Hello,
I am new to the forum. I'd greatly appreciate a fixlist.txt for this...
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 15-08-2012
Ran by SYSTEM at 16-08-2012 21:24:59
Running from F:\
Windows 7 Professional Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [142616 2011-06-28] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [176408 2011-06-28] (Intel Corporation)
HKLM\...\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2010-10-01] (CyberLink Corp.)
HKLM\...\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-09-17] (CyberLink Corp.)
HKLM\...\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM\...\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2215768 2011-12-06] (Intuit Inc. All rights reserved.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36800 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [823224 2012-07-27] (Adobe Systems Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Default\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1174016 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1174016 2010-11-20] (Microsoft Corporation)
HKU\QBDataServiceUser22\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1174016 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll [X]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
================================ Services (Whitelisted) ==================
2 atashost; "C:\Windows\system32\atashost.exe" [134456 2012-07-17] (Cisco WebEx LLC)
2 CSAPrintService; C:\Windows\csasvc.exe [118784 2009-11-10] (Thomson Reuters)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 GoToAssist; "C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe" Start=service [16680 2012-01-12] (Citrix Online, a division of Citrix Systems, Inc.)
2 jhi_service; C:\Program Files\Intel\Services\IPT\jhi_service.exe [212944 2011-02-23] (Intel Corporation)
2 QBVSS; "C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe" [1248256 2011-08-19] (Intuit Inc.)
3 QuickBooksDB22; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB22 [679936 2011-08-19] (Intuit, Inc.)
3 RoxMediaDB12OEM; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe" [1116656 2010-11-25] (Sonic Solutions)
2 RoxWatch12; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-11-25] (Sonic Solutions)
2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 netvsc; C:\Windows\System32\DRIVERS\netvsc60.sys [126464 2010-11-20] (Microsoft Corporation)
3 SynthVid; C:\Windows\System32\DRIVERS\VMBusVideoM.sys [19456 2010-11-20] (Microsoft Corporation)
3 catchme; \??\C:\Users\ACCOUN~1\AppData\Local\Temp\catchme.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-16 15:31 - 2012-08-16 15:31 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-16 15:26 - 2012-08-16 15:26 - 00254152 ____A (Secure By Design Inc.) C:\Users\accountant\Downloads\Ninite Essentials Installer.exe
2012-08-16 15:19 - 2012-08-16 15:19 - 04009167 ____A C:\Users\accountant\Downloads\ServicesRepair.exe
2012-08-16 15:18 - 2012-08-16 15:18 - 00138120 ____A (ESET) C:\Users\accountant\Downloads\ESETSirefefRemover.exe
2012-08-16 15:13 - 2012-08-16 15:15 - 02030547 ____A C:\Users\accountant\Downloads\EZ_Sirefix.exe
2012-08-16 14:27 - 2012-08-16 14:27 - 00000000 ____D C:\Users\All Users\Sophos
2012-08-16 14:26 - 2012-08-16 14:26 - 77801992 ____A (Sophos Limited) C:\Users\accountant\Downloads\Sophos Virus Removal Tool.exe
2012-08-16 14:26 - 2012-08-16 14:26 - 00003217 ____A C:\Users\accountant\Desktop\Sophos Virus Removal Tool.lnk
2012-08-16 14:26 - 2012-08-16 14:26 - 00000000 ____D C:\Program Files\Sophos
2012-08-16 14:04 - 2008-05-07 21:03 - 00303616 ____A ( ) C:\SetACL.exe
2012-08-16 13:55 - 2012-08-16 14:07 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2012-08-16 13:55 - 2012-08-16 13:55 - 00000207 ____A C:\Windows\tweaking.com-regbackup-ACCOUNTING1A-Microsoft-Windows-7-Professional-(32-bit).dat
2012-08-16 13:55 - 2004-06-11 15:33 - 00290304 ____A (Microsoft Corporation) C:\subinacl.exe
2012-08-16 13:54 - 2012-08-16 13:54 - 00000000 ____D C:\RegBackup
2012-08-16 13:53 - 2012-08-16 13:53 - 00002239 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2012-08-16 13:53 - 2012-08-16 13:53 - 00000000 ____D C:\Program Files\Tweaking.com
2012-08-16 13:49 - 2012-08-16 15:15 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-08-16 13:13 - 2012-08-16 13:13 - 00014705 ____A C:\ComboFix.txt
2012-08-16 13:01 - 2012-08-16 13:01 - 00000000 ____D C:\Users\accountant\AppData\Roaming\TeamViewer
2012-08-16 12:53 - 2012-08-16 12:53 - 00001917 ____A C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2012-08-16 12:32 - 2012-08-16 12:32 - 00000000 ____D C:\Users\All Users\Dumps
2012-08-16 11:26 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00000000 ____D C:\Program Files\Common Files\Java
2012-08-16 10:31 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-16 10:31 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-16 10:31 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-16 10:31 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-16 10:31 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-16 10:31 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-16 10:31 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-16 10:31 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-16 10:31 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-16 10:31 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-16 10:31 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-16 10:31 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-16 10:31 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-16 10:31 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-16 10:30 - 2012-07-18 09:47 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-16 10:30 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-16 10:30 - 2012-07-04 13:14 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-16 10:30 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-16 10:30 - 2012-05-13 20:33 - 00769024 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-16 10:30 - 2012-05-04 23:46 - 00400896 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-16 10:30 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-16 10:30 - 2012-02-10 21:37 - 00317440 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-16 10:19 - 2012-08-16 10:19 - 00000000 ____D C:\Windows\SoftwareDistribution.old
2012-08-16 10:06 - 2012-08-16 10:06 - 00000376 ____A C:\Users\accountant\AppData\Roamingprivacy.xml
2012-08-15 13:49 - 2012-08-16 09:45 - 00000347 ____A C:\Windows\System32\checkdnsid.xml
2012-08-15 13:37 - 2012-08-15 13:37 - 00000000 ____D C:\Users\All Users\bdch
2012-08-15 13:34 - 2012-08-15 13:34 - 00000385 ____A C:\Windows\System32\user_gensett.xml
2012-08-15 13:33 - 2012-08-15 13:33 - 00000000 ____D C:\Users\All Users\BDLogging
2012-08-15 13:33 - 2009-07-14 10:27 - 01461992 ____A (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01009.dll
2012-08-15 13:33 - 2007-04-11 07:11 - 00511328 ____A (Microsoft Corporation) C:\Windows\capicom.dll
2012-08-15 13:32 - 2012-08-16 12:36 - 00000000 ____D C:\Program Files\Bitdefender
2012-08-15 13:32 - 2012-08-16 12:34 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2012-08-15 13:32 - 2012-08-15 13:32 - 02426224 ____A C:\Users\accountant\Downloads\bitdefender_antivirus.exe
2012-08-15 13:32 - 2012-08-15 13:32 - 00000000 ____D C:\Users\accountant\AppData\Roaming\QuickScan
2012-08-15 11:13 - 2012-08-15 11:13 - 00017408 ____A C:\Users\accountant\AppData\Local\WebpageIcons.db
2012-08-15 10:56 - 2012-08-15 10:57 - 181528160 ____A (Kaspersky Lab) C:\Users\accountant\Downloads\kav2012_12.0.0.374aEN_2839.exe
2012-08-15 10:02 - 2012-08-15 10:02 - 03098616 ____A (Secunia) C:\Users\accountant\Downloads\PSISetup.exe
2012-08-15 10:02 - 2012-08-15 10:02 - 00000000 ____D C:\Users\accountant\AppData\Local\Secunia PSI
2012-08-15 10:02 - 2012-08-15 10:02 - 00000000 ____D C:\Program Files\Secunia
2012-08-15 09:40 - 2012-08-16 13:14 - 00000000 ____D C:\Qoobox
2012-08-15 09:40 - 2012-08-15 09:54 - 00000000 ____D C:\Windows\erdnt
2012-08-15 09:40 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-08-15 09:40 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-08-15 09:40 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-08-15 09:30 - 2012-08-15 09:30 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-15 09:25 - 2012-08-15 09:25 - 00144936 ____A C:\Windows\Minidump\081512-43555-01.dmp
2012-08-15 09:17 - 2012-08-15 09:17 - 00053248 ____A C:\Windows\System32\zlib.dll
2012-08-15 09:16 - 2012-08-16 13:28 - 00000000 ____D C:\Users\accountant\Desktop\D7
2012-08-15 09:15 - 2012-08-16 15:12 - 00000583 ____A C:\Users\accountant\Desktop\notes.txt
2012-08-15 09:10 - 2012-08-15 09:10 - 00000000 ____D C:\smtmp
2012-08-15 09:07 - 2012-08-15 09:10 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6Sr
2012-08-15 09:07 - 2012-08-15 09:10 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6S
2012-08-14 05:58 - 2012-08-15 09:25 - 00000000 ____D C:\Windows\Minidump
2012-08-14 05:58 - 2012-08-14 05:58 - 00151112 ____A C:\Windows\Minidump\081412-47923-01.dmp
2012-08-14 05:57 - 2012-08-15 09:24 - 383022766 ____A C:\Windows\MEMORY.DMP
2012-08-09 12:07 - 2012-08-09 12:07 - 00000496 ___RA C:\CSI Realty Investment LLC6.30.12.lgb
2012-08-09 12:03 - 2012-08-09 13:04 - 17731584 ___RA C:\CSI Realty Investment LLC6.30.12.QBW
2012-08-09 12:03 - 2012-08-09 13:04 - 05373952 ___RA C:\CSI Realty Investment LLC6.30.12.QBW.TLG
2012-08-09 12:03 - 2012-08-09 13:04 - 00000382 ____A C:\CSI Realty Investment LLC6.30.12.QBW.ND
2012-08-09 12:03 - 2012-08-09 12:04 - 00000389 ____A C:\CSI Realty Investment LLC6.30.12.QBW.DSN
2012-08-09 12:03 - 2012-08-09 12:03 - 00000388 ____A C:\CSI Realty Investment LLC6.30.12.ND
2012-08-09 12:03 - 2012-08-09 12:03 - 00000000 ____D C:\Restored_CSI Realty Investment LLC6.30.12_Files
2012-07-31 09:46 - 2012-07-31 09:46 - 00000496 ___RA C:\FL_LARSO.QBB.lgb
2012-07-31 09:40 - 2012-08-09 12:03 - 138842112 ___RA C:\FL_LARSO.QBB.QBW
2012-07-31 09:40 - 2012-08-09 12:03 - 05832704 ___RA C:\FL_LARSO.QBB.QBW.TLG
2012-07-31 09:40 - 2012-08-09 12:03 - 00000362 ____A C:\FL_LARSO.QBB.QBW.ND
2012-07-31 09:40 - 2012-08-09 11:56 - 00000389 ____A C:\FL_LARSO.QBB.QBW.DSN
2012-07-31 09:40 - 2012-07-31 09:40 - 00000393 ____A C:\FL_LARSO.QBB.ND
2012-07-31 09:40 - 2012-07-31 09:40 - 00000000 ____D C:\Restored_FL_LARSO.QBB_Files
2012-07-31 09:39 - 2012-07-31 09:39 - 110243840 ____A C:\FL_LARSON.QBW
2012-07-31 09:39 - 2012-07-31 09:39 - 00000393 ____A C:\FL_LARSON.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 00000389 ____A C:\FL_LARSON.QBW.DSN
2012-07-31 09:39 - 2012-07-31 09:39 - 00000355 ____A C:\FL_LARSON.QBW.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 00000000 ____D C:\Restored_FL_LARSON_Files
2012-07-19 14:20 - 2012-07-19 14:20 - 00000496 ___RA C:\george_a.PICKERING.lgb
2012-07-17 09:03 - 2012-07-19 07:06 - 00000000 ____D C:\Users\All Users\WebEx
2012-07-17 08:58 - 2012-07-17 08:58 - 00170738 ____A C:\Users\accountant\Downloads\WBXRemoveTool.zip
2012-07-17 08:41 - 2012-07-17 08:41 - 00217400 ____A (Cisco WebEx LLC) C:\Windows\System32\atsckernel.exe
2012-07-17 08:41 - 2012-07-17 08:41 - 00134456 ____A (Cisco WebEx LLC) C:\Windows\System32\atashost.exe
============ 3 Months Modified Files ========================
2012-08-16 17:14 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-16 17:14 - 2009-07-13 20:39 - 00049306 ____A C:\Windows\setupact.log
2012-08-16 17:14 - 2009-07-13 20:34 - 00021312 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-16 17:14 - 2009-07-13 20:34 - 00021312 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-16 17:11 - 2011-12-15 07:58 - 01481260 ____A C:\Windows\WindowsUpdate.log
2012-08-16 15:31 - 2012-05-03 06:55 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-16 15:31 - 2010-11-20 13:01 - 00800016 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-16 15:26 - 2012-08-16 15:26 - 00254152 ____A (Secure By Design Inc.) C:\Users\accountant\Downloads\Ninite Essentials Installer.exe
2012-08-16 15:19 - 2012-08-16 15:19 - 04009167 ____A C:\Users\accountant\Downloads\ServicesRepair.exe
2012-08-16 15:18 - 2012-08-16 15:18 - 00138120 ____A (ESET) C:\Users\accountant\Downloads\ESETSirefefRemover.exe
2012-08-16 15:15 - 2012-08-16 15:13 - 02030547 ____A C:\Users\accountant\Downloads\EZ_Sirefix.exe
2012-08-16 15:12 - 2012-08-15 09:15 - 00000583 ____A C:\Users\accountant\Desktop\notes.txt
2012-08-16 14:56 - 2012-04-11 03:57 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-16 14:26 - 2012-08-16 14:26 - 77801992 ____A (Sophos Limited) C:\Users\accountant\Downloads\Sophos Virus Removal Tool.exe
2012-08-16 14:26 - 2012-08-16 14:26 - 00003217 ____A C:\Users\accountant\Desktop\Sophos Virus Removal Tool.lnk
2012-08-16 14:10 - 2011-12-28 05:57 - 00124464 ____A C:\Users\accountant\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-16 14:09 - 2009-07-13 20:33 - 00436384 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 14:07 - 2012-08-16 13:55 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2012-08-16 13:55 - 2012-08-16 13:55 - 00000207 ____A C:\Windows\tweaking.com-regbackup-ACCOUNTING1A-Microsoft-Windows-7-Professional-(32-bit).dat
2012-08-16 13:53 - 2012-08-16 13:53 - 00002239 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2012-08-16 13:15 - 2010-11-20 13:48 - 00123400 ____A C:\Windows\PFRO.log
2012-08-16 13:13 - 2012-08-16 13:13 - 00014705 ____A C:\ComboFix.txt
2012-08-16 13:12 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini
2012-08-16 13:12 - 2009-07-13 18:04 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts_bak_858
2012-08-16 12:53 - 2012-08-16 12:53 - 00001917 ____A C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2012-08-16 11:24 - 2012-08-16 11:24 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2012-08-16 11:24 - 2011-12-25 12:03 - 00246760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-08-16 11:24 - 2011-12-25 12:03 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-08-16 11:24 - 2011-12-25 12:03 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-08-16 11:24 - 2011-12-15 08:07 - 00746984 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-08-16 10:34 - 2011-12-25 11:53 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-16 10:06 - 2012-08-16 10:06 - 00000376 ____A C:\Users\accountant\AppData\Roamingprivacy.xml
2012-08-16 09:45 - 2012-08-15 13:49 - 00000347 ____A C:\Windows\System32\checkdnsid.xml
2012-08-15 13:34 - 2012-08-15 13:34 - 00000385 ____A C:\Windows\System32\user_gensett.xml
2012-08-15 13:32 - 2012-08-15 13:32 - 02426224 ____A C:\Users\accountant\Downloads\bitdefender_antivirus.exe
2012-08-15 11:13 - 2012-08-15 11:13 - 00017408 ____A C:\Users\accountant\AppData\Local\WebpageIcons.db
2012-08-15 11:03 - 2012-02-09 05:01 - 00002016 ____A C:\Users\Public\Desktop\Adobe Acrobat X Standard.lnk
2012-08-15 10:57 - 2012-08-15 10:56 - 181528160 ____A (Kaspersky Lab) C:\Users\accountant\Downloads\kav2012_12.0.0.374aEN_2839.exe
2012-08-15 10:56 - 2012-04-11 03:57 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-15 10:56 - 2011-12-15 08:00 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-15 10:02 - 2012-08-15 10:02 - 03098616 ____A (Secunia) C:\Users\accountant\Downloads\PSISetup.exe
2012-08-15 09:25 - 2012-08-15 09:25 - 00144936 ____A C:\Windows\Minidump\081512-43555-01.dmp
2012-08-15 09:24 - 2012-08-14 05:57 - 383022766 ____A C:\Windows\MEMORY.DMP
2012-08-15 09:17 - 2012-08-15 09:17 - 00053248 ____A C:\Windows\System32\zlib.dll
2012-08-15 09:10 - 2012-08-15 09:07 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6Sr
2012-08-15 09:10 - 2012-08-15 09:07 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6S
2012-08-14 05:58 - 2012-08-14 05:58 - 00151112 ____A C:\Windows\Minidump\081412-47923-01.dmp
2012-08-11 00:07 - 2011-12-28 05:30 - 00000120 ____A C:\Windows\System32\config\netlogon.ftl
2012-08-09 13:04 - 2012-08-09 12:03 - 17731584 ___RA C:\CSI Realty Investment LLC6.30.12.QBW
2012-08-09 13:04 - 2012-08-09 12:03 - 05373952 ___RA C:\CSI Realty Investment LLC6.30.12.QBW.TLG
2012-08-09 13:04 - 2012-08-09 12:03 - 00000382 ____A C:\CSI Realty Investment LLC6.30.12.QBW.ND
2012-08-09 13:04 - 2011-12-28 07:44 - 00000324 ____A C:\Windows\CSAAPP.INI
2012-08-09 12:07 - 2012-08-09 12:07 - 00000496 ___RA C:\CSI Realty Investment LLC6.30.12.lgb
2012-08-09 12:04 - 2012-08-09 12:03 - 00000389 ____A C:\CSI Realty Investment LLC6.30.12.QBW.DSN
2012-08-09 12:03 - 2012-08-09 12:03 - 00000388 ____A C:\CSI Realty Investment LLC6.30.12.ND
2012-08-09 12:03 - 2012-07-31 09:40 - 138842112 ___RA C:\FL_LARSO.QBB.QBW
2012-08-09 12:03 - 2012-07-31 09:40 - 05832704 ___RA C:\FL_LARSO.QBB.QBW.TLG
2012-08-09 12:03 - 2012-07-31 09:40 - 00000362 ____A C:\FL_LARSO.QBB.QBW.ND
2012-08-09 11:56 - 2012-07-31 09:40 - 00000389 ____A C:\FL_LARSO.QBB.QBW.DSN
2012-08-04 03:13 - 2009-07-13 20:53 - 00022182 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-31 09:46 - 2012-07-31 09:46 - 00000496 ___RA C:\FL_LARSO.QBB.lgb
2012-07-31 09:40 - 2012-07-31 09:40 - 00000393 ____A C:\FL_LARSO.QBB.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 110243840 ____A C:\FL_LARSON.QBW
2012-07-31 09:39 - 2012-07-31 09:39 - 00000393 ____A C:\FL_LARSON.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 00000389 ____A C:\FL_LARSON.QBW.DSN
2012-07-31 09:39 - 2012-07-31 09:39 - 00000355 ____A C:\FL_LARSON.QBW.ND
2012-07-31 09:39 - 2012-03-28 04:23 - 00000386 ____A C:\Law Office Of David P Sorrenti, P.C..QBW.ND
2012-07-31 09:39 - 2012-03-28 04:21 - 21295104 ___RA C:\Law Office Of David P Sorrenti, P.C..QBW
2012-07-31 09:39 - 2011-12-28 06:37 - 00589824 ___RA C:\Law Office Of David P Sorrenti, P.C..QBW.TLG
2012-07-31 09:38 - 2012-03-28 04:23 - 00000389 ____A C:\Law Office Of David P Sorrenti, P.C..QBW.DSN
2012-07-30 10:48 - 2012-04-07 11:50 - 03473408 ___RA C:\DICKINSON0910.QBW.TLG
2012-07-30 10:48 - 2012-04-07 11:49 - 72265728 ___RA C:\DICKINSON0910.QBW
2012-07-30 10:48 - 2012-04-07 11:49 - 00000363 ____A C:\DICKINSON0910.QBW.ND
2012-07-23 07:04 - 2012-04-07 11:49 - 00000389 ____A C:\DICKINSON0910.QBW.DSN
2012-07-23 07:03 - 2012-02-28 06:00 - 96026624 ___RA C:\george_a.PICKERING.qbw
2012-07-23 07:03 - 2012-02-28 06:00 - 00327680 ___RA C:\george_a.PICKERING.QBW.TLG
2012-07-23 07:03 - 2012-02-28 06:00 - 00000368 ____A C:\george_a.PICKERING.qbw.ND
2012-07-19 14:20 - 2012-07-19 14:20 - 00000496 ___RA C:\george_a.PICKERING.lgb
2012-07-19 14:20 - 2012-02-28 06:00 - 00000389 ____A C:\george_a.PICKERING.qbw.DSN
2012-07-18 09:47 - 2012-08-16 10:30 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-17 10:48 - 2012-07-02 05:08 - 06684672 ___RA C:\NE Patriot Truck Tire Inc.QBW.TLG
2012-07-17 10:48 - 2012-07-02 05:07 - 198266880 ___RA C:\NE Patriot Truck Tire Inc.QBW
2012-07-17 10:48 - 2012-07-02 05:07 - 00000375 ____A C:\NE Patriot Truck Tire Inc.QBW.ND
2012-07-17 10:33 - 2012-07-02 05:07 - 00000389 ____A C:\NE Patriot Truck Tire Inc.QBW.DSN
2012-07-17 08:58 - 2012-07-17 08:58 - 00170738 ____A C:\Users\accountant\Downloads\WBXRemoveTool.zip
2012-07-17 08:41 - 2012-07-17 08:41 - 00217400 ____A (Cisco WebEx LLC) C:\Windows\System32\atsckernel.exe
2012-07-17 08:41 - 2012-07-17 08:41 - 00134456 ____A (Cisco WebEx LLC) C:\Windows\System32\atashost.exe
2012-07-13 04:04 - 2011-12-28 11:52 - 00001476 ____A C:\Users\accountant\Desktop\ProSystem fx Tax.LNK
2012-07-13 04:04 - 2011-12-28 07:22 - 00670574 ____A C:\sysfile.log
2012-07-12 08:22 - 2012-03-06 10:28 - 00000365 ____A C:\Club eX (PandL).QBW.ND
2012-07-12 08:22 - 2012-03-06 10:27 - 31801344 ___RA C:\Club eX (PandL).QBW
2012-07-12 08:22 - 2012-03-06 10:27 - 03735552 ___RA C:\Club eX (PandL).QBW.TLG
2012-07-12 05:22 - 2012-03-06 10:28 - 00000389 ____A C:\Club eX (PandL).QBW.DSN
2012-07-12 05:21 - 2012-03-12 10:01 - 10616832 ___RA C:\62_PORTER STREET RENTAL.QBW
2012-07-12 05:21 - 2012-03-12 10:01 - 00327680 ___RA C:\62_PORTER STREET RENTAL.QBW.TLG
2012-07-12 05:21 - 2012-03-12 10:01 - 00000389 ____A C:\62_PORTER STREET RENTAL.QBW.DSN
2012-07-12 05:21 - 2012-03-12 10:01 - 00000373 ____A C:\62_PORTER STREET RENTAL.QBW.ND
2012-07-11 23:01 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-11 23:00 - 2012-07-11 23:00 - 00264530 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-04 13:16 - 2012-08-16 10:30 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 13:14 - 2012-08-16 10:30 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 13:14 - 2012-08-16 10:30 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-02 05:17 - 2012-07-02 05:17 - 00000496 ___RA C:\NE Patriot Truck Tire Inc.lgb
2012-07-02 05:08 - 2012-07-02 05:08 - 00000521 ____A C:\NE Patriot Truck Tire Inc.ND
2012-07-02 05:07 - 2012-04-03 06:02 - 00327680 ___RA C:\Dickinson Weymouth Building.QBW.TLG
2012-07-02 05:07 - 2012-04-03 06:01 - 11735040 ___RA C:\Dickinson Weymouth Building.qbw
2012-07-02 05:07 - 2012-04-03 06:01 - 00000389 ____A C:\Dickinson Weymouth Building.qbw.DSN
2012-07-02 05:07 - 2012-04-03 06:01 - 00000377 ____A C:\Dickinson Weymouth Building.qbw.ND
2012-06-28 16:52 - 2012-08-16 10:31 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 16:27 - 2012-08-16 10:31 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 16:16 - 2012-08-16 10:31 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 16:09 - 2012-08-16 10:31 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 16:09 - 2012-08-16 10:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 16:08 - 2012-08-16 10:31 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 16:07 - 2012-08-16 10:31 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 16:06 - 2012-08-16 10:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 16:04 - 2012-08-16 10:31 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 16:04 - 2012-08-16 10:31 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 16:01 - 2012-08-16 10:31 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 16:01 - 2012-08-16 10:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 16:00 - 2012-08-16 10:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 15:57 - 2012-08-16 10:31 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-21 05:27 - 2012-04-10 09:43 - 148955136 ___RA C:\kwalterqbb.QBW
2012-06-21 05:27 - 2012-04-10 09:43 - 02490368 ___RA C:\kwalterqbb.QBW.TLG
2012-06-21 05:27 - 2012-04-10 09:43 - 00000360 ____A C:\kwalterqbb.QBW.ND
2012-06-21 05:26 - 2012-04-10 09:43 - 00000389 ____A C:\kwalterqbb.QBW.DSN
2012-06-19 04:56 - 2012-03-29 12:38 - 00000368 ____A C:\MccormickInsurance.QBW.ND
2012-06-13 23:18 - 2012-03-29 12:38 - 69038080 ___RA C:\MccormickInsurance.QBW
2012-06-13 23:18 - 2012-03-29 12:38 - 00589824 ___RA C:\MccormickInsurance.QBW.TLG
2012-06-12 04:45 - 2012-03-29 12:38 - 00000389 ____A C:\MccormickInsurance.QBW.DSN
2012-06-08 20:41 - 2012-07-11 01:01 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-06 16:59 - 2012-06-06 16:59 - 01070152 ____A (Microsoft Corporation) C:\Windows\System32\MSCOMCTL.OCX
2012-06-05 21:05 - 2012-07-11 01:01 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-11 01:01 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-11 01:01 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 12:05 - 2012-06-05 11:05 - 17641472 ___RA C:\Advanced Service Inc.2011.QBW
2012-06-05 12:05 - 2012-06-05 11:05 - 02883584 ___RA C:\Advanced Service Inc.2011.QBW.TLG
2012-06-05 12:05 - 2012-06-05 11:05 - 00000375 ____A C:\Advanced Service Inc.2011.QBW.ND
2012-06-05 11:18 - 2012-06-05 11:18 - 00000496 ___RA C:\Advanced Service Inc.2011.lgb
2012-06-05 11:06 - 2012-06-05 11:05 - 00000389 ____A C:\Advanced Service Inc.2011.QBW.DSN
2012-06-05 11:05 - 2012-06-05 11:05 - 00000417 ____A C:\Advanced Service Inc.2011.ND
2012-06-05 11:03 - 2012-04-24 09:03 - 06619136 ___RA C:\Advanced Service Inc..QBW.TLG
2012-06-05 10:03 - 2012-04-24 09:09 - 00000496 ___RA C:\Advanced Service Inc..lgb
2012-06-02 14:19 - 2012-06-20 21:43 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 21:43 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 21:43 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 21:43 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 21:43 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 21:43 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 21:43 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-20 21:43 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-20 21:43 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:45 - 2012-07-11 01:01 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-11 01:01 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-11 01:01 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-11 01:01 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-11 01:01 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 05:48 - 2012-04-10 12:04 - 25780224 ___RA C:\KDS Vending Inc..QBW
2012-06-01 05:48 - 2012-04-10 12:04 - 00327680 ___RA C:\KDS Vending Inc..QBW.TLG
2012-06-01 05:48 - 2012-04-10 12:04 - 00000366 ____A C:\KDS Vending Inc..QBW.ND
2012-06-01 05:46 - 2012-04-10 12:04 - 00000389 ____A C:\KDS Vending Inc..QBW.DSN
2012-05-31 08:25 - 2011-12-25 11:53 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 07:19 - 2012-03-15 11:01 - 00000358 ____A C:\Ability_.QBW.ND
2012-05-29 07:16 - 2012-03-15 11:01 - 28905472 ___RA C:\Ability_.QBW
2012-05-29 07:16 - 2012-03-15 11:01 - 06553600 ___RA C:\Ability_.QBW.TLG
2012-05-22 04:33 - 2012-05-22 04:33 - 01393736 ____A (Citrix Online, a division of Citrix Systems, Inc.) C:\Users\accountant\gotomypc_626.exe
2012-05-21 12:57 - 2012-03-15 11:01 - 00000389 ____A C:\Ability_.QBW.DSN
ZeroAccess:
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\L
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\U
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\L\00000004.@
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\L\201d3dde
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4068.94 MB
Available physical RAM: 3537.97 MB
Total Pagefile: 4067.23 MB
Available Pagefile: 3540.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.68 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:221.54 GB) (Free:161.08 GB) NTFS
3 Drive f: (HIRENS) (Removable) (Total:3.72 GB) (Free:2.88 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:11.29 GB) (Free:6.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 Online 3822 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 11 GB 40 MB
Partition 3 Primary 221 GB 11 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 11 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 221 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3821 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F HIRENS FAT32 Removable 3821 MB Healthy
==================================================================================
Last Boot: 2012-08-06 20:06
======================= End Of Log ==========================
Here's the search.txt
Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 2012-08-16 21:34:19
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\erdnt\cache\services.exe
[2012-08-15 09:54] - [2012-08-15 09:32] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===
I am new to the forum. I'd greatly appreciate a fixlist.txt for this...
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 15-08-2012
Ran by SYSTEM at 16-08-2012 21:24:59
Running from F:\
Windows 7 Professional Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [142616 2011-06-28] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [176408 2011-06-28] (Intel Corporation)
HKLM\...\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2010-10-01] (CyberLink Corp.)
HKLM\...\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-09-17] (CyberLink Corp.)
HKLM\...\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM\...\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2215768 2011-12-06] (Intuit Inc. All rights reserved.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36800 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [823224 2012-07-27] (Adobe Systems Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Default\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1174016 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1174016 2010-11-20] (Microsoft Corporation)
HKU\QBDataServiceUser22\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1174016 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll [X]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
================================ Services (Whitelisted) ==================
2 atashost; "C:\Windows\system32\atashost.exe" [134456 2012-07-17] (Cisco WebEx LLC)
2 CSAPrintService; C:\Windows\csasvc.exe [118784 2009-11-10] (Thomson Reuters)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 GoToAssist; "C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe" Start=service [16680 2012-01-12] (Citrix Online, a division of Citrix Systems, Inc.)
2 jhi_service; C:\Program Files\Intel\Services\IPT\jhi_service.exe [212944 2011-02-23] (Intel Corporation)
2 QBVSS; "C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe" [1248256 2011-08-19] (Intuit Inc.)
3 QuickBooksDB22; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB22 [679936 2011-08-19] (Intuit, Inc.)
3 RoxMediaDB12OEM; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe" [1116656 2010-11-25] (Sonic Solutions)
2 RoxWatch12; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-11-25] (Sonic Solutions)
2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 netvsc; C:\Windows\System32\DRIVERS\netvsc60.sys [126464 2010-11-20] (Microsoft Corporation)
3 SynthVid; C:\Windows\System32\DRIVERS\VMBusVideoM.sys [19456 2010-11-20] (Microsoft Corporation)
3 catchme; \??\C:\Users\ACCOUN~1\AppData\Local\Temp\catchme.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-16 15:31 - 2012-08-16 15:31 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-16 15:26 - 2012-08-16 15:26 - 00254152 ____A (Secure By Design Inc.) C:\Users\accountant\Downloads\Ninite Essentials Installer.exe
2012-08-16 15:19 - 2012-08-16 15:19 - 04009167 ____A C:\Users\accountant\Downloads\ServicesRepair.exe
2012-08-16 15:18 - 2012-08-16 15:18 - 00138120 ____A (ESET) C:\Users\accountant\Downloads\ESETSirefefRemover.exe
2012-08-16 15:13 - 2012-08-16 15:15 - 02030547 ____A C:\Users\accountant\Downloads\EZ_Sirefix.exe
2012-08-16 14:27 - 2012-08-16 14:27 - 00000000 ____D C:\Users\All Users\Sophos
2012-08-16 14:26 - 2012-08-16 14:26 - 77801992 ____A (Sophos Limited) C:\Users\accountant\Downloads\Sophos Virus Removal Tool.exe
2012-08-16 14:26 - 2012-08-16 14:26 - 00003217 ____A C:\Users\accountant\Desktop\Sophos Virus Removal Tool.lnk
2012-08-16 14:26 - 2012-08-16 14:26 - 00000000 ____D C:\Program Files\Sophos
2012-08-16 14:04 - 2008-05-07 21:03 - 00303616 ____A ( ) C:\SetACL.exe
2012-08-16 13:55 - 2012-08-16 14:07 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2012-08-16 13:55 - 2012-08-16 13:55 - 00000207 ____A C:\Windows\tweaking.com-regbackup-ACCOUNTING1A-Microsoft-Windows-7-Professional-(32-bit).dat
2012-08-16 13:55 - 2004-06-11 15:33 - 00290304 ____A (Microsoft Corporation) C:\subinacl.exe
2012-08-16 13:54 - 2012-08-16 13:54 - 00000000 ____D C:\RegBackup
2012-08-16 13:53 - 2012-08-16 13:53 - 00002239 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2012-08-16 13:53 - 2012-08-16 13:53 - 00000000 ____D C:\Program Files\Tweaking.com
2012-08-16 13:49 - 2012-08-16 15:15 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-08-16 13:13 - 2012-08-16 13:13 - 00014705 ____A C:\ComboFix.txt
2012-08-16 13:01 - 2012-08-16 13:01 - 00000000 ____D C:\Users\accountant\AppData\Roaming\TeamViewer
2012-08-16 12:53 - 2012-08-16 12:53 - 00001917 ____A C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2012-08-16 12:32 - 2012-08-16 12:32 - 00000000 ____D C:\Users\All Users\Dumps
2012-08-16 11:26 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00000000 ____D C:\Program Files\Common Files\Java
2012-08-16 10:31 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-16 10:31 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-16 10:31 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-16 10:31 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-16 10:31 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-16 10:31 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-16 10:31 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-16 10:31 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-16 10:31 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-16 10:31 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-16 10:31 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-16 10:31 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-16 10:31 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-16 10:31 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-16 10:30 - 2012-07-18 09:47 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-16 10:30 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-16 10:30 - 2012-07-04 13:14 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-16 10:30 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-16 10:30 - 2012-05-13 20:33 - 00769024 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-16 10:30 - 2012-05-04 23:46 - 00400896 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-16 10:30 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-16 10:30 - 2012-02-10 21:37 - 00317440 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-16 10:19 - 2012-08-16 10:19 - 00000000 ____D C:\Windows\SoftwareDistribution.old
2012-08-16 10:06 - 2012-08-16 10:06 - 00000376 ____A C:\Users\accountant\AppData\Roamingprivacy.xml
2012-08-15 13:49 - 2012-08-16 09:45 - 00000347 ____A C:\Windows\System32\checkdnsid.xml
2012-08-15 13:37 - 2012-08-15 13:37 - 00000000 ____D C:\Users\All Users\bdch
2012-08-15 13:34 - 2012-08-15 13:34 - 00000385 ____A C:\Windows\System32\user_gensett.xml
2012-08-15 13:33 - 2012-08-15 13:33 - 00000000 ____D C:\Users\All Users\BDLogging
2012-08-15 13:33 - 2009-07-14 10:27 - 01461992 ____A (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01009.dll
2012-08-15 13:33 - 2007-04-11 07:11 - 00511328 ____A (Microsoft Corporation) C:\Windows\capicom.dll
2012-08-15 13:32 - 2012-08-16 12:36 - 00000000 ____D C:\Program Files\Bitdefender
2012-08-15 13:32 - 2012-08-16 12:34 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2012-08-15 13:32 - 2012-08-15 13:32 - 02426224 ____A C:\Users\accountant\Downloads\bitdefender_antivirus.exe
2012-08-15 13:32 - 2012-08-15 13:32 - 00000000 ____D C:\Users\accountant\AppData\Roaming\QuickScan
2012-08-15 11:13 - 2012-08-15 11:13 - 00017408 ____A C:\Users\accountant\AppData\Local\WebpageIcons.db
2012-08-15 10:56 - 2012-08-15 10:57 - 181528160 ____A (Kaspersky Lab) C:\Users\accountant\Downloads\kav2012_12.0.0.374aEN_2839.exe
2012-08-15 10:02 - 2012-08-15 10:02 - 03098616 ____A (Secunia) C:\Users\accountant\Downloads\PSISetup.exe
2012-08-15 10:02 - 2012-08-15 10:02 - 00000000 ____D C:\Users\accountant\AppData\Local\Secunia PSI
2012-08-15 10:02 - 2012-08-15 10:02 - 00000000 ____D C:\Program Files\Secunia
2012-08-15 09:40 - 2012-08-16 13:14 - 00000000 ____D C:\Qoobox
2012-08-15 09:40 - 2012-08-15 09:54 - 00000000 ____D C:\Windows\erdnt
2012-08-15 09:40 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-08-15 09:40 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-08-15 09:40 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-08-15 09:40 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-08-15 09:30 - 2012-08-15 09:30 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-15 09:25 - 2012-08-15 09:25 - 00144936 ____A C:\Windows\Minidump\081512-43555-01.dmp
2012-08-15 09:17 - 2012-08-15 09:17 - 00053248 ____A C:\Windows\System32\zlib.dll
2012-08-15 09:16 - 2012-08-16 13:28 - 00000000 ____D C:\Users\accountant\Desktop\D7
2012-08-15 09:15 - 2012-08-16 15:12 - 00000583 ____A C:\Users\accountant\Desktop\notes.txt
2012-08-15 09:10 - 2012-08-15 09:10 - 00000000 ____D C:\smtmp
2012-08-15 09:07 - 2012-08-15 09:10 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6Sr
2012-08-15 09:07 - 2012-08-15 09:10 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6S
2012-08-14 05:58 - 2012-08-15 09:25 - 00000000 ____D C:\Windows\Minidump
2012-08-14 05:58 - 2012-08-14 05:58 - 00151112 ____A C:\Windows\Minidump\081412-47923-01.dmp
2012-08-14 05:57 - 2012-08-15 09:24 - 383022766 ____A C:\Windows\MEMORY.DMP
2012-08-09 12:07 - 2012-08-09 12:07 - 00000496 ___RA C:\CSI Realty Investment LLC6.30.12.lgb
2012-08-09 12:03 - 2012-08-09 13:04 - 17731584 ___RA C:\CSI Realty Investment LLC6.30.12.QBW
2012-08-09 12:03 - 2012-08-09 13:04 - 05373952 ___RA C:\CSI Realty Investment LLC6.30.12.QBW.TLG
2012-08-09 12:03 - 2012-08-09 13:04 - 00000382 ____A C:\CSI Realty Investment LLC6.30.12.QBW.ND
2012-08-09 12:03 - 2012-08-09 12:04 - 00000389 ____A C:\CSI Realty Investment LLC6.30.12.QBW.DSN
2012-08-09 12:03 - 2012-08-09 12:03 - 00000388 ____A C:\CSI Realty Investment LLC6.30.12.ND
2012-08-09 12:03 - 2012-08-09 12:03 - 00000000 ____D C:\Restored_CSI Realty Investment LLC6.30.12_Files
2012-07-31 09:46 - 2012-07-31 09:46 - 00000496 ___RA C:\FL_LARSO.QBB.lgb
2012-07-31 09:40 - 2012-08-09 12:03 - 138842112 ___RA C:\FL_LARSO.QBB.QBW
2012-07-31 09:40 - 2012-08-09 12:03 - 05832704 ___RA C:\FL_LARSO.QBB.QBW.TLG
2012-07-31 09:40 - 2012-08-09 12:03 - 00000362 ____A C:\FL_LARSO.QBB.QBW.ND
2012-07-31 09:40 - 2012-08-09 11:56 - 00000389 ____A C:\FL_LARSO.QBB.QBW.DSN
2012-07-31 09:40 - 2012-07-31 09:40 - 00000393 ____A C:\FL_LARSO.QBB.ND
2012-07-31 09:40 - 2012-07-31 09:40 - 00000000 ____D C:\Restored_FL_LARSO.QBB_Files
2012-07-31 09:39 - 2012-07-31 09:39 - 110243840 ____A C:\FL_LARSON.QBW
2012-07-31 09:39 - 2012-07-31 09:39 - 00000393 ____A C:\FL_LARSON.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 00000389 ____A C:\FL_LARSON.QBW.DSN
2012-07-31 09:39 - 2012-07-31 09:39 - 00000355 ____A C:\FL_LARSON.QBW.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 00000000 ____D C:\Restored_FL_LARSON_Files
2012-07-19 14:20 - 2012-07-19 14:20 - 00000496 ___RA C:\george_a.PICKERING.lgb
2012-07-17 09:03 - 2012-07-19 07:06 - 00000000 ____D C:\Users\All Users\WebEx
2012-07-17 08:58 - 2012-07-17 08:58 - 00170738 ____A C:\Users\accountant\Downloads\WBXRemoveTool.zip
2012-07-17 08:41 - 2012-07-17 08:41 - 00217400 ____A (Cisco WebEx LLC) C:\Windows\System32\atsckernel.exe
2012-07-17 08:41 - 2012-07-17 08:41 - 00134456 ____A (Cisco WebEx LLC) C:\Windows\System32\atashost.exe
============ 3 Months Modified Files ========================
2012-08-16 17:14 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-16 17:14 - 2009-07-13 20:39 - 00049306 ____A C:\Windows\setupact.log
2012-08-16 17:14 - 2009-07-13 20:34 - 00021312 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-16 17:14 - 2009-07-13 20:34 - 00021312 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-16 17:11 - 2011-12-15 07:58 - 01481260 ____A C:\Windows\WindowsUpdate.log
2012-08-16 15:31 - 2012-05-03 06:55 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-16 15:31 - 2010-11-20 13:01 - 00800016 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-16 15:26 - 2012-08-16 15:26 - 00254152 ____A (Secure By Design Inc.) C:\Users\accountant\Downloads\Ninite Essentials Installer.exe
2012-08-16 15:19 - 2012-08-16 15:19 - 04009167 ____A C:\Users\accountant\Downloads\ServicesRepair.exe
2012-08-16 15:18 - 2012-08-16 15:18 - 00138120 ____A (ESET) C:\Users\accountant\Downloads\ESETSirefefRemover.exe
2012-08-16 15:15 - 2012-08-16 15:13 - 02030547 ____A C:\Users\accountant\Downloads\EZ_Sirefix.exe
2012-08-16 15:12 - 2012-08-15 09:15 - 00000583 ____A C:\Users\accountant\Desktop\notes.txt
2012-08-16 14:56 - 2012-04-11 03:57 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-16 14:26 - 2012-08-16 14:26 - 77801992 ____A (Sophos Limited) C:\Users\accountant\Downloads\Sophos Virus Removal Tool.exe
2012-08-16 14:26 - 2012-08-16 14:26 - 00003217 ____A C:\Users\accountant\Desktop\Sophos Virus Removal Tool.lnk
2012-08-16 14:10 - 2011-12-28 05:57 - 00124464 ____A C:\Users\accountant\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-16 14:09 - 2009-07-13 20:33 - 00436384 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 14:07 - 2012-08-16 13:55 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2012-08-16 13:55 - 2012-08-16 13:55 - 00000207 ____A C:\Windows\tweaking.com-regbackup-ACCOUNTING1A-Microsoft-Windows-7-Professional-(32-bit).dat
2012-08-16 13:53 - 2012-08-16 13:53 - 00002239 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2012-08-16 13:15 - 2010-11-20 13:48 - 00123400 ____A C:\Windows\PFRO.log
2012-08-16 13:13 - 2012-08-16 13:13 - 00014705 ____A C:\ComboFix.txt
2012-08-16 13:12 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini
2012-08-16 13:12 - 2009-07-13 18:04 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts_bak_858
2012-08-16 12:53 - 2012-08-16 12:53 - 00001917 ____A C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2012-08-16 11:24 - 2012-08-16 11:24 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-08-16 11:24 - 2012-08-16 11:24 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2012-08-16 11:24 - 2011-12-25 12:03 - 00246760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-08-16 11:24 - 2011-12-25 12:03 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-08-16 11:24 - 2011-12-25 12:03 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-08-16 11:24 - 2011-12-15 08:07 - 00746984 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-08-16 10:34 - 2011-12-25 11:53 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-16 10:06 - 2012-08-16 10:06 - 00000376 ____A C:\Users\accountant\AppData\Roamingprivacy.xml
2012-08-16 09:45 - 2012-08-15 13:49 - 00000347 ____A C:\Windows\System32\checkdnsid.xml
2012-08-15 13:34 - 2012-08-15 13:34 - 00000385 ____A C:\Windows\System32\user_gensett.xml
2012-08-15 13:32 - 2012-08-15 13:32 - 02426224 ____A C:\Users\accountant\Downloads\bitdefender_antivirus.exe
2012-08-15 11:13 - 2012-08-15 11:13 - 00017408 ____A C:\Users\accountant\AppData\Local\WebpageIcons.db
2012-08-15 11:03 - 2012-02-09 05:01 - 00002016 ____A C:\Users\Public\Desktop\Adobe Acrobat X Standard.lnk
2012-08-15 10:57 - 2012-08-15 10:56 - 181528160 ____A (Kaspersky Lab) C:\Users\accountant\Downloads\kav2012_12.0.0.374aEN_2839.exe
2012-08-15 10:56 - 2012-04-11 03:57 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-15 10:56 - 2011-12-15 08:00 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-15 10:02 - 2012-08-15 10:02 - 03098616 ____A (Secunia) C:\Users\accountant\Downloads\PSISetup.exe
2012-08-15 09:25 - 2012-08-15 09:25 - 00144936 ____A C:\Windows\Minidump\081512-43555-01.dmp
2012-08-15 09:24 - 2012-08-14 05:57 - 383022766 ____A C:\Windows\MEMORY.DMP
2012-08-15 09:17 - 2012-08-15 09:17 - 00053248 ____A C:\Windows\System32\zlib.dll
2012-08-15 09:10 - 2012-08-15 09:07 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6Sr
2012-08-15 09:10 - 2012-08-15 09:07 - 00000064 ____A C:\Users\All Users\-o7Df7eFNHOSv6S
2012-08-14 05:58 - 2012-08-14 05:58 - 00151112 ____A C:\Windows\Minidump\081412-47923-01.dmp
2012-08-11 00:07 - 2011-12-28 05:30 - 00000120 ____A C:\Windows\System32\config\netlogon.ftl
2012-08-09 13:04 - 2012-08-09 12:03 - 17731584 ___RA C:\CSI Realty Investment LLC6.30.12.QBW
2012-08-09 13:04 - 2012-08-09 12:03 - 05373952 ___RA C:\CSI Realty Investment LLC6.30.12.QBW.TLG
2012-08-09 13:04 - 2012-08-09 12:03 - 00000382 ____A C:\CSI Realty Investment LLC6.30.12.QBW.ND
2012-08-09 13:04 - 2011-12-28 07:44 - 00000324 ____A C:\Windows\CSAAPP.INI
2012-08-09 12:07 - 2012-08-09 12:07 - 00000496 ___RA C:\CSI Realty Investment LLC6.30.12.lgb
2012-08-09 12:04 - 2012-08-09 12:03 - 00000389 ____A C:\CSI Realty Investment LLC6.30.12.QBW.DSN
2012-08-09 12:03 - 2012-08-09 12:03 - 00000388 ____A C:\CSI Realty Investment LLC6.30.12.ND
2012-08-09 12:03 - 2012-07-31 09:40 - 138842112 ___RA C:\FL_LARSO.QBB.QBW
2012-08-09 12:03 - 2012-07-31 09:40 - 05832704 ___RA C:\FL_LARSO.QBB.QBW.TLG
2012-08-09 12:03 - 2012-07-31 09:40 - 00000362 ____A C:\FL_LARSO.QBB.QBW.ND
2012-08-09 11:56 - 2012-07-31 09:40 - 00000389 ____A C:\FL_LARSO.QBB.QBW.DSN
2012-08-04 03:13 - 2009-07-13 20:53 - 00022182 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-31 09:46 - 2012-07-31 09:46 - 00000496 ___RA C:\FL_LARSO.QBB.lgb
2012-07-31 09:40 - 2012-07-31 09:40 - 00000393 ____A C:\FL_LARSO.QBB.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 110243840 ____A C:\FL_LARSON.QBW
2012-07-31 09:39 - 2012-07-31 09:39 - 00000393 ____A C:\FL_LARSON.ND
2012-07-31 09:39 - 2012-07-31 09:39 - 00000389 ____A C:\FL_LARSON.QBW.DSN
2012-07-31 09:39 - 2012-07-31 09:39 - 00000355 ____A C:\FL_LARSON.QBW.ND
2012-07-31 09:39 - 2012-03-28 04:23 - 00000386 ____A C:\Law Office Of David P Sorrenti, P.C..QBW.ND
2012-07-31 09:39 - 2012-03-28 04:21 - 21295104 ___RA C:\Law Office Of David P Sorrenti, P.C..QBW
2012-07-31 09:39 - 2011-12-28 06:37 - 00589824 ___RA C:\Law Office Of David P Sorrenti, P.C..QBW.TLG
2012-07-31 09:38 - 2012-03-28 04:23 - 00000389 ____A C:\Law Office Of David P Sorrenti, P.C..QBW.DSN
2012-07-30 10:48 - 2012-04-07 11:50 - 03473408 ___RA C:\DICKINSON0910.QBW.TLG
2012-07-30 10:48 - 2012-04-07 11:49 - 72265728 ___RA C:\DICKINSON0910.QBW
2012-07-30 10:48 - 2012-04-07 11:49 - 00000363 ____A C:\DICKINSON0910.QBW.ND
2012-07-23 07:04 - 2012-04-07 11:49 - 00000389 ____A C:\DICKINSON0910.QBW.DSN
2012-07-23 07:03 - 2012-02-28 06:00 - 96026624 ___RA C:\george_a.PICKERING.qbw
2012-07-23 07:03 - 2012-02-28 06:00 - 00327680 ___RA C:\george_a.PICKERING.QBW.TLG
2012-07-23 07:03 - 2012-02-28 06:00 - 00000368 ____A C:\george_a.PICKERING.qbw.ND
2012-07-19 14:20 - 2012-07-19 14:20 - 00000496 ___RA C:\george_a.PICKERING.lgb
2012-07-19 14:20 - 2012-02-28 06:00 - 00000389 ____A C:\george_a.PICKERING.qbw.DSN
2012-07-18 09:47 - 2012-08-16 10:30 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-17 10:48 - 2012-07-02 05:08 - 06684672 ___RA C:\NE Patriot Truck Tire Inc.QBW.TLG
2012-07-17 10:48 - 2012-07-02 05:07 - 198266880 ___RA C:\NE Patriot Truck Tire Inc.QBW
2012-07-17 10:48 - 2012-07-02 05:07 - 00000375 ____A C:\NE Patriot Truck Tire Inc.QBW.ND
2012-07-17 10:33 - 2012-07-02 05:07 - 00000389 ____A C:\NE Patriot Truck Tire Inc.QBW.DSN
2012-07-17 08:58 - 2012-07-17 08:58 - 00170738 ____A C:\Users\accountant\Downloads\WBXRemoveTool.zip
2012-07-17 08:41 - 2012-07-17 08:41 - 00217400 ____A (Cisco WebEx LLC) C:\Windows\System32\atsckernel.exe
2012-07-17 08:41 - 2012-07-17 08:41 - 00134456 ____A (Cisco WebEx LLC) C:\Windows\System32\atashost.exe
2012-07-13 04:04 - 2011-12-28 11:52 - 00001476 ____A C:\Users\accountant\Desktop\ProSystem fx Tax.LNK
2012-07-13 04:04 - 2011-12-28 07:22 - 00670574 ____A C:\sysfile.log
2012-07-12 08:22 - 2012-03-06 10:28 - 00000365 ____A C:\Club eX (PandL).QBW.ND
2012-07-12 08:22 - 2012-03-06 10:27 - 31801344 ___RA C:\Club eX (PandL).QBW
2012-07-12 08:22 - 2012-03-06 10:27 - 03735552 ___RA C:\Club eX (PandL).QBW.TLG
2012-07-12 05:22 - 2012-03-06 10:28 - 00000389 ____A C:\Club eX (PandL).QBW.DSN
2012-07-12 05:21 - 2012-03-12 10:01 - 10616832 ___RA C:\62_PORTER STREET RENTAL.QBW
2012-07-12 05:21 - 2012-03-12 10:01 - 00327680 ___RA C:\62_PORTER STREET RENTAL.QBW.TLG
2012-07-12 05:21 - 2012-03-12 10:01 - 00000389 ____A C:\62_PORTER STREET RENTAL.QBW.DSN
2012-07-12 05:21 - 2012-03-12 10:01 - 00000373 ____A C:\62_PORTER STREET RENTAL.QBW.ND
2012-07-11 23:01 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-11 23:00 - 2012-07-11 23:00 - 00264530 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-04 13:16 - 2012-08-16 10:30 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 13:14 - 2012-08-16 10:30 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 13:14 - 2012-08-16 10:30 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-02 05:17 - 2012-07-02 05:17 - 00000496 ___RA C:\NE Patriot Truck Tire Inc.lgb
2012-07-02 05:08 - 2012-07-02 05:08 - 00000521 ____A C:\NE Patriot Truck Tire Inc.ND
2012-07-02 05:07 - 2012-04-03 06:02 - 00327680 ___RA C:\Dickinson Weymouth Building.QBW.TLG
2012-07-02 05:07 - 2012-04-03 06:01 - 11735040 ___RA C:\Dickinson Weymouth Building.qbw
2012-07-02 05:07 - 2012-04-03 06:01 - 00000389 ____A C:\Dickinson Weymouth Building.qbw.DSN
2012-07-02 05:07 - 2012-04-03 06:01 - 00000377 ____A C:\Dickinson Weymouth Building.qbw.ND
2012-06-28 16:52 - 2012-08-16 10:31 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 16:27 - 2012-08-16 10:31 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 16:16 - 2012-08-16 10:31 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 16:09 - 2012-08-16 10:31 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 16:09 - 2012-08-16 10:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 16:08 - 2012-08-16 10:31 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 16:07 - 2012-08-16 10:31 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 16:06 - 2012-08-16 10:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 16:04 - 2012-08-16 10:31 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 16:04 - 2012-08-16 10:31 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 16:01 - 2012-08-16 10:31 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 16:01 - 2012-08-16 10:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 16:00 - 2012-08-16 10:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 15:57 - 2012-08-16 10:31 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-21 05:27 - 2012-04-10 09:43 - 148955136 ___RA C:\kwalterqbb.QBW
2012-06-21 05:27 - 2012-04-10 09:43 - 02490368 ___RA C:\kwalterqbb.QBW.TLG
2012-06-21 05:27 - 2012-04-10 09:43 - 00000360 ____A C:\kwalterqbb.QBW.ND
2012-06-21 05:26 - 2012-04-10 09:43 - 00000389 ____A C:\kwalterqbb.QBW.DSN
2012-06-19 04:56 - 2012-03-29 12:38 - 00000368 ____A C:\MccormickInsurance.QBW.ND
2012-06-13 23:18 - 2012-03-29 12:38 - 69038080 ___RA C:\MccormickInsurance.QBW
2012-06-13 23:18 - 2012-03-29 12:38 - 00589824 ___RA C:\MccormickInsurance.QBW.TLG
2012-06-12 04:45 - 2012-03-29 12:38 - 00000389 ____A C:\MccormickInsurance.QBW.DSN
2012-06-08 20:41 - 2012-07-11 01:01 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-06 16:59 - 2012-06-06 16:59 - 01070152 ____A (Microsoft Corporation) C:\Windows\System32\MSCOMCTL.OCX
2012-06-05 21:05 - 2012-07-11 01:01 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-11 01:01 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-11 01:01 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 12:05 - 2012-06-05 11:05 - 17641472 ___RA C:\Advanced Service Inc.2011.QBW
2012-06-05 12:05 - 2012-06-05 11:05 - 02883584 ___RA C:\Advanced Service Inc.2011.QBW.TLG
2012-06-05 12:05 - 2012-06-05 11:05 - 00000375 ____A C:\Advanced Service Inc.2011.QBW.ND
2012-06-05 11:18 - 2012-06-05 11:18 - 00000496 ___RA C:\Advanced Service Inc.2011.lgb
2012-06-05 11:06 - 2012-06-05 11:05 - 00000389 ____A C:\Advanced Service Inc.2011.QBW.DSN
2012-06-05 11:05 - 2012-06-05 11:05 - 00000417 ____A C:\Advanced Service Inc.2011.ND
2012-06-05 11:03 - 2012-04-24 09:03 - 06619136 ___RA C:\Advanced Service Inc..QBW.TLG
2012-06-05 10:03 - 2012-04-24 09:09 - 00000496 ___RA C:\Advanced Service Inc..lgb
2012-06-02 14:19 - 2012-06-20 21:43 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 21:43 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 21:43 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 21:43 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 21:43 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 21:43 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 21:43 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-20 21:43 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-20 21:43 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:45 - 2012-07-11 01:01 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-11 01:01 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-11 01:01 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-11 01:01 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-11 01:01 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 05:48 - 2012-04-10 12:04 - 25780224 ___RA C:\KDS Vending Inc..QBW
2012-06-01 05:48 - 2012-04-10 12:04 - 00327680 ___RA C:\KDS Vending Inc..QBW.TLG
2012-06-01 05:48 - 2012-04-10 12:04 - 00000366 ____A C:\KDS Vending Inc..QBW.ND
2012-06-01 05:46 - 2012-04-10 12:04 - 00000389 ____A C:\KDS Vending Inc..QBW.DSN
2012-05-31 08:25 - 2011-12-25 11:53 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 07:19 - 2012-03-15 11:01 - 00000358 ____A C:\Ability_.QBW.ND
2012-05-29 07:16 - 2012-03-15 11:01 - 28905472 ___RA C:\Ability_.QBW
2012-05-29 07:16 - 2012-03-15 11:01 - 06553600 ___RA C:\Ability_.QBW.TLG
2012-05-22 04:33 - 2012-05-22 04:33 - 01393736 ____A (Citrix Online, a division of Citrix Systems, Inc.) C:\Users\accountant\gotomypc_626.exe
2012-05-21 12:57 - 2012-03-15 11:01 - 00000389 ____A C:\Ability_.QBW.DSN
ZeroAccess:
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\L
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\U
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\L\00000004.@
C:\Windows\Installer\{67e3dd18-32c0-b79c-cbac-30c508c782b5}\L\201d3dde
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4068.94 MB
Available physical RAM: 3537.97 MB
Total Pagefile: 4067.23 MB
Available Pagefile: 3540.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.68 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:221.54 GB) (Free:161.08 GB) NTFS
3 Drive f: (HIRENS) (Removable) (Total:3.72 GB) (Free:2.88 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:11.29 GB) (Free:6.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 Online 3822 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 11 GB 40 MB
Partition 3 Primary 221 GB 11 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 11 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 221 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3821 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F HIRENS FAT32 Removable 3821 MB Healthy
==================================================================================
Last Boot: 2012-08-06 20:06
======================= End Of Log ==========================
Here's the search.txt
Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 2012-08-16 21:34:19
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\erdnt\cache\services.exe
[2012-08-15 09:54] - [2012-08-15 09:32] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===