ____A C:\Users\jah\Downloads\fixlist.txt
2012-11-23 13:07 - 2012-11-23 13:07 - 01461039 ____A (Farbar) C:\Users\jah\Downloads\FRST64.exe
2012-11-23 11:17 - 2012-11-23 11:17 - 00036680 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
2012-11-22 23:15 - 2012-11-22 23:17 - 12961620 ____A C:\Users\jah\Downloads\mbar-1.01.0.1009.zip
2012-11-22 19:02 - 2012-11-22 19:02 - 00001945 ____A C:\Windows\epplauncher.mif
2012-11-22 19:00 - 2012-11-22 19:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-11-22 19:00 - 2012-11-22 19:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-11-22 18:25 - 2012-11-22 18:45 - 13529576 ____A (Microsoft Corporation) C:\Users\jah\Downloads\mseinstall.exe
2012-11-22 18:14 - 2012-11-22 18:14 - 00000000 ____D C:\Users\jah\Application Data\Malwarebytes
2012-11-22 18:14 - 2012-11-22 18:14 - 00000000 ____D C:\Users\jah\AppData\Roaming\Malwarebytes
2012-11-22 18:13 - 2012-11-22 18:13 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-22 18:13 - 2012-11-22 18:13 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-22 18:13 - 2012-11-22 18:13 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-11-22 18:13 - 2012-11-22 18:13 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-11-22 18:13 - 2012-11-22 18:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-22 18:13 - 2012-09-29 18:54 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-11-22 18:05 - 2012-11-22 18:12 - 10669952 ____A (Malwarebytes Corporation ) C:\Users\jah\Downloads\mbam-setup-1.65.1.1000.exe
2012-11-15 10:26 - 2012-01-31 06:44 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
==================== One Month Modified Files and Folders =======
2012-12-10 08:57 - 2009-07-13 23:10 - 01199752 ____A C:\Windows\WindowsUpdate.log
2012-12-10 08:56 - 2009-07-13 22:51 - 00030623 ____A C:\Windows\setupact.log
2012-12-08 11:24 - 2009-07-13 22:45 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-12-08 11:24 - 2009-07-13 22:45 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-12-08 11:21 - 2009-07-13 23:13 - 00714754 ____A C:\Windows\System32\PerfStringBackup.INI
2012-12-08 11:17 - 2009-07-13 23:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-08 10:59 - 2012-12-08 10:59 - 00000000 ____D C:\Program Files\SAMSUNG
2012-12-08 10:58 - 2012-12-08 10:58 - 00000000 ____D C:\Users\All Users\Samsung
2012-12-08 10:58 - 2012-12-08 10:58 - 00000000 ____D C:\Users\All Users\Application Data\Samsung
2012-12-08 10:58 - 2012-12-08 10:57 - 00000000 ____D C:\Samsung Galaxy S3 QCom ToolKit
2012-12-08 10:57 - 2012-12-08 10:57 - 00001651 ____A C:\Users\jah\Desktop\Samsung GS3 QCom ToolKit.lnk
2012-12-08 10:26 - 2012-12-08 10:26 - 07444480 ____A C:\Users\jah\Desktop\recovery-clockwork-touch-6.0.1.2-d2spr.tar
2012-12-08 10:25 - 2012-12-08 10:25 - 06410240 ____A C:\Users\jah\Desktop\Sprint_Stock_Recovery.tar
2012-12-08 09:45 - 2012-12-08 09:45 - 00000000 ____D C:\Users\jah\Desktop\Odin3-v1.85
2012-12-08 09:42 - 2012-12-08 09:42 - 01461029 ____A (Farbar) C:\Users\jah\Desktop\FRST64(1).exe
2012-12-07 14:09 - 2012-12-07 14:09 - 00683568 ____A C:\Windows\Minidump\120712-18876-01.dmp
2012-12-07 14:09 - 2012-09-08 22:42 - 00000000 ____D C:\Windows\Minidump
2012-12-07 14:09 - 2012-09-08 22:41 - 374365794 ____A C:\Windows\MEMORY.DMP
2012-12-06 19:11 - 2012-10-29 14:52 - 00000000 ____D C:\Users\jah\My Documents\Misc
2012-12-06 19:11 - 2012-10-29 14:52 - 00000000 ____D C:\Users\jah\Documents\Misc
2012-12-06 18:07 - 2012-12-06 18:06 - 00000030 ____A C:\Users\jah\Desktop\New Text Document.txt
2012-12-06 14:07 - 2012-12-06 14:06 - 00683568 ____A C:\Windows\Minidump\120612-17799-01.dmp
2012-12-05 09:28 - 2012-11-03 16:31 - 00000000 ____D C:\Users\jah\Application Data\SoftGrid Client
2012-12-05 09:28 - 2012-11-03 16:31 - 00000000 ____D C:\Users\jah\AppData\Roaming\SoftGrid Client
2012-12-04 18:15 - 2012-12-04 18:15 - 00000000 ____D C:\Program Files (x86)\ESET
2012-12-04 18:14 - 2012-12-04 18:14 - 02322184 ____A (ESET) C:\Users\jah\Downloads\esetsmartinstaller_enu.exe
2012-12-04 18:02 - 2012-12-04 18:02 - 00448512 ____A (OldTimer Tools) C:\Users\jah\Desktop\TFC.exe
2012-12-04 18:02 - 2012-12-04 18:01 - 00696153 ____A (Farbar) C:\Users\jah\Desktop\FSS.exe
2012-12-04 18:01 - 2012-12-04 18:01 - 00856731 ____A C:\Users\jah\Desktop\SecurityCheck.exe
2012-12-04 17:58 - 2012-11-27 14:54 - 00000000 ____D C:\Users\jah\Local Settings\Novatel Wireless
2012-12-04 17:58 - 2012-11-27 14:54 - 00000000 ____D C:\Users\jah\Local Settings\Application Data\Novatel Wireless
2012-12-04 17:58 - 2012-11-27 14:54 - 00000000 ____D C:\Users\jah\AppData\Local\Novatel Wireless
2012-12-04 17:53 - 2012-12-04 17:53 - 00000000 ____D C:\_OTL
2012-12-04 17:52 - 2012-12-04 17:51 - 00602112 ____A (OldTimer Tools) C:\Users\jah\Desktop\OTL.exe
2012-11-29 21:06 - 2012-11-26 19:27 - 00000000 ____D C:\Program Files (x86)\Sendori
2012-11-29 21:05 - 2012-11-26 19:28 - 00000000 ____D C:\Users\All Users\Sendori
2012-11-29 21:05 - 2012-11-26 19:28 - 00000000 ____D C:\Users\All Users\Application Data\Sendori
2012-11-27 09:34 - 2012-11-27 09:34 - 00000000 ____D C:\Users\All Users\PDF Architect
2012-11-27 09:34 - 2012-11-27 09:34 - 00000000 ____D C:\Users\All Users\Application Data\PDF Architect
2012-11-27 09:30 - 2010-11-17 20:47 - 00010474 ____A C:\Windows\PFRO.log
2012-11-26 20:04 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\Application Data\SoftGrid Client
2012-11-26 20:04 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\AppData\Roaming\SoftGrid Client
2012-11-26 19:36 - 2012-11-26 19:36 - 00069384 ____A C:\Users\JMS\Downloads\TS010169559.dotx
2012-11-26 19:32 - 2012-11-26 19:32 - 00000000 ____D C:\Users\JMS\Application Data\PDF Architect
2012-11-26 19:32 - 2012-11-26 19:32 - 00000000 ____D C:\Users\JMS\AppData\Roaming\PDF Architect
2012-11-26 19:28 - 2012-11-26 19:28 - 00000000 ____D C:\Users\JMS\Application Data\APP_NAME_NON_STRING
2012-11-26 19:28 - 2012-11-26 19:28 - 00000000 ____D C:\Users\JMS\AppData\Roaming\APP_NAME_NON_STRING
2012-11-26 19:28 - 2012-11-26 19:27 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\Application Data\pdfforge
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\Application Data\OpenCandy
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\AppData\Roaming\pdfforge
2012-11-26 19:27 - 2012-11-26 19:27 - 00000000 ____D C:\Users\jah\AppData\Roaming\OpenCandy
2012-11-26 19:21 - 2012-11-26 19:21 - 00457048 ____A (pdfforge GbR ) C:\Users\JMS\Downloads\PDFCreatorWebSetup.exe
2012-11-26 19:17 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\Local Settings\SoftGrid Client
2012-11-26 19:17 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\Local Settings\Application Data\SoftGrid Client
2012-11-26 19:17 - 2012-11-26 19:17 - 00000000 ____D C:\Users\JMS\AppData\Local\SoftGrid Client
2012-11-26 13:12 - 2012-11-26 19:28 - 00321384 ____A (Sendori) C:\Windows\SysWOW64\Sendori.dll
2012-11-23 18:18 - 2012-11-23 18:09 - 00000000 ____D C:\Qoobox
2012-11-23 18:18 - 2009-07-13 21:20 - 00000000 __RHD C:\users\Default
2012-11-23 18:16 - 2012-11-23 18:09 - 00000000 ____D C:\Windows\erdnt
2012-11-23 18:15 - 2009-07-13 20:34 - 00000215 ____A C:\Windows\system.ini
2012-11-23 17:42 - 2012-11-03 11:46 - 00000000 ____D C:\Users\jah\Desktop\From Phone
2012-11-23 15:18 - 2012-11-23 15:18 - 00279088 ____A C:\Windows\Minidump\112312-19936-01.dmp
2012-11-23 13:34 - 2012-11-23 13:34 - 00000317 ____A C:\Users\jah\Downloads\fixlist.txt
2012-11-23 13:07 - 2012-11-23 13:07 - 01461039 ____A (Farbar) C:\Users\jah\Downloads\FRST64.exe
2012-11-23 11:17 - 2012-11-23 11:17 - 00036680 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
2012-11-22 23:17 - 2012-11-22 23:15 - 12961620 ____A C:\Users\jah\Downloads\mbar-1.01.0.1009.zip
2012-11-22 19:02 - 2012-11-22 19:02 - 00001945 ____A C:\Windows\epplauncher.mif
2012-11-22 19:00 - 2012-11-22 19:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-11-22 19:00 - 2012-11-22 19:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-11-22 18:45 - 2012-11-22 18:25 - 13529576 ____A (Microsoft Corporation) C:\Users\jah\Downloads\mseinstall.exe
2012-11-22 18:14 - 2012-11-22 18:14 - 00000000 ____D C:\Users\jah\Application Data\Malwarebytes
2012-11-22 18:14 - 2012-11-22 18:14 - 00000000 ____D C:\Users\jah\AppData\Roaming\Malwarebytes
2012-11-22 18:13 - 2012-11-22 18:13 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-22 18:13 - 2012-11-22 18:13 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-22 18:13 - 2012-11-22 18:13 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-11-22 18:13 - 2012-11-22 18:13 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-11-22 18:13 - 2012-11-22 18:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-22 18:12 - 2012-11-22 18:05 - 10669952 ____A (Malwarebytes Corporation ) C:\Users\jah\Downloads\mbam-setup-1.65.1.1000.exe
2012-11-15 09:05 - 2010-11-17 19:29 - 00000000 ____D C:\Program Files (x86)\Dell
2012-11-13 18:51 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\System32\NDF
2012-11-13 18:40 - 2011-01-15 07:44 - 00000073 ____A C:\Windows\SysWOW64\ToasterLauncherLog.log
2012-11-13 18:40 - 2011-01-15 07:42 - 00000000 ____D C:\Users\jah\Local Settings\SoftThinks
2012-11-13 18:40 - 2011-01-15 07:42 - 00000000 ____D C:\Users\jah\Local Settings\Application Data\SoftThinks
2012-11-13 18:40 - 2011-01-15 07:42 - 00000000 ____D C:\Users\jah\AppData\Local\SoftThinks
2012-11-11 14:49 - 2012-11-06 17:22 - 00000000 ____D C:\Users\JMS\Application Data\JungleDisk
2012-11-11 14:49 - 2012-11-06 17:22 - 00000000 ____D C:\Users\JMS\AppData\Roaming\JungleDisk
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b\@
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b\L
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b\U
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b\L\00000004.@
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b\L\4cce1f70
C:\$Recycle.Bin\S-1-5-21-4169508272-3924329090-955796134-1000\$c614d3bf243a3fd7a4fd36cd3756874b\L\55490ac4
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-11-22 17:49:08
Restore point made on: 2012-11-22 23:18:28
Restore point made on: 2012-11-22 23:50:24
Restore point made on: 2012-11-23 11:37:24
Restore point made on: 2012-11-23 18:01:27
Restore point made on: 2012-11-26 19:18:30
Restore point made on: 2012-11-27 09:33:25
Restore point made on: 2012-11-29 11:40:36
Restore point made on: 2012-11-30 12:43:18
Restore point made on: 2012-12-03 13:23:44
Restore point made on: 2012-12-05 18:31:14
Restore point made on: 2012-12-07 09:02:34
==================== Memory info ===========================
Percentage of memory in use: 14%
Total physical RAM: 3892.52 MB
Available physical RAM: 3339.3 MB
Total Pagefile: 3890.67 MB
Available Pagefile: 3328.34 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:417.64 GB) NTFS
3 Drive e: (XP-KOMKU) (Removable) (Total:3.73 GB) (Free:2.67 GB) FAT
4 Drive f: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.53 GB) NTFS ==>[System with boot components (obtained from reading drive)]
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 Online 3821 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 14 GB 101 MB
Partition 3 Primary 451 GB 14 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 101 MB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 F RECOVERY NTFS Partition 14 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3821 MB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 0E
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E XP-KOMKU FAT Removable 3821 MB Healthy
=========================================================
Last Boot: 2012-12-05 18:57
==================== End Of Log =============================