N9ZN-Extra
Posts: 26 +0
I am running Windows 7 32 bit. I had MS firewall and security essentials active but this trojan got through anyway. The only thing I have done was a re-install of MS Security Essentials since the copy I had was missing services.
I look forward to getting this fixed so I can recover a few things and re-image the drive afterward. Here is the Log file from FarBar...
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-08-2012
Ran by SYSTEM at 10-08-2012 05:24:58
Running from F:\FarBar recovery tool
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [Bing Bar] "C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\mswinext.exe" [273672 2010-10-11] (Microsoft Corp.)
HKLM\...\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [1573448 2010-02-18] (Logitech Inc.)
HKLM\...\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE [3203144 2010-02-18] (Logitech Inc.)
HKLM\...\Run: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" [357448 2010-02-18] (Logitech Inc.)
HKLM\...\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [439568 2010-05-10] (Microsoft Corporation)
HKLM\...\Run: [ProfilerU] "C:\Program Files\Saitek\SD6\Software\ProfilerU.exe" [237568 2009-06-03] (Saitek)
HKLM\...\Run: [SaiMfd] "C:\Program Files\Saitek\SD6\Software\SaiMfd.exe" [131072 2009-06-03] (Saitek)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM\...\Run: [NVRaidService] C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe [163944 2010-04-08] (NVIDIA Corporation)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [10820200 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe" [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [BingDesktop] C:\Program Files\Microsoft\BingDesktop\BingDesktop.exe /fromkey [1858152 2012-03-30] (Microsoft Corp.)
HKLM\...\Run: [Logitech Utility] Logi_MwX.Exe [x]
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Administrator\...\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-08] (Samsung Electronics Co., Ltd.)
HKU\Administrator\...\Run: [Facebook Update] "C:\Users\EternalKharas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKU\EternalKharas\...\Run: [Epson Stylus NX420(Network)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCA.EXE /FU "C:\Users\ETERNA~1\AppData\Local\Temp\E_SE9F6.tmp" /EF "HKCU" [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\EternalKharas\...\Run: [Facebook Update] "C:\Users\EternalKharas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKU\EternalKharas\...\Run: [hysoxqihotur] C:\Users\EternalKharas\hysoxqihotur.exe [93648 2012-08-09] (AOpen)
HKU\Guest\...\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-08] (Samsung Electronics Co., Ltd.)
HKU\Guest\...\Run: [Facebook Update] "C:\Users\EternalKharas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
Tcpip\Parameters: [DhcpNameServer] 65.32.5.111 65.32.5.112
Startup: C:\Users\EternalKharas\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
================================ Services (Whitelisted) ==================
2 BingDesktopUpdate; "C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe" [151656 2012-03-30] (Microsoft Corp.)
3 CHWBOLOCH; C:\Users\ETERNA~1\AppData\Local\Temp\CHWBOLOCH.exe [490368 2012-06-27] (Sysinternals - www.sysinternals.com)
3 CPETLYED; C:\Users\ETERNA~1\AppData\Local\Temp\CPETLYED.exe [506752 2012-06-27] (Sysinternals - www.sysinternals.com)
2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-08-10] ()
3 Futuremark SystemInfo Service; "C:\Program Files\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe" [128928 2010-11-11] (Futuremark Corporation)
2 iReboot; "C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exe" [9216 2008-04-27] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
2 nHancer; "C:\Program Files\nHancer\nHancerService.exe" [39936 2010-05-02] (KSE - Korndörfer Software Engineering)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-08-10] ()
2 nTuneService; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe /StartService [191080 2010-03-22] (NVIDIA)
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [167936 2007-01-20] ()
2 StatusAgent4; C:\Windows\system32\SAgent4.exe [131072 2006-12-19] (SEIKO EPSON CORPORATION)
2 UpdateCenterService; C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe /StartService [195176 2009-11-06] (NVIDIA)
========================== Drivers (Whitelisted) =============
2 cpuz134; \??\C:\Windows\system32\drivers\cpuz134_x32.sys [20328 2010-07-09] (Windows (R) Win 7 DDK provider)
3 DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [23456 2010-07-12] (Phoenix Technologies)
3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-07-05] ()
1 HWiNFO32; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS [21624 2012-05-10] (REALiX(tm))
3 LHidFlt2; C:\Windows\System32\DRIVERS\LHidFlt2.Sys [25505 2003-12-17] (Logitech, Inc.)
3 LHidUsb; C:\Windows\System32\Drivers\LHidUsb.Sys [37887 2003-12-17] (Logitech, Inc.)
3 LMouFlt2; C:\Windows\System32\DRIVERS\LMouFlt2.Sys [70801 2003-12-17] (Logitech, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 NVNET; C:\Windows\System32\DRIVERS\nvmf6232.sys [295272 2009-11-11] (NVIDIA Corporation)
3 nvoclock; C:\Windows\System32\DRIVERS\nvoclock.sys [38248 2009-09-15] (NVIDIA Corp.)
3 physX32; C:\Windows\System32\DRIVERS\physX32.sys [120960 2008-02-29] (AGEIA Technologies, Inc.)
3 RTCore32; \??\C:\Program Files\EVGA Precision\RTCore32.sys [4608 2005-05-25] ()
3 SaiH075C; C:\Windows\System32\DRIVERS\SaiH075C.sys [132232 2007-05-01] (Saitek)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2012-05-10] (Duplex Secure Ltd.)
3 GPU-Z; \??\C:\Users\ETERNA~1\AppData\Local\Temp\GPU-Z.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-10 05:24 - 2012-08-10 05:24 - 00000000 ____D C:\FRST
2012-08-09 22:51 - 2012-08-09 22:51 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-09 22:09 - 2012-08-09 22:09 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-09 22:05 - 2012-08-09 22:05 - 00093648 ____A (AOpen) C:\Users\EternalKharas\hysoxqihotur.exe
2012-08-08 08:24 - 2012-08-08 08:24 - 00155840 ____A C:\Windows\Minidump\080812-25911-01.dmp
2012-08-07 09:02 - 2012-08-07 09:02 - 00111487 ____A C:\Users\EternalKharas\Documents\bank transfer 080712(2).xps
2012-08-07 05:49 - 2012-08-07 05:49 - 00000124 ____A C:\Users\EternalKharas\Desktop\HOME PAGE.txt
2012-08-07 04:07 - 2012-08-07 04:07 - 00111173 ____A C:\Users\EternalKharas\Documents\bank transfer 080712.xps
2012-08-03 07:29 - 2012-08-03 07:29 - 00196947 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage E-mailconfirmnation080312.xps
2012-08-03 07:00 - 2012-08-03 07:00 - 00159584 ____A C:\Users\EternalKharas\Documents\BrightHouse080312.xps
2012-08-03 05:54 - 2012-08-03 05:54 - 00111378 ____A C:\Users\EternalKharas\Documents\bank transfer 080312.xps
2012-08-03 04:56 - 2012-08-03 04:56 - 00117132 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage080312.xps
2012-08-03 03:50 - 2012-08-03 03:50 - 00000318 ____A C:\Users\EternalKharas\Desktop\Curse Client.appref-ms
2012-08-02 13:14 - 2012-08-02 13:14 - 00110956 ____A C:\Users\EternalKharas\Documents\bank transfer 080212.xps
2012-07-31 21:32 - 2012-07-31 21:32 - 00000097 ____A C:\Users\EternalKharas\Desktop\sephora.txt
2012-07-30 15:48 - 2012-07-30 15:49 - 00159552 ____A C:\Windows\Minidump\073012-34491-01.dmp
2012-07-30 14:38 - 2012-07-30 14:38 - 00161846 ____A C:\Users\EternalKharas\Documents\THIAGO2.xps
2012-07-30 14:10 - 2012-07-30 14:10 - 00111119 ____A C:\Users\EternalKharas\Documents\bank transfer 073012.xps
2012-07-29 00:43 - 2012-07-29 00:43 - 00111225 ____A C:\Users\EternalKharas\Documents\bank transfer 072912.xps
2012-07-28 05:56 - 2012-07-28 07:26 - 00000000 ____D C:\Users\EternalKharas\Documents\Business donations
2012-07-27 21:14 - 2012-07-27 21:14 - 00111373 ____A C:\Users\EternalKharas\Documents\bank transfer 072812.xps
2012-07-27 17:03 - 2012-07-27 17:03 - 00000000 ____D C:\Users\All Users\SolarWinds
2012-07-27 17:03 - 2012-07-27 17:03 - 00000000 ____D C:\Program Files\SolarWinds
2012-07-27 17:02 - 2012-07-27 17:02 - 00922042 ____A C:\Users\EternalKharas\Downloads\SolarWinds-Permissions-Analyzer-v1.0.0.zip
2012-07-27 17:02 - 2012-07-27 17:02 - 00000000 ____D C:\Users\EternalKharas\Downloads\SolarWinds-Permissions-Analyzer-v1.0.0
2012-07-24 02:17 - 2012-07-24 02:17 - 00001794 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(11).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00106888 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(10).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00102602 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(9).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00165939 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(6).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00138056 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(8).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00134007 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(7).htm
2012-07-24 02:14 - 2012-07-24 02:14 - 00104885 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(5).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00072213 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(9).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00056712 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(10).htm
2012-07-24 02:12 - 2012-07-24 02:12 - 00095829 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(8).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00115579 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(7).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00113343 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(6).htm
2012-07-24 02:10 - 2012-07-24 02:10 - 00155229 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(5).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00190068 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(3).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00181032 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(4).htm
2012-07-24 01:56 - 2012-07-24 01:56 - 00081496 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(4).htm
2012-07-24 01:55 - 2012-07-24 01:55 - 00070096 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(3).htm
2012-07-24 01:54 - 2012-07-24 01:54 - 00116002 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(2).htm
2012-07-24 01:53 - 2012-07-24 01:53 - 00115839 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24.htm
2012-07-23 21:15 - 2012-08-01 22:16 - 00008655 ____A C:\Users\EternalKharas\Desktop\Christina.txt
2012-07-23 15:04 - 2012-07-23 15:04 - 00246295 ____A C:\Users\EternalKharas\Documents\Thiago's order 1.xps
2012-07-23 13:12 - 2012-07-23 13:12 - 00111120 ____A C:\Users\EternalKharas\Documents\bank transfer THIAGO 1.xps
2012-07-21 10:29 - 2012-07-21 10:29 - 00000000 ____D C:\Users\EternalKharas\Downloads\the_whigs
2012-07-21 09:01 - 2012-07-21 10:29 - 07251231 ____A C:\Users\EternalKharas\Downloads\the_whigs.zip
2012-07-20 22:27 - 2012-07-21 02:13 - 00002961 ____A C:\Users\EternalKharas\Desktop\Stacy.txt
2012-07-19 05:23 - 2012-07-19 05:24 - 00000000 ____D C:\Program Files\HWiNFO32
2012-07-18 18:16 - 2012-07-18 18:16 - 00000000 __SHD C:\found.001
2012-07-16 23:24 - 2012-07-16 23:24 - 00000524 ____A C:\Users\EternalKharas\Desktop\Turn off Media Center Updates.htm
2012-07-16 06:13 - 2012-07-16 06:13 - 00111145 ____A C:\Users\EternalKharas\Documents\bank transfer 071612.xps
2012-07-15 23:12 - 2012-08-09 14:29 - 00000345 ____A C:\Users\EternalKharas\Desktop\MUSIC CODES (MARLBORO).txt
2012-07-14 22:49 - 2012-07-14 22:49 - 00136219 ____A C:\Users\EternalKharas\Documents\newegg071512.xps
2012-07-13 10:43 - 2012-07-13 10:43 - 00111413 ____A C:\Users\EternalKharas\Documents\bank transfer 071312.xps
2012-07-12 19:28 - 2012-07-12 19:28 - 00110872 ____A C:\Users\EternalKharas\Documents\bank transfer 071212.xps
2012-07-12 00:15 - 2012-07-12 00:15 - 00159400 ____A C:\Users\EternalKharas\Documents\BrightHouse071212.xps
2012-07-11 01:42 - 2012-07-11 01:42 - 00153512 ____A C:\Windows\Minidump\071112-36660-01.dmp
============ 3 Months Modified Files ========================
2012-08-09 23:19 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 23:18 - 2010-12-31 18:50 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-09 23:18 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 23:18 - 2009-07-13 20:39 - 00876280 ____A C:\Windows\setupact.log
2012-08-09 23:10 - 2012-06-19 07:37 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 23:03 - 2010-05-04 16:08 - 00148150 ____A C:\Windows\PFRO.log
2012-08-09 22:52 - 2011-06-29 04:33 - 01400340 ____A C:\Windows\WindowsUpdate.log
2012-08-09 22:52 - 2011-01-27 01:11 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 22:51 - 2011-06-29 03:46 - 00838082 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 22:41 - 2010-05-04 16:01 - 00019920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 22:41 - 2010-05-04 16:01 - 00019920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 22:40 - 2011-08-28 16:30 - 00000960 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1850465905-1816852967-2060930716-1000UA.job
2012-08-09 22:05 - 2012-08-09 22:05 - 00093648 ____A (AOpen) C:\Users\EternalKharas\hysoxqihotur.exe
2012-08-09 21:59 - 2010-12-31 18:50 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-09 15:00 - 2012-05-04 13:03 - 00002290 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-09 14:29 - 2012-07-15 23:12 - 00000345 ____A C:\Users\EternalKharas\Desktop\MUSIC CODES (MARLBORO).txt
2012-08-09 04:21 - 2012-07-09 02:48 - 00009549 ____A C:\Users\EternalKharas\Desktop\crash.txt
2012-08-09 03:34 - 2011-08-28 16:30 - 00000938 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1850465905-1816852967-2060930716-1000Core.job
2012-08-08 08:24 - 2012-08-08 08:24 - 00155840 ____A C:\Windows\Minidump\080812-25911-01.dmp
2012-08-07 09:02 - 2012-08-07 09:02 - 00111487 ____A C:\Users\EternalKharas\Documents\bank transfer 080712(2).xps
2012-08-07 05:49 - 2012-08-07 05:49 - 00000124 ____A C:\Users\EternalKharas\Desktop\HOME PAGE.txt
2012-08-07 04:07 - 2012-08-07 04:07 - 00111173 ____A C:\Users\EternalKharas\Documents\bank transfer 080712.xps
2012-08-03 07:29 - 2012-08-03 07:29 - 00196947 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage E-mailconfirmnation080312.xps
2012-08-03 07:00 - 2012-08-03 07:00 - 00159584 ____A C:\Users\EternalKharas\Documents\BrightHouse080312.xps
2012-08-03 05:54 - 2012-08-03 05:54 - 00111378 ____A C:\Users\EternalKharas\Documents\bank transfer 080312.xps
2012-08-03 04:56 - 2012-08-03 04:56 - 00117132 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage080312.xps
2012-08-03 03:50 - 2012-08-03 03:50 - 00000318 ____A C:\Users\EternalKharas\Desktop\Curse Client.appref-ms
2012-08-02 13:14 - 2012-08-02 13:14 - 00110956 ____A C:\Users\EternalKharas\Documents\bank transfer 080212.xps
2012-08-02 08:56 - 2012-04-03 20:42 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 08:56 - 2011-05-19 12:08 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-01 22:16 - 2012-07-23 21:15 - 00008655 ____A C:\Users\EternalKharas\Desktop\Christina.txt
2012-07-31 21:32 - 2012-07-31 21:32 - 00000097 ____A C:\Users\EternalKharas\Desktop\sephora.txt
2012-07-30 15:49 - 2012-07-30 15:48 - 00159552 ____A C:\Windows\Minidump\073012-34491-01.dmp
2012-07-30 14:38 - 2012-07-30 14:38 - 00161846 ____A C:\Users\EternalKharas\Documents\THIAGO2.xps
2012-07-30 14:10 - 2012-07-30 14:10 - 00111119 ____A C:\Users\EternalKharas\Documents\bank transfer 073012.xps
2012-07-29 00:43 - 2012-07-29 00:43 - 00111225 ____A C:\Users\EternalKharas\Documents\bank transfer 072912.xps
2012-07-27 21:14 - 2012-07-27 21:14 - 00111373 ____A C:\Users\EternalKharas\Documents\bank transfer 072812.xps
2012-07-27 17:02 - 2012-07-27 17:02 - 00922042 ____A C:\Users\EternalKharas\Downloads\SolarWinds-Permissions-Analyzer-v1.0.0.zip
2012-07-27 04:46 - 2011-07-01 22:55 - 00007676 ____A C:\Users\EternalKharas\AppData\Local\Resmon.ResmonCfg
2012-07-24 02:17 - 2012-07-24 02:17 - 00001794 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(11).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00106888 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(10).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00102602 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(9).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00165939 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(6).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00138056 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(8).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00134007 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(7).htm
2012-07-24 02:14 - 2012-07-24 02:14 - 00104885 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(5).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00072213 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(9).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00056712 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(10).htm
2012-07-24 02:12 - 2012-07-24 02:12 - 00095829 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(8).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00115579 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(7).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00113343 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(6).htm
2012-07-24 02:10 - 2012-07-24 02:10 - 00155229 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(5).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00190068 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(3).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00181032 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(4).htm
2012-07-24 01:56 - 2012-07-24 01:56 - 00081496 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(4).htm
2012-07-24 01:55 - 2012-07-24 01:55 - 00070096 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(3).htm
2012-07-24 01:54 - 2012-07-24 01:54 - 00116002 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(2).htm
2012-07-24 01:53 - 2012-07-24 01:53 - 00115839 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24.htm
2012-07-23 15:04 - 2012-07-23 15:04 - 00246295 ____A C:\Users\EternalKharas\Documents\Thiago's order 1.xps
2012-07-23 13:12 - 2012-07-23 13:12 - 00111120 ____A C:\Users\EternalKharas\Documents\bank transfer THIAGO 1.xps
2012-07-21 10:29 - 2012-07-21 09:01 - 07251231 ____A C:\Users\EternalKharas\Downloads\the_whigs.zip
2012-07-21 02:13 - 2012-07-20 22:27 - 00002961 ____A C:\Users\EternalKharas\Desktop\Stacy.txt
2012-07-16 23:24 - 2012-07-16 23:24 - 00000524 ____A C:\Users\EternalKharas\Desktop\Turn off Media Center Updates.htm
2012-07-16 06:13 - 2012-07-16 06:13 - 00111145 ____A C:\Users\EternalKharas\Documents\bank transfer 071612.xps
2012-07-14 22:49 - 2012-07-14 22:49 - 00136219 ____A C:\Users\EternalKharas\Documents\newegg071512.xps
2012-07-13 10:43 - 2012-07-13 10:43 - 00111413 ____A C:\Users\EternalKharas\Documents\bank transfer 071312.xps
2012-07-12 19:28 - 2012-07-12 19:28 - 00110872 ____A C:\Users\EternalKharas\Documents\bank transfer 071212.xps
2012-07-12 00:15 - 2012-07-12 00:15 - 00159400 ____A C:\Users\EternalKharas\Documents\BrightHouse071212.xps
2012-07-11 01:42 - 2012-07-11 01:42 - 00153512 ____A C:\Windows\Minidump\071112-36660-01.dmp
2012-07-10 23:39 - 2009-07-13 20:33 - 00415344 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 23:01 - 2011-07-14 03:03 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-10 18:58 - 2012-07-10 18:58 - 00014336 ____A C:\Users\EternalKharas\Desktop\PAST and PRESENT.xls
2012-07-09 19:41 - 2010-06-11 02:33 - 00001220 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-09 08:08 - 2012-07-09 08:08 - 00111187 ____A C:\Users\EternalKharas\Documents\bank transfer 070912.xps
2012-07-08 17:25 - 2012-07-08 17:25 - 00224817 ____A C:\Users\EternalKharas\Desktop\Bubble.xps
2012-07-06 23:51 - 2012-07-06 23:51 - 00110723 ____A C:\Users\EternalKharas\Documents\bank transfer 070712.xps
2012-07-06 13:08 - 2012-07-06 12:46 - 00000724 ____A C:\Users\EternalKharas\Desktop\bigmyke.txt
2012-07-02 03:22 - 2012-07-02 03:22 - 00135354 ____A C:\Users\EternalKharas\Desktop\NeweggOrder.xps
2012-07-02 01:20 - 2012-07-02 01:20 - 00001226 ____A C:\Users\EternalKharas\Desktop\Revo Uninstaller.lnk
2012-07-01 09:04 - 2012-07-01 09:04 - 00110732 ____A C:\Users\EternalKharas\Documents\bank transfer 070112.xps
2012-06-29 23:05 - 2012-06-29 23:05 - 00020622 ____A C:\Users\EternalKharas\Documents\Backup of GTX480.wbk
2012-06-29 22:47 - 2012-06-27 08:38 - 00003940 ____A C:\Users\EternalKharas\Documents\GTX480.txt
2012-06-27 20:53 - 2012-06-27 08:57 - 00000193 ____A C:\Users\EternalKharas\Documents\GTX.txt
2012-06-26 12:33 - 2012-06-26 12:33 - 01058784 ____A (techPowerUp (www.techpowerup.com)) C:\Users\EternalKharas\Downloads\GPU-Z.0.6.2 (2).exe
2012-06-26 12:30 - 2012-06-26 12:30 - 01058784 ____A (techPowerUp (www.techpowerup.com)) C:\Users\EternalKharas\Downloads\GPU-Z.0.6.2.exe
2012-06-26 12:30 - 2012-06-26 12:30 - 01058784 ____A (techPowerUp (www.techpowerup.com)) C:\Users\EternalKharas\Downloads\GPU-Z.0.6.2 (1).exe
2012-06-25 12:19 - 2012-05-06 23:24 - 00209920 __ASH C:\Users\EternalKharas\Documents\Thumbs.db
2012-06-25 12:14 - 2012-06-25 12:03 - 00001766 ____A C:\Users\EternalKharas\Desktop\LCD Calculator v2.Vbs
2012-06-25 07:54 - 2012-06-25 07:54 - 00111388 ____A C:\Users\EternalKharas\Documents\bank transfer 062512.xps
2012-06-22 18:31 - 2012-06-22 18:30 - 00151229 ____A C:\Users\EternalKharas\Documents\WOW CARD 062212.xps
2012-06-22 03:11 - 2012-06-22 03:11 - 00000274 ____A C:\Users\EternalKharas\Downloads\Performance_PC's_Newsletter (1).vcf
2012-06-22 03:09 - 2012-06-22 03:09 - 00000274 ____A C:\Users\EternalKharas\Downloads\Performance_PC's_Newsletter.vcf
2012-06-21 23:35 - 2012-06-21 23:35 - 00187801 ____A C:\Users\EternalKharas\Documents\metropcs payment 062212.xps
2012-06-19 06:41 - 2012-06-19 06:41 - 00111381 ____A C:\Users\EternalKharas\Documents\bank transfer 061912.xps
2012-06-19 03:06 - 2012-06-19 03:06 - 00158616 ____A C:\Windows\Minidump\061912-24164-01.dmp
2012-06-19 01:30 - 2012-06-19 01:30 - 00000875 ____A C:\Users\Public\Desktop\Steam.lnk
2012-06-17 01:10 - 2012-06-17 01:10 - 00130488 ____A C:\Users\EternalKharas\Documents\Toshiba repair disk.xps
2012-06-16 06:46 - 2012-06-16 06:46 - 00111031 ____A C:\Users\EternalKharas\Documents\bank transfer 061612.xps
2012-06-11 18:40 - 2012-07-10 23:01 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 06:48 - 2012-06-11 06:48 - 00110917 ____A C:\Users\EternalKharas\Documents\bank transfer 061112.xps
2012-06-09 13:10 - 2012-06-09 13:10 - 00111512 ____A C:\Users\EternalKharas\Documents\bank transfer 060912(2).xps
2012-06-09 12:58 - 2012-06-09 12:58 - 00111496 ____A C:\Users\EternalKharas\Documents\bank transfer 060912.xps
2012-06-08 20:41 - 2012-07-10 15:01 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 18:47 - 2012-06-08 18:47 - 00111386 ____A C:\Users\EternalKharas\Documents\bank transfer 060812.xps
2012-06-08 11:23 - 2012-06-08 11:23 - 00001219 ___AH C:\Windows\System32\config\Journal - Shortcut.lnk
2012-06-08 11:23 - 2012-06-08 11:23 - 00000914 ___AH C:\Windows\System32\config\userdiff - Shortcut.lnk
2012-06-08 11:23 - 2012-06-08 11:23 - 00000914 ___AH C:\Windows\System32\config\software - Shortcut.lnk
2012-06-08 11:23 - 2012-06-08 11:23 - 00000902 ___AH C:\Windows\System32\config\system - Shortcut.lnk
2012-06-08 09:42 - 2012-06-08 09:25 - 1060726784 ____A C:\Users\EternalKharas\Desktop\jonathan.iso
2012-06-05 21:05 - 2012-07-10 15:01 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 15:01 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 15:01 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-04 04:29 - 2012-06-04 04:29 - 00111204 ____A C:\Users\EternalKharas\Documents\bank transfer 060412.xps
2012-06-02 14:19 - 2012-06-20 17:46 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 17:46 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 17:46 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 17:46 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 17:46 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 17:46 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 17:46 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-20 17:45 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-20 17:45 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-10 23:04 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-10 23:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-10 23:04 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-10 23:04 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-10 23:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 23:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-10 23:04 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-10 23:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 23:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 23:04 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-10 23:04 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-10 23:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 23:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 23:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 22:13 - 2012-06-01 22:13 - 00001036 ____A C:\Users\EternalKharas\Desktop\EVGA Precision.lnk
2012-06-01 20:45 - 2012-07-10 15:01 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 15:01 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 15:01 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 15:01 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 15:01 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-31 20:13 - 2012-03-22 19:27 - 00001050 ____A C:\Users\EternalKharas\Desktop\EVGA Precision X.lnk
2012-05-31 19:54 - 2012-05-31 19:54 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2012-05-25 09:38 - 2012-05-25 09:38 - 00001108 ____A C:\Users\EternalKharas\Documents\sally ansell (2).txt
2012-05-24 19:01 - 2012-05-24 19:01 - 00001362 ____A C:\Users\EternalKharas\Documents\sallyansel(2).txt
2012-05-24 13:38 - 2012-05-24 13:38 - 00187937 ____A C:\Users\EternalKharas\Documents\metropcs payment 052412.xps
2012-05-23 05:55 - 2012-05-23 05:55 - 00002885 ____A C:\Users\EternalKharas\Documents\sallyansel.txt
2012-05-23 01:35 - 2012-05-23 01:35 - 00111345 ____A C:\Users\EternalKharas\Documents\bank transfer 052312.xps
2012-05-22 17:30 - 2012-05-22 17:30 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\System32\rmoc3260.dll
2012-05-22 17:30 - 2012-05-22 17:30 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5016.dll
2012-05-22 17:30 - 2012-05-22 17:30 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5032.dll
2012-05-22 17:30 - 2012-05-22 17:30 - 00001016 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-05-22 17:29 - 2012-05-22 17:29 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\msvcp71.dll
2012-05-22 17:29 - 2012-05-22 17:29 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\msvcr71.dll
2012-05-22 17:29 - 2012-05-22 17:29 - 00272896 ____A (Progressive Networks) C:\Windows\System32\pncrt.dll
2012-05-21 19:30 - 2012-05-21 19:30 - 00002170 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-05-21 18:18 - 2012-05-21 18:18 - 00001815 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-21 10:28 - 2012-05-21 10:28 - 03896832 ____A C:\Users\EternalKharas\Downloads\ARGALIWYSETUP.EXE
2012-05-18 23:44 - 2012-05-18 23:44 - 00111124 ____A C:\Users\EternalKharas\Documents\bank transfer 051912.xps
2012-05-14 22:21 - 2012-05-14 22:21 - 00423744 ____A C:\Windows\System32\nvStreaming.exe
2012-05-13 23:08 - 2011-06-29 09:18 - 00000927 ____A C:\Users\Guest\Desktop\MagicDisc.lnk
2012-05-13 23:08 - 2011-06-29 09:18 - 00000927 ____A C:\Users\EternalKharas\Desktop\MagicDisc.lnk
2012-05-13 23:08 - 2011-06-29 09:18 - 00000927 ____A C:\Users\Administrator\Desktop\MagicDisc.lnk
2012-05-13 22:54 - 2012-05-13 22:54 - 00001773 ____A C:\Users\Guest\Desktop\MagicISO.lnk
2012-05-13 22:54 - 2012-05-13 22:54 - 00001773 ____A C:\Users\EternalKharas\Desktop\MagicISO.lnk
2012-05-13 22:54 - 2012-05-13 22:54 - 00001773 ____A C:\Users\Administrator\Desktop\MagicISO.lnk
ZeroAccess:
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\@
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\L
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\n
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\U
ZeroAccess:
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\@
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\L
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\n
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 8190.54 MB
Available physical RAM: 7607.41 MB
Total Pagefile: 8188.82 MB
Available Pagefile: 7630.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:148.96 GB) (Free:4.57 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (GRMCULFRER_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
4 Drive f: (USB MEMORY) (Removable) (Total:0.12 GB) (Free:0.08 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 123 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 31 KB
Partition 2 Primary 148 GB 48 MB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 148 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 122 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F USB MEMORY FAT Removable 122 MB Healthy
==================================================================================
Last Boot: 2012-08-07 08:07
======================= End Of Log ==========================
I look forward to getting this fixed so I can recover a few things and re-image the drive afterward. Here is the Log file from FarBar...
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-08-2012
Ran by SYSTEM at 10-08-2012 05:24:58
Running from F:\FarBar recovery tool
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [Bing Bar] "C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\mswinext.exe" [273672 2010-10-11] (Microsoft Corp.)
HKLM\...\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [1573448 2010-02-18] (Logitech Inc.)
HKLM\...\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE [3203144 2010-02-18] (Logitech Inc.)
HKLM\...\Run: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" [357448 2010-02-18] (Logitech Inc.)
HKLM\...\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [439568 2010-05-10] (Microsoft Corporation)
HKLM\...\Run: [ProfilerU] "C:\Program Files\Saitek\SD6\Software\ProfilerU.exe" [237568 2009-06-03] (Saitek)
HKLM\...\Run: [SaiMfd] "C:\Program Files\Saitek\SD6\Software\SaiMfd.exe" [131072 2009-06-03] (Saitek)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM\...\Run: [NVRaidService] C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe [163944 2010-04-08] (NVIDIA Corporation)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [10820200 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe" [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [BingDesktop] C:\Program Files\Microsoft\BingDesktop\BingDesktop.exe /fromkey [1858152 2012-03-30] (Microsoft Corp.)
HKLM\...\Run: [Logitech Utility] Logi_MwX.Exe [x]
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Administrator\...\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-08] (Samsung Electronics Co., Ltd.)
HKU\Administrator\...\Run: [Facebook Update] "C:\Users\EternalKharas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKU\EternalKharas\...\Run: [Epson Stylus NX420(Network)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCA.EXE /FU "C:\Users\ETERNA~1\AppData\Local\Temp\E_SE9F6.tmp" /EF "HKCU" [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\EternalKharas\...\Run: [Facebook Update] "C:\Users\EternalKharas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKU\EternalKharas\...\Run: [hysoxqihotur] C:\Users\EternalKharas\hysoxqihotur.exe [93648 2012-08-09] (AOpen)
HKU\Guest\...\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-08] (Samsung Electronics Co., Ltd.)
HKU\Guest\...\Run: [Facebook Update] "C:\Users\EternalKharas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
Tcpip\Parameters: [DhcpNameServer] 65.32.5.111 65.32.5.112
Startup: C:\Users\EternalKharas\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
================================ Services (Whitelisted) ==================
2 BingDesktopUpdate; "C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe" [151656 2012-03-30] (Microsoft Corp.)
3 CHWBOLOCH; C:\Users\ETERNA~1\AppData\Local\Temp\CHWBOLOCH.exe [490368 2012-06-27] (Sysinternals - www.sysinternals.com)
3 CPETLYED; C:\Users\ETERNA~1\AppData\Local\Temp\CPETLYED.exe [506752 2012-06-27] (Sysinternals - www.sysinternals.com)
2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-08-10] ()
3 Futuremark SystemInfo Service; "C:\Program Files\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe" [128928 2010-11-11] (Futuremark Corporation)
2 iReboot; "C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exe" [9216 2008-04-27] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
2 nHancer; "C:\Program Files\nHancer\nHancerService.exe" [39936 2010-05-02] (KSE - Korndörfer Software Engineering)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-08-10] ()
2 nTuneService; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe /StartService [191080 2010-03-22] (NVIDIA)
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [167936 2007-01-20] ()
2 StatusAgent4; C:\Windows\system32\SAgent4.exe [131072 2006-12-19] (SEIKO EPSON CORPORATION)
2 UpdateCenterService; C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe /StartService [195176 2009-11-06] (NVIDIA)
========================== Drivers (Whitelisted) =============
2 cpuz134; \??\C:\Windows\system32\drivers\cpuz134_x32.sys [20328 2010-07-09] (Windows (R) Win 7 DDK provider)
3 DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [23456 2010-07-12] (Phoenix Technologies)
3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-07-05] ()
1 HWiNFO32; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS [21624 2012-05-10] (REALiX(tm))
3 LHidFlt2; C:\Windows\System32\DRIVERS\LHidFlt2.Sys [25505 2003-12-17] (Logitech, Inc.)
3 LHidUsb; C:\Windows\System32\Drivers\LHidUsb.Sys [37887 2003-12-17] (Logitech, Inc.)
3 LMouFlt2; C:\Windows\System32\DRIVERS\LMouFlt2.Sys [70801 2003-12-17] (Logitech, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 NVNET; C:\Windows\System32\DRIVERS\nvmf6232.sys [295272 2009-11-11] (NVIDIA Corporation)
3 nvoclock; C:\Windows\System32\DRIVERS\nvoclock.sys [38248 2009-09-15] (NVIDIA Corp.)
3 physX32; C:\Windows\System32\DRIVERS\physX32.sys [120960 2008-02-29] (AGEIA Technologies, Inc.)
3 RTCore32; \??\C:\Program Files\EVGA Precision\RTCore32.sys [4608 2005-05-25] ()
3 SaiH075C; C:\Windows\System32\DRIVERS\SaiH075C.sys [132232 2007-05-01] (Saitek)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2012-05-10] (Duplex Secure Ltd.)
3 GPU-Z; \??\C:\Users\ETERNA~1\AppData\Local\Temp\GPU-Z.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-10 05:24 - 2012-08-10 05:24 - 00000000 ____D C:\FRST
2012-08-09 22:51 - 2012-08-09 22:51 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-09 22:09 - 2012-08-09 22:09 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-09 22:05 - 2012-08-09 22:05 - 00093648 ____A (AOpen) C:\Users\EternalKharas\hysoxqihotur.exe
2012-08-08 08:24 - 2012-08-08 08:24 - 00155840 ____A C:\Windows\Minidump\080812-25911-01.dmp
2012-08-07 09:02 - 2012-08-07 09:02 - 00111487 ____A C:\Users\EternalKharas\Documents\bank transfer 080712(2).xps
2012-08-07 05:49 - 2012-08-07 05:49 - 00000124 ____A C:\Users\EternalKharas\Desktop\HOME PAGE.txt
2012-08-07 04:07 - 2012-08-07 04:07 - 00111173 ____A C:\Users\EternalKharas\Documents\bank transfer 080712.xps
2012-08-03 07:29 - 2012-08-03 07:29 - 00196947 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage E-mailconfirmnation080312.xps
2012-08-03 07:00 - 2012-08-03 07:00 - 00159584 ____A C:\Users\EternalKharas\Documents\BrightHouse080312.xps
2012-08-03 05:54 - 2012-08-03 05:54 - 00111378 ____A C:\Users\EternalKharas\Documents\bank transfer 080312.xps
2012-08-03 04:56 - 2012-08-03 04:56 - 00117132 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage080312.xps
2012-08-03 03:50 - 2012-08-03 03:50 - 00000318 ____A C:\Users\EternalKharas\Desktop\Curse Client.appref-ms
2012-08-02 13:14 - 2012-08-02 13:14 - 00110956 ____A C:\Users\EternalKharas\Documents\bank transfer 080212.xps
2012-07-31 21:32 - 2012-07-31 21:32 - 00000097 ____A C:\Users\EternalKharas\Desktop\sephora.txt
2012-07-30 15:48 - 2012-07-30 15:49 - 00159552 ____A C:\Windows\Minidump\073012-34491-01.dmp
2012-07-30 14:38 - 2012-07-30 14:38 - 00161846 ____A C:\Users\EternalKharas\Documents\THIAGO2.xps
2012-07-30 14:10 - 2012-07-30 14:10 - 00111119 ____A C:\Users\EternalKharas\Documents\bank transfer 073012.xps
2012-07-29 00:43 - 2012-07-29 00:43 - 00111225 ____A C:\Users\EternalKharas\Documents\bank transfer 072912.xps
2012-07-28 05:56 - 2012-07-28 07:26 - 00000000 ____D C:\Users\EternalKharas\Documents\Business donations
2012-07-27 21:14 - 2012-07-27 21:14 - 00111373 ____A C:\Users\EternalKharas\Documents\bank transfer 072812.xps
2012-07-27 17:03 - 2012-07-27 17:03 - 00000000 ____D C:\Users\All Users\SolarWinds
2012-07-27 17:03 - 2012-07-27 17:03 - 00000000 ____D C:\Program Files\SolarWinds
2012-07-27 17:02 - 2012-07-27 17:02 - 00922042 ____A C:\Users\EternalKharas\Downloads\SolarWinds-Permissions-Analyzer-v1.0.0.zip
2012-07-27 17:02 - 2012-07-27 17:02 - 00000000 ____D C:\Users\EternalKharas\Downloads\SolarWinds-Permissions-Analyzer-v1.0.0
2012-07-24 02:17 - 2012-07-24 02:17 - 00001794 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(11).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00106888 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(10).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00102602 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(9).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00165939 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(6).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00138056 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(8).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00134007 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(7).htm
2012-07-24 02:14 - 2012-07-24 02:14 - 00104885 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(5).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00072213 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(9).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00056712 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(10).htm
2012-07-24 02:12 - 2012-07-24 02:12 - 00095829 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(8).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00115579 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(7).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00113343 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(6).htm
2012-07-24 02:10 - 2012-07-24 02:10 - 00155229 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(5).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00190068 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(3).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00181032 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(4).htm
2012-07-24 01:56 - 2012-07-24 01:56 - 00081496 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(4).htm
2012-07-24 01:55 - 2012-07-24 01:55 - 00070096 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(3).htm
2012-07-24 01:54 - 2012-07-24 01:54 - 00116002 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(2).htm
2012-07-24 01:53 - 2012-07-24 01:53 - 00115839 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24.htm
2012-07-23 21:15 - 2012-08-01 22:16 - 00008655 ____A C:\Users\EternalKharas\Desktop\Christina.txt
2012-07-23 15:04 - 2012-07-23 15:04 - 00246295 ____A C:\Users\EternalKharas\Documents\Thiago's order 1.xps
2012-07-23 13:12 - 2012-07-23 13:12 - 00111120 ____A C:\Users\EternalKharas\Documents\bank transfer THIAGO 1.xps
2012-07-21 10:29 - 2012-07-21 10:29 - 00000000 ____D C:\Users\EternalKharas\Downloads\the_whigs
2012-07-21 09:01 - 2012-07-21 10:29 - 07251231 ____A C:\Users\EternalKharas\Downloads\the_whigs.zip
2012-07-20 22:27 - 2012-07-21 02:13 - 00002961 ____A C:\Users\EternalKharas\Desktop\Stacy.txt
2012-07-19 05:23 - 2012-07-19 05:24 - 00000000 ____D C:\Program Files\HWiNFO32
2012-07-18 18:16 - 2012-07-18 18:16 - 00000000 __SHD C:\found.001
2012-07-16 23:24 - 2012-07-16 23:24 - 00000524 ____A C:\Users\EternalKharas\Desktop\Turn off Media Center Updates.htm
2012-07-16 06:13 - 2012-07-16 06:13 - 00111145 ____A C:\Users\EternalKharas\Documents\bank transfer 071612.xps
2012-07-15 23:12 - 2012-08-09 14:29 - 00000345 ____A C:\Users\EternalKharas\Desktop\MUSIC CODES (MARLBORO).txt
2012-07-14 22:49 - 2012-07-14 22:49 - 00136219 ____A C:\Users\EternalKharas\Documents\newegg071512.xps
2012-07-13 10:43 - 2012-07-13 10:43 - 00111413 ____A C:\Users\EternalKharas\Documents\bank transfer 071312.xps
2012-07-12 19:28 - 2012-07-12 19:28 - 00110872 ____A C:\Users\EternalKharas\Documents\bank transfer 071212.xps
2012-07-12 00:15 - 2012-07-12 00:15 - 00159400 ____A C:\Users\EternalKharas\Documents\BrightHouse071212.xps
2012-07-11 01:42 - 2012-07-11 01:42 - 00153512 ____A C:\Windows\Minidump\071112-36660-01.dmp
============ 3 Months Modified Files ========================
2012-08-09 23:19 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 23:18 - 2010-12-31 18:50 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-09 23:18 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 23:18 - 2009-07-13 20:39 - 00876280 ____A C:\Windows\setupact.log
2012-08-09 23:10 - 2012-06-19 07:37 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 23:03 - 2010-05-04 16:08 - 00148150 ____A C:\Windows\PFRO.log
2012-08-09 22:52 - 2011-06-29 04:33 - 01400340 ____A C:\Windows\WindowsUpdate.log
2012-08-09 22:52 - 2011-01-27 01:11 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 22:51 - 2011-06-29 03:46 - 00838082 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 22:41 - 2010-05-04 16:01 - 00019920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 22:41 - 2010-05-04 16:01 - 00019920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 22:40 - 2011-08-28 16:30 - 00000960 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1850465905-1816852967-2060930716-1000UA.job
2012-08-09 22:05 - 2012-08-09 22:05 - 00093648 ____A (AOpen) C:\Users\EternalKharas\hysoxqihotur.exe
2012-08-09 21:59 - 2010-12-31 18:50 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-09 15:00 - 2012-05-04 13:03 - 00002290 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-09 14:29 - 2012-07-15 23:12 - 00000345 ____A C:\Users\EternalKharas\Desktop\MUSIC CODES (MARLBORO).txt
2012-08-09 04:21 - 2012-07-09 02:48 - 00009549 ____A C:\Users\EternalKharas\Desktop\crash.txt
2012-08-09 03:34 - 2011-08-28 16:30 - 00000938 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1850465905-1816852967-2060930716-1000Core.job
2012-08-08 08:24 - 2012-08-08 08:24 - 00155840 ____A C:\Windows\Minidump\080812-25911-01.dmp
2012-08-07 09:02 - 2012-08-07 09:02 - 00111487 ____A C:\Users\EternalKharas\Documents\bank transfer 080712(2).xps
2012-08-07 05:49 - 2012-08-07 05:49 - 00000124 ____A C:\Users\EternalKharas\Desktop\HOME PAGE.txt
2012-08-07 04:07 - 2012-08-07 04:07 - 00111173 ____A C:\Users\EternalKharas\Documents\bank transfer 080712.xps
2012-08-03 07:29 - 2012-08-03 07:29 - 00196947 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage E-mailconfirmnation080312.xps
2012-08-03 07:00 - 2012-08-03 07:00 - 00159584 ____A C:\Users\EternalKharas\Documents\BrightHouse080312.xps
2012-08-03 05:54 - 2012-08-03 05:54 - 00111378 ____A C:\Users\EternalKharas\Documents\bank transfer 080312.xps
2012-08-03 04:56 - 2012-08-03 04:56 - 00117132 ____A C:\Users\EternalKharas\Documents\MetroSelfStorage080312.xps
2012-08-03 03:50 - 2012-08-03 03:50 - 00000318 ____A C:\Users\EternalKharas\Desktop\Curse Client.appref-ms
2012-08-02 13:14 - 2012-08-02 13:14 - 00110956 ____A C:\Users\EternalKharas\Documents\bank transfer 080212.xps
2012-08-02 08:56 - 2012-04-03 20:42 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 08:56 - 2011-05-19 12:08 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-01 22:16 - 2012-07-23 21:15 - 00008655 ____A C:\Users\EternalKharas\Desktop\Christina.txt
2012-07-31 21:32 - 2012-07-31 21:32 - 00000097 ____A C:\Users\EternalKharas\Desktop\sephora.txt
2012-07-30 15:49 - 2012-07-30 15:48 - 00159552 ____A C:\Windows\Minidump\073012-34491-01.dmp
2012-07-30 14:38 - 2012-07-30 14:38 - 00161846 ____A C:\Users\EternalKharas\Documents\THIAGO2.xps
2012-07-30 14:10 - 2012-07-30 14:10 - 00111119 ____A C:\Users\EternalKharas\Documents\bank transfer 073012.xps
2012-07-29 00:43 - 2012-07-29 00:43 - 00111225 ____A C:\Users\EternalKharas\Documents\bank transfer 072912.xps
2012-07-27 21:14 - 2012-07-27 21:14 - 00111373 ____A C:\Users\EternalKharas\Documents\bank transfer 072812.xps
2012-07-27 17:02 - 2012-07-27 17:02 - 00922042 ____A C:\Users\EternalKharas\Downloads\SolarWinds-Permissions-Analyzer-v1.0.0.zip
2012-07-27 04:46 - 2011-07-01 22:55 - 00007676 ____A C:\Users\EternalKharas\AppData\Local\Resmon.ResmonCfg
2012-07-24 02:17 - 2012-07-24 02:17 - 00001794 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(11).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00106888 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(10).htm
2012-07-24 02:16 - 2012-07-24 02:16 - 00102602 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(9).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00165939 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(6).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00138056 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(8).htm
2012-07-24 02:15 - 2012-07-24 02:15 - 00134007 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(7).htm
2012-07-24 02:14 - 2012-07-24 02:14 - 00104885 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(5).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00072213 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(9).htm
2012-07-24 02:13 - 2012-07-24 02:13 - 00056712 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(10).htm
2012-07-24 02:12 - 2012-07-24 02:12 - 00095829 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(8).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00115579 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(7).htm
2012-07-24 02:11 - 2012-07-24 02:11 - 00113343 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(6).htm
2012-07-24 02:10 - 2012-07-24 02:10 - 00155229 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(5).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00190068 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(3).htm
2012-07-24 02:00 - 2012-07-24 02:00 - 00181032 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(4).htm
2012-07-24 01:56 - 2012-07-24 01:56 - 00081496 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(4).htm
2012-07-24 01:55 - 2012-07-24 01:55 - 00070096 ____A C:\Users\EternalKharas\Documents\READPMArchive_2012-07-24(3).htm
2012-07-24 01:54 - 2012-07-24 01:54 - 00116002 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24(2).htm
2012-07-24 01:53 - 2012-07-24 01:53 - 00115839 ____A C:\Users\EternalKharas\Documents\SENTPMArchive_2012-07-24.htm
2012-07-23 15:04 - 2012-07-23 15:04 - 00246295 ____A C:\Users\EternalKharas\Documents\Thiago's order 1.xps
2012-07-23 13:12 - 2012-07-23 13:12 - 00111120 ____A C:\Users\EternalKharas\Documents\bank transfer THIAGO 1.xps
2012-07-21 10:29 - 2012-07-21 09:01 - 07251231 ____A C:\Users\EternalKharas\Downloads\the_whigs.zip
2012-07-21 02:13 - 2012-07-20 22:27 - 00002961 ____A C:\Users\EternalKharas\Desktop\Stacy.txt
2012-07-16 23:24 - 2012-07-16 23:24 - 00000524 ____A C:\Users\EternalKharas\Desktop\Turn off Media Center Updates.htm
2012-07-16 06:13 - 2012-07-16 06:13 - 00111145 ____A C:\Users\EternalKharas\Documents\bank transfer 071612.xps
2012-07-14 22:49 - 2012-07-14 22:49 - 00136219 ____A C:\Users\EternalKharas\Documents\newegg071512.xps
2012-07-13 10:43 - 2012-07-13 10:43 - 00111413 ____A C:\Users\EternalKharas\Documents\bank transfer 071312.xps
2012-07-12 19:28 - 2012-07-12 19:28 - 00110872 ____A C:\Users\EternalKharas\Documents\bank transfer 071212.xps
2012-07-12 00:15 - 2012-07-12 00:15 - 00159400 ____A C:\Users\EternalKharas\Documents\BrightHouse071212.xps
2012-07-11 01:42 - 2012-07-11 01:42 - 00153512 ____A C:\Windows\Minidump\071112-36660-01.dmp
2012-07-10 23:39 - 2009-07-13 20:33 - 00415344 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 23:01 - 2011-07-14 03:03 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-10 18:58 - 2012-07-10 18:58 - 00014336 ____A C:\Users\EternalKharas\Desktop\PAST and PRESENT.xls
2012-07-09 19:41 - 2010-06-11 02:33 - 00001220 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-09 08:08 - 2012-07-09 08:08 - 00111187 ____A C:\Users\EternalKharas\Documents\bank transfer 070912.xps
2012-07-08 17:25 - 2012-07-08 17:25 - 00224817 ____A C:\Users\EternalKharas\Desktop\Bubble.xps
2012-07-06 23:51 - 2012-07-06 23:51 - 00110723 ____A C:\Users\EternalKharas\Documents\bank transfer 070712.xps
2012-07-06 13:08 - 2012-07-06 12:46 - 00000724 ____A C:\Users\EternalKharas\Desktop\bigmyke.txt
2012-07-02 03:22 - 2012-07-02 03:22 - 00135354 ____A C:\Users\EternalKharas\Desktop\NeweggOrder.xps
2012-07-02 01:20 - 2012-07-02 01:20 - 00001226 ____A C:\Users\EternalKharas\Desktop\Revo Uninstaller.lnk
2012-07-01 09:04 - 2012-07-01 09:04 - 00110732 ____A C:\Users\EternalKharas\Documents\bank transfer 070112.xps
2012-06-29 23:05 - 2012-06-29 23:05 - 00020622 ____A C:\Users\EternalKharas\Documents\Backup of GTX480.wbk
2012-06-29 22:47 - 2012-06-27 08:38 - 00003940 ____A C:\Users\EternalKharas\Documents\GTX480.txt
2012-06-27 20:53 - 2012-06-27 08:57 - 00000193 ____A C:\Users\EternalKharas\Documents\GTX.txt
2012-06-26 12:33 - 2012-06-26 12:33 - 01058784 ____A (techPowerUp (www.techpowerup.com)) C:\Users\EternalKharas\Downloads\GPU-Z.0.6.2 (2).exe
2012-06-26 12:30 - 2012-06-26 12:30 - 01058784 ____A (techPowerUp (www.techpowerup.com)) C:\Users\EternalKharas\Downloads\GPU-Z.0.6.2.exe
2012-06-26 12:30 - 2012-06-26 12:30 - 01058784 ____A (techPowerUp (www.techpowerup.com)) C:\Users\EternalKharas\Downloads\GPU-Z.0.6.2 (1).exe
2012-06-25 12:19 - 2012-05-06 23:24 - 00209920 __ASH C:\Users\EternalKharas\Documents\Thumbs.db
2012-06-25 12:14 - 2012-06-25 12:03 - 00001766 ____A C:\Users\EternalKharas\Desktop\LCD Calculator v2.Vbs
2012-06-25 07:54 - 2012-06-25 07:54 - 00111388 ____A C:\Users\EternalKharas\Documents\bank transfer 062512.xps
2012-06-22 18:31 - 2012-06-22 18:30 - 00151229 ____A C:\Users\EternalKharas\Documents\WOW CARD 062212.xps
2012-06-22 03:11 - 2012-06-22 03:11 - 00000274 ____A C:\Users\EternalKharas\Downloads\Performance_PC's_Newsletter (1).vcf
2012-06-22 03:09 - 2012-06-22 03:09 - 00000274 ____A C:\Users\EternalKharas\Downloads\Performance_PC's_Newsletter.vcf
2012-06-21 23:35 - 2012-06-21 23:35 - 00187801 ____A C:\Users\EternalKharas\Documents\metropcs payment 062212.xps
2012-06-19 06:41 - 2012-06-19 06:41 - 00111381 ____A C:\Users\EternalKharas\Documents\bank transfer 061912.xps
2012-06-19 03:06 - 2012-06-19 03:06 - 00158616 ____A C:\Windows\Minidump\061912-24164-01.dmp
2012-06-19 01:30 - 2012-06-19 01:30 - 00000875 ____A C:\Users\Public\Desktop\Steam.lnk
2012-06-17 01:10 - 2012-06-17 01:10 - 00130488 ____A C:\Users\EternalKharas\Documents\Toshiba repair disk.xps
2012-06-16 06:46 - 2012-06-16 06:46 - 00111031 ____A C:\Users\EternalKharas\Documents\bank transfer 061612.xps
2012-06-11 18:40 - 2012-07-10 23:01 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 06:48 - 2012-06-11 06:48 - 00110917 ____A C:\Users\EternalKharas\Documents\bank transfer 061112.xps
2012-06-09 13:10 - 2012-06-09 13:10 - 00111512 ____A C:\Users\EternalKharas\Documents\bank transfer 060912(2).xps
2012-06-09 12:58 - 2012-06-09 12:58 - 00111496 ____A C:\Users\EternalKharas\Documents\bank transfer 060912.xps
2012-06-08 20:41 - 2012-07-10 15:01 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 18:47 - 2012-06-08 18:47 - 00111386 ____A C:\Users\EternalKharas\Documents\bank transfer 060812.xps
2012-06-08 11:23 - 2012-06-08 11:23 - 00001219 ___AH C:\Windows\System32\config\Journal - Shortcut.lnk
2012-06-08 11:23 - 2012-06-08 11:23 - 00000914 ___AH C:\Windows\System32\config\userdiff - Shortcut.lnk
2012-06-08 11:23 - 2012-06-08 11:23 - 00000914 ___AH C:\Windows\System32\config\software - Shortcut.lnk
2012-06-08 11:23 - 2012-06-08 11:23 - 00000902 ___AH C:\Windows\System32\config\system - Shortcut.lnk
2012-06-08 09:42 - 2012-06-08 09:25 - 1060726784 ____A C:\Users\EternalKharas\Desktop\jonathan.iso
2012-06-05 21:05 - 2012-07-10 15:01 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 15:01 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 15:01 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-04 04:29 - 2012-06-04 04:29 - 00111204 ____A C:\Users\EternalKharas\Documents\bank transfer 060412.xps
2012-06-02 14:19 - 2012-06-20 17:46 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 17:46 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 17:46 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 17:46 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 17:46 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 17:46 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 17:46 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-20 17:45 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-20 17:45 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-10 23:04 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-10 23:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-10 23:04 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-10 23:04 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-10 23:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 23:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-10 23:04 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-10 23:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 23:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 23:04 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-10 23:04 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-10 23:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 23:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 23:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 22:13 - 2012-06-01 22:13 - 00001036 ____A C:\Users\EternalKharas\Desktop\EVGA Precision.lnk
2012-06-01 20:45 - 2012-07-10 15:01 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 15:01 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 15:01 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 15:01 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 15:01 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-31 20:13 - 2012-03-22 19:27 - 00001050 ____A C:\Users\EternalKharas\Desktop\EVGA Precision X.lnk
2012-05-31 19:54 - 2012-05-31 19:54 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2012-05-25 09:38 - 2012-05-25 09:38 - 00001108 ____A C:\Users\EternalKharas\Documents\sally ansell (2).txt
2012-05-24 19:01 - 2012-05-24 19:01 - 00001362 ____A C:\Users\EternalKharas\Documents\sallyansel(2).txt
2012-05-24 13:38 - 2012-05-24 13:38 - 00187937 ____A C:\Users\EternalKharas\Documents\metropcs payment 052412.xps
2012-05-23 05:55 - 2012-05-23 05:55 - 00002885 ____A C:\Users\EternalKharas\Documents\sallyansel.txt
2012-05-23 01:35 - 2012-05-23 01:35 - 00111345 ____A C:\Users\EternalKharas\Documents\bank transfer 052312.xps
2012-05-22 17:30 - 2012-05-22 17:30 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\System32\rmoc3260.dll
2012-05-22 17:30 - 2012-05-22 17:30 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5016.dll
2012-05-22 17:30 - 2012-05-22 17:30 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5032.dll
2012-05-22 17:30 - 2012-05-22 17:30 - 00001016 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-05-22 17:29 - 2012-05-22 17:29 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\msvcp71.dll
2012-05-22 17:29 - 2012-05-22 17:29 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\msvcr71.dll
2012-05-22 17:29 - 2012-05-22 17:29 - 00272896 ____A (Progressive Networks) C:\Windows\System32\pncrt.dll
2012-05-21 19:30 - 2012-05-21 19:30 - 00002170 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-05-21 18:18 - 2012-05-21 18:18 - 00001815 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-21 10:28 - 2012-05-21 10:28 - 03896832 ____A C:\Users\EternalKharas\Downloads\ARGALIWYSETUP.EXE
2012-05-18 23:44 - 2012-05-18 23:44 - 00111124 ____A C:\Users\EternalKharas\Documents\bank transfer 051912.xps
2012-05-14 22:21 - 2012-05-14 22:21 - 00423744 ____A C:\Windows\System32\nvStreaming.exe
2012-05-13 23:08 - 2011-06-29 09:18 - 00000927 ____A C:\Users\Guest\Desktop\MagicDisc.lnk
2012-05-13 23:08 - 2011-06-29 09:18 - 00000927 ____A C:\Users\EternalKharas\Desktop\MagicDisc.lnk
2012-05-13 23:08 - 2011-06-29 09:18 - 00000927 ____A C:\Users\Administrator\Desktop\MagicDisc.lnk
2012-05-13 22:54 - 2012-05-13 22:54 - 00001773 ____A C:\Users\Guest\Desktop\MagicISO.lnk
2012-05-13 22:54 - 2012-05-13 22:54 - 00001773 ____A C:\Users\EternalKharas\Desktop\MagicISO.lnk
2012-05-13 22:54 - 2012-05-13 22:54 - 00001773 ____A C:\Users\Administrator\Desktop\MagicISO.lnk
ZeroAccess:
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\@
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\L
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\n
C:\Windows\Installer\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\U
ZeroAccess:
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\@
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\L
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\n
C:\Users\EternalKharas\AppData\Local\{aec20ce0-3b62-6463-9d60-f6936e9e0aa7}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 8190.54 MB
Available physical RAM: 7607.41 MB
Total Pagefile: 8188.82 MB
Available Pagefile: 7630.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:148.96 GB) (Free:4.57 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (GRMCULFRER_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
4 Drive f: (USB MEMORY) (Removable) (Total:0.12 GB) (Free:0.08 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 123 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 31 KB
Partition 2 Primary 148 GB 48 MB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 148 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 122 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F USB MEMORY FAT Removable 122 MB Healthy
==================================================================================
Last Boot: 2012-08-07 08:07
======================= End Of Log ==========================