I got hit by the live platinum security and thought I had that issue cleared up but was then met with sirefef and the shutting down of the system. I've gone ahead and run the Farbar scans, here are the logs. Thanks for any help you can provide.
FRST log:
Scan result of Farbar Recovery Scan Tool Version: 20-07-2012 01
Ran by SYSTEM at 24-07-2012 17:15:23
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe [95728 2009-09-16] (PC-Doctor, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [x]
HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-26] (Sony Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Joni\...\Run: [Google Update] "C:\Users\Joni\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-10-17] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 NVNET; C:\Windows\System32\DRIVERS\nvmf6264.sys [339744 2009-07-30] (NVIDIA Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-24 17:15 - 2012-07-24 17:15 - 00000000 ____D C:\FRST
2012-07-19 09:11 - 2012-07-24 17:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-19 09:11 - 2012-07-19 09:11 - 00000000 ____D C:\Users\Joni\AppData\Roaming\Malwarebytes
2012-07-19 09:11 - 2012-07-19 09:11 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-19 09:02 - 2012-07-19 12:30 - 00001238 ____A C:\Users\Joni\Desktop\FixExec.txt
2012-07-19 06:53 - 2012-07-24 17:03 - 00000000 ____D C:\Users\All Users\7812A1690008CB200009235DF875F002
2012-07-12 15:50 - 2012-07-12 15:50 - 00000000 ____D C:\Users\Joni\AppData\Roaming\Skunk Studios
2012-07-12 15:43 - 2012-07-12 15:43 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\grim-tales-the-wishes-collectors-edition_s1_l1_gF7284T1L1_d1800559122.exe
2012-07-11 23:17 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 23:16 - 2012-07-11 23:17 - 00265426 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-11 23:02 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 23:02 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 23:02 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 23:02 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 23:02 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 23:02 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 23:02 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 23:02 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 23:02 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 23:02 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 23:02 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 23:02 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 23:02 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 23:02 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 23:02 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 23:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 23:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 23:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 23:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 23:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 23:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 23:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 23:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 12:25 - 2012-07-11 12:25 - 09822920 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-11 00:55 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 00:55 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 00:55 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 00:55 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 00:55 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 00:55 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 00:55 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 00:55 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 00:55 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 00:55 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 00:55 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 00:55 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 00:55 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 00:55 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 00:55 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 00:55 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 00:55 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 00:55 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 00:55 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-05 03:44 - 2012-07-05 03:45 - 00318904 ____A (Microsoft Corporation) C:\Users\Joni\Downloads\wmpfirefoxplugin.exe
2012-07-01 17:19 - 2012-07-01 17:19 - 00002297 ____A C:\Users\Joni\Desktop\Slingo Mystery.lnk
2012-07-01 17:19 - 2012-07-01 17:19 - 00001212 ____A C:\Users\Joni\Desktop\Games of the Month.lnk
2012-07-01 17:19 - 2012-07-01 17:19 - 00000000 ____D C:\Users\Joni\AppData\Roaming\Oberon Media
2012-07-01 17:19 - 2012-07-01 17:19 - 00000000 ____D C:\Program Files (x86)\Oberon Media SIDR
2012-07-01 17:04 - 2012-07-19 04:33 - 00000266 ____A C:\Windows\Tasks\CandyUpdater.job
2012-07-01 17:04 - 2012-07-01 17:04 - 00000000 ____D C:\Users\Joni\AppData\Local\ArcadeCandy
2012-07-01 17:01 - 2012-07-01 17:01 - 01272776 ____A C:\Users\Joni\Downloads\ArcadeCandyGames(1).exe
2012-07-01 05:54 - 2012-07-01 05:54 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-30 14:33 - 2012-06-30 14:33 - 00002210 ____A C:\Users\Public\Desktop\Play Flux Family Secrets - The Book of Oracles.lnk
2012-06-30 14:33 - 2012-06-30 14:33 - 00001312 ____A C:\Users\Public\Desktop\More Great Games.lnk
2012-06-30 14:32 - 2012-06-30 14:33 - 00000000 ____D C:\Program Files (x86)\Flux Family Secrets - The Book of Oracles
2012-06-25 19:12 - 2012-06-25 20:33 - 00001780 ____A C:\Users\Joni\AppData\Roaming\result.db
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
============ 3 Months Modified Files ========================
2012-07-24 13:10 - 2011-08-03 17:47 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-24 13:10 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-24 13:10 - 2009-07-13 20:51 - 00039191 ____A C:\Windows\setupact.log
2012-07-24 13:05 - 2011-08-03 15:02 - 01061060 ____A C:\Windows\WindowsUpdate.log
2012-07-19 12:30 - 2012-07-19 09:02 - 00001238 ____A C:\Users\Joni\Desktop\FixExec.txt
2012-07-19 04:43 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-19 04:43 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-19 04:34 - 2012-06-09 16:00 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-19 04:34 - 2011-10-17 05:14 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3273348302-90664181-4027946035-1001Core.job
2012-07-19 04:34 - 2011-08-03 17:47 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-19 04:33 - 2012-07-01 17:04 - 00000266 ____A C:\Windows\Tasks\CandyUpdater.job
2012-07-19 04:33 - 2011-10-17 05:14 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3273348302-90664181-4027946035-1001UA.job
2012-07-12 15:43 - 2012-07-12 15:43 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\grim-tales-the-wishes-collectors-edition_s1_l1_gF7284T1L1_d1800559122.exe
2012-07-11 23:35 - 2011-08-11 05:00 - 00000328 ____A C:\Windows\Tasks\HPCeeScheduleForJoni.job
2012-07-11 23:35 - 2009-07-13 20:45 - 00329176 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 23:34 - 2009-11-25 12:10 - 00186056 ____A C:\Windows\PFRO.log
2012-07-11 23:17 - 2012-07-11 23:16 - 00265426 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-11 23:03 - 2011-08-03 15:41 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 12:25 - 2012-07-11 12:25 - 09822920 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-11 12:25 - 2012-06-09 16:00 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 12:25 - 2011-08-03 16:36 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 11:08 - 2011-10-17 05:15 - 00002397 ____A C:\Users\Joni\Desktop\Google Chrome.lnk
2012-07-08 09:52 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-05 03:45 - 2012-07-05 03:44 - 00318904 ____A (Microsoft Corporation) C:\Users\Joni\Downloads\wmpfirefoxplugin.exe
2012-07-01 17:19 - 2012-07-01 17:19 - 00002297 ____A C:\Users\Joni\Desktop\Slingo Mystery.lnk
2012-07-01 17:19 - 2012-07-01 17:19 - 00001212 ____A C:\Users\Joni\Desktop\Games of the Month.lnk
2012-07-01 17:01 - 2012-07-01 17:01 - 01272776 ____A C:\Users\Joni\Downloads\ArcadeCandyGames(1).exe
2012-06-30 14:33 - 2012-06-30 14:33 - 00002210 ____A C:\Users\Public\Desktop\Play Flux Family Secrets - The Book of Oracles.lnk
2012-06-30 14:33 - 2012-06-30 14:33 - 00001312 ____A C:\Users\Public\Desktop\More Great Games.lnk
2012-06-30 06:25 - 2011-08-03 15:09 - 00000544 ____A C:\Windows\Tasks\PCDRScheduledMaintenance.job
2012-06-25 20:33 - 2012-06-25 19:12 - 00001780 ____A C:\Users\Joni\AppData\Roaming\result.db
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
2012-06-19 16:27 - 2012-06-19 16:27 - 00002135 ____A C:\Users\Public\Desktop\Play Dark Strokes - Sins of the Fathers.lnk
2012-06-19 16:25 - 2012-06-19 16:25 - 00002232 ____A C:\Users\Public\Desktop\Play Nightmares from the Deep - The Cursed Heart.lnk
2012-06-19 15:48 - 2012-06-19 15:48 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p146088874_s1_l1.exe
2012-06-11 19:08 - 2012-07-11 23:17 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 13:18 - 2012-06-10 13:18 - 00002361 ____A C:\Users\Public\Desktop\Play Final Cut - Death on the Silver Screen Collector's Edition.lnk
2012-06-09 17:24 - 2012-06-09 17:24 - 01307080 ____A C:\Users\Joni\Downloads\ArcadeCandyGames.exe
2012-06-08 21:43 - 2012-07-11 00:55 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 00:55 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-06 09:42 - 2012-06-06 09:42 - 00988888 ____A (Solid State Networks) C:\Users\Joni\Downloads\install_flashplayer11x64_mssa_aih.exe
2012-06-05 22:06 - 2012-07-11 00:55 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 00:55 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 00:55 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 00:55 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 00:55 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 00:55 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:47 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 05:46 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 05:46 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 05:47 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 05:46 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 05:46 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-21 05:46 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 23:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 23:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 23:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 23:02 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:04 - 2012-07-11 23:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:04 - 2012-07-11 23:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:03 - 2012-07-11 23:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 23:02 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 23:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 23:02 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 23:02 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 23:02 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 23:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 23:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 23:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 23:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 23:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:25 - 2012-07-11 23:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:23 - 2012-07-11 23:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 23:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 23:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 23:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 23:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 23:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 23:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 00:55 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 00:55 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 00:55 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 00:55 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 00:55 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 00:55 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 00:55 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 00:55 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 00:55 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 09:56 - 2012-06-01 09:56 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p144501816_s1_l1.exe
2012-05-30 05:18 - 2012-05-30 05:18 - 00002186 ____A C:\Users\Public\Desktop\Play Spirit Walkers - Curse of the Cypress Witch.lnk
2012-05-28 06:06 - 2012-05-28 06:06 - 00001945 ____A C:\Users\Public\Desktop\Play Slingo Supreme 2.lnk
2012-05-28 06:05 - 2012-05-28 06:05 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143938691_s1_l1(1).exe
2012-05-27 16:52 - 2012-05-27 16:52 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143943849_s1_l1.exe
2012-05-27 08:22 - 2012-05-27 08:22 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143938691_s1_l1.exe
2012-05-22 15:44 - 2012-05-22 15:44 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143427769_s1_l1(2).exe
2012-05-22 15:42 - 2012-05-22 15:42 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143427769_s1_l1.exe
2012-05-22 15:42 - 2012-05-22 15:42 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143427769_s1_l1(1).exe
2012-05-22 06:26 - 2012-05-22 06:26 - 00010240 ____A C:\Users\Joni\Documents\OSU checklist.wps
2012-05-22 06:26 - 2011-12-02 07:25 - 00000180 ____A C:\Users\Joni\AppData\Roaming\wklnhst.dat
2012-05-21 14:43 - 2012-05-21 14:43 - 00001848 ____A C:\Users\Public\Desktop\Play Clutter.lnk
2012-05-21 05:38 - 2012-05-21 05:38 - 00002052 ____A C:\Users\Public\Desktop\Play Clutter II - He Said She Said.lnk
2012-05-05 12:47 - 2012-05-05 12:47 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p141553254_s1_l1(1).exe
2012-05-05 12:46 - 2012-05-05 12:46 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p141553254_s1_l1.exe
2012-05-05 09:54 - 2012-05-05 09:54 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\house-of-1000-doors-palm-of-zoroaster-ce_s1_l1_gF7105T1L1_d1728737362.exe
2012-05-05 09:53 - 2012-05-05 09:53 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\house-of-1000-doors-palm-of-zoroaster-ce_s1_l1_gF7105T1L1_d1728736752.exe
2012-05-04 03:06 - 2012-06-19 12:33 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-19 12:33 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-19 12:33 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-19 12:34 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-19 12:33 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 15:49 - 2011-08-03 16:26 - 00001945 ____A C:\Windows\epplauncher.mif
2012-04-26 15:48 - 2011-08-03 16:25 - 00743538 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
ZeroAccess:
C:\Windows\Installer\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}
C:\Windows\Installer\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\L
ZeroAccess:
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\@
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\L
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 33%
Total physical RAM: 1918.49 MB
Available physical RAM: 1281.89 MB
Total Pagefile: 1918.49 MB
Available Pagefile: 1273.02 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (COMPAQ) (Fixed) (Total:288.27 GB) (Free:171.77 GB) NTFS
2 Drive e: (FACTORY_IMAGE) (Fixed) (Total:9.72 GB) (Free:1.46 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: () (Removable) (Total:7.45 GB) (Free:7.4 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.08 GB) (Free:0.07 GB) NTFS
6 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7633 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 288 GB 101 MB
Partition 3 Primary 9 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C COMPAQ NTFS Partition 288 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FACTORY_IMA NTFS Partition 9 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7633 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7633 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 02:08
======================= End Of Log ==========================
Search log:
Farbar Recovery Scan Tool Version: 20-07-2012 01
Ran by SYSTEM at 2012-07-24 17:17:30
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
FRST log:
Scan result of Farbar Recovery Scan Tool Version: 20-07-2012 01
Ran by SYSTEM at 24-07-2012 17:15:23
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe [95728 2009-09-16] (PC-Doctor, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [x]
HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-26] (Sony Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Joni\...\Run: [Google Update] "C:\Users\Joni\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-10-17] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 NVNET; C:\Windows\System32\DRIVERS\nvmf6264.sys [339744 2009-07-30] (NVIDIA Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-24 17:15 - 2012-07-24 17:15 - 00000000 ____D C:\FRST
2012-07-19 09:11 - 2012-07-24 17:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-19 09:11 - 2012-07-19 09:11 - 00000000 ____D C:\Users\Joni\AppData\Roaming\Malwarebytes
2012-07-19 09:11 - 2012-07-19 09:11 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-19 09:02 - 2012-07-19 12:30 - 00001238 ____A C:\Users\Joni\Desktop\FixExec.txt
2012-07-19 06:53 - 2012-07-24 17:03 - 00000000 ____D C:\Users\All Users\7812A1690008CB200009235DF875F002
2012-07-12 15:50 - 2012-07-12 15:50 - 00000000 ____D C:\Users\Joni\AppData\Roaming\Skunk Studios
2012-07-12 15:43 - 2012-07-12 15:43 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\grim-tales-the-wishes-collectors-edition_s1_l1_gF7284T1L1_d1800559122.exe
2012-07-11 23:17 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 23:16 - 2012-07-11 23:17 - 00265426 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-11 23:02 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 23:02 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 23:02 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 23:02 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 23:02 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 23:02 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 23:02 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 23:02 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 23:02 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 23:02 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 23:02 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 23:02 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 23:02 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 23:02 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 23:02 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 23:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 23:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 23:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 23:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 23:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 23:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 23:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 23:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 12:25 - 2012-07-11 12:25 - 09822920 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-11 00:55 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 00:55 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 00:55 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 00:55 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 00:55 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 00:55 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 00:55 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 00:55 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 00:55 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 00:55 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 00:55 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 00:55 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 00:55 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 00:55 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 00:55 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 00:55 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 00:55 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 00:55 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 00:55 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-05 03:44 - 2012-07-05 03:45 - 00318904 ____A (Microsoft Corporation) C:\Users\Joni\Downloads\wmpfirefoxplugin.exe
2012-07-01 17:19 - 2012-07-01 17:19 - 00002297 ____A C:\Users\Joni\Desktop\Slingo Mystery.lnk
2012-07-01 17:19 - 2012-07-01 17:19 - 00001212 ____A C:\Users\Joni\Desktop\Games of the Month.lnk
2012-07-01 17:19 - 2012-07-01 17:19 - 00000000 ____D C:\Users\Joni\AppData\Roaming\Oberon Media
2012-07-01 17:19 - 2012-07-01 17:19 - 00000000 ____D C:\Program Files (x86)\Oberon Media SIDR
2012-07-01 17:04 - 2012-07-19 04:33 - 00000266 ____A C:\Windows\Tasks\CandyUpdater.job
2012-07-01 17:04 - 2012-07-01 17:04 - 00000000 ____D C:\Users\Joni\AppData\Local\ArcadeCandy
2012-07-01 17:01 - 2012-07-01 17:01 - 01272776 ____A C:\Users\Joni\Downloads\ArcadeCandyGames(1).exe
2012-07-01 05:54 - 2012-07-01 05:54 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-30 14:33 - 2012-06-30 14:33 - 00002210 ____A C:\Users\Public\Desktop\Play Flux Family Secrets - The Book of Oracles.lnk
2012-06-30 14:33 - 2012-06-30 14:33 - 00001312 ____A C:\Users\Public\Desktop\More Great Games.lnk
2012-06-30 14:32 - 2012-06-30 14:33 - 00000000 ____D C:\Program Files (x86)\Flux Family Secrets - The Book of Oracles
2012-06-25 19:12 - 2012-06-25 20:33 - 00001780 ____A C:\Users\Joni\AppData\Roaming\result.db
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
============ 3 Months Modified Files ========================
2012-07-24 13:10 - 2011-08-03 17:47 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-24 13:10 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-24 13:10 - 2009-07-13 20:51 - 00039191 ____A C:\Windows\setupact.log
2012-07-24 13:05 - 2011-08-03 15:02 - 01061060 ____A C:\Windows\WindowsUpdate.log
2012-07-19 12:30 - 2012-07-19 09:02 - 00001238 ____A C:\Users\Joni\Desktop\FixExec.txt
2012-07-19 04:43 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-19 04:43 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-19 04:34 - 2012-06-09 16:00 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-19 04:34 - 2011-10-17 05:14 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3273348302-90664181-4027946035-1001Core.job
2012-07-19 04:34 - 2011-08-03 17:47 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-19 04:33 - 2012-07-01 17:04 - 00000266 ____A C:\Windows\Tasks\CandyUpdater.job
2012-07-19 04:33 - 2011-10-17 05:14 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3273348302-90664181-4027946035-1001UA.job
2012-07-12 15:43 - 2012-07-12 15:43 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\grim-tales-the-wishes-collectors-edition_s1_l1_gF7284T1L1_d1800559122.exe
2012-07-11 23:35 - 2011-08-11 05:00 - 00000328 ____A C:\Windows\Tasks\HPCeeScheduleForJoni.job
2012-07-11 23:35 - 2009-07-13 20:45 - 00329176 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 23:34 - 2009-11-25 12:10 - 00186056 ____A C:\Windows\PFRO.log
2012-07-11 23:17 - 2012-07-11 23:16 - 00265426 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-11 23:03 - 2011-08-03 15:41 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 12:25 - 2012-07-11 12:25 - 09822920 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-11 12:25 - 2012-06-09 16:00 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 12:25 - 2011-08-03 16:36 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 11:08 - 2011-10-17 05:15 - 00002397 ____A C:\Users\Joni\Desktop\Google Chrome.lnk
2012-07-08 09:52 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-05 03:45 - 2012-07-05 03:44 - 00318904 ____A (Microsoft Corporation) C:\Users\Joni\Downloads\wmpfirefoxplugin.exe
2012-07-01 17:19 - 2012-07-01 17:19 - 00002297 ____A C:\Users\Joni\Desktop\Slingo Mystery.lnk
2012-07-01 17:19 - 2012-07-01 17:19 - 00001212 ____A C:\Users\Joni\Desktop\Games of the Month.lnk
2012-07-01 17:01 - 2012-07-01 17:01 - 01272776 ____A C:\Users\Joni\Downloads\ArcadeCandyGames(1).exe
2012-06-30 14:33 - 2012-06-30 14:33 - 00002210 ____A C:\Users\Public\Desktop\Play Flux Family Secrets - The Book of Oracles.lnk
2012-06-30 14:33 - 2012-06-30 14:33 - 00001312 ____A C:\Users\Public\Desktop\More Great Games.lnk
2012-06-30 06:25 - 2011-08-03 15:09 - 00000544 ____A C:\Windows\Tasks\PCDRScheduledMaintenance.job
2012-06-25 20:33 - 2012-06-25 19:12 - 00001780 ____A C:\Users\Joni\AppData\Roaming\result.db
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
2012-06-19 16:27 - 2012-06-19 16:27 - 00002135 ____A C:\Users\Public\Desktop\Play Dark Strokes - Sins of the Fathers.lnk
2012-06-19 16:25 - 2012-06-19 16:25 - 00002232 ____A C:\Users\Public\Desktop\Play Nightmares from the Deep - The Cursed Heart.lnk
2012-06-19 15:48 - 2012-06-19 15:48 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p146088874_s1_l1.exe
2012-06-11 19:08 - 2012-07-11 23:17 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 13:18 - 2012-06-10 13:18 - 00002361 ____A C:\Users\Public\Desktop\Play Final Cut - Death on the Silver Screen Collector's Edition.lnk
2012-06-09 17:24 - 2012-06-09 17:24 - 01307080 ____A C:\Users\Joni\Downloads\ArcadeCandyGames.exe
2012-06-08 21:43 - 2012-07-11 00:55 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 00:55 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-06 09:42 - 2012-06-06 09:42 - 00988888 ____A (Solid State Networks) C:\Users\Joni\Downloads\install_flashplayer11x64_mssa_aih.exe
2012-06-05 22:06 - 2012-07-11 00:55 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 00:55 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 00:55 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 00:55 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 00:55 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 00:55 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:47 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 05:46 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 05:46 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 05:47 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 05:46 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 05:46 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-21 05:46 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 23:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 23:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 23:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 23:02 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:04 - 2012-07-11 23:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:04 - 2012-07-11 23:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:03 - 2012-07-11 23:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 23:02 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 23:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 23:02 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 23:02 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 23:02 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 23:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 23:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 23:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 23:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 23:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:25 - 2012-07-11 23:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:23 - 2012-07-11 23:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 23:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 23:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 23:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 23:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 23:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 23:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 00:55 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 00:55 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 00:55 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 00:55 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 00:55 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 00:55 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 00:55 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 00:55 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 00:55 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 09:56 - 2012-06-01 09:56 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p144501816_s1_l1.exe
2012-05-30 05:18 - 2012-05-30 05:18 - 00002186 ____A C:\Users\Public\Desktop\Play Spirit Walkers - Curse of the Cypress Witch.lnk
2012-05-28 06:06 - 2012-05-28 06:06 - 00001945 ____A C:\Users\Public\Desktop\Play Slingo Supreme 2.lnk
2012-05-28 06:05 - 2012-05-28 06:05 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143938691_s1_l1(1).exe
2012-05-27 16:52 - 2012-05-27 16:52 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143943849_s1_l1.exe
2012-05-27 08:22 - 2012-05-27 08:22 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143938691_s1_l1.exe
2012-05-22 15:44 - 2012-05-22 15:44 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143427769_s1_l1(2).exe
2012-05-22 15:42 - 2012-05-22 15:42 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143427769_s1_l1.exe
2012-05-22 15:42 - 2012-05-22 15:42 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p143427769_s1_l1(1).exe
2012-05-22 06:26 - 2012-05-22 06:26 - 00010240 ____A C:\Users\Joni\Documents\OSU checklist.wps
2012-05-22 06:26 - 2011-12-02 07:25 - 00000180 ____A C:\Users\Joni\AppData\Roaming\wklnhst.dat
2012-05-21 14:43 - 2012-05-21 14:43 - 00001848 ____A C:\Users\Public\Desktop\Play Clutter.lnk
2012-05-21 05:38 - 2012-05-21 05:38 - 00002052 ____A C:\Users\Public\Desktop\Play Clutter II - He Said She Said.lnk
2012-05-05 12:47 - 2012-05-05 12:47 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p141553254_s1_l1(1).exe
2012-05-05 12:46 - 2012-05-05 12:46 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\bigfishgames_p141553254_s1_l1.exe
2012-05-05 09:54 - 2012-05-05 09:54 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\house-of-1000-doors-palm-of-zoroaster-ce_s1_l1_gF7105T1L1_d1728737362.exe
2012-05-05 09:53 - 2012-05-05 09:53 - 00212224 ____A (Big Fish Games) C:\Users\Joni\Downloads\house-of-1000-doors-palm-of-zoroaster-ce_s1_l1_gF7105T1L1_d1728736752.exe
2012-05-04 03:06 - 2012-06-19 12:33 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-19 12:33 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-19 12:33 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-19 12:34 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-19 12:33 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 15:49 - 2011-08-03 16:26 - 00001945 ____A C:\Windows\epplauncher.mif
2012-04-26 15:48 - 2011-08-03 16:25 - 00743538 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
ZeroAccess:
C:\Windows\Installer\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}
C:\Windows\Installer\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\L
ZeroAccess:
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\@
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\L
C:\Users\Joni\AppData\Local\{ecaef146-6f03-bb2d-ffdf-c21cbfcc103e}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 33%
Total physical RAM: 1918.49 MB
Available physical RAM: 1281.89 MB
Total Pagefile: 1918.49 MB
Available Pagefile: 1273.02 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (COMPAQ) (Fixed) (Total:288.27 GB) (Free:171.77 GB) NTFS
2 Drive e: (FACTORY_IMAGE) (Fixed) (Total:9.72 GB) (Free:1.46 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: () (Removable) (Total:7.45 GB) (Free:7.4 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.08 GB) (Free:0.07 GB) NTFS
6 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7633 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 288 GB 101 MB
Partition 3 Primary 9 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C COMPAQ NTFS Partition 288 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FACTORY_IMA NTFS Partition 9 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7633 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7633 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 02:08
======================= End Of Log ==========================
Search log:
Farbar Recovery Scan Tool Version: 20-07-2012 01
Ran by SYSTEM at 2012-07-24 17:17:30
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======