Jason Sizemore
Posts: 16 +0
Good evening -- and thank you very much for any assistance!
Scan result of Farbar Recovery Scan Tool Version: 21-06-2012
Ran by SYSTEM at 21-06-2012 10:34:35
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [610360 2009-09-14] ()
HKLM\...\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe [95728 2009-09-16] (PC-Doctor, Inc.)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [2710856 2009-11-01] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon [767312 2009-09-03] (CANON INC.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-08-24] (Hewlett-Packard)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [YSearchProtection] "C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe" [111856 2009-02-23] (Yahoo! Inc)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2009-09-28] (CANON INC.)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-04-08] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1391272 2012-01-03] (Ask)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Lesley\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet [6276408 2011-06-16] (Yahoo! Inc.)
HKU\Lesley\...\Run: [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe [111856 2009-02-23] (Yahoo! Inc)
HKU\Lesley\...\Run: [cdloader] "C:\Users\Lesley\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK [50592 2010-12-03] (magicJack L.P.)
HKU\Lesley\...\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe [3069192 2010-08-19] (TechSmith Corporation)
HKU\Lesley\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-02-13] (Google Inc.)
HKU\Lesley\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Lesley\...\Run: [Apple] rundll32.exe "C:\Users\Lesley\AppData\Local\Apple Computer\Apple\kfarzsdif.dll",CreateInstance [446976 2012-06-19] (CANON INC.)
HKU\Mcx1-LESLEY-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-13] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\UpdatusUser\...\Run: [Apple] rundll32.exe "C:\Users\Lesley\AppData\Local\Apple Computer\Apple\kfarzsdif.dll",CreateInstance [446976 2012-06-19] (CANON INC.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\PictureMover.lnk
ShortcutTarget: PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
Startup: C:\Users\Lesley\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Lesley\Start Menu\Programs\Startup\Xfire.lnk
ShortcutTarget: Xfire.lnk -> C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.)
==================== Services (Whitelisted) ======
2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-10-13] (Microsoft Corporation)
2 CLDTVHNService; C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [75048 2009-09-17] ()
3 DAUpdaterSvc; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-07-26] (BioWare)
2 HiPatchService; "C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe" [8704 2012-04-05] (Hi-Rez Studios)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 HCW85BDA; C:\Windows\System32\Drivers\HCW85BDA.sys [1705600 2009-09-11] (Hauppauge Computer Works)
0 Lbd; C:\Windows\System32\Drivers\Lbd.sys [69152 2010-09-22] (Lavasoft AB)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
2 ntk_dtv; \??\C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\ntk_dtv_64.sys [82416 2009-09-17] (Cyberlink Corp.)
3 sonydcam; C:\Windows\System32\Drivers\sonydcam.sys [33792 2009-07-13] (Microsoft Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-21 10:21 - 2012-06-21 10:34 - 00000000 ____D C:\FRST
2012-06-20 20:12 - 2012-06-20 20:12 - 00000000 ____A C:\Users\Lesley\Desktop\New Text Document.txt
2012-06-20 19:43 - 2012-06-20 19:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 19:39 - 2012-06-03 20:35 - 56731752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe
2012-06-20 19:21 - 2012-06-20 19:29 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-20 19:16 - 2012-06-20 19:16 - 00000218 ____A C:\Windows\System32\bootdelete.lst
2012-06-20 19:09 - 2012-06-20 20:06 - 00000000 ____D C:\Program Files\HitmanPro
2012-06-20 19:05 - 2012-06-20 19:16 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-20 17:57 - 2012-06-20 17:57 - 00000000 ____D C:\Users\All Users\B7E8586B0004471E0021BF46B4EB2367
2012-06-15 15:00 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-06-15 15:00 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-06-15 11:21 - 2012-06-15 11:21 - 00001169 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-06-14 00:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 00:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 00:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 00:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 00:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 00:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 00:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 00:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 00:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 00:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 00:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 00:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 00:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 00:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 00:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 00:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 00:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 00:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 00:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 00:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 00:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 00:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 00:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 00:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 00:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 00:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 00:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 00:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 12:46 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 12:46 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 12:46 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 12:46 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 12:46 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 12:46 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 12:46 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 12:46 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 12:46 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 12:46 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 12:46 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 12:46 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 12:46 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 12:46 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 12:46 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 12:46 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 12:46 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 18:21 - 2012-06-12 18:21 - 00002778 ____A C:\Users\Lesley\.recently-used.xbel
2012-06-12 14:54 - 2012-06-12 14:54 - 00000044 ____A C:\Users\Lesley\.gtk-bookmarks
2012-06-07 17:03 - 2012-06-07 17:03 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-06-07 16:16 - 2012-06-20 20:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-07 16:16 - 2012-06-07 17:20 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
============ 3 Months Modified Files and Folders =============
2012-06-21 10:34 - 2012-06-21 10:21 - 00000000 ____D C:\FRST
2012-06-21 07:32 - 2009-07-13 21:13 - 00799990 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-21 07:31 - 2011-10-22 10:19 - 00000000 ___RD C:\Users\Lesley\Dropbox
2012-06-21 07:31 - 2011-10-22 10:14 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\Dropbox
2012-06-21 07:31 - 2011-06-27 15:17 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-21 07:30 - 2011-09-27 13:42 - 00011487 ____A C:\Windows\setupact.log
2012-06-21 07:30 - 2009-11-23 23:55 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-21 07:30 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-20 20:12 - 2012-06-20 20:12 - 00000000 ____A C:\Users\Lesley\Desktop\New Text Document.txt
2012-06-20 20:10 - 2009-07-13 21:08 - 00032560 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-20 20:06 - 2012-06-20 19:09 - 00000000 ____D C:\Program Files\HitmanPro
2012-06-20 20:04 - 2012-06-07 16:16 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-20 19:49 - 2009-12-07 02:58 - 01541805 ____A C:\Windows\WindowsUpdate.log
2012-06-20 19:44 - 2011-12-23 17:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-20 19:43 - 2012-06-20 19:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 19:43 - 2011-12-23 17:33 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-20 19:43 - 2010-05-26 11:12 - 00813648 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-20 19:29 - 2012-06-20 19:21 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-20 19:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-20 19:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-20 19:16 - 2012-06-20 19:16 - 00000218 ____A C:\Windows\System32\bootdelete.lst
2012-06-20 19:16 - 2012-06-20 19:05 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-20 18:51 - 2011-09-27 13:42 - 00022182 ____A C:\Windows\PFRO.log
2012-06-20 18:48 - 2011-06-27 15:17 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-20 18:35 - 2010-02-08 22:14 - 00000000 ____D C:\Users\Lesley\AppData\Local\CrashDumps
2012-06-20 18:34 - 2011-10-06 18:55 - 00000000 ____D C:\Users\All Users\Xfire
2012-06-20 18:07 - 2011-11-27 13:26 - 00000258 _RASH C:\Users\All Users\ntuser.pol
2012-06-20 17:57 - 2012-06-20 17:57 - 00000000 ____D C:\Users\All Users\B7E8586B0004471E0021BF46B4EB2367
2012-06-19 23:01 - 2010-02-09 09:13 - 00000000 ____D C:\Users\Lesley\AppData\Local\Apple Computer
2012-06-18 19:39 - 2012-02-25 16:29 - 00000000 ____D C:\Users\Lesley\Desktop\
2012-06-17 18:34 - 2011-10-06 18:55 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\Xfire
2012-06-17 05:19 - 2011-10-22 10:19 - 00001025 ____A C:\Users\Lesley\Desktop\Dropbox.lnk
2012-06-17 05:00 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-06-17 04:23 - 2010-02-10 14:52 - 00000336 ____A C:\Windows\Tasks\HPCeeScheduleForLesley.job
2012-06-15 17:47 - 2010-02-10 14:15 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-15 17:46 - 2010-02-10 14:13 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\HP Support Assistant
2012-06-15 17:46 - 2010-02-09 12:45 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\HpUpdate
2012-06-15 15:02 - 2011-05-27 18:24 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2012-06-15 15:01 - 2011-01-13 02:18 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2012-06-15 11:21 - 2012-06-15 11:21 - 00001169 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-06-15 11:21 - 2011-10-06 18:55 - 00000000 ____D C:\Users\Lesley\AppData\Local\Funcom
2012-06-15 11:21 - 2011-10-06 18:54 - 00000000 ____D C:\Program Files (x86)\Funcom
2012-06-14 18:59 - 2012-05-21 19:25 - 00000000 ____D C:\Users\Lesley\Desktop\ENG 125
2012-06-14 00:24 - 2009-07-13 20:45 - 00434392 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 00:08 - 2010-02-09 08:04 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-14 00:04 - 2010-02-08 12:12 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-12 18:22 - 2011-02-18 22:21 - 00000000 ____D C:\Users\Lesley\.gimp-2.6
2012-06-12 18:21 - 2012-06-12 18:21 - 00002778 ____A C:\Users\Lesley\.recently-used.xbel
2012-06-12 18:21 - 2011-02-18 22:53 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\gtk-2.0
2012-06-12 18:21 - 2010-02-07 23:58 - 00000000 ____D C:\users\Lesley
2012-06-12 14:54 - 2012-06-12 14:54 - 00000044 ____A C:\Users\Lesley\.gtk-bookmarks
2012-06-11 13:49 - 2011-06-27 15:17 - 00002346 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-07 17:20 - 2012-06-07 16:16 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-07 17:20 - 2011-07-14 15:07 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-07 17:03 - 2012-06-07 17:03 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-06-07 16:29 - 2012-02-13 15:02 - 00001976 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-06-03 20:35 - 2012-06-20 19:39 - 56731752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe
2012-06-01 17:35 - 2011-05-06 17:02 - 00001854 ____A C:\GhostObjGAFix.xml
2012-05-31 10:24 - 2010-02-08 12:08 - 00000544 ____A C:\Windows\Tasks\PCDRScheduledMaintenance.job
2012-05-31 00:43 - 2012-04-22 10:37 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-31 00:43 - 2012-04-22 10:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-21 19:25 - 2012-02-11 15:24 - 00000000 ____D C:\Users\Lesley\Desktop\Ashford
2012-05-19 07:03 - 2012-05-19 07:03 - 00000843 ____A C:\Users\Lesley\Downloads\disney-boys.ics
2012-05-17 18:47 - 2012-06-14 00:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 00:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 00:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 00:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 00:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 00:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 00:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 00:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 00:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 00:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 00:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 00:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 00:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 00:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 00:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 00:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 00:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 00:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 00:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 00:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 00:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 00:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 00:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 00:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 00:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 00:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-06-15 15:00 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2010-08-08 20:35 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2010-08-08 20:35 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2010-03-24 20:09 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:48 - 2009-11-23 23:36 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 02:48 - 2009-11-23 23:36 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 01:29 - 2011-10-07 07:56 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2011-10-07 07:56 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2011-10-07 07:56 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2011-10-07 07:56 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2011-10-07 07:56 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 23:21 - 2012-05-14 23:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-14 17:32 - 2012-06-13 12:46 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-12 00:24 - 2011-10-06 18:55 - 00000000 ____D C:\Program Files (x86)\Xfire
2012-05-12 00:00 - 2009-07-13 23:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-09 06:59 - 2010-06-25 17:05 - 00002491 ____A C:\Users\Public\Desktop\Safari.lnk
2012-05-09 06:59 - 2010-06-25 17:05 - 00000000 ____D C:\Program Files (x86)\Safari
2012-05-09 06:58 - 2012-05-09 06:58 - 00001745 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-05-09 06:58 - 2012-05-09 06:58 - 00000000 ____D C:\Program Files\iTunes
2012-05-09 06:58 - 2012-05-09 06:58 - 00000000 ____D C:\Program Files\iPod
2012-05-09 06:58 - 2011-06-13 04:03 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-05-04 03:06 - 2012-06-13 12:46 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 12:46 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 12:46 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-02 18:54 - 2012-05-02 18:54 - 00042392 ____A C:\Windows\SysWOW64\xfcodec.dll
2012-05-02 18:54 - 2012-05-02 18:54 - 00028056 ____A C:\Windows\System32\xfcodec64.dll
2012-05-01 17:35 - 2010-02-08 14:44 - 00001218 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-05-01 00:01 - 2012-05-01 00:00 - 00000000 ____D C:\66bffd94977db677cf795c49bf8a8f
2012-05-01 00:00 - 2012-05-01 00:00 - 00000000 ____D C:\Windows\TempA6C9B4FB-5073-C59C-DCB7-95497F4B8072-Signatures
2012-04-30 21:40 - 2012-06-13 12:46 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 12:46 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 17:39 - 2011-05-20 17:15 - 00001854 ____A C:\Users\Lesley\AppData\Roaming\GhostObjGAFix.xml
2012-04-25 21:41 - 2012-06-13 12:46 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 12:46 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 12:46 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 12:46 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 12:46 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 12:46 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 12:46 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 12:46 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 12:46 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-21 09:21 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-04-20 09:00 - 2012-01-14 19:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-04-20 08:59 - 2012-01-14 19:12 - 00001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-04-16 21:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-14 08:15 - 2012-04-14 08:15 - 00001842 ____A C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
2012-04-14 08:15 - 2012-04-14 08:15 - 00001831 ____A C:\Users\Public\Desktop\Global Agenda Live.lnk
2012-04-14 08:15 - 2011-04-21 10:09 - 00000003 ____A C:\Windows\System32\HRUPPROG.TXT
2012-04-14 08:15 - 2011-04-07 11:25 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2012-04-07 04:31 - 2012-06-13 12:46 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 12:46 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 12:56 - 2010-12-08 17:00 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-31 14:21 - 2011-05-24 17:00 - 00000000 ____D C:\Program Files (x86)\RIFT Game
2012-03-30 03:35 - 2012-05-11 19:22 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-24 15:07 - 2012-03-24 15:07 - 00000000 ____D C:\Users\Lesley\AppData\Local\SWTOR
ZeroAccess:
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\@
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\L
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\n
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U\00000001.@
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U\80000000.@
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U\800000cb.@
ZeroAccess:
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}\@
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}\L
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 8119.08 MB
Available physical RAM: 7154.27 MB
Total Pagefile: 8117.23 MB
Available Pagefile: 7141.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (HP) (Fixed) (Total:920.43 GB) (Free:636.68 GB) NTFS
2 Drive e: (FACTORY_IMAGE) (Fixed) (Total:10.98 GB) (Free:1.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (SHREK) (CDROM) (Total:7.94 GB) (Free:0 GB) UDF
4 Drive g: () (Removable) (Total:0.24 GB) (Free:0.23 GB) FAT
9 Drive x: (Boot) (Fixed) (Total:0.08 GB) (Free:0.07 GB) NTFS
10 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 244 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 920 GB 101 MB
Partition 3 Primary 10 GB 920 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C HP NTFS Partition 920 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FACTORY_IMA NTFS Partition 10 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 244 MB 49 KB
======================================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 244 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-17 22:16
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 21-06-2012
Ran by SYSTEM at 21-06-2012 10:34:35
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [610360 2009-09-14] ()
HKLM\...\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe [95728 2009-09-16] (PC-Doctor, Inc.)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [2710856 2009-11-01] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon [767312 2009-09-03] (CANON INC.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-08-24] (Hewlett-Packard)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [YSearchProtection] "C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe" [111856 2009-02-23] (Yahoo! Inc)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2009-09-28] (CANON INC.)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-04-08] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1391272 2012-01-03] (Ask)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\Lesley\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet [6276408 2011-06-16] (Yahoo! Inc.)
HKU\Lesley\...\Run: [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe [111856 2009-02-23] (Yahoo! Inc)
HKU\Lesley\...\Run: [cdloader] "C:\Users\Lesley\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK [50592 2010-12-03] (magicJack L.P.)
HKU\Lesley\...\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe [3069192 2010-08-19] (TechSmith Corporation)
HKU\Lesley\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-02-13] (Google Inc.)
HKU\Lesley\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Lesley\...\Run: [Apple] rundll32.exe "C:\Users\Lesley\AppData\Local\Apple Computer\Apple\kfarzsdif.dll",CreateInstance [446976 2012-06-19] (CANON INC.)
HKU\Mcx1-LESLEY-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-13] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1685048 2009-09-29] (Hewlett-Packard)
HKU\UpdatusUser\...\Run: [Apple] rundll32.exe "C:\Users\Lesley\AppData\Local\Apple Computer\Apple\kfarzsdif.dll",CreateInstance [446976 2012-06-19] (CANON INC.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\PictureMover.lnk
ShortcutTarget: PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
Startup: C:\Users\Lesley\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Lesley\Start Menu\Programs\Startup\Xfire.lnk
ShortcutTarget: Xfire.lnk -> C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.)
==================== Services (Whitelisted) ======
2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-10-13] (Microsoft Corporation)
2 CLDTVHNService; C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [75048 2009-09-17] ()
3 DAUpdaterSvc; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-07-26] (BioWare)
2 HiPatchService; "C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe" [8704 2012-04-05] (Hi-Rez Studios)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 HCW85BDA; C:\Windows\System32\Drivers\HCW85BDA.sys [1705600 2009-09-11] (Hauppauge Computer Works)
0 Lbd; C:\Windows\System32\Drivers\Lbd.sys [69152 2010-09-22] (Lavasoft AB)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
2 ntk_dtv; \??\C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\ntk_dtv_64.sys [82416 2009-09-17] (Cyberlink Corp.)
3 sonydcam; C:\Windows\System32\Drivers\sonydcam.sys [33792 2009-07-13] (Microsoft Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-21 10:21 - 2012-06-21 10:34 - 00000000 ____D C:\FRST
2012-06-20 20:12 - 2012-06-20 20:12 - 00000000 ____A C:\Users\Lesley\Desktop\New Text Document.txt
2012-06-20 19:43 - 2012-06-20 19:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 19:39 - 2012-06-03 20:35 - 56731752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe
2012-06-20 19:21 - 2012-06-20 19:29 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-20 19:16 - 2012-06-20 19:16 - 00000218 ____A C:\Windows\System32\bootdelete.lst
2012-06-20 19:09 - 2012-06-20 20:06 - 00000000 ____D C:\Program Files\HitmanPro
2012-06-20 19:05 - 2012-06-20 19:16 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-20 17:57 - 2012-06-20 17:57 - 00000000 ____D C:\Users\All Users\B7E8586B0004471E0021BF46B4EB2367
2012-06-15 15:00 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-06-15 15:00 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-06-15 15:00 - 2012-05-15 02:48 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-06-15 11:21 - 2012-06-15 11:21 - 00001169 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-06-14 00:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 00:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 00:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 00:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 00:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 00:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 00:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 00:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 00:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 00:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 00:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 00:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 00:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 00:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 00:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 00:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 00:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 00:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 00:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 00:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 00:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 00:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 00:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 00:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 00:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 00:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 00:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 00:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 12:46 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 12:46 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 12:46 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 12:46 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 12:46 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 12:46 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 12:46 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 12:46 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 12:46 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 12:46 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 12:46 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 12:46 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 12:46 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 12:46 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 12:46 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 12:46 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 12:46 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 18:21 - 2012-06-12 18:21 - 00002778 ____A C:\Users\Lesley\.recently-used.xbel
2012-06-12 14:54 - 2012-06-12 14:54 - 00000044 ____A C:\Users\Lesley\.gtk-bookmarks
2012-06-07 17:03 - 2012-06-07 17:03 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-06-07 16:16 - 2012-06-20 20:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-07 16:16 - 2012-06-07 17:20 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
============ 3 Months Modified Files and Folders =============
2012-06-21 10:34 - 2012-06-21 10:21 - 00000000 ____D C:\FRST
2012-06-21 07:32 - 2009-07-13 21:13 - 00799990 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-21 07:31 - 2011-10-22 10:19 - 00000000 ___RD C:\Users\Lesley\Dropbox
2012-06-21 07:31 - 2011-10-22 10:14 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\Dropbox
2012-06-21 07:31 - 2011-06-27 15:17 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-21 07:30 - 2011-09-27 13:42 - 00011487 ____A C:\Windows\setupact.log
2012-06-21 07:30 - 2009-11-23 23:55 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-21 07:30 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-20 20:12 - 2012-06-20 20:12 - 00000000 ____A C:\Users\Lesley\Desktop\New Text Document.txt
2012-06-20 20:10 - 2009-07-13 21:08 - 00032560 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-20 20:06 - 2012-06-20 19:09 - 00000000 ____D C:\Program Files\HitmanPro
2012-06-20 20:04 - 2012-06-07 16:16 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-20 19:49 - 2009-12-07 02:58 - 01541805 ____A C:\Windows\WindowsUpdate.log
2012-06-20 19:44 - 2011-12-23 17:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-20 19:43 - 2012-06-20 19:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 19:43 - 2011-12-23 17:33 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-20 19:43 - 2010-05-26 11:12 - 00813648 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-20 19:29 - 2012-06-20 19:21 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-20 19:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-20 19:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-20 19:16 - 2012-06-20 19:16 - 00000218 ____A C:\Windows\System32\bootdelete.lst
2012-06-20 19:16 - 2012-06-20 19:05 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-20 18:51 - 2011-09-27 13:42 - 00022182 ____A C:\Windows\PFRO.log
2012-06-20 18:48 - 2011-06-27 15:17 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-20 18:35 - 2010-02-08 22:14 - 00000000 ____D C:\Users\Lesley\AppData\Local\CrashDumps
2012-06-20 18:34 - 2011-10-06 18:55 - 00000000 ____D C:\Users\All Users\Xfire
2012-06-20 18:07 - 2011-11-27 13:26 - 00000258 _RASH C:\Users\All Users\ntuser.pol
2012-06-20 17:57 - 2012-06-20 17:57 - 00000000 ____D C:\Users\All Users\B7E8586B0004471E0021BF46B4EB2367
2012-06-19 23:01 - 2010-02-09 09:13 - 00000000 ____D C:\Users\Lesley\AppData\Local\Apple Computer
2012-06-18 19:39 - 2012-02-25 16:29 - 00000000 ____D C:\Users\Lesley\Desktop\
2012-06-17 18:34 - 2011-10-06 18:55 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\Xfire
2012-06-17 05:19 - 2011-10-22 10:19 - 00001025 ____A C:\Users\Lesley\Desktop\Dropbox.lnk
2012-06-17 05:00 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-06-17 04:23 - 2010-02-10 14:52 - 00000336 ____A C:\Windows\Tasks\HPCeeScheduleForLesley.job
2012-06-15 17:47 - 2010-02-10 14:15 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-15 17:46 - 2010-02-10 14:13 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\HP Support Assistant
2012-06-15 17:46 - 2010-02-09 12:45 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\HpUpdate
2012-06-15 15:02 - 2011-05-27 18:24 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2012-06-15 15:01 - 2011-01-13 02:18 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2012-06-15 11:21 - 2012-06-15 11:21 - 00001169 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-06-15 11:21 - 2011-10-06 18:55 - 00000000 ____D C:\Users\Lesley\AppData\Local\Funcom
2012-06-15 11:21 - 2011-10-06 18:54 - 00000000 ____D C:\Program Files (x86)\Funcom
2012-06-14 18:59 - 2012-05-21 19:25 - 00000000 ____D C:\Users\Lesley\Desktop\ENG 125
2012-06-14 00:24 - 2009-07-13 20:45 - 00434392 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 00:08 - 2010-02-09 08:04 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-14 00:04 - 2010-02-08 12:12 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-12 18:22 - 2011-02-18 22:21 - 00000000 ____D C:\Users\Lesley\.gimp-2.6
2012-06-12 18:21 - 2012-06-12 18:21 - 00002778 ____A C:\Users\Lesley\.recently-used.xbel
2012-06-12 18:21 - 2011-02-18 22:53 - 00000000 ____D C:\Users\Lesley\AppData\Roaming\gtk-2.0
2012-06-12 18:21 - 2010-02-07 23:58 - 00000000 ____D C:\users\Lesley
2012-06-12 14:54 - 2012-06-12 14:54 - 00000044 ____A C:\Users\Lesley\.gtk-bookmarks
2012-06-11 13:49 - 2011-06-27 15:17 - 00002346 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-07 17:20 - 2012-06-07 16:16 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-07 17:20 - 2011-07-14 15:07 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-07 17:03 - 2012-06-07 17:03 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-06-07 16:29 - 2012-02-13 15:02 - 00001976 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-06-03 20:35 - 2012-06-20 19:39 - 56731752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe
2012-06-01 17:35 - 2011-05-06 17:02 - 00001854 ____A C:\GhostObjGAFix.xml
2012-05-31 10:24 - 2010-02-08 12:08 - 00000544 ____A C:\Windows\Tasks\PCDRScheduledMaintenance.job
2012-05-31 00:43 - 2012-04-22 10:37 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-31 00:43 - 2012-04-22 10:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-21 19:25 - 2012-02-11 15:24 - 00000000 ____D C:\Users\Lesley\Desktop\Ashford
2012-05-19 07:03 - 2012-05-19 07:03 - 00000843 ____A C:\Users\Lesley\Downloads\disney-boys.ics
2012-05-17 18:47 - 2012-06-14 00:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 00:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 00:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 00:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 00:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 00:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 00:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 00:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 00:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 00:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 00:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 00:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 00:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 00:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 00:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 00:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 00:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 00:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 00:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 00:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 00:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 00:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 00:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 00:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 00:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 00:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-06-15 15:00 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-06-15 15:00 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2011-10-07 07:55 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2010-08-08 20:35 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2010-08-08 20:35 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2010-03-24 20:09 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:48 - 2009-11-23 23:36 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 02:48 - 2009-11-23 23:36 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 01:29 - 2011-10-07 07:56 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2011-10-07 07:56 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2011-10-07 07:56 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2011-10-07 07:56 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2011-10-07 07:56 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 23:21 - 2012-05-14 23:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-14 17:32 - 2012-06-13 12:46 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-12 00:24 - 2011-10-06 18:55 - 00000000 ____D C:\Program Files (x86)\Xfire
2012-05-12 00:00 - 2009-07-13 23:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-09 06:59 - 2010-06-25 17:05 - 00002491 ____A C:\Users\Public\Desktop\Safari.lnk
2012-05-09 06:59 - 2010-06-25 17:05 - 00000000 ____D C:\Program Files (x86)\Safari
2012-05-09 06:58 - 2012-05-09 06:58 - 00001745 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-05-09 06:58 - 2012-05-09 06:58 - 00000000 ____D C:\Program Files\iTunes
2012-05-09 06:58 - 2012-05-09 06:58 - 00000000 ____D C:\Program Files\iPod
2012-05-09 06:58 - 2011-06-13 04:03 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-05-04 03:06 - 2012-06-13 12:46 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 12:46 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 12:46 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-02 18:54 - 2012-05-02 18:54 - 00042392 ____A C:\Windows\SysWOW64\xfcodec.dll
2012-05-02 18:54 - 2012-05-02 18:54 - 00028056 ____A C:\Windows\System32\xfcodec64.dll
2012-05-01 17:35 - 2010-02-08 14:44 - 00001218 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-05-01 00:01 - 2012-05-01 00:00 - 00000000 ____D C:\66bffd94977db677cf795c49bf8a8f
2012-05-01 00:00 - 2012-05-01 00:00 - 00000000 ____D C:\Windows\TempA6C9B4FB-5073-C59C-DCB7-95497F4B8072-Signatures
2012-04-30 21:40 - 2012-06-13 12:46 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 12:46 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 17:39 - 2011-05-20 17:15 - 00001854 ____A C:\Users\Lesley\AppData\Roaming\GhostObjGAFix.xml
2012-04-25 21:41 - 2012-06-13 12:46 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 12:46 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 12:46 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 12:46 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 12:46 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 12:46 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 12:46 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 12:46 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 12:46 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-21 09:21 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-04-20 09:00 - 2012-01-14 19:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-04-20 08:59 - 2012-01-14 19:12 - 00001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-04-16 21:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-14 08:15 - 2012-04-14 08:15 - 00001842 ____A C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
2012-04-14 08:15 - 2012-04-14 08:15 - 00001831 ____A C:\Users\Public\Desktop\Global Agenda Live.lnk
2012-04-14 08:15 - 2011-04-21 10:09 - 00000003 ____A C:\Windows\System32\HRUPPROG.TXT
2012-04-14 08:15 - 2011-04-07 11:25 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2012-04-07 04:31 - 2012-06-13 12:46 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 12:46 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 12:56 - 2010-12-08 17:00 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-31 14:21 - 2011-05-24 17:00 - 00000000 ____D C:\Program Files (x86)\RIFT Game
2012-03-30 03:35 - 2012-05-11 19:22 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-24 15:07 - 2012-03-24 15:07 - 00000000 ____D C:\Users\Lesley\AppData\Local\SWTOR
ZeroAccess:
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\@
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\L
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\n
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U\00000001.@
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U\80000000.@
C:\Windows\Installer\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U\800000cb.@
ZeroAccess:
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}\@
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}\L
C:\Users\Lesley\AppData\Local\{158c8fff-81b9-d19c-0d64-10c52a39c730}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 8119.08 MB
Available physical RAM: 7154.27 MB
Total Pagefile: 8117.23 MB
Available Pagefile: 7141.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (HP) (Fixed) (Total:920.43 GB) (Free:636.68 GB) NTFS
2 Drive e: (FACTORY_IMAGE) (Fixed) (Total:10.98 GB) (Free:1.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (SHREK) (CDROM) (Total:7.94 GB) (Free:0 GB) UDF
4 Drive g: () (Removable) (Total:0.24 GB) (Free:0.23 GB) FAT
9 Drive x: (Boot) (Fixed) (Total:0.08 GB) (Free:0.07 GB) NTFS
10 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 244 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 920 GB 101 MB
Partition 3 Primary 10 GB 920 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C HP NTFS Partition 920 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E FACTORY_IMA NTFS Partition 10 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 244 MB 49 KB
======================================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 244 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-17 22:16
======================= End Of Log ==========================