micfrost
Posts: 13 +0
I have the Sirefef "1-minute-restart" on my Windows 7 32-bit laptop. MSE found Sirefef but failed to clean the pc.Now I'm stuck with the 1 minute restart warning. Any help is much appreciated. THX. Here is the result of the Farbar Scan Tool:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 27-08-2012
Ran by SYSTEM at 28-08-2012 00:51:58
Running from F:\
Windows 7 Ultimate (X86) OS Language: Danish
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-09] (IDT, Inc.)
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [488816 2011-01-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe [91648 2010-07-29] (IvoSoft)
HKLM\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM\...\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe -tray [2572288 2011-03-28] (Bdrive Inc.)
HKLM\...\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [479232 2005-07-15] (Google Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 10\MMReminderService.exe [38248 2011-11-10] (Mindjet)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [SonicWALLNetExtender] C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe -hideGUI -clearReboot [1244192 2012-04-13] (SonicWALL Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\mfj\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [357696 2010-04-01] (DT Soft Ltd)
HKU\mfj\...\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
HKU\mfj\...\Run: [Google Update] "C:\Users\mfj\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-07-05] (Google Inc.)
HKU\mfj\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\mfj\...\Run: [Spotify Web Helper] "C:\Users\mfj\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1193176 2012-08-22] ()
HKU\mfj\...\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart [12218904 2012-07-20] (Google)
Tcpip\Parameters: [DhcpNameServer] 193.162.153.164 194.239.134.83
Tcpip\..\Interfaces\{D6E18644-2FF9-49E4-9E5C-84E527CF5167}: [NameServer]192.168.10.30 192.168.10.38
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
ShortcutTarget: Snagit 9.lnk -> C:\Program Files\TechSmith\Snagit 9\Snagit32.exe (TechSmith Corporation)
========================== Services (Whitelisted) ========================
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d511891fb5bff1e2\aestsrv.exe [81920 2009-03-03] (Andrea Electronics Corporation)
2 emaudsv; C:\Windows\System32\emaudsv.exe [21504 2010-10-06] (E-MU Systems)
2 ndsvc; C:\Program Files\NetDrive\ndsvc.exe [1868800 2011-03-28] (Bdrive Inc.)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-07-05] (Skype Technologies S.A.)
2 SONICWALL_NetExtender; C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEService.exe [330784 2012-04-13] (SonicWALL Inc.)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d511891fb5bff1e2\STacSV.exe [229458 2010-03-09] (IDT, Inc.)
2 ccmsetup; "C:\Windows\system32\ccmsetup\ccmsetup.exe" /runservice /config:MobileClient.tcf [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
==================== Drivers (Whitelisted) ===================
3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-14] (Microsoft Corporation)
3 emusba10; C:\Windows\System32\DRIVERS\emusba10.sys [164696 2010-10-06] (E-MU Systems)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 ndfs; \??\C:\Program Files\NetDrive\ndfs.sys [49432 2011-03-25] (MacroData Inc.)
3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7087616 2011-01-19] (Intel Corporation)
3 NxDrv; C:\Windows\System32\DRIVERS\NxDrv.sys [21888 2011-07-28] (SonicWALL Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-08-07] (Duplex Secure Ltd.)
3 SSLDrv; C:\Windows\System32\DRIVERS\SSLDrv.sys [20504 2008-02-05] (SonicWALL Inc.)
3 connctfy; C:\Windows\System32\DRIVERS\connctfy.sys [x]
3 connctfyMP; C:\Windows\System32\DRIVERS\connctfy.sys [x]
3 cpuz132; \??\C:\Users\mfj\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-08-28 00:51 - 2012-08-28 00:51 - 00000000 ____D C:\FRST
2012-08-27 23:46 - 2012-08-27 23:46 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\depnekxc.sys
2012-08-27 23:44 - 2012-08-27 23:44 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vkmddvkd.sys
2012-08-26 07:09 - 2012-08-26 07:09 - 00000000 ____A C:\Users\mfj\Downloads\6864.tmp
2012-08-26 07:07 - 2012-08-26 07:07 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-08-26 06:45 - 2012-08-26 07:12 - 00000000 ____D C:\Users\mfj\Desktop\Sirefef
2012-08-26 06:42 - 2012-08-26 06:42 - 00000000 ____A C:\Users\mfj\Downloads\8B87.tmp
2012-08-26 06:18 - 2012-08-26 06:18 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-26 06:15 - 2012-08-26 06:15 - 10300288 ____A (Microsoft Corporation) C:\Users\mfj\Desktop\mseinstall.exe
2012-08-26 05:51 - 2012-08-26 05:51 - 00000000 ____D C:\Users\mfj\AppData\Roaming\Totusoft
2012-08-26 05:51 - 2012-08-26 05:51 - 00000000 ____D C:\Program Files\LAN Speed Test
2012-08-18 08:09 - 2012-08-18 08:09 - 10762240 ____A C:\Users\mfj\Desktop\VideoStation-x86-1.0-0038.spk
2012-08-18 07:53 - 2012-08-18 07:54 - 99399680 ____A C:\Users\mfj\Desktop\DSM_DS710+_2567.pat
2012-08-18 07:21 - 2012-08-18 07:21 - 00000000 ____D C:\Program Files\Oracle
2012-08-18 07:21 - 2012-08-18 07:21 - 00000000 ____D C:\Program Files\Common Files\Java
2012-08-18 07:20 - 2012-07-05 21:06 - 00772544 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-08-18 07:20 - 2012-07-05 21:06 - 00227760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-08-18 07:18 - 2012-08-18 07:18 - 00893936 ____A (Oracle Corporation) C:\Users\mfj\Desktop\chromeinstall-7u5.exe
2012-08-17 15:21 - 2012-08-17 15:21 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-08-17 15:20 - 2012-08-17 15:21 - 00000000 ____D C:\Program Files\iTunes
2012-08-17 15:20 - 2012-08-17 15:20 - 00000000 ____D C:\Program Files\iPod
2012-08-09 01:53 - 2012-08-09 01:53 - 00000000 ____D C:\Users\mfj\Downloads\Diverse dokumenter
2012-08-09 01:43 - 2012-08-09 01:43 - 00000000 ____D C:\Users\mfj\AppData\Roaming\FileZilla
2012-08-09 01:39 - 2012-08-09 01:39 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2012-08-09 01:38 - 2012-08-09 01:38 - 04518720 ____A (FileZilla Project) C:\Users\mfj\Desktop\FileZilla_3.5.3_win32-setup.exe
2012-08-06 16:15 - 2012-08-06 16:15 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2012-08-06 16:15 - 2012-08-06 16:15 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2012-08-01 06:50 - 2012-08-01 06:51 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-08-01 06:44 - 2012-08-01 06:44 - 11557320 ____A C:\Users\mfj\Desktop\DELL_TOUCHPAD----POINTING-ST_A15_R298882.exe
2012-08-01 06:44 - 2011-01-05 19:42 - 00284792 ____A (Alps Electric Co., Ltd.) C:\Windows\System32\Drivers\Apfiltr.sys
2012-08-01 06:44 - 2010-12-17 01:52 - 00115640 ____A (Alps Electric Co., Ltd.) C:\Windows\System32\Vxdif.dll
============ 3 Months Modified Files ========================
2012-08-27 23:46 - 2012-08-27 23:46 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\depnekxc.sys
2012-08-27 23:45 - 2010-08-07 08:28 - 00027798 ____A C:\Windows\PFRO.log
2012-08-27 23:44 - 2012-08-27 23:44 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vkmddvkd.sys
2012-08-27 23:40 - 2012-06-02 07:10 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-27 23:40 - 2011-06-02 06:01 - 01166803 ____A C:\ndsvc.log
2012-08-27 23:40 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-27 23:40 - 2009-07-14 05:39 - 00078672 ____A C:\Windows\setupact.log
2012-08-27 23:38 - 2010-08-06 22:41 - 01459826 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-27 23:24 - 2012-07-08 05:12 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-27 23:24 - 2012-06-02 07:10 - 00000914 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-27 23:24 - 2011-07-05 20:19 - 00000934 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1261810894-1184621077-381352119-1000UA.job
2012-08-27 23:24 - 2011-07-05 20:19 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1261810894-1184621077-381352119-1000Core.job
2012-08-26 07:13 - 2009-07-14 00:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-26 07:09 - 2012-08-26 07:09 - 00000000 ____A C:\Users\mfj\Downloads\6864.tmp
2012-08-26 06:42 - 2012-08-26 06:42 - 00000000 ____A C:\Users\mfj\Downloads\8B87.tmp
2012-08-26 06:19 - 2010-08-06 22:40 - 02058276 ____A C:\Windows\WindowsUpdate.log
2012-08-26 06:18 - 2011-05-22 06:00 - 00001912 ____A C:\Windows\epplauncher.mif
2012-08-26 06:15 - 2012-08-26 06:15 - 10300288 ____A (Microsoft Corporation) C:\Users\mfj\Desktop\mseinstall.exe
2012-08-24 18:54 - 2009-07-14 05:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-24 18:54 - 2009-07-14 05:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-23 19:31 - 2010-08-07 09:45 - 00001992 ___AH C:\Users\mfj\Documents\Default.rdp
2012-08-20 11:27 - 2010-12-06 07:14 - 00234295 ____A C:\Users\mfj\danid.log
2012-08-18 08:09 - 2012-08-18 08:09 - 10762240 ____A C:\Users\mfj\Desktop\VideoStation-x86-1.0-0038.spk
2012-08-18 07:54 - 2012-08-18 07:53 - 99399680 ____A C:\Users\mfj\Desktop\DSM_DS710+_2567.pat
2012-08-18 07:19 - 2012-04-01 08:50 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-08-18 07:19 - 2012-04-01 08:50 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-08-18 07:18 - 2012-08-18 07:18 - 00893936 ____A (Oracle Corporation) C:\Users\mfj\Desktop\chromeinstall-7u5.exe
2012-08-17 15:21 - 2012-08-17 15:21 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-08-17 15:13 - 2010-08-07 09:48 - 00000344 ____A C:\Windows\System32\config\netlogon.ftl
2012-08-14 22:26 - 2012-07-08 05:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-14 22:26 - 2012-07-08 05:12 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-09 02:30 - 2010-12-01 14:36 - 00017920 ____A C:\Users\mfj\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-09 01:38 - 2012-08-09 01:38 - 04518720 ____A (FileZilla Project) C:\Users\mfj\Desktop\FileZilla_3.5.3_win32-setup.exe
2012-08-08 09:47 - 2010-12-06 07:14 - 01121896 ____A C:\Users\mfj\danid.log.1
2012-08-01 06:51 - 2012-08-01 06:50 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-08-01 06:45 - 2010-08-07 09:40 - 00036508 ____A C:\Windows\DPINST.LOG
2012-08-01 06:44 - 2012-08-01 06:44 - 11557320 ____A C:\Users\mfj\Desktop\DELL_TOUCHPAD----POINTING-ST_A15_R298882.exe
2012-07-24 10:43 - 2012-07-24 08:17 - 00000172 ____A C:\Users\mfj\Desktop\Allan.txt
2012-07-18 19:56 - 2012-07-18 19:56 - 00000000 _RASH C:\MSDOS.SYS
2012-07-18 19:56 - 2012-07-18 19:56 - 00000000 _RASH C:\IO.SYS
2012-07-18 19:55 - 2012-07-18 19:55 - 00022016 ____A C:\Users\mfj\Desktop\optical.exe
2012-07-14 06:14 - 2009-07-14 05:33 - 00413144 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 05:18 - 2010-08-07 08:25 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-05 21:06 - 2012-08-18 07:20 - 00772544 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-07-05 21:06 - 2012-08-18 07:20 - 00227760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-07-05 21:06 - 2010-12-06 07:12 - 00687544 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-07-01 09:54 - 2012-07-01 09:54 - 00000382 ____A C:\Users\mfj\Desktop\Lot of 9 Star Wars Vintage Original Trilogy Collection VOTC Figures NEW MOC - eBay.url
2012-06-23 05:25 - 2012-06-23 05:25 - 00001771 ____A C:\Users\mfj\Desktop\iTunes.lnk
2012-06-12 03:40 - 2012-07-12 05:17 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 05:41 - 2012-07-11 21:04 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 19:51 - 2012-06-08 19:51 - 00667344 ____A C:\Users\mfj\Desktop\mp3gain-win-1_2_5.exe
2012-06-08 04:08 - 2012-06-08 03:20 - 00003468 ____A C:\Users\mfj\Desktop\mikkelaude.txt
2012-06-06 06:05 - 2012-07-11 21:04 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 06:05 - 2012-07-11 21:04 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 06:03 - 2012-07-11 21:04 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-22 21:42 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:12 - 2012-06-22 21:42 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:12 - 2012-06-22 21:42 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-22 21:42 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:12 - 2012-06-22 21:42 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 07:12 - 2012-06-02 07:12 - 00001643 ____A C:\Users\mfj\Desktop\Google Drive.lnk
2012-06-02 05:45 - 2012-07-11 21:04 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 05:45 - 2012-07-11 21:04 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 05:40 - 2012-07-11 21:04 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 05:40 - 2012-07-11 21:04 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 05:39 - 2012-07-11 21:04 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
ZeroAccess:
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\@
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\n
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L\00000004.@
ZeroAccess:
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\n
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L\00000004.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\00000004.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\00000008.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\000000cb.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\80000000.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\80000032.@
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-18 07:19:50
Restore point made on: 2012-08-18 07:20:58
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 4047.9 MB
Available physical RAM: 3522.96 MB
Total Pagefile: 4046.18 MB
Available Pagefile: 3532.5 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.48 MB
==================== Partitions ============================
1 Drive c: () (Fixed) (Total:119.14 GB) (Free:17.51 GB) NTFS
3 Drive f: () (Removable) (Total:3.73 GB) (Free:3.54 GB) NTFS
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (Reserveret til systemet) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Str. Ledig Dyn GPT
-------- ------------- ------- ------- --- ---
Disk 0 Online 119 GB 0 B
Disk 1 Online 3817 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Str. Forskydning
------------- ---------------- ------- -----------
Partition 1 Prim‘r 100 MB 1024 KB
Partition 2 Prim‘r 119 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Skjult: Nej
Aktiv : Ja
Forskydning I byte: 1048576
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
--------- ---- ---------- ----- ---------- ------- --------- --------
* Diskenhed 1 Y Reserveret NTFS Partition 100 MB I orden
==================================================================================
Disk: 0
Partition 2
Type : 07
Skjult: Nej
Aktiv : Nej
Forskydning I byte: 105906176
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
--------- ---- ---------- ----- ---------- ------- --------- --------
* Diskenhed 2 C NTFS Partition 119 GB I orden
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Str. Forskydning
------------- ---------------- ------- -----------
Partition 1 Prim‘r 3817 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Skjult: Nej
Aktiv : Ja
Forskydning I byte: 32256
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
--------- ---- ---------- ----- ---------- ------- --------- --------
* Diskenhed 3 F NTFS Flytbar 3817 MB I orden
==================================================================================
Last Boot: 2012-08-19 07:30
==================== End Of Log =============================
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 27-08-2012
Ran by SYSTEM at 28-08-2012 00:51:58
Running from F:\
Windows 7 Ultimate (X86) OS Language: Danish
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-09] (IDT, Inc.)
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [488816 2011-01-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe [91648 2010-07-29] (IvoSoft)
HKLM\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM\...\Run: [Netdrive] C:\Program Files\NetDrive\netdrive.exe -tray [2572288 2011-03-28] (Bdrive Inc.)
HKLM\...\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [479232 2005-07-15] (Google Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 10\MMReminderService.exe [38248 2011-11-10] (Mindjet)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [SonicWALLNetExtender] C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe -hideGUI -clearReboot [1244192 2012-04-13] (SonicWALL Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\mfj\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [357696 2010-04-01] (DT Soft Ltd)
HKU\mfj\...\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
HKU\mfj\...\Run: [Google Update] "C:\Users\mfj\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-07-05] (Google Inc.)
HKU\mfj\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\mfj\...\Run: [Spotify Web Helper] "C:\Users\mfj\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1193176 2012-08-22] ()
HKU\mfj\...\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart [12218904 2012-07-20] (Google)
Tcpip\Parameters: [DhcpNameServer] 193.162.153.164 194.239.134.83
Tcpip\..\Interfaces\{D6E18644-2FF9-49E4-9E5C-84E527CF5167}: [NameServer]192.168.10.30 192.168.10.38
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
ShortcutTarget: Snagit 9.lnk -> C:\Program Files\TechSmith\Snagit 9\Snagit32.exe (TechSmith Corporation)
========================== Services (Whitelisted) ========================
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d511891fb5bff1e2\aestsrv.exe [81920 2009-03-03] (Andrea Electronics Corporation)
2 emaudsv; C:\Windows\System32\emaudsv.exe [21504 2010-10-06] (E-MU Systems)
2 ndsvc; C:\Program Files\NetDrive\ndsvc.exe [1868800 2011-03-28] (Bdrive Inc.)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-07-05] (Skype Technologies S.A.)
2 SONICWALL_NetExtender; C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEService.exe [330784 2012-04-13] (SonicWALL Inc.)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d511891fb5bff1e2\STacSV.exe [229458 2010-03-09] (IDT, Inc.)
2 ccmsetup; "C:\Windows\system32\ccmsetup\ccmsetup.exe" /runservice /config:MobileClient.tcf [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
==================== Drivers (Whitelisted) ===================
3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-14] (Microsoft Corporation)
3 emusba10; C:\Windows\System32\DRIVERS\emusba10.sys [164696 2010-10-06] (E-MU Systems)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 ndfs; \??\C:\Program Files\NetDrive\ndfs.sys [49432 2011-03-25] (MacroData Inc.)
3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7087616 2011-01-19] (Intel Corporation)
3 NxDrv; C:\Windows\System32\DRIVERS\NxDrv.sys [21888 2011-07-28] (SonicWALL Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-08-07] (Duplex Secure Ltd.)
3 SSLDrv; C:\Windows\System32\DRIVERS\SSLDrv.sys [20504 2008-02-05] (SonicWALL Inc.)
3 connctfy; C:\Windows\System32\DRIVERS\connctfy.sys [x]
3 connctfyMP; C:\Windows\System32\DRIVERS\connctfy.sys [x]
3 cpuz132; \??\C:\Users\mfj\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-08-28 00:51 - 2012-08-28 00:51 - 00000000 ____D C:\FRST
2012-08-27 23:46 - 2012-08-27 23:46 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\depnekxc.sys
2012-08-27 23:44 - 2012-08-27 23:44 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vkmddvkd.sys
2012-08-26 07:09 - 2012-08-26 07:09 - 00000000 ____A C:\Users\mfj\Downloads\6864.tmp
2012-08-26 07:07 - 2012-08-26 07:07 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-08-26 06:45 - 2012-08-26 07:12 - 00000000 ____D C:\Users\mfj\Desktop\Sirefef
2012-08-26 06:42 - 2012-08-26 06:42 - 00000000 ____A C:\Users\mfj\Downloads\8B87.tmp
2012-08-26 06:18 - 2012-08-26 06:18 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-26 06:15 - 2012-08-26 06:15 - 10300288 ____A (Microsoft Corporation) C:\Users\mfj\Desktop\mseinstall.exe
2012-08-26 05:51 - 2012-08-26 05:51 - 00000000 ____D C:\Users\mfj\AppData\Roaming\Totusoft
2012-08-26 05:51 - 2012-08-26 05:51 - 00000000 ____D C:\Program Files\LAN Speed Test
2012-08-18 08:09 - 2012-08-18 08:09 - 10762240 ____A C:\Users\mfj\Desktop\VideoStation-x86-1.0-0038.spk
2012-08-18 07:53 - 2012-08-18 07:54 - 99399680 ____A C:\Users\mfj\Desktop\DSM_DS710+_2567.pat
2012-08-18 07:21 - 2012-08-18 07:21 - 00000000 ____D C:\Program Files\Oracle
2012-08-18 07:21 - 2012-08-18 07:21 - 00000000 ____D C:\Program Files\Common Files\Java
2012-08-18 07:20 - 2012-07-05 21:06 - 00772544 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-08-18 07:20 - 2012-07-05 21:06 - 00227760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-08-18 07:18 - 2012-08-18 07:18 - 00893936 ____A (Oracle Corporation) C:\Users\mfj\Desktop\chromeinstall-7u5.exe
2012-08-17 15:21 - 2012-08-17 15:21 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-08-17 15:20 - 2012-08-17 15:21 - 00000000 ____D C:\Program Files\iTunes
2012-08-17 15:20 - 2012-08-17 15:20 - 00000000 ____D C:\Program Files\iPod
2012-08-09 01:53 - 2012-08-09 01:53 - 00000000 ____D C:\Users\mfj\Downloads\Diverse dokumenter
2012-08-09 01:43 - 2012-08-09 01:43 - 00000000 ____D C:\Users\mfj\AppData\Roaming\FileZilla
2012-08-09 01:39 - 2012-08-09 01:39 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2012-08-09 01:38 - 2012-08-09 01:38 - 04518720 ____A (FileZilla Project) C:\Users\mfj\Desktop\FileZilla_3.5.3_win32-setup.exe
2012-08-06 16:15 - 2012-08-06 16:15 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2012-08-06 16:15 - 2012-08-06 16:15 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2012-08-01 06:50 - 2012-08-01 06:51 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-08-01 06:44 - 2012-08-01 06:44 - 11557320 ____A C:\Users\mfj\Desktop\DELL_TOUCHPAD----POINTING-ST_A15_R298882.exe
2012-08-01 06:44 - 2011-01-05 19:42 - 00284792 ____A (Alps Electric Co., Ltd.) C:\Windows\System32\Drivers\Apfiltr.sys
2012-08-01 06:44 - 2010-12-17 01:52 - 00115640 ____A (Alps Electric Co., Ltd.) C:\Windows\System32\Vxdif.dll
============ 3 Months Modified Files ========================
2012-08-27 23:46 - 2012-08-27 23:46 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\depnekxc.sys
2012-08-27 23:45 - 2010-08-07 08:28 - 00027798 ____A C:\Windows\PFRO.log
2012-08-27 23:44 - 2012-08-27 23:44 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vkmddvkd.sys
2012-08-27 23:40 - 2012-06-02 07:10 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-27 23:40 - 2011-06-02 06:01 - 01166803 ____A C:\ndsvc.log
2012-08-27 23:40 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-27 23:40 - 2009-07-14 05:39 - 00078672 ____A C:\Windows\setupact.log
2012-08-27 23:38 - 2010-08-06 22:41 - 01459826 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-27 23:24 - 2012-07-08 05:12 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-27 23:24 - 2012-06-02 07:10 - 00000914 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-27 23:24 - 2011-07-05 20:19 - 00000934 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1261810894-1184621077-381352119-1000UA.job
2012-08-27 23:24 - 2011-07-05 20:19 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1261810894-1184621077-381352119-1000Core.job
2012-08-26 07:13 - 2009-07-14 00:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-26 07:09 - 2012-08-26 07:09 - 00000000 ____A C:\Users\mfj\Downloads\6864.tmp
2012-08-26 06:42 - 2012-08-26 06:42 - 00000000 ____A C:\Users\mfj\Downloads\8B87.tmp
2012-08-26 06:19 - 2010-08-06 22:40 - 02058276 ____A C:\Windows\WindowsUpdate.log
2012-08-26 06:18 - 2011-05-22 06:00 - 00001912 ____A C:\Windows\epplauncher.mif
2012-08-26 06:15 - 2012-08-26 06:15 - 10300288 ____A (Microsoft Corporation) C:\Users\mfj\Desktop\mseinstall.exe
2012-08-24 18:54 - 2009-07-14 05:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-24 18:54 - 2009-07-14 05:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-23 19:31 - 2010-08-07 09:45 - 00001992 ___AH C:\Users\mfj\Documents\Default.rdp
2012-08-20 11:27 - 2010-12-06 07:14 - 00234295 ____A C:\Users\mfj\danid.log
2012-08-18 08:09 - 2012-08-18 08:09 - 10762240 ____A C:\Users\mfj\Desktop\VideoStation-x86-1.0-0038.spk
2012-08-18 07:54 - 2012-08-18 07:53 - 99399680 ____A C:\Users\mfj\Desktop\DSM_DS710+_2567.pat
2012-08-18 07:19 - 2012-04-01 08:50 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-08-18 07:19 - 2012-04-01 08:50 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-08-18 07:18 - 2012-08-18 07:18 - 00893936 ____A (Oracle Corporation) C:\Users\mfj\Desktop\chromeinstall-7u5.exe
2012-08-17 15:21 - 2012-08-17 15:21 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-08-17 15:13 - 2010-08-07 09:48 - 00000344 ____A C:\Windows\System32\config\netlogon.ftl
2012-08-14 22:26 - 2012-07-08 05:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-14 22:26 - 2012-07-08 05:12 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-09 02:30 - 2010-12-01 14:36 - 00017920 ____A C:\Users\mfj\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-09 01:38 - 2012-08-09 01:38 - 04518720 ____A (FileZilla Project) C:\Users\mfj\Desktop\FileZilla_3.5.3_win32-setup.exe
2012-08-08 09:47 - 2010-12-06 07:14 - 01121896 ____A C:\Users\mfj\danid.log.1
2012-08-01 06:51 - 2012-08-01 06:50 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-08-01 06:45 - 2010-08-07 09:40 - 00036508 ____A C:\Windows\DPINST.LOG
2012-08-01 06:44 - 2012-08-01 06:44 - 11557320 ____A C:\Users\mfj\Desktop\DELL_TOUCHPAD----POINTING-ST_A15_R298882.exe
2012-07-24 10:43 - 2012-07-24 08:17 - 00000172 ____A C:\Users\mfj\Desktop\Allan.txt
2012-07-18 19:56 - 2012-07-18 19:56 - 00000000 _RASH C:\MSDOS.SYS
2012-07-18 19:56 - 2012-07-18 19:56 - 00000000 _RASH C:\IO.SYS
2012-07-18 19:55 - 2012-07-18 19:55 - 00022016 ____A C:\Users\mfj\Desktop\optical.exe
2012-07-14 06:14 - 2009-07-14 05:33 - 00413144 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 05:18 - 2010-08-07 08:25 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-05 21:06 - 2012-08-18 07:20 - 00772544 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-07-05 21:06 - 2012-08-18 07:20 - 00227760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-07-05 21:06 - 2010-12-06 07:12 - 00687544 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-07-01 09:54 - 2012-07-01 09:54 - 00000382 ____A C:\Users\mfj\Desktop\Lot of 9 Star Wars Vintage Original Trilogy Collection VOTC Figures NEW MOC - eBay.url
2012-06-23 05:25 - 2012-06-23 05:25 - 00001771 ____A C:\Users\mfj\Desktop\iTunes.lnk
2012-06-12 03:40 - 2012-07-12 05:17 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 05:41 - 2012-07-11 21:04 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 19:51 - 2012-06-08 19:51 - 00667344 ____A C:\Users\mfj\Desktop\mp3gain-win-1_2_5.exe
2012-06-08 04:08 - 2012-06-08 03:20 - 00003468 ____A C:\Users\mfj\Desktop\mikkelaude.txt
2012-06-06 06:05 - 2012-07-11 21:04 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 06:05 - 2012-07-11 21:04 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 06:03 - 2012-07-11 21:04 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-22 21:42 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-22 21:42 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:12 - 2012-06-22 21:42 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:12 - 2012-06-22 21:42 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-22 21:42 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:12 - 2012-06-22 21:42 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 07:12 - 2012-06-02 07:12 - 00001643 ____A C:\Users\mfj\Desktop\Google Drive.lnk
2012-06-02 05:45 - 2012-07-11 21:04 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 05:45 - 2012-07-11 21:04 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 05:40 - 2012-07-11 21:04 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 05:40 - 2012-07-11 21:04 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 05:39 - 2012-07-11 21:04 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
ZeroAccess:
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\@
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\n
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U
C:\Windows\Installer\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L\00000004.@
ZeroAccess:
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\n
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\L\00000004.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\00000004.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\00000008.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\000000cb.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\80000000.@
C:\Users\mfj\AppData\Local\{54cdaa9b-4a80-5ae8-db58-eae7cb63bb6f}\U\80000032.@
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-18 07:19:50
Restore point made on: 2012-08-18 07:20:58
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 4047.9 MB
Available physical RAM: 3522.96 MB
Total Pagefile: 4046.18 MB
Available Pagefile: 3532.5 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.48 MB
==================== Partitions ============================
1 Drive c: () (Fixed) (Total:119.14 GB) (Free:17.51 GB) NTFS
3 Drive f: () (Removable) (Total:3.73 GB) (Free:3.54 GB) NTFS
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (Reserveret til systemet) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Str. Ledig Dyn GPT
-------- ------------- ------- ------- --- ---
Disk 0 Online 119 GB 0 B
Disk 1 Online 3817 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Str. Forskydning
------------- ---------------- ------- -----------
Partition 1 Prim‘r 100 MB 1024 KB
Partition 2 Prim‘r 119 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Skjult: Nej
Aktiv : Ja
Forskydning I byte: 1048576
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
--------- ---- ---------- ----- ---------- ------- --------- --------
* Diskenhed 1 Y Reserveret NTFS Partition 100 MB I orden
==================================================================================
Disk: 0
Partition 2
Type : 07
Skjult: Nej
Aktiv : Nej
Forskydning I byte: 105906176
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
--------- ---- ---------- ----- ---------- ------- --------- --------
* Diskenhed 2 C NTFS Partition 119 GB I orden
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Str. Forskydning
------------- ---------------- ------- -----------
Partition 1 Prim‘r 3817 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Skjult: Nej
Aktiv : Ja
Forskydning I byte: 32256
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
--------- ---- ---------- ----- ---------- ------- --------- --------
* Diskenhed 3 F NTFS Flytbar 3817 MB I orden
==================================================================================
Last Boot: 2012-08-19 07:30
==================== End Of Log =============================