I also seem to be having the same issues as everyone else. This virus was somehow able to install itself and after running MSE in safe mode, I determined it was sirefef and when trying to remove or quarantine it with MSE, it forces a restart. I have included the logs from both the FRST scan and the specific Search of services.exe. Thanks for any help you can give!
1 - FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 26-07-2012 07:00:17
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash [1617920 2011-01-26] (Intel® Corporation)
HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-07-27] (Intel(R) Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2012-01-16] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-10-21] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-10-21] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-10-21] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2012-01-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [636032 2012-03-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-01-31] ()
HKLM-x32\...\Run: [VMM Mode Selection] C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe [43520 2011-02-14] ()
HKU\Kris\...\Run: [F.lux] "C:\Users\Kris\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
HKU\Kris\...\Run: [ShutdownGuard] "C:\Program Files\ShutdownGuard\ShutdownGuard.exe" -hide [46080 2010-12-05] (Stefan Sundin)
HKU\Kris\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-16] (Valve Corporation)
HKU\Kris\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3077528 2011-08-17] ()
HKU\Kris\...\Run: [RadeonPro] "C:\Program Files (x86)\RadeonPro\RadeonPro.exe" [1832448 2011-02-09] (Mr. John aka japamd)
HKU\Kris\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [642424 2012-02-08] (BitTorrent, Inc.)
HKU\Kris\...\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [393216 2012-03-08] (AMD)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.200.1
Startup: C:\Users\Kris\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
3 HPAuto; "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" [682040 2011-02-16] (Hewlett-Packard)
3 hpCMSrv; "C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe" [1071160 2011-02-15] (Hewlett-Packard Development Company L.P.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-27] ()
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2009-07-16] ()
2 RadeonPro Support Service; "C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe" [12800 2011-02-09] (Mr. John aka japamd)
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-22] (Intel Corporation)
========================== Drivers (Whitelisted) =============
3 tap0801; C:\Windows\System32\Drivers\tap0801.sys [30720 2005-04-13] (The OpenVPN Project)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-26 02:16 - 2012-07-26 02:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1E33B99AF709D0
2012-07-26 02:16 - 2012-07-26 02:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\husehwaz.sys
2012-07-26 01:45 - 2012-07-26 01:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C64FE463A62EB169
2012-07-26 01:35 - 2012-07-26 01:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87992FDC4C857C96
2012-07-26 01:30 - 2012-07-26 01:31 - 00003191 ____A C:\Windows\WindowsUpdate.log
2012-07-26 01:30 - 2012-07-26 01:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-26 01:30 - 2012-07-26 01:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-26 01:29 - 2012-07-26 01:29 - 12621696 ____A (Microsoft Corporation) C:\Users\Kris\Downloads\mseinstall.exe
2012-07-26 01:18 - 2012-07-26 01:18 - 00000056 ____A C:\Windows\setupact.log
2012-07-26 01:18 - 2012-07-26 01:18 - 00000000 ____A C:\Windows\setuperr.log
2012-07-24 23:32 - 2012-07-24 23:32 - 00000000 ____D C:\Program Files (x86)\EPUB to MOBI
2012-07-24 23:28 - 2012-07-24 23:28 - 01519124 ____A (epubtomobi.com ) C:\Users\Kris\Downloads\epubtomobi_setup.exe
2012-07-23 12:41 - 2012-07-25 08:43 - 00000000 ____D C:\Users\Kris\AppData\Local\Downloaded Installations
2012-07-23 12:40 - 2012-07-23 12:41 - 16884522 ____A (Oleg N. Scherbakov) C:\Users\Kris\Downloads\su-setup.exe
2012-07-23 07:51 - 2012-07-23 07:51 - 00064080 ____A C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2012-07-21 21:42 - 2012-07-24 12:22 - 00000000 ____D C:\Users\Kris\AppData\Roaming\six-updater
2012-07-21 21:42 - 2012-07-23 21:36 - 00000000 ____D C:\Users\Kris\AppData\Local\SIX_Projects
2012-07-21 21:42 - 2012-07-21 21:42 - 00000000 ____D C:\Users\Kris\AppData\Roaming\six-zsync
2012-07-21 21:41 - 2012-07-21 21:41 - 00000000 ____D C:\Program Files (x86)\SIX Projects
2012-07-21 20:35 - 2012-07-25 08:47 - 00000000 ____D C:\Users\Kris\AppData\Local\ArmA 2 OA
2012-07-21 20:26 - 2012-07-23 13:06 - 00000000 ____D C:\Users\Kris\Documents\ArmA 2
2012-07-21 20:26 - 2012-07-21 20:26 - 00000000 ____D C:\Users\Kris\AppData\Local\ArmA 2
2012-07-20 21:25 - 2012-07-20 21:25 - 00000000 ____D C:\Program Files\ATI
2012-07-20 14:20 - 2012-07-20 14:20 - 00000000 ____D C:\Users\Kris\AppData\Roaming\ATI
2012-07-20 14:20 - 2012-07-20 14:20 - 00000000 ____D C:\Users\Kris\AppData\Local\ATI
2012-07-20 14:20 - 2012-07-20 14:20 - 00000000 ____D C:\Users\All Users\ATI
2012-07-20 13:23 - 2012-07-20 13:23 - 00000000 ____D C:\Users\All Users\AMD
2012-07-20 13:19 - 2012-07-20 13:22 - 00000000 ____D C:\Program Files\ATI Technologies
2012-07-20 11:09 - 2012-07-20 11:09 - 00000000 ____D C:\Program Files\HTC
2012-07-20 11:08 - 2012-07-20 11:08 - 00000000 ____D C:\Program Files (x86)\HTC
2012-07-19 22:02 - 2012-07-19 22:03 - 00389606 ____A C:\Users\Kris\Downloads\Wrath of the Lamb Version 1.48 (CT Version 1.0 Final).CT
2012-07-18 16:21 - 2012-07-18 16:21 - 00000000 ____D C:\Users\Kris\Documents\Gaslamp Games
2012-07-18 11:36 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-18 11:31 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-18 11:31 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-18 11:31 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-18 11:31 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-18 11:31 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-18 11:31 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-18 11:31 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-18 11:31 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-18 11:31 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-18 11:31 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-18 11:31 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-18 11:31 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-18 11:31 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-18 11:31 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-18 11:31 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-18 11:31 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-18 11:31 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-18 11:31 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-18 11:31 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-18 11:31 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-18 11:31 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-18 11:31 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-18 11:31 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-18 11:31 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-18 11:31 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-18 11:31 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-18 11:31 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-18 11:31 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-18 11:30 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-18 11:30 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-18 11:30 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-18 11:30 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-18 11:30 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-18 11:30 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-18 11:30 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-18 11:30 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-18 11:30 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-18 11:30 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-18 11:30 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-18 11:30 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-18 11:30 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-18 11:30 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-18 11:30 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-18 11:30 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-18 11:30 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-18 11:30 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-18 11:30 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-08 20:53 - 2012-07-08 20:54 - 00000000 ____D C:\Program Files (x86)\OpenVPN
2012-07-08 20:51 - 2012-07-08 20:51 - 01685512 ____A C:\Users\Kris\Downloads\openvpn-2.1_rc19-install.exe
2012-07-07 21:02 - 2012-07-07 21:02 - 01549882 ____A C:\Users\Kris\Downloads\desmume-0.9.8-win64.zip
2012-07-07 20:57 - 2012-07-07 20:57 - 00161188 ____A C:\Users\Kris\Downloads\NO$GBA.2.6a.zip
2012-07-05 21:03 - 2012-07-05 21:03 - 00043976 ____A C:\Users\Kris\Documents\bookmarks.html
2012-07-05 20:13 - 2012-07-05 20:13 - 00000000 ____D C:\Program Files (x86)\CDisplay
2012-07-05 20:12 - 2012-07-05 20:12 - 01158444 ____A C:\Users\Kris\Downloads\setup.zip
2012-07-05 14:34 - 2012-07-11 21:46 - 00000600 ____A C:\Users\Kris\AppData\Local\PUTTY.RND
2012-07-04 15:04 - 2012-07-04 17:08 - 00000600 ____A C:\Users\Kris\AppData\Roaming\winscp.rnd
2012-07-04 15:04 - 2012-07-04 15:04 - 00000000 ____D C:\Program Files (x86)\WinSCP
2012-07-04 14:50 - 2012-07-04 14:45 - 05527637 ____A C:\Users\Kris\Downloads\Torrent Backups.rar
2012-07-04 13:28 - 2012-07-04 13:28 - 03390816 ____A (Martin Prikryl ) C:\Users\Kris\Downloads\winscp438setup-sponsored.exe
2012-07-04 10:20 - 2012-07-04 10:20 - 01119521 ____A C:\Users\Kris\Downloads\openvpn-2.0.9-gui-1.0.3-install.exe
2012-07-03 22:04 - 2012-07-03 22:19 - 278998882 ____A (leshcat ) C:\Users\Kris\Downloads\Catalyst_12.6_WHQL_UnifL.exe
2012-07-01 14:47 - 2012-07-01 14:48 - 04903985 ____A (Skylabs) C:\Users\Kris\Downloads\OCTGN Setup-3.0.1.11.exe
2012-06-28 16:51 - 2012-07-25 20:17 - 00000000 ____D C:\Users\Kris\Feral
2012-06-28 16:24 - 2012-07-25 17:23 - 00000000 ____D C:\Users\Kris\AppData\Roaming\FileZilla
2012-06-28 16:24 - 2012-06-28 16:24 - 00001960 ____A C:\Users\Public\Desktop\FileZilla Client.lnk
2012-06-28 16:23 - 2012-06-28 16:24 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2012-06-28 16:23 - 2012-06-28 16:23 - 04518720 ____A (FileZilla Project) C:\Users\Kris\Downloads\FileZilla_3.5.3_win32-setup.exe
============ 3 Months Modified Files ========================
2012-07-26 02:16 - 2012-07-26 02:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1E33B99AF709D0
2012-07-26 02:16 - 2012-07-26 02:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\husehwaz.sys
2012-07-26 02:05 - 2009-07-13 21:13 - 00795444 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-26 01:45 - 2012-07-26 01:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C64FE463A62EB169
2012-07-26 01:35 - 2012-07-26 01:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87992FDC4C857C96
2012-07-26 01:31 - 2012-07-26 01:30 - 00003191 ____A C:\Windows\WindowsUpdate.log
2012-07-26 01:30 - 2011-08-16 21:13 - 00809594 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-26 01:30 - 2011-08-16 21:13 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-26 01:29 - 2012-07-26 01:29 - 12621696 ____A (Microsoft Corporation) C:\Users\Kris\Downloads\mseinstall.exe
2012-07-26 01:26 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-26 01:26 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-26 01:18 - 2012-07-26 01:18 - 00000056 ____A C:\Windows\setupact.log
2012-07-26 01:18 - 2012-07-26 01:18 - 00000000 ____A C:\Windows\setuperr.log
2012-07-26 01:18 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-26 00:43 - 2012-05-16 23:30 - 00001069 ____A C:\Users\Public\Desktop\Malwarebyte.lnk
2012-07-24 23:28 - 2012-07-24 23:28 - 01519124 ____A (epubtomobi.com ) C:\Users\Kris\Downloads\epubtomobi_setup.exe
2012-07-23 12:41 - 2012-07-23 12:40 - 16884522 ____A (Oleg N. Scherbakov) C:\Users\Kris\Downloads\su-setup.exe
2012-07-23 07:51 - 2012-07-23 07:51 - 00064080 ____A C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2012-07-23 07:51 - 2011-08-17 17:46 - 00064080 ____A C:\Users\Kris\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-20 08:55 - 2012-02-09 04:58 - 00000328 ____A C:\Windows\Tasks\HPCeeScheduleForKris.job
2012-07-19 22:03 - 2012-07-19 22:02 - 00389606 ____A C:\Users\Kris\Downloads\Wrath of the Lamb Version 1.48 (CT Version 1.0 Final).CT
2012-07-19 15:09 - 2012-01-16 16:25 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-07-19 15:08 - 2012-01-16 17:29 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-19 13:16 - 2009-07-13 20:45 - 00293480 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 11:32 - 2011-08-16 21:04 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-17 08:06 - 2012-04-01 12:33 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-17 08:06 - 2011-08-17 18:03 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 21:46 - 2012-07-05 14:34 - 00000600 ____A C:\Users\Kris\AppData\Local\PUTTY.RND
2012-07-08 20:51 - 2012-07-08 20:51 - 01685512 ____A C:\Users\Kris\Downloads\openvpn-2.1_rc19-install.exe
2012-07-08 19:05 - 2012-05-20 09:58 - 00022528 __ASH C:\Users\Kris\Thumbs.db
2012-07-07 21:02 - 2012-07-07 21:02 - 01549882 ____A C:\Users\Kris\Downloads\desmume-0.9.8-win64.zip
2012-07-07 20:57 - 2012-07-07 20:57 - 00161188 ____A C:\Users\Kris\Downloads\NO$GBA.2.6a.zip
2012-07-05 21:03 - 2012-07-05 21:03 - 00043976 ____A C:\Users\Kris\Documents\bookmarks.html
2012-07-05 20:12 - 2012-07-05 20:12 - 01158444 ____A C:\Users\Kris\Downloads\setup.zip
2012-07-04 17:08 - 2012-07-04 15:04 - 00000600 ____A C:\Users\Kris\AppData\Roaming\winscp.rnd
2012-07-04 14:45 - 2012-07-04 14:50 - 05527637 ____A C:\Users\Kris\Downloads\Torrent Backups.rar
2012-07-04 13:28 - 2012-07-04 13:28 - 03390816 ____A (Martin Prikryl ) C:\Users\Kris\Downloads\winscp438setup-sponsored.exe
2012-07-04 10:20 - 2012-07-04 10:20 - 01119521 ____A C:\Users\Kris\Downloads\openvpn-2.0.9-gui-1.0.3-install.exe
2012-07-03 22:40 - 2011-07-27 23:38 - 00000352 ____A C:\Users\Kris\Documents\Links.txt
2012-07-03 22:19 - 2012-07-03 22:04 - 278998882 ____A (leshcat ) C:\Users\Kris\Downloads\Catalyst_12.6_WHQL_UnifL.exe
2012-07-03 09:46 - 2011-08-16 21:12 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-01 14:48 - 2012-07-01 14:47 - 04903985 ____A (Skylabs) C:\Users\Kris\Downloads\OCTGN Setup-3.0.1.11.exe
2012-06-28 16:24 - 2012-06-28 16:24 - 00001960 ____A C:\Users\Public\Desktop\FileZilla Client.lnk
2012-06-28 16:23 - 2012-06-28 16:23 - 04518720 ____A (FileZilla Project) C:\Users\Kris\Downloads\FileZilla_3.5.3_win32-setup.exe
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
2012-06-22 15:08 - 2012-06-22 15:08 - 07171633 ____A (Dark Byte ) C:\Users\Kris\Downloads\CheatEngine62.exe
2012-06-21 19:44 - 2012-06-21 19:44 - 00002543 ____A C:\Users\Kris\Desktop\Magic The Gathering.lnk
2012-06-20 11:59 - 2012-06-20 11:59 - 00001777 ____A C:\Users\Kris\Documents\Wilmington Info.txt
2012-06-20 09:19 - 2012-06-20 09:19 - 00001825 ____A C:\Users\Kris\Desktop\OCTGN.lnk
2012-06-19 23:33 - 2012-06-19 23:33 - 00000988 ____A C:\Users\Kris\Desktop\Magic Workstation.lnk
2012-06-19 23:33 - 2012-06-19 23:33 - 00000941 ____A C:\Users\Kris\Desktop\MWS Online Play.lnk
2012-06-19 23:33 - 2012-06-19 23:32 - 09690219 ____A C:\Users\Kris\Downloads\mws094f.exe
2012-06-14 19:40 - 2011-11-09 22:00 - 00581837 ____A C:\Users\Kris\Downloads\SolEditInstall.exe
2012-06-11 19:08 - 2012-07-18 11:36 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-18 11:30 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-18 11:30 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-18 11:30 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-18 11:30 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-18 11:30 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-18 11:30 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-18 11:30 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-18 11:30 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 02:36 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-19 02:36 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-19 02:36 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-19 02:36 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-19 02:36 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-18 11:31 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-18 11:31 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-18 11:31 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-18 11:31 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-18 11:31 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-18 11:31 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-18 11:31 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-18 11:31 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-18 11:31 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-18 11:31 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-18 11:31 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-18 11:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-18 11:31 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-18 11:31 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-18 11:31 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-18 11:31 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-18 11:31 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-18 11:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-18 11:31 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-18 11:31 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-18 11:31 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-18 11:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-18 11:31 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-18 11:31 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-18 11:31 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-18 11:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-18 11:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-18 11:31 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-18 11:30 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-18 11:30 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-18 11:30 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-18 11:30 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-18 11:30 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-18 11:30 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-18 11:30 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-18 11:30 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-18 11:30 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-26 16:00 - 2012-05-26 16:00 - 00000068 ____A C:\Users\Kris\Documents\Bnet.txt
2012-05-26 13:58 - 2012-05-26 13:58 - 00000000 ____A C:\Windows\ativpsrm.bin
2012-05-26 11:12 - 2012-05-26 10:30 - 284703496 ____A (leshcat ) C:\Users\Kris\Downloads\Catalyst_12.3_UP2_UnifL.exe
2012-05-26 10:32 - 2012-05-26 10:31 - 01691498 ____A C:\Users\Kris\Documents\Izalith - One.3ga
2012-05-26 10:31 - 2012-05-26 10:31 - 02072188 ____A C:\Users\Kris\Documents\Izalith - Two.3ga
2012-05-24 13:21 - 2012-05-24 13:21 - 00001082 ____A C:\Users\Kris\Desktop\MSI Afterburner.lnk
2012-05-24 13:21 - 2012-05-24 13:21 - 00000931 ____A C:\Users\Kris\Desktop\RadeonPro.lnk
2012-05-21 21:55 - 2012-05-21 21:55 - 02442688 ____A (Mr. John aka japamd ) C:\Users\Kris\Downloads\RadeonPro_RC1.exe
2012-05-21 21:50 - 2012-05-21 21:48 - 24139013 ____A C:\Users\Kris\Downloads\MSIAfterburnerSetup221.zip
2012-05-21 19:19 - 2012-05-21 19:19 - 00001542 ____A C:\Users\Kris\AppData\Local\PDLSetup.20120521.231907.txt
2012-05-21 18:09 - 2012-05-21 18:04 - 02162441 ____A C:\Users\Kris\Downloads\RadarSync PC Updater 3.7+Patch[h33t][eSpNs].rar
2012-05-21 14:48 - 2012-05-21 14:48 - 08134792 ____A C:\Users\Kris\Documents\torrent backups .rar
2012-05-21 14:13 - 2012-05-21 14:13 - 08140200 ____A C:\Users\Kris\Documents\utorrent backup.utb
2012-05-20 23:16 - 2012-05-20 23:14 - 00001149 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-20 23:10 - 2012-05-20 23:02 - 32288896 ____A (Blizzard Entertainment) C:\Users\Kris\Downloads\Diablo-III-Setup-enUS.exe
2012-05-20 14:48 - 2012-05-20 14:48 - 00000967 ____A C:\Users\Public\Desktop\PowerISO.lnk
2012-05-16 23:15 - 2011-08-23 16:58 - 00001798 ____A C:\Users\All Users\hpzinstall.log
2012-05-14 08:12 - 2012-04-28 18:16 - 00007597 ____A C:\Users\Kris\AppData\Local\resmon.resmoncfg
2012-05-12 15:43 - 2011-08-16 22:29 - 05227019 ____A C:\Users\Kris\Downloads\namebench-1.3.1-Windows.exe
2012-05-04 03:06 - 2012-06-14 15:37 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-14 15:37 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-14 15:37 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-14 15:37 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-14 15:37 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-14 15:37 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
ZeroAccess:
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\@
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\L
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\n
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\U
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 8139.86 MB
Available physical RAM: 7230.03 MB
Total Pagefile: 8138.01 MB
Available Pagefile: 7222.97 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:683.99 GB) (Free:53.17 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:14.36 GB) (Free:1.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.08 GB) FAT32
5 Drive h: () (Removable) (Total:14.8 GB) (Free:14.79 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 683 GB 200 MB
Partition 3 Primary 14 GB 684 GB
Partition 4 Primary 102 MB 698 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 683 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 102 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 1240 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 14 GB Healthy
==================================================================================
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
==========================================================
Last Boot: 2012-07-18 14:55
======================= End Of Log ==========================
2 - Search.txt
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-26 07:02:38
Running from H:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
1 - FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 26-07-2012 07:00:17
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash [1617920 2011-01-26] (Intel® Corporation)
HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-07-27] (Intel(R) Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2012-01-16] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-10-21] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-10-21] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-10-21] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2012-01-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [636032 2012-03-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-01-31] ()
HKLM-x32\...\Run: [VMM Mode Selection] C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe [43520 2011-02-14] ()
HKU\Kris\...\Run: [F.lux] "C:\Users\Kris\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
HKU\Kris\...\Run: [ShutdownGuard] "C:\Program Files\ShutdownGuard\ShutdownGuard.exe" -hide [46080 2010-12-05] (Stefan Sundin)
HKU\Kris\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-16] (Valve Corporation)
HKU\Kris\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3077528 2011-08-17] ()
HKU\Kris\...\Run: [RadeonPro] "C:\Program Files (x86)\RadeonPro\RadeonPro.exe" [1832448 2011-02-09] (Mr. John aka japamd)
HKU\Kris\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [642424 2012-02-08] (BitTorrent, Inc.)
HKU\Kris\...\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [393216 2012-03-08] (AMD)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.200.1
Startup: C:\Users\Kris\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
3 HPAuto; "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" [682040 2011-02-16] (Hewlett-Packard)
3 hpCMSrv; "C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe" [1071160 2011-02-15] (Hewlett-Packard Development Company L.P.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-27] ()
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2009-07-16] ()
2 RadeonPro Support Service; "C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe" [12800 2011-02-09] (Mr. John aka japamd)
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2010-12-22] (Intel Corporation)
========================== Drivers (Whitelisted) =============
3 tap0801; C:\Windows\System32\Drivers\tap0801.sys [30720 2005-04-13] (The OpenVPN Project)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-26 02:16 - 2012-07-26 02:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1E33B99AF709D0
2012-07-26 02:16 - 2012-07-26 02:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\husehwaz.sys
2012-07-26 01:45 - 2012-07-26 01:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C64FE463A62EB169
2012-07-26 01:35 - 2012-07-26 01:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87992FDC4C857C96
2012-07-26 01:30 - 2012-07-26 01:31 - 00003191 ____A C:\Windows\WindowsUpdate.log
2012-07-26 01:30 - 2012-07-26 01:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-26 01:30 - 2012-07-26 01:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-26 01:29 - 2012-07-26 01:29 - 12621696 ____A (Microsoft Corporation) C:\Users\Kris\Downloads\mseinstall.exe
2012-07-26 01:18 - 2012-07-26 01:18 - 00000056 ____A C:\Windows\setupact.log
2012-07-26 01:18 - 2012-07-26 01:18 - 00000000 ____A C:\Windows\setuperr.log
2012-07-24 23:32 - 2012-07-24 23:32 - 00000000 ____D C:\Program Files (x86)\EPUB to MOBI
2012-07-24 23:28 - 2012-07-24 23:28 - 01519124 ____A (epubtomobi.com ) C:\Users\Kris\Downloads\epubtomobi_setup.exe
2012-07-23 12:41 - 2012-07-25 08:43 - 00000000 ____D C:\Users\Kris\AppData\Local\Downloaded Installations
2012-07-23 12:40 - 2012-07-23 12:41 - 16884522 ____A (Oleg N. Scherbakov) C:\Users\Kris\Downloads\su-setup.exe
2012-07-23 07:51 - 2012-07-23 07:51 - 00064080 ____A C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2012-07-21 21:42 - 2012-07-24 12:22 - 00000000 ____D C:\Users\Kris\AppData\Roaming\six-updater
2012-07-21 21:42 - 2012-07-23 21:36 - 00000000 ____D C:\Users\Kris\AppData\Local\SIX_Projects
2012-07-21 21:42 - 2012-07-21 21:42 - 00000000 ____D C:\Users\Kris\AppData\Roaming\six-zsync
2012-07-21 21:41 - 2012-07-21 21:41 - 00000000 ____D C:\Program Files (x86)\SIX Projects
2012-07-21 20:35 - 2012-07-25 08:47 - 00000000 ____D C:\Users\Kris\AppData\Local\ArmA 2 OA
2012-07-21 20:26 - 2012-07-23 13:06 - 00000000 ____D C:\Users\Kris\Documents\ArmA 2
2012-07-21 20:26 - 2012-07-21 20:26 - 00000000 ____D C:\Users\Kris\AppData\Local\ArmA 2
2012-07-20 21:25 - 2012-07-20 21:25 - 00000000 ____D C:\Program Files\ATI
2012-07-20 14:20 - 2012-07-20 14:20 - 00000000 ____D C:\Users\Kris\AppData\Roaming\ATI
2012-07-20 14:20 - 2012-07-20 14:20 - 00000000 ____D C:\Users\Kris\AppData\Local\ATI
2012-07-20 14:20 - 2012-07-20 14:20 - 00000000 ____D C:\Users\All Users\ATI
2012-07-20 13:23 - 2012-07-20 13:23 - 00000000 ____D C:\Users\All Users\AMD
2012-07-20 13:19 - 2012-07-20 13:22 - 00000000 ____D C:\Program Files\ATI Technologies
2012-07-20 11:09 - 2012-07-20 11:09 - 00000000 ____D C:\Program Files\HTC
2012-07-20 11:08 - 2012-07-20 11:08 - 00000000 ____D C:\Program Files (x86)\HTC
2012-07-19 22:02 - 2012-07-19 22:03 - 00389606 ____A C:\Users\Kris\Downloads\Wrath of the Lamb Version 1.48 (CT Version 1.0 Final).CT
2012-07-18 16:21 - 2012-07-18 16:21 - 00000000 ____D C:\Users\Kris\Documents\Gaslamp Games
2012-07-18 11:36 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-18 11:31 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-18 11:31 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-18 11:31 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-18 11:31 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-18 11:31 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-18 11:31 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-18 11:31 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-18 11:31 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-18 11:31 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-18 11:31 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-18 11:31 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-18 11:31 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-18 11:31 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-18 11:31 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-18 11:31 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-18 11:31 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-18 11:31 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-18 11:31 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-18 11:31 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-18 11:31 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-18 11:31 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-18 11:31 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-18 11:31 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-18 11:31 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-18 11:31 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-18 11:31 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-18 11:31 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-18 11:31 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-18 11:30 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-18 11:30 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-18 11:30 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-18 11:30 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-18 11:30 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-18 11:30 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-18 11:30 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-18 11:30 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-18 11:30 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-18 11:30 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-18 11:30 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-18 11:30 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-18 11:30 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-18 11:30 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-18 11:30 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-18 11:30 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-18 11:30 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-18 11:30 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-18 11:30 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-08 20:53 - 2012-07-08 20:54 - 00000000 ____D C:\Program Files (x86)\OpenVPN
2012-07-08 20:51 - 2012-07-08 20:51 - 01685512 ____A C:\Users\Kris\Downloads\openvpn-2.1_rc19-install.exe
2012-07-07 21:02 - 2012-07-07 21:02 - 01549882 ____A C:\Users\Kris\Downloads\desmume-0.9.8-win64.zip
2012-07-07 20:57 - 2012-07-07 20:57 - 00161188 ____A C:\Users\Kris\Downloads\NO$GBA.2.6a.zip
2012-07-05 21:03 - 2012-07-05 21:03 - 00043976 ____A C:\Users\Kris\Documents\bookmarks.html
2012-07-05 20:13 - 2012-07-05 20:13 - 00000000 ____D C:\Program Files (x86)\CDisplay
2012-07-05 20:12 - 2012-07-05 20:12 - 01158444 ____A C:\Users\Kris\Downloads\setup.zip
2012-07-05 14:34 - 2012-07-11 21:46 - 00000600 ____A C:\Users\Kris\AppData\Local\PUTTY.RND
2012-07-04 15:04 - 2012-07-04 17:08 - 00000600 ____A C:\Users\Kris\AppData\Roaming\winscp.rnd
2012-07-04 15:04 - 2012-07-04 15:04 - 00000000 ____D C:\Program Files (x86)\WinSCP
2012-07-04 14:50 - 2012-07-04 14:45 - 05527637 ____A C:\Users\Kris\Downloads\Torrent Backups.rar
2012-07-04 13:28 - 2012-07-04 13:28 - 03390816 ____A (Martin Prikryl ) C:\Users\Kris\Downloads\winscp438setup-sponsored.exe
2012-07-04 10:20 - 2012-07-04 10:20 - 01119521 ____A C:\Users\Kris\Downloads\openvpn-2.0.9-gui-1.0.3-install.exe
2012-07-03 22:04 - 2012-07-03 22:19 - 278998882 ____A (leshcat ) C:\Users\Kris\Downloads\Catalyst_12.6_WHQL_UnifL.exe
2012-07-01 14:47 - 2012-07-01 14:48 - 04903985 ____A (Skylabs) C:\Users\Kris\Downloads\OCTGN Setup-3.0.1.11.exe
2012-06-28 16:51 - 2012-07-25 20:17 - 00000000 ____D C:\Users\Kris\Feral
2012-06-28 16:24 - 2012-07-25 17:23 - 00000000 ____D C:\Users\Kris\AppData\Roaming\FileZilla
2012-06-28 16:24 - 2012-06-28 16:24 - 00001960 ____A C:\Users\Public\Desktop\FileZilla Client.lnk
2012-06-28 16:23 - 2012-06-28 16:24 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2012-06-28 16:23 - 2012-06-28 16:23 - 04518720 ____A (FileZilla Project) C:\Users\Kris\Downloads\FileZilla_3.5.3_win32-setup.exe
============ 3 Months Modified Files ========================
2012-07-26 02:16 - 2012-07-26 02:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1E33B99AF709D0
2012-07-26 02:16 - 2012-07-26 02:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\husehwaz.sys
2012-07-26 02:05 - 2009-07-13 21:13 - 00795444 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-26 01:45 - 2012-07-26 01:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C64FE463A62EB169
2012-07-26 01:35 - 2012-07-26 01:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87992FDC4C857C96
2012-07-26 01:31 - 2012-07-26 01:30 - 00003191 ____A C:\Windows\WindowsUpdate.log
2012-07-26 01:30 - 2011-08-16 21:13 - 00809594 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-26 01:30 - 2011-08-16 21:13 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-26 01:29 - 2012-07-26 01:29 - 12621696 ____A (Microsoft Corporation) C:\Users\Kris\Downloads\mseinstall.exe
2012-07-26 01:26 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-26 01:26 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-26 01:18 - 2012-07-26 01:18 - 00000056 ____A C:\Windows\setupact.log
2012-07-26 01:18 - 2012-07-26 01:18 - 00000000 ____A C:\Windows\setuperr.log
2012-07-26 01:18 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-26 00:43 - 2012-05-16 23:30 - 00001069 ____A C:\Users\Public\Desktop\Malwarebyte.lnk
2012-07-24 23:28 - 2012-07-24 23:28 - 01519124 ____A (epubtomobi.com ) C:\Users\Kris\Downloads\epubtomobi_setup.exe
2012-07-23 12:41 - 2012-07-23 12:40 - 16884522 ____A (Oleg N. Scherbakov) C:\Users\Kris\Downloads\su-setup.exe
2012-07-23 07:51 - 2012-07-23 07:51 - 00064080 ____A C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2012-07-23 07:51 - 2011-08-17 17:46 - 00064080 ____A C:\Users\Kris\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-20 08:55 - 2012-02-09 04:58 - 00000328 ____A C:\Windows\Tasks\HPCeeScheduleForKris.job
2012-07-19 22:03 - 2012-07-19 22:02 - 00389606 ____A C:\Users\Kris\Downloads\Wrath of the Lamb Version 1.48 (CT Version 1.0 Final).CT
2012-07-19 15:09 - 2012-01-16 16:25 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-07-19 15:08 - 2012-01-16 17:29 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-19 13:16 - 2009-07-13 20:45 - 00293480 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 11:32 - 2011-08-16 21:04 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-17 08:06 - 2012-04-01 12:33 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-17 08:06 - 2011-08-17 18:03 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 21:46 - 2012-07-05 14:34 - 00000600 ____A C:\Users\Kris\AppData\Local\PUTTY.RND
2012-07-08 20:51 - 2012-07-08 20:51 - 01685512 ____A C:\Users\Kris\Downloads\openvpn-2.1_rc19-install.exe
2012-07-08 19:05 - 2012-05-20 09:58 - 00022528 __ASH C:\Users\Kris\Thumbs.db
2012-07-07 21:02 - 2012-07-07 21:02 - 01549882 ____A C:\Users\Kris\Downloads\desmume-0.9.8-win64.zip
2012-07-07 20:57 - 2012-07-07 20:57 - 00161188 ____A C:\Users\Kris\Downloads\NO$GBA.2.6a.zip
2012-07-05 21:03 - 2012-07-05 21:03 - 00043976 ____A C:\Users\Kris\Documents\bookmarks.html
2012-07-05 20:12 - 2012-07-05 20:12 - 01158444 ____A C:\Users\Kris\Downloads\setup.zip
2012-07-04 17:08 - 2012-07-04 15:04 - 00000600 ____A C:\Users\Kris\AppData\Roaming\winscp.rnd
2012-07-04 14:45 - 2012-07-04 14:50 - 05527637 ____A C:\Users\Kris\Downloads\Torrent Backups.rar
2012-07-04 13:28 - 2012-07-04 13:28 - 03390816 ____A (Martin Prikryl ) C:\Users\Kris\Downloads\winscp438setup-sponsored.exe
2012-07-04 10:20 - 2012-07-04 10:20 - 01119521 ____A C:\Users\Kris\Downloads\openvpn-2.0.9-gui-1.0.3-install.exe
2012-07-03 22:40 - 2011-07-27 23:38 - 00000352 ____A C:\Users\Kris\Documents\Links.txt
2012-07-03 22:19 - 2012-07-03 22:04 - 278998882 ____A (leshcat ) C:\Users\Kris\Downloads\Catalyst_12.6_WHQL_UnifL.exe
2012-07-03 09:46 - 2011-08-16 21:12 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-01 14:48 - 2012-07-01 14:47 - 04903985 ____A (Skylabs) C:\Users\Kris\Downloads\OCTGN Setup-3.0.1.11.exe
2012-06-28 16:24 - 2012-06-28 16:24 - 00001960 ____A C:\Users\Public\Desktop\FileZilla Client.lnk
2012-06-28 16:23 - 2012-06-28 16:23 - 04518720 ____A (FileZilla Project) C:\Users\Kris\Downloads\FileZilla_3.5.3_win32-setup.exe
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
2012-06-22 15:08 - 2012-06-22 15:08 - 07171633 ____A (Dark Byte ) C:\Users\Kris\Downloads\CheatEngine62.exe
2012-06-21 19:44 - 2012-06-21 19:44 - 00002543 ____A C:\Users\Kris\Desktop\Magic The Gathering.lnk
2012-06-20 11:59 - 2012-06-20 11:59 - 00001777 ____A C:\Users\Kris\Documents\Wilmington Info.txt
2012-06-20 09:19 - 2012-06-20 09:19 - 00001825 ____A C:\Users\Kris\Desktop\OCTGN.lnk
2012-06-19 23:33 - 2012-06-19 23:33 - 00000988 ____A C:\Users\Kris\Desktop\Magic Workstation.lnk
2012-06-19 23:33 - 2012-06-19 23:33 - 00000941 ____A C:\Users\Kris\Desktop\MWS Online Play.lnk
2012-06-19 23:33 - 2012-06-19 23:32 - 09690219 ____A C:\Users\Kris\Downloads\mws094f.exe
2012-06-14 19:40 - 2011-11-09 22:00 - 00581837 ____A C:\Users\Kris\Downloads\SolEditInstall.exe
2012-06-11 19:08 - 2012-07-18 11:36 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-18 11:30 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-18 11:30 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-18 11:30 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-18 11:30 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-18 11:30 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-18 11:30 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-18 11:30 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-18 11:30 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 02:36 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 02:36 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-19 02:36 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-19 02:36 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-19 02:36 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-19 02:36 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-18 11:31 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-18 11:31 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-18 11:31 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-18 11:31 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-18 11:31 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-18 11:31 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-18 11:31 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-18 11:31 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-18 11:31 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-18 11:31 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-18 11:31 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-18 11:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-18 11:31 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-18 11:31 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-18 11:31 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-18 11:31 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-18 11:31 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-18 11:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-18 11:31 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-18 11:31 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-18 11:31 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-18 11:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-18 11:31 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-18 11:31 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-18 11:31 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-18 11:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-18 11:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-18 11:31 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-18 11:30 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-18 11:30 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-18 11:30 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-18 11:30 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-18 11:30 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-18 11:30 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-18 11:30 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-18 11:30 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-18 11:30 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-26 16:00 - 2012-05-26 16:00 - 00000068 ____A C:\Users\Kris\Documents\Bnet.txt
2012-05-26 13:58 - 2012-05-26 13:58 - 00000000 ____A C:\Windows\ativpsrm.bin
2012-05-26 11:12 - 2012-05-26 10:30 - 284703496 ____A (leshcat ) C:\Users\Kris\Downloads\Catalyst_12.3_UP2_UnifL.exe
2012-05-26 10:32 - 2012-05-26 10:31 - 01691498 ____A C:\Users\Kris\Documents\Izalith - One.3ga
2012-05-26 10:31 - 2012-05-26 10:31 - 02072188 ____A C:\Users\Kris\Documents\Izalith - Two.3ga
2012-05-24 13:21 - 2012-05-24 13:21 - 00001082 ____A C:\Users\Kris\Desktop\MSI Afterburner.lnk
2012-05-24 13:21 - 2012-05-24 13:21 - 00000931 ____A C:\Users\Kris\Desktop\RadeonPro.lnk
2012-05-21 21:55 - 2012-05-21 21:55 - 02442688 ____A (Mr. John aka japamd ) C:\Users\Kris\Downloads\RadeonPro_RC1.exe
2012-05-21 21:50 - 2012-05-21 21:48 - 24139013 ____A C:\Users\Kris\Downloads\MSIAfterburnerSetup221.zip
2012-05-21 19:19 - 2012-05-21 19:19 - 00001542 ____A C:\Users\Kris\AppData\Local\PDLSetup.20120521.231907.txt
2012-05-21 18:09 - 2012-05-21 18:04 - 02162441 ____A C:\Users\Kris\Downloads\RadarSync PC Updater 3.7+Patch[h33t][eSpNs].rar
2012-05-21 14:48 - 2012-05-21 14:48 - 08134792 ____A C:\Users\Kris\Documents\torrent backups .rar
2012-05-21 14:13 - 2012-05-21 14:13 - 08140200 ____A C:\Users\Kris\Documents\utorrent backup.utb
2012-05-20 23:16 - 2012-05-20 23:14 - 00001149 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-20 23:10 - 2012-05-20 23:02 - 32288896 ____A (Blizzard Entertainment) C:\Users\Kris\Downloads\Diablo-III-Setup-enUS.exe
2012-05-20 14:48 - 2012-05-20 14:48 - 00000967 ____A C:\Users\Public\Desktop\PowerISO.lnk
2012-05-16 23:15 - 2011-08-23 16:58 - 00001798 ____A C:\Users\All Users\hpzinstall.log
2012-05-14 08:12 - 2012-04-28 18:16 - 00007597 ____A C:\Users\Kris\AppData\Local\resmon.resmoncfg
2012-05-12 15:43 - 2011-08-16 22:29 - 05227019 ____A C:\Users\Kris\Downloads\namebench-1.3.1-Windows.exe
2012-05-04 03:06 - 2012-06-14 15:37 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-14 15:37 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-14 15:37 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-14 15:37 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-14 15:37 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-14 15:37 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
ZeroAccess:
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\@
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\L
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\n
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\U
C:\Users\Kris\AppData\Local\{17fa1868-de07-0457-3d17-6e3b055b5d80}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 8139.86 MB
Available physical RAM: 7230.03 MB
Total Pagefile: 8138.01 MB
Available Pagefile: 7222.97 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:683.99 GB) (Free:53.17 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:14.36 GB) (Free:1.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.08 GB) FAT32
5 Drive h: () (Removable) (Total:14.8 GB) (Free:14.79 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 683 GB 200 MB
Partition 3 Primary 14 GB 684 GB
Partition 4 Primary 102 MB 698 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 683 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 102 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 1240 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 14 GB Healthy
==================================================================================
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
==========================================================
Last Boot: 2012-07-18 14:55
======================= End Of Log ==========================
2 - Search.txt
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-26 07:02:38
Running from H:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======