hekawila
Posts: 23 +0
Hi,
PC started having problems a couple of days ago. Now every time I log in a critical error message occurs causing the computer to restart in 60 secs. Therefore most of the preliminary steps I have been unable to do.
I anticipation of your request to use Farbar I have pasted the log below.
Many many thanks for your help:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 16-07-2012 01
Ran by SYSTEM at 20-07-2012 22:48:54
Running from J:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [8120864 2009-12-03] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-06-03] (CyberLink)
HKLM\...\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [x]
HKLM\...\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" [2587008 2012-04-04] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [488984 2007-02-07] (Logitech Inc.)
HKLM\...\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide [774168 2007-02-07] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Henry Desktop\...\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-12] (BitTorrent, Inc.)
HKU\Henry Desktop\...\Run: [Google Update] "C:\Users\Henry Desktop\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-04-04] (Google Inc.)
HKU\Henry Desktop\...\Run: [Grid Service] "C:\Program Files\GridService\peer.exe" -n Grid [4993024 2008-12-30] (FS2YOU)
HKU\Test\...\Run: [Google Update] "C:\Users\Test\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-04-14] (Google Inc.)
HKU\Test\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2009-07-13] (Microsoft Corporation)
HKU\Test\...\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-12] (BitTorrent, Inc.)
HKU\Test\...\Run: [3RVX] C:\Program Files\3RVX\3RVX.exe [159232 2008-10-13] (matt.malensek.net)
HKU\Test\...\Run: [Radio Downloader] "C:\Program Files\Radio Downloader\Radio Downloader.exe" /hidemainwindow [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\Henry Desktop\Start Menu\Programs\Startup\PS3 Media Server.lnk
ShortcutTarget: PS3 Media Server.lnk -> C:\Program Files\PS3 Media Server\PMS.exe (PS3 Media Server)
================================ Services (Whitelisted) ==================
4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [284672 2011-01-04] (Advanced Micro Devices, Inc.)
4 AMD Reservation Manager; "C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe" [140224 2010-06-16] (Advanced Micro Devices)
4 AVGIDSAgent; "C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe" [5160568 2012-07-04] (AVG Technologies CZ, s.r.o.)
4 avgwd; "C:\Program Files\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-13] (AVG Technologies CZ, s.r.o.)
4 BecHelperService; C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe [1737464 2010-01-28] ()
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
4 LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [105248 2007-02-06] (Logitech Inc.)
4 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] ()
4 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-06-19] (Skype Technologies S.A.)
4 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-02-28] (Skype Technologies)
4 LVPrcSrv; c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
4 PSI_SVC_2; "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" [x]
2 RoxLiveShare10; "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" [x]
2 SessionLauncher; C:\Users\Test\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
========================== Drivers (Whitelisted) =============
0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11832 2009-07-07] (Advanced Micro Devices Inc.)
3 AtiHdmiService; C:\Windows\System32\drivers\AtiHdmi.sys [100352 2009-11-18] (ATI Technologies, Inc.)
3 CamDrL; C:\Windows\System32\DRIVERS\Camdrl.sys [1075360 2007-02-03] (Logitech Inc.)
3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
0 DasBoot; C:\Windows\system32\drivers\DasBoot.SYS [20744 2012-01-17] ()
0 DasBootF; C:\Windows\system32\drivers\DasBootF.SYS [59272 2012-01-17] ()
3 DroidCam; C:\Windows\System32\drivers\droidcam.sys [22656 2012-03-24] (Dev47Apps)
3 HTCAND32; C:\Windows\System32\Drivers\ANDROIDUSB.sys [25088 2009-10-26] (HTC, Corporation)
3 htcnprot; C:\Windows\System32\DRIVERS\htcnprot.sys [23040 2010-06-23] (Windows (R) Win 7 DDK provider)
3 LVcKap; C:\Windows\System32\DRIVERS\LVcKap.sys [1691808 2007-02-06] ()
3 LVMVDrv; C:\Windows\System32\DRIVERS\LVMVDrv.sys [1964064 2007-02-06] (Logitech Inc.)
3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25632 2007-02-06] ()
3 LVUSBSta; C:\Windows\System32\DRIVERS\LVUSBSta.sys [41504 2007-02-03] (Logitech Inc.)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-07-19] (Malwarebytes Corporation)
2 mdvrmng; \??\C:\Windows\system32\drivers\mdvrmng.sys [10240 2010-01-28] ()
3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [48640 2010-03-18] (MotioninJoy)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 PRSBDrvr; C:\Windows\System32\DRIVERS\PRSBDrvr.sys [28424 2012-01-17] ()
3 RTL8192su; C:\Windows\System32\DRIVERS\RTL8192su.sys [597536 2010-02-05] (Realtek Semiconductor Corporation )
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [15872 2009-07-13] (Microsoft Corporation)
3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [61984 2009-11-24] (Microsoft Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-20 21:52 - 2012-07-20 22:11 - 00000000 ____D C:\FRST
2012-07-20 13:25 - 2012-07-20 13:25 - 00100864 ____A (GMER) C:\ffxdrpog.sys
2012-07-20 13:24 - 2012-07-20 13:24 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rtuppmes.sys
2012-07-20 13:21 - 2011-07-16 13:21 - 00302592 ____A C:\Users\Henry Desktop\Desktop\gmer.exe
2012-07-19 14:23 - 2012-01-17 12:55 - 00028424 ____A C:\Windows\System32\Drivers\PRSBDrvr.sys
2012-07-19 14:08 - 2012-07-19 14:16 - 00193850 ____A C:\Windows\System32\PHOOKSmf2.TXT
2012-07-19 14:06 - 2012-07-20 13:25 - 00185898 ____A C:\Windows\System32\PHOOKSmf.txt
2012-07-19 14:04 - 2012-07-20 13:21 - 00000000 ____D C:\Windows\System32\DBBK
2012-07-19 14:04 - 2012-07-19 14:23 - 00103218 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe.log
2012-07-19 14:04 - 2012-07-19 14:01 - 01415784 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe
2012-07-19 14:04 - 2012-03-22 08:17 - 00225664 ____A C:\Windows\System32\Drivers\DasBootS.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00059272 ____A C:\Windows\System32\Drivers\DasBootF.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00027528 ____A C:\Windows\System32\Drivers\DasBootK.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00020744 ____A C:\Windows\System32\Drivers\DasBoot.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00009096 ____A C:\Windows\System32\Drivers\DasBootI.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00009096 ____A C:\Windows\System32\Drivers\DasBootE.SYS
2012-07-19 14:04 - 2010-05-03 17:37 - 00003072 ____A C:\Windows\System32\Drivers\DasBootD.SYS
2012-07-19 13:12 - 2012-07-19 13:12 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-07-18 22:22 - 2012-07-18 22:22 - 04024320 ____A C:\Program Files\GUT1813.tmp
2012-07-18 22:22 - 2012-07-18 22:22 - 00000000 ____D C:\Program Files\GUM1812.tmp
2012-07-18 22:21 - 2012-07-18 22:21 - 00005543 ____A C:\Windows\System32\commonpriv.log
2012-07-18 22:21 - 2012-07-18 22:21 - 00000000 ____A C:\Windows\System32\commonpriv.log.lock
2012-07-18 22:12 - 2012-07-18 22:13 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-18 15:41 - 2012-07-18 15:46 - 363740113 ____A C:\Users\Test\Desktop\WI-03-HDz.mp4
2012-07-18 15:36 - 2012-07-18 15:41 - 352755015 ____A C:\Users\Test\Desktop\WI-04-HDz.mp4
2012-07-18 13:50 - 2012-07-18 15:01 - 213900562 ____A C:\Users\Test\Desktop\WI-03-HDz.rmvb
2012-07-18 13:50 - 2012-07-18 14:41 - 211327234 ____A C:\Users\Test\Desktop\WI-04-HDz.rmvb
2012-07-18 13:48 - 2012-07-18 13:54 - 38093336 ____A C:\Users\Test\Desktop\WI-02-HDz.rmvb
2012-07-17 22:16 - 2012-07-17 23:09 - 00000000 ____D C:\Users\Test\Downloads\Witness Insecurity Epi 1 to 2
2012-07-17 22:16 - 2012-07-17 23:01 - 281410256 ____A C:\Users\Test\Downloads\Blackout.1x03.HDTV.x264-FoV.mp4
2012-07-17 12:41 - 2012-07-17 12:41 - 03875048 ____A (AVG Technologies) C:\Users\Test\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-16 14:05 - 2012-07-16 14:16 - 651161283 ____A C:\Users\Test\Desktop\TC-E05-TVBN.mp4
2012-07-16 14:04 - 2012-07-16 14:03 - 458485249 ____A C:\Users\Test\Desktop\TC-E05-TVBN.rmvb
2012-07-16 13:56 - 2012-07-16 14:03 - 00000000 ____D C:\Users\Test\Downloads\Tiger Cubs
2012-07-15 14:09 - 2012-07-15 14:19 - 535306122 ____A C:\Users\Test\Desktop\TVBOXNOW-Tiger-Cubs-Ch04.mp4
2012-07-15 08:12 - 2012-07-15 08:30 - 1464984547 ____A C:\Users\Test\Downloads\The.Four.2012.DVDRip.x264.AAC-CkreleaSe.mkv
2012-07-15 08:11 - 2012-07-15 08:11 - 00000000 ____D C:\Users\Test\Downloads\The.Four.2012.DVDscr.x264.AC3-JYK
2012-07-14 22:15 - 2012-07-14 22:16 - 00000000 ____D C:\Users\All Users\6C82ED420009B0E872A08290F875F020
2012-07-12 13:55 - 2012-07-12 14:03 - 383421941 ____A C:\Users\Test\Downloads\Blackout.S01E01.HDTV.x264-TLA.mp4
2012-07-12 13:55 - 2012-07-12 14:02 - 318454617 ____A C:\Users\Test\Downloads\Blackout.1x02.HDTV.x264-FoV.mp4
2012-07-10 15:14 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 15:14 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 15:14 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 15:14 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 15:14 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 15:14 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 15:14 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 15:14 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 15:14 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 15:14 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 15:14 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 15:13 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 15:13 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 15:13 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 15:09 - 2012-07-10 15:09 - 00263480 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-10 15:09 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 13:04 - 2012-07-10 13:07 - 00000000 ____D C:\Users\Test\Downloads\Lockout {2012} DVDRIP. Jaybob
2012-07-10 12:15 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 12:15 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 12:15 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 12:15 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 12:15 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 12:15 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 12:14 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 12:14 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 12:14 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 12:14 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-10 12:14 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-10 12:14 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-10 12:14 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-02 22:12 - 2012-07-02 22:21 - 587214217 ____A C:\Users\Test\Desktop\TVBOXNOW_Tiger_Cubs_Ch02.mp4
2012-06-29 23:35 - 2012-06-30 06:03 - 00000000 ____D C:\Users\Test\Downloads\Nightfall.2012.BDRip.x264.AC3-theonlyh
2012-06-25 22:08 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-25 22:08 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-25 22:08 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-25 22:08 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-25 22:07 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-25 22:07 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-25 22:07 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-25 22:07 - 2012-06-02 06:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-25 22:07 - 2012-06-02 06:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-25 07:04 - 2012-06-25 07:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-25 02:29 - 2012-06-25 02:31 - 00000000 ____D C:\Users\Test\Desktop\MumJanice
2012-06-24 08:44 - 2012-06-24 08:57 - 76529032 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E09.HDTV.x264-LOL.mp4
2012-06-24 07:05 - 2012-06-24 07:21 - 328288462 ____A C:\Users\Test\Downloads\Continuum.S01E04.HDTV.x264-2HD.mp4
2012-06-24 07:05 - 2012-06-24 07:16 - 321097571 ____A C:\Users\Test\Downloads\Continuum.S01E03.HDTV.x264-2HD.mp4
2012-06-24 06:58 - 2012-06-24 07:14 - 292296605 ____A C:\Users\Test\Downloads\Continuum.S01E02.HDTV.x264-2HD.mp4
2012-06-24 05:33 - 2012-06-24 05:47 - 306667368 ____A C:\Users\Test\Downloads\Continuum.S01E01.HDTV.x264-2HD.mp4
2012-06-23 23:33 - 2012-06-23 23:48 - 00000000 ____D C:\Users\Test\Downloads\LMFAO - Sorry For Party Rocking (DeLuxe Edition) 320KB (2011) TBS
2012-06-23 23:30 - 2012-06-24 14:29 - 00000000 ____D C:\Users\Test\Downloads\Flo_Rida-R.O.O.T.S-(RapGodFathers.com)
2012-06-23 15:44 - 2012-06-23 21:38 - 00000000 ____D C:\Users\Test\Downloads\Flo-Rida-Mail.On.Sunday-(2008)-[NoFS]
2012-06-22 23:13 - 2012-06-23 01:45 - 725708800 ____A C:\Users\Test\Downloads\Love.Lifting.CAN.avi
2012-06-21 22:40 - 2012-06-21 22:47 - 00000000 ____D C:\Users\Test\Downloads\A Simple Life.2011.BDRip.AC3.x264-LooKMaNe
============ 3 Months Modified Files ========================
2012-07-20 13:25 - 2012-07-20 13:25 - 00100864 ____A (GMER) C:\ffxdrpog.sys
2012-07-20 13:25 - 2012-07-19 14:06 - 00185898 ____A C:\Windows\System32\PHOOKSmf.txt
2012-07-20 13:24 - 2012-07-20 13:24 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rtuppmes.sys
2012-07-20 13:24 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-20 13:23 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-20 13:23 - 2009-07-13 20:39 - 00202449 ____A C:\Windows\setupact.log
2012-07-19 14:23 - 2012-07-19 14:04 - 00103218 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe.log
2012-07-19 14:16 - 2012-07-19 14:08 - 00193850 ____A C:\Windows\System32\PHOOKSmf2.TXT
2012-07-19 14:07 - 2011-04-14 12:21 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1004UA.job
2012-07-19 14:01 - 2012-07-19 14:04 - 01415784 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe
2012-07-19 13:42 - 2010-10-03 09:48 - 00287232 __ASH C:\Users\Henry Desktop\Thumbs.db
2012-07-19 13:31 - 2010-04-08 10:32 - 06241792 __ASH C:\Users\Henry Desktop\Desktop\Thumbs.db
2012-07-19 13:12 - 2012-07-19 13:12 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-07-19 13:07 - 2011-04-14 12:21 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1004Core.job
2012-07-18 22:26 - 2010-04-04 14:45 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1001UA.job
2012-07-18 22:26 - 2010-04-04 14:45 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1001Core.job
2012-07-18 22:22 - 2012-07-18 22:22 - 04024320 ____A C:\Program Files\GUT1813.tmp
2012-07-18 22:21 - 2012-07-18 22:21 - 00005543 ____A C:\Windows\System32\commonpriv.log
2012-07-18 22:21 - 2012-07-18 22:21 - 00000000 ____A C:\Windows\System32\commonpriv.log.lock
2012-07-18 22:20 - 2010-02-16 08:03 - 00038296 ____A C:\Windows\PFRO.log
2012-07-18 22:13 - 2012-02-01 23:36 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-18 22:13 - 2010-04-04 14:35 - 01217789 ____A C:\Windows\WindowsUpdate.log
2012-07-18 22:12 - 2010-02-15 08:52 - 00752288 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-18 22:09 - 2009-07-13 20:34 - 00009920 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-18 22:09 - 2009-07-13 20:34 - 00009920 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-18 15:47 - 2012-04-27 12:39 - 00055214 ____A C:\MP4debug.log
2012-07-18 15:46 - 2012-07-18 15:41 - 363740113 ____A C:\Users\Test\Desktop\WI-03-HDz.mp4
2012-07-18 15:41 - 2012-07-18 15:36 - 352755015 ____A C:\Users\Test\Desktop\WI-04-HDz.mp4
2012-07-18 15:01 - 2012-07-18 13:50 - 213900562 ____A C:\Users\Test\Desktop\WI-03-HDz.rmvb
2012-07-18 14:41 - 2012-07-18 13:50 - 211327234 ____A C:\Users\Test\Desktop\WI-04-HDz.rmvb
2012-07-18 13:54 - 2012-07-18 13:48 - 38093336 ____A C:\Users\Test\Desktop\WI-02-HDz.rmvb
2012-07-17 23:01 - 2012-07-17 22:16 - 281410256 ____A C:\Users\Test\Downloads\Blackout.1x03.HDTV.x264-FoV.mp4
2012-07-17 12:54 - 2011-12-23 01:08 - 00000939 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-07-17 12:41 - 2012-07-17 12:41 - 03875048 ____A (AVG Technologies) C:\Users\Test\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-16 14:16 - 2012-07-16 14:05 - 651161283 ____A C:\Users\Test\Desktop\TC-E05-TVBN.mp4
2012-07-16 14:03 - 2012-07-16 14:04 - 458485249 ____A C:\Users\Test\Desktop\TC-E05-TVBN.rmvb
2012-07-15 14:19 - 2012-07-15 14:09 - 535306122 ____A C:\Users\Test\Desktop\TVBOXNOW-Tiger-Cubs-Ch04.mp4
2012-07-15 08:30 - 2012-07-15 08:12 - 1464984547 ____A C:\Users\Test\Downloads\The.Four.2012.DVDRip.x264.AAC-CkreleaSe.mkv
2012-07-14 22:26 - 2010-04-04 14:46 - 00002448 ____A C:\Users\Henry Desktop\Desktop\Google Chrome.lnk
2012-07-12 14:03 - 2012-07-12 13:55 - 383421941 ____A C:\Users\Test\Downloads\Blackout.S01E01.HDTV.x264-TLA.mp4
2012-07-12 14:02 - 2012-07-12 13:55 - 318454617 ____A C:\Users\Test\Downloads\Blackout.1x02.HDTV.x264-FoV.mp4
2012-07-11 22:05 - 2011-04-14 12:22 - 00002403 ____A C:\Users\Test\Desktop\Google Chrome.lnk
2012-07-10 22:06 - 2009-07-13 20:33 - 00462472 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 15:13 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-10 15:09 - 2012-07-10 15:09 - 00263480 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-10 15:09 - 2010-02-16 02:43 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-08 13:00 - 2010-04-15 10:48 - 00000400 ____A C:\Windows\Tasks\SmartDefrag.job
2012-07-08 02:41 - 2011-10-09 08:41 - 00000004 ____A C:\authres.html
2012-07-03 04:46 - 2011-04-04 13:58 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 22:21 - 2012-07-02 22:12 - 587214217 ____A C:\Users\Test\Desktop\TVBOXNOW_Tiger_Cubs_Ch02.mp4
2012-06-30 07:03 - 2009-07-13 20:53 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-25 07:04 - 2012-06-25 07:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-24 08:57 - 2012-06-24 08:44 - 76529032 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E09.HDTV.x264-LOL.mp4
2012-06-24 08:27 - 2011-05-19 12:19 - 00398848 __ASH C:\Users\Test\Thumbs.db
2012-06-24 07:21 - 2012-06-24 07:05 - 328288462 ____A C:\Users\Test\Downloads\Continuum.S01E04.HDTV.x264-2HD.mp4
2012-06-24 07:16 - 2012-06-24 07:05 - 321097571 ____A C:\Users\Test\Downloads\Continuum.S01E03.HDTV.x264-2HD.mp4
2012-06-24 07:14 - 2012-06-24 06:58 - 292296605 ____A C:\Users\Test\Downloads\Continuum.S01E02.HDTV.x264-2HD.mp4
2012-06-24 05:47 - 2012-06-24 05:33 - 306667368 ____A C:\Users\Test\Downloads\Continuum.S01E01.HDTV.x264-2HD.mp4
2012-06-23 01:45 - 2012-06-22 23:13 - 725708800 ____A C:\Users\Test\Downloads\Love.Lifting.CAN.avi
2012-06-16 06:33 - 2012-06-16 06:33 - 00217658 ____A C:\Users\Test\Desktop\Phones4U.xps
2012-06-16 06:33 - 2012-06-16 06:33 - 00217658 ____A C:\Users\Public\Documents\phones4u.xps
2012-06-11 21:20 - 2012-06-11 14:22 - 1662391690 ____A C:\Users\Test\Downloads\Floating.City.720p.X264.AAC.FDZone.dead.mkv
2012-06-11 18:40 - 2012-07-10 15:09 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 00:25 - 2012-06-10 00:24 - 17623196 ____A C:\Users\Test\Desktop\LengMoCN_Charmaine_Fong-Dun_U_Dare-CDS-CPOP-2011-iUKoO.zip
2012-06-08 20:41 - 2012-07-10 12:14 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 21:05 - 2012-07-10 12:15 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 12:14 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 12:14 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-03 01:05 - 2012-06-03 00:48 - 1576748279 ____A C:\Users\Test\Downloads\Marrying.Mr.Perfect.2012.BRRip.x264.AC3-theonlyh.mkv
2012-06-02 14:19 - 2012-06-25 22:08 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-25 22:08 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-25 22:08 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-25 22:07 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-25 22:07 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-25 22:08 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-25 22:07 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-25 22:07 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-25 22:07 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-10 15:13 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-10 15:13 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-10 15:14 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-10 15:14 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-10 15:14 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:25 - 2012-07-10 15:13 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:23 - 2012-07-10 15:14 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-10 15:14 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 15:14 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 15:14 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-10 15:14 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-10 15:14 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 15:14 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 15:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:45 - 2012-07-10 12:15 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 12:15 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 12:15 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 12:15 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 12:15 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-30 04:12 - 2012-05-30 04:12 - 00194387 ____A C:\Users\Test\Downloads\photo.htm
2012-05-26 05:49 - 2012-05-26 03:52 - 274980726 ____A C:\Users\Test\Desktop\TVBOXNOW-Master-Of-Play-Ch03.rmvb
2012-05-26 04:37 - 2012-05-26 03:52 - 274942217 ____A C:\Users\Test\Desktop\TVBOXNOW Master Of Play Ch04.rmvb
2012-05-26 04:12 - 2012-05-26 04:06 - 501066736 ____A C:\Users\Henry Desktop\Desktop\TVBOXNOW Master Of Play Ch02.AVI
2012-05-26 04:06 - 2012-05-26 04:00 - 424804536 ____A C:\Users\Henry Desktop\Desktop\TVBOXNOW-Master-Of-Play-Ch01.AVI
2012-05-18 15:49 - 2012-05-17 22:53 - 376082111 ____A C:\Users\Test\Downloads\Missing.2012.S01E10.HDTV.x264-LOL.mp4
2012-05-18 15:46 - 2012-05-17 22:55 - 266599476 ____A C:\Users\Test\Downloads\Touch.S01E10.HDTV.x264-LOL.mp4
2012-05-18 10:11 - 2012-05-18 10:11 - 00001092 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-16 01:48 - 2012-05-16 01:48 - 00428180 ____A C:\Users\Test\Desktop\Attachments_2012_05_16.zip
2012-05-14 13:15 - 2012-05-14 13:12 - 79766350 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E08.HDTV.x264-LOL.mp4
2012-05-12 23:04 - 2010-04-05 03:13 - 00000917 ____A C:\Users\Public\Desktop\礣orrent.lnk
2012-05-10 22:25 - 2012-05-10 22:17 - 236401318 ____A C:\Users\Test\Downloads\Touch.S01E09.HDTV.x264-LOL.mp4
2012-05-08 22:29 - 2012-05-08 21:04 - 316594668 ____A C:\Users\Test\Downloads\Missing.2012.S01E09.HDTV.x264-LOL.mp4
2012-05-08 21:21 - 2012-05-08 21:07 - 261137980 ____A C:\Users\Test\Downloads\Touch.S01E08.HDTV.x264-LOL.mp4
2012-05-08 21:14 - 2012-05-08 21:07 - 286470184 ____A C:\Users\Test\Downloads\Missing.2012.S01E08.HDTV.x264-LOL.mp4
2012-05-08 21:11 - 2012-05-08 21:08 - 93288502 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E06.HDTV.x264-LOL.mp4
2012-04-29 00:48 - 2011-04-11 22:50 - 00123520 ____A C:\Users\Test\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-28 08:02 - 2010-04-04 14:38 - 00123520 ____A C:\Users\Henry Desktop\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-27 19:17 - 2012-06-12 21:19 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 15:31 - 2012-04-08 02:23 - 00002038 ____A C:\Users\Public\Desktop\Logitech QuickCam.lnk
2012-04-27 12:39 - 2012-04-27 12:39 - 00001037 ____A C:\Users\Test\Desktop\WinAVI MP4 Converter.lnk
2012-04-27 12:39 - 2012-04-27 12:39 - 00001037 ____A C:\Users\Henry Desktop\Desktop\WinAVI MP4 Converter.lnk
2012-04-27 02:06 - 2012-04-27 02:06 - 00001418 ____A C:\Windows\xpsp1hfm.log
2012-04-27 02:04 - 2010-02-16 07:13 - 00104603 ____A C:\Windows\DirectX.log
2012-04-27 01:53 - 2012-04-27 01:53 - 00000807 ____A C:\Windows\MSI30-KB884016.log
2012-04-25 20:45 - 2012-06-12 21:19 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-12 21:19 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-12 21:19 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 20:36 - 2012-07-10 12:14 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-07-10 12:14 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-07-10 12:14 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 13:34 - 2012-04-23 13:00 - 510922263 ____A C:\Users\Test\Downloads\The.Amazing.Race.S20E09.HDTV.x264-2HD.mp4
2012-04-22 01:37 - 2010-12-09 00:12 - 00002503 ____A C:\Users\Public\Desktop\Skype.lnk
ZeroAccess:
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\@
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\L
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\U
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\L\00000004.@
ZeroAccess:
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\@
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\L
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\n
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 4094.3 MB
Available physical RAM: 3381.31 MB
Total Pagefile: 4092.58 MB
Available Pagefile: 3516.69 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.62 MB
======================= Partitions =========================
1 Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:108.97 GB) NTFS
2 Drive e: (Recover) (Fixed) (Total:20 GB) (Free:9.75 GB) NTFS
4 Drive g: (LSI_DVD_RECORDER_VOLUME) (CDROM) (Total:1.54 GB) (Free:0 GB) UDF
7 Drive j: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 Online 966 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 910 GB 101 MB
Partition 3 Primary 20 GB 910 GB
Partition 4 OEM 1025 MB 930 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Boot NTFS Partition 910 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recover NTFS Partition 20 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 12
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 NTFS Partition 1025 MB Healthy Hidden
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 965 MB 16 KB
==================================================================================
Disk: 4
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J FAT Removable 965 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-08 01:17
======================= End Of Log ==========================
PC started having problems a couple of days ago. Now every time I log in a critical error message occurs causing the computer to restart in 60 secs. Therefore most of the preliminary steps I have been unable to do.
I anticipation of your request to use Farbar I have pasted the log below.
Many many thanks for your help:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 16-07-2012 01
Ran by SYSTEM at 20-07-2012 22:48:54
Running from J:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [8120864 2009-12-03] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-06-03] (CyberLink)
HKLM\...\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [x]
HKLM\...\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" [2587008 2012-04-04] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [488984 2007-02-07] (Logitech Inc.)
HKLM\...\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide [774168 2007-02-07] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Henry Desktop\...\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-12] (BitTorrent, Inc.)
HKU\Henry Desktop\...\Run: [Google Update] "C:\Users\Henry Desktop\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-04-04] (Google Inc.)
HKU\Henry Desktop\...\Run: [Grid Service] "C:\Program Files\GridService\peer.exe" -n Grid [4993024 2008-12-30] (FS2YOU)
HKU\Test\...\Run: [Google Update] "C:\Users\Test\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-04-14] (Google Inc.)
HKU\Test\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2009-07-13] (Microsoft Corporation)
HKU\Test\...\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-12] (BitTorrent, Inc.)
HKU\Test\...\Run: [3RVX] C:\Program Files\3RVX\3RVX.exe [159232 2008-10-13] (matt.malensek.net)
HKU\Test\...\Run: [Radio Downloader] "C:\Program Files\Radio Downloader\Radio Downloader.exe" /hidemainwindow [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\Henry Desktop\Start Menu\Programs\Startup\PS3 Media Server.lnk
ShortcutTarget: PS3 Media Server.lnk -> C:\Program Files\PS3 Media Server\PMS.exe (PS3 Media Server)
================================ Services (Whitelisted) ==================
4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [284672 2011-01-04] (Advanced Micro Devices, Inc.)
4 AMD Reservation Manager; "C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe" [140224 2010-06-16] (Advanced Micro Devices)
4 AVGIDSAgent; "C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe" [5160568 2012-07-04] (AVG Technologies CZ, s.r.o.)
4 avgwd; "C:\Program Files\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-13] (AVG Technologies CZ, s.r.o.)
4 BecHelperService; C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe [1737464 2010-01-28] ()
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
4 LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [105248 2007-02-06] (Logitech Inc.)
4 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] ()
4 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-06-19] (Skype Technologies S.A.)
4 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-02-28] (Skype Technologies)
4 LVPrcSrv; c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
4 PSI_SVC_2; "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" [x]
2 RoxLiveShare10; "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" [x]
2 SessionLauncher; C:\Users\Test\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
========================== Drivers (Whitelisted) =============
0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11832 2009-07-07] (Advanced Micro Devices Inc.)
3 AtiHdmiService; C:\Windows\System32\drivers\AtiHdmi.sys [100352 2009-11-18] (ATI Technologies, Inc.)
3 CamDrL; C:\Windows\System32\DRIVERS\Camdrl.sys [1075360 2007-02-03] (Logitech Inc.)
3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
0 DasBoot; C:\Windows\system32\drivers\DasBoot.SYS [20744 2012-01-17] ()
0 DasBootF; C:\Windows\system32\drivers\DasBootF.SYS [59272 2012-01-17] ()
3 DroidCam; C:\Windows\System32\drivers\droidcam.sys [22656 2012-03-24] (Dev47Apps)
3 HTCAND32; C:\Windows\System32\Drivers\ANDROIDUSB.sys [25088 2009-10-26] (HTC, Corporation)
3 htcnprot; C:\Windows\System32\DRIVERS\htcnprot.sys [23040 2010-06-23] (Windows (R) Win 7 DDK provider)
3 LVcKap; C:\Windows\System32\DRIVERS\LVcKap.sys [1691808 2007-02-06] ()
3 LVMVDrv; C:\Windows\System32\DRIVERS\LVMVDrv.sys [1964064 2007-02-06] (Logitech Inc.)
3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25632 2007-02-06] ()
3 LVUSBSta; C:\Windows\System32\DRIVERS\LVUSBSta.sys [41504 2007-02-03] (Logitech Inc.)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-07-19] (Malwarebytes Corporation)
2 mdvrmng; \??\C:\Windows\system32\drivers\mdvrmng.sys [10240 2010-01-28] ()
3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [48640 2010-03-18] (MotioninJoy)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 PRSBDrvr; C:\Windows\System32\DRIVERS\PRSBDrvr.sys [28424 2012-01-17] ()
3 RTL8192su; C:\Windows\System32\DRIVERS\RTL8192su.sys [597536 2010-02-05] (Realtek Semiconductor Corporation )
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [15872 2009-07-13] (Microsoft Corporation)
3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [61984 2009-11-24] (Microsoft Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-20 21:52 - 2012-07-20 22:11 - 00000000 ____D C:\FRST
2012-07-20 13:25 - 2012-07-20 13:25 - 00100864 ____A (GMER) C:\ffxdrpog.sys
2012-07-20 13:24 - 2012-07-20 13:24 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rtuppmes.sys
2012-07-20 13:21 - 2011-07-16 13:21 - 00302592 ____A C:\Users\Henry Desktop\Desktop\gmer.exe
2012-07-19 14:23 - 2012-01-17 12:55 - 00028424 ____A C:\Windows\System32\Drivers\PRSBDrvr.sys
2012-07-19 14:08 - 2012-07-19 14:16 - 00193850 ____A C:\Windows\System32\PHOOKSmf2.TXT
2012-07-19 14:06 - 2012-07-20 13:25 - 00185898 ____A C:\Windows\System32\PHOOKSmf.txt
2012-07-19 14:04 - 2012-07-20 13:21 - 00000000 ____D C:\Windows\System32\DBBK
2012-07-19 14:04 - 2012-07-19 14:23 - 00103218 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe.log
2012-07-19 14:04 - 2012-07-19 14:01 - 01415784 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe
2012-07-19 14:04 - 2012-03-22 08:17 - 00225664 ____A C:\Windows\System32\Drivers\DasBootS.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00059272 ____A C:\Windows\System32\Drivers\DasBootF.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00027528 ____A C:\Windows\System32\Drivers\DasBootK.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00020744 ____A C:\Windows\System32\Drivers\DasBoot.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00009096 ____A C:\Windows\System32\Drivers\DasBootI.SYS
2012-07-19 14:04 - 2012-01-17 12:55 - 00009096 ____A C:\Windows\System32\Drivers\DasBootE.SYS
2012-07-19 14:04 - 2010-05-03 17:37 - 00003072 ____A C:\Windows\System32\Drivers\DasBootD.SYS
2012-07-19 13:12 - 2012-07-19 13:12 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-07-18 22:22 - 2012-07-18 22:22 - 04024320 ____A C:\Program Files\GUT1813.tmp
2012-07-18 22:22 - 2012-07-18 22:22 - 00000000 ____D C:\Program Files\GUM1812.tmp
2012-07-18 22:21 - 2012-07-18 22:21 - 00005543 ____A C:\Windows\System32\commonpriv.log
2012-07-18 22:21 - 2012-07-18 22:21 - 00000000 ____A C:\Windows\System32\commonpriv.log.lock
2012-07-18 22:12 - 2012-07-18 22:13 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-18 15:41 - 2012-07-18 15:46 - 363740113 ____A C:\Users\Test\Desktop\WI-03-HDz.mp4
2012-07-18 15:36 - 2012-07-18 15:41 - 352755015 ____A C:\Users\Test\Desktop\WI-04-HDz.mp4
2012-07-18 13:50 - 2012-07-18 15:01 - 213900562 ____A C:\Users\Test\Desktop\WI-03-HDz.rmvb
2012-07-18 13:50 - 2012-07-18 14:41 - 211327234 ____A C:\Users\Test\Desktop\WI-04-HDz.rmvb
2012-07-18 13:48 - 2012-07-18 13:54 - 38093336 ____A C:\Users\Test\Desktop\WI-02-HDz.rmvb
2012-07-17 22:16 - 2012-07-17 23:09 - 00000000 ____D C:\Users\Test\Downloads\Witness Insecurity Epi 1 to 2
2012-07-17 22:16 - 2012-07-17 23:01 - 281410256 ____A C:\Users\Test\Downloads\Blackout.1x03.HDTV.x264-FoV.mp4
2012-07-17 12:41 - 2012-07-17 12:41 - 03875048 ____A (AVG Technologies) C:\Users\Test\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-16 14:05 - 2012-07-16 14:16 - 651161283 ____A C:\Users\Test\Desktop\TC-E05-TVBN.mp4
2012-07-16 14:04 - 2012-07-16 14:03 - 458485249 ____A C:\Users\Test\Desktop\TC-E05-TVBN.rmvb
2012-07-16 13:56 - 2012-07-16 14:03 - 00000000 ____D C:\Users\Test\Downloads\Tiger Cubs
2012-07-15 14:09 - 2012-07-15 14:19 - 535306122 ____A C:\Users\Test\Desktop\TVBOXNOW-Tiger-Cubs-Ch04.mp4
2012-07-15 08:12 - 2012-07-15 08:30 - 1464984547 ____A C:\Users\Test\Downloads\The.Four.2012.DVDRip.x264.AAC-CkreleaSe.mkv
2012-07-15 08:11 - 2012-07-15 08:11 - 00000000 ____D C:\Users\Test\Downloads\The.Four.2012.DVDscr.x264.AC3-JYK
2012-07-14 22:15 - 2012-07-14 22:16 - 00000000 ____D C:\Users\All Users\6C82ED420009B0E872A08290F875F020
2012-07-12 13:55 - 2012-07-12 14:03 - 383421941 ____A C:\Users\Test\Downloads\Blackout.S01E01.HDTV.x264-TLA.mp4
2012-07-12 13:55 - 2012-07-12 14:02 - 318454617 ____A C:\Users\Test\Downloads\Blackout.1x02.HDTV.x264-FoV.mp4
2012-07-10 15:14 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 15:14 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 15:14 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 15:14 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 15:14 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 15:14 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 15:14 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 15:14 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 15:14 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 15:14 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 15:14 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 15:13 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 15:13 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 15:13 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 15:09 - 2012-07-10 15:09 - 00263480 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-10 15:09 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 13:04 - 2012-07-10 13:07 - 00000000 ____D C:\Users\Test\Downloads\Lockout {2012} DVDRIP. Jaybob
2012-07-10 12:15 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 12:15 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 12:15 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 12:15 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 12:15 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 12:15 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 12:14 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 12:14 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 12:14 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 12:14 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-10 12:14 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-10 12:14 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-10 12:14 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-02 22:12 - 2012-07-02 22:21 - 587214217 ____A C:\Users\Test\Desktop\TVBOXNOW_Tiger_Cubs_Ch02.mp4
2012-06-29 23:35 - 2012-06-30 06:03 - 00000000 ____D C:\Users\Test\Downloads\Nightfall.2012.BDRip.x264.AC3-theonlyh
2012-06-25 22:08 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-25 22:08 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-25 22:08 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-25 22:08 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-25 22:07 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-25 22:07 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-25 22:07 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-25 22:07 - 2012-06-02 06:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-25 22:07 - 2012-06-02 06:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-25 07:04 - 2012-06-25 07:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-25 02:29 - 2012-06-25 02:31 - 00000000 ____D C:\Users\Test\Desktop\MumJanice
2012-06-24 08:44 - 2012-06-24 08:57 - 76529032 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E09.HDTV.x264-LOL.mp4
2012-06-24 07:05 - 2012-06-24 07:21 - 328288462 ____A C:\Users\Test\Downloads\Continuum.S01E04.HDTV.x264-2HD.mp4
2012-06-24 07:05 - 2012-06-24 07:16 - 321097571 ____A C:\Users\Test\Downloads\Continuum.S01E03.HDTV.x264-2HD.mp4
2012-06-24 06:58 - 2012-06-24 07:14 - 292296605 ____A C:\Users\Test\Downloads\Continuum.S01E02.HDTV.x264-2HD.mp4
2012-06-24 05:33 - 2012-06-24 05:47 - 306667368 ____A C:\Users\Test\Downloads\Continuum.S01E01.HDTV.x264-2HD.mp4
2012-06-23 23:33 - 2012-06-23 23:48 - 00000000 ____D C:\Users\Test\Downloads\LMFAO - Sorry For Party Rocking (DeLuxe Edition) 320KB (2011) TBS
2012-06-23 23:30 - 2012-06-24 14:29 - 00000000 ____D C:\Users\Test\Downloads\Flo_Rida-R.O.O.T.S-(RapGodFathers.com)
2012-06-23 15:44 - 2012-06-23 21:38 - 00000000 ____D C:\Users\Test\Downloads\Flo-Rida-Mail.On.Sunday-(2008)-[NoFS]
2012-06-22 23:13 - 2012-06-23 01:45 - 725708800 ____A C:\Users\Test\Downloads\Love.Lifting.CAN.avi
2012-06-21 22:40 - 2012-06-21 22:47 - 00000000 ____D C:\Users\Test\Downloads\A Simple Life.2011.BDRip.AC3.x264-LooKMaNe
============ 3 Months Modified Files ========================
2012-07-20 13:25 - 2012-07-20 13:25 - 00100864 ____A (GMER) C:\ffxdrpog.sys
2012-07-20 13:25 - 2012-07-19 14:06 - 00185898 ____A C:\Windows\System32\PHOOKSmf.txt
2012-07-20 13:24 - 2012-07-20 13:24 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rtuppmes.sys
2012-07-20 13:24 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-20 13:23 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-20 13:23 - 2009-07-13 20:39 - 00202449 ____A C:\Windows\setupact.log
2012-07-19 14:23 - 2012-07-19 14:04 - 00103218 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe.log
2012-07-19 14:16 - 2012-07-19 14:08 - 00193850 ____A C:\Windows\System32\PHOOKSmf2.TXT
2012-07-19 14:07 - 2011-04-14 12:21 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1004UA.job
2012-07-19 14:01 - 2012-07-19 14:04 - 01415784 ____A C:\Users\Henry Desktop\Desktop\yorkyt.exe
2012-07-19 13:42 - 2010-10-03 09:48 - 00287232 __ASH C:\Users\Henry Desktop\Thumbs.db
2012-07-19 13:31 - 2010-04-08 10:32 - 06241792 __ASH C:\Users\Henry Desktop\Desktop\Thumbs.db
2012-07-19 13:12 - 2012-07-19 13:12 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-07-19 13:07 - 2011-04-14 12:21 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1004Core.job
2012-07-18 22:26 - 2010-04-04 14:45 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1001UA.job
2012-07-18 22:26 - 2010-04-04 14:45 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-603813022-4084152872-712802821-1001Core.job
2012-07-18 22:22 - 2012-07-18 22:22 - 04024320 ____A C:\Program Files\GUT1813.tmp
2012-07-18 22:21 - 2012-07-18 22:21 - 00005543 ____A C:\Windows\System32\commonpriv.log
2012-07-18 22:21 - 2012-07-18 22:21 - 00000000 ____A C:\Windows\System32\commonpriv.log.lock
2012-07-18 22:20 - 2010-02-16 08:03 - 00038296 ____A C:\Windows\PFRO.log
2012-07-18 22:13 - 2012-02-01 23:36 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-18 22:13 - 2010-04-04 14:35 - 01217789 ____A C:\Windows\WindowsUpdate.log
2012-07-18 22:12 - 2010-02-15 08:52 - 00752288 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-18 22:09 - 2009-07-13 20:34 - 00009920 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-18 22:09 - 2009-07-13 20:34 - 00009920 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-18 15:47 - 2012-04-27 12:39 - 00055214 ____A C:\MP4debug.log
2012-07-18 15:46 - 2012-07-18 15:41 - 363740113 ____A C:\Users\Test\Desktop\WI-03-HDz.mp4
2012-07-18 15:41 - 2012-07-18 15:36 - 352755015 ____A C:\Users\Test\Desktop\WI-04-HDz.mp4
2012-07-18 15:01 - 2012-07-18 13:50 - 213900562 ____A C:\Users\Test\Desktop\WI-03-HDz.rmvb
2012-07-18 14:41 - 2012-07-18 13:50 - 211327234 ____A C:\Users\Test\Desktop\WI-04-HDz.rmvb
2012-07-18 13:54 - 2012-07-18 13:48 - 38093336 ____A C:\Users\Test\Desktop\WI-02-HDz.rmvb
2012-07-17 23:01 - 2012-07-17 22:16 - 281410256 ____A C:\Users\Test\Downloads\Blackout.1x03.HDTV.x264-FoV.mp4
2012-07-17 12:54 - 2011-12-23 01:08 - 00000939 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-07-17 12:41 - 2012-07-17 12:41 - 03875048 ____A (AVG Technologies) C:\Users\Test\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-16 14:16 - 2012-07-16 14:05 - 651161283 ____A C:\Users\Test\Desktop\TC-E05-TVBN.mp4
2012-07-16 14:03 - 2012-07-16 14:04 - 458485249 ____A C:\Users\Test\Desktop\TC-E05-TVBN.rmvb
2012-07-15 14:19 - 2012-07-15 14:09 - 535306122 ____A C:\Users\Test\Desktop\TVBOXNOW-Tiger-Cubs-Ch04.mp4
2012-07-15 08:30 - 2012-07-15 08:12 - 1464984547 ____A C:\Users\Test\Downloads\The.Four.2012.DVDRip.x264.AAC-CkreleaSe.mkv
2012-07-14 22:26 - 2010-04-04 14:46 - 00002448 ____A C:\Users\Henry Desktop\Desktop\Google Chrome.lnk
2012-07-12 14:03 - 2012-07-12 13:55 - 383421941 ____A C:\Users\Test\Downloads\Blackout.S01E01.HDTV.x264-TLA.mp4
2012-07-12 14:02 - 2012-07-12 13:55 - 318454617 ____A C:\Users\Test\Downloads\Blackout.1x02.HDTV.x264-FoV.mp4
2012-07-11 22:05 - 2011-04-14 12:22 - 00002403 ____A C:\Users\Test\Desktop\Google Chrome.lnk
2012-07-10 22:06 - 2009-07-13 20:33 - 00462472 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 15:13 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-10 15:09 - 2012-07-10 15:09 - 00263480 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-10 15:09 - 2010-02-16 02:43 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-08 13:00 - 2010-04-15 10:48 - 00000400 ____A C:\Windows\Tasks\SmartDefrag.job
2012-07-08 02:41 - 2011-10-09 08:41 - 00000004 ____A C:\authres.html
2012-07-03 04:46 - 2011-04-04 13:58 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 22:21 - 2012-07-02 22:12 - 587214217 ____A C:\Users\Test\Desktop\TVBOXNOW_Tiger_Cubs_Ch02.mp4
2012-06-30 07:03 - 2009-07-13 20:53 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-25 07:04 - 2012-06-25 07:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-24 08:57 - 2012-06-24 08:44 - 76529032 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E09.HDTV.x264-LOL.mp4
2012-06-24 08:27 - 2011-05-19 12:19 - 00398848 __ASH C:\Users\Test\Thumbs.db
2012-06-24 07:21 - 2012-06-24 07:05 - 328288462 ____A C:\Users\Test\Downloads\Continuum.S01E04.HDTV.x264-2HD.mp4
2012-06-24 07:16 - 2012-06-24 07:05 - 321097571 ____A C:\Users\Test\Downloads\Continuum.S01E03.HDTV.x264-2HD.mp4
2012-06-24 07:14 - 2012-06-24 06:58 - 292296605 ____A C:\Users\Test\Downloads\Continuum.S01E02.HDTV.x264-2HD.mp4
2012-06-24 05:47 - 2012-06-24 05:33 - 306667368 ____A C:\Users\Test\Downloads\Continuum.S01E01.HDTV.x264-2HD.mp4
2012-06-23 01:45 - 2012-06-22 23:13 - 725708800 ____A C:\Users\Test\Downloads\Love.Lifting.CAN.avi
2012-06-16 06:33 - 2012-06-16 06:33 - 00217658 ____A C:\Users\Test\Desktop\Phones4U.xps
2012-06-16 06:33 - 2012-06-16 06:33 - 00217658 ____A C:\Users\Public\Documents\phones4u.xps
2012-06-11 21:20 - 2012-06-11 14:22 - 1662391690 ____A C:\Users\Test\Downloads\Floating.City.720p.X264.AAC.FDZone.dead.mkv
2012-06-11 18:40 - 2012-07-10 15:09 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 00:25 - 2012-06-10 00:24 - 17623196 ____A C:\Users\Test\Desktop\LengMoCN_Charmaine_Fong-Dun_U_Dare-CDS-CPOP-2011-iUKoO.zip
2012-06-08 20:41 - 2012-07-10 12:14 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 21:05 - 2012-07-10 12:15 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 12:14 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 12:14 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-03 01:05 - 2012-06-03 00:48 - 1576748279 ____A C:\Users\Test\Downloads\Marrying.Mr.Perfect.2012.BRRip.x264.AC3-theonlyh.mkv
2012-06-02 14:19 - 2012-06-25 22:08 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-25 22:08 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-25 22:08 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-25 22:07 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-25 22:07 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-25 22:08 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-25 22:07 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-25 22:07 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-25 22:07 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-10 15:13 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-10 15:13 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-10 15:14 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-10 15:14 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-10 15:14 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:25 - 2012-07-10 15:13 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:23 - 2012-07-10 15:14 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-10 15:14 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 15:14 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 15:14 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-10 15:14 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-10 15:14 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 15:14 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 15:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:45 - 2012-07-10 12:15 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 12:15 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 12:15 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 12:15 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 12:15 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-30 04:12 - 2012-05-30 04:12 - 00194387 ____A C:\Users\Test\Downloads\photo.htm
2012-05-26 05:49 - 2012-05-26 03:52 - 274980726 ____A C:\Users\Test\Desktop\TVBOXNOW-Master-Of-Play-Ch03.rmvb
2012-05-26 04:37 - 2012-05-26 03:52 - 274942217 ____A C:\Users\Test\Desktop\TVBOXNOW Master Of Play Ch04.rmvb
2012-05-26 04:12 - 2012-05-26 04:06 - 501066736 ____A C:\Users\Henry Desktop\Desktop\TVBOXNOW Master Of Play Ch02.AVI
2012-05-26 04:06 - 2012-05-26 04:00 - 424804536 ____A C:\Users\Henry Desktop\Desktop\TVBOXNOW-Master-Of-Play-Ch01.AVI
2012-05-18 15:49 - 2012-05-17 22:53 - 376082111 ____A C:\Users\Test\Downloads\Missing.2012.S01E10.HDTV.x264-LOL.mp4
2012-05-18 15:46 - 2012-05-17 22:55 - 266599476 ____A C:\Users\Test\Downloads\Touch.S01E10.HDTV.x264-LOL.mp4
2012-05-18 10:11 - 2012-05-18 10:11 - 00001092 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-16 01:48 - 2012-05-16 01:48 - 00428180 ____A C:\Users\Test\Desktop\Attachments_2012_05_16.zip
2012-05-14 13:15 - 2012-05-14 13:12 - 79766350 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E08.HDTV.x264-LOL.mp4
2012-05-12 23:04 - 2010-04-05 03:13 - 00000917 ____A C:\Users\Public\Desktop\礣orrent.lnk
2012-05-10 22:25 - 2012-05-10 22:17 - 236401318 ____A C:\Users\Test\Downloads\Touch.S01E09.HDTV.x264-LOL.mp4
2012-05-08 22:29 - 2012-05-08 21:04 - 316594668 ____A C:\Users\Test\Downloads\Missing.2012.S01E09.HDTV.x264-LOL.mp4
2012-05-08 21:21 - 2012-05-08 21:07 - 261137980 ____A C:\Users\Test\Downloads\Touch.S01E08.HDTV.x264-LOL.mp4
2012-05-08 21:14 - 2012-05-08 21:07 - 286470184 ____A C:\Users\Test\Downloads\Missing.2012.S01E08.HDTV.x264-LOL.mp4
2012-05-08 21:11 - 2012-05-08 21:08 - 93288502 ____A C:\Users\Test\Downloads\Bobs.Burgers.S02E06.HDTV.x264-LOL.mp4
2012-04-29 00:48 - 2011-04-11 22:50 - 00123520 ____A C:\Users\Test\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-28 08:02 - 2010-04-04 14:38 - 00123520 ____A C:\Users\Henry Desktop\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-27 19:17 - 2012-06-12 21:19 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 15:31 - 2012-04-08 02:23 - 00002038 ____A C:\Users\Public\Desktop\Logitech QuickCam.lnk
2012-04-27 12:39 - 2012-04-27 12:39 - 00001037 ____A C:\Users\Test\Desktop\WinAVI MP4 Converter.lnk
2012-04-27 12:39 - 2012-04-27 12:39 - 00001037 ____A C:\Users\Henry Desktop\Desktop\WinAVI MP4 Converter.lnk
2012-04-27 02:06 - 2012-04-27 02:06 - 00001418 ____A C:\Windows\xpsp1hfm.log
2012-04-27 02:04 - 2010-02-16 07:13 - 00104603 ____A C:\Windows\DirectX.log
2012-04-27 01:53 - 2012-04-27 01:53 - 00000807 ____A C:\Windows\MSI30-KB884016.log
2012-04-25 20:45 - 2012-06-12 21:19 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-12 21:19 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-12 21:19 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 20:36 - 2012-07-10 12:14 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-07-10 12:14 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-07-10 12:14 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 13:34 - 2012-04-23 13:00 - 510922263 ____A C:\Users\Test\Downloads\The.Amazing.Race.S20E09.HDTV.x264-2HD.mp4
2012-04-22 01:37 - 2010-12-09 00:12 - 00002503 ____A C:\Users\Public\Desktop\Skype.lnk
ZeroAccess:
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\@
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\L
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\U
C:\Windows\Installer\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\L\00000004.@
ZeroAccess:
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\@
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\L
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\n
C:\Users\Test\AppData\Local\{75bd8795-729e-3e2a-6b32-659cf4473ab0}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 4094.3 MB
Available physical RAM: 3381.31 MB
Total Pagefile: 4092.58 MB
Available Pagefile: 3516.69 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.62 MB
======================= Partitions =========================
1 Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:108.97 GB) NTFS
2 Drive e: (Recover) (Fixed) (Total:20 GB) (Free:9.75 GB) NTFS
4 Drive g: (LSI_DVD_RECORDER_VOLUME) (CDROM) (Total:1.54 GB) (Free:0 GB) UDF
7 Drive j: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 Online 966 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 910 GB 101 MB
Partition 3 Primary 20 GB 910 GB
Partition 4 OEM 1025 MB 930 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Boot NTFS Partition 910 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recover NTFS Partition 20 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 12
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 NTFS Partition 1025 MB Healthy Hidden
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 965 MB 16 KB
==================================================================================
Disk: 4
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J FAT Removable 965 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-08 01:17
======================= End Of Log ==========================