Anthony140
Posts: 6 +0
I'm having trouble getting rid of the sirefef trojan. I, like many others who have posted recently, am getting an error message upon bootup telling me that a critical error has occured, and reboots within a minute, which is leaving me no time to try any virus removal programs. I'm running Windows 7 64bit. I have already run FRST, and I the scan results are posted below. I've also run the search for services.exe, which I'm putting in the next post. Thanks, any help would be very much appreciated.
Scan result of Farbar Recovery Scan Tool Version: 17-06-2012 04
Ran by SYSTEM at 18-06-2012 22:31:28
Running from H:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 24.177.176.38 71.92.29.130
HKLM\...\InprocServer32: [Default-wbemess] \\.\globalroot\systemroot\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\n. ATTENTION! ====> ZeroAccess
==================== Services (Whitelisted) ======
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 RemoteAccess; C:\Windows\SysWOW64\mprdin.dll [1725952 2012-05-27] ()
4 Mcx2Svc; C:\Windows\SysWOW64\Mcx2Svc.dll [x]
========================== Drivers (Whitelisted) =============
3 AE1000; C:\Windows\System32\DRIVERS\ae1000w7.sys [1101600 2010-02-12] (Ralink Technology Corp.)
3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [19968 2011-02-23] (Microsoft Corporation)
3 epmntdrv; \??\C:\Windows\system32\epmntdrv.sys [16776 2010-07-15] ()
3 EuGdiDrv; \??\C:\Windows\system32\EuGdiDrv.sys [9096 2010-07-15] ()
3 pbfilter; \??\C:\Program Files\PeerBlock\pbfilter.sys [24176 2010-11-06] ()
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
NETSVCx32: Mcx2Svc -> C:\Windows\SysWOW64\Mcx2Svc.dll ==> No File.
============ One Month Created Files and Folders ==============
2012-06-18 22:31 - 2012-06-18 22:31 - 00000000 ____D C:\FRST
2012-06-17 19:57 - 2012-06-17 20:07 - 00218563 ____A C:\Users\Anthony\Downloads\yorkyt.exe.log
2012-06-17 19:55 - 2012-06-17 19:55 - 01415784 ____A C:\Users\Anthony\Downloads\yorkyt.exe
2012-06-17 17:57 - 2012-06-17 17:57 - 00000036 ____A C:\Users\Anthony\AppData\Local\housecall.guid.cache
2012-06-17 17:57 - 2012-06-17 17:57 - 00000000 ____D C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019
2012-06-17 17:50 - 2012-06-17 17:50 - 04731392 ____A (AVAST Software) C:\Users\Anthony\Downloads\aswMBR.exe
2012-06-17 17:49 - 2012-06-17 17:49 - 02048818 ____A C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019.zip
2012-06-17 17:25 - 2012-06-18 19:19 - 00832286 ____A C:\Windows\ntbtlog.txt
2012-06-17 17:18 - 2012-06-17 17:18 - 00000000 ____D C:\Users\Anthony\AppData\Local\ElevatedDiagnostics
2012-06-17 17:17 - 2012-06-17 17:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\MicrosoftFixit.WindowsFirewall.RNP.81263412915320082.4.1.Run.exe
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-17 17:11 - 2012-06-17 17:11 - 12621696 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\mseinstall.exe
2012-06-17 17:06 - 2012-06-17 17:06 - 00000000 ____D C:\Users\Anthony\Downloads\NBA TV
2012-06-17 17:01 - 2012-06-17 17:01 - 00229548 ____A C:\Users\Anthony\Downloads\1055.BFE.reg
2012-06-17 17:01 - 2012-06-17 17:01 - 00006396 ____A C:\Users\Anthony\Downloads\0677.mpssvc.reg
2012-06-17 16:56 - 2012-06-17 16:56 - 00012168 ____A C:\Users\Anthony\Downloads\+-Demonoid.me-+_NBA_TV_The_Dream_Team_Documentary_720p_HD_x264_590534.5606.torrent
2012-06-14 19:22 - 2012-06-14 19:23 - 00000000 ____D C:\Users\Anthony\Downloads\A Brief History of Thought
2012-06-14 19:21 - 2012-06-14 19:21 - 00006962 ____A C:\Users\Anthony\Downloads\[[Demonoid.me]]-A_Brief_History_of_Thought_A_Philosophical_Guide_to_Living_(2011)_epub_mobi_590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00026709 ____A C:\Users\Anthony\Downloads\NY_Times_Bestseller_Combined_Print_and_Ebook_Fiction_Top_15_for_June_17th-_=Demonoid.me=__590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00000000 ____D C:\Users\Anthony\Downloads\Fiction
2012-06-13 00:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 00:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 00:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 00:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 00:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 00:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 00:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 00:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 00:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 00:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 00:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 00:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 00:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 00:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 00:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 00:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 00:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 00:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 00:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 00:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 00:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 00:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 00:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 00:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 00:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 00:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 00:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 00:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 14:03 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 14:03 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 14:03 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 14:03 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 14:03 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 14:03 - 2012-04-27 21:32 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-06-12 14:03 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 14:03 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 14:03 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 14:03 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 14:03 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 14:03 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 14:02 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 14:02 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 14:02 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 14:02 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 14:02 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 14:02 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-09 18:39 - 2012-06-09 19:15 - 00000000 ____D C:\Users\Anthony\Downloads\30 Life changing books
2012-06-09 18:36 - 2012-06-09 18:36 - 00015084 ____A C:\Users\Anthony\Downloads\_=Demonoid.me=_-30_life_changing_books_(sex_relationships_money_fitness_bdsm_music_travel_spirituality_cooking_drawing_etc)_590534.5606.torrent
2012-06-07 16:44 - 2012-06-07 17:35 - 00000000 ____D C:\Users\Anthony\Downloads\Arrested Development
2012-06-07 16:41 - 2012-06-07 16:41 - 00054312 ____A C:\Users\Anthony\Downloads\Arrested_Development_[Season_1_3]_Full-[[Demonoid.me]]_590534.5606.torrent
2012-06-05 17:24 - 2012-06-07 16:50 - 00000000 ____D C:\Users\Anthony\Downloads\PBS EMPIRES Medici Godfathers
2012-05-30 18:20 - 2012-05-30 18:20 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-27 18:09 - 2012-05-27 18:09 - 01725952 ____A C:\Windows\SysWOW64\mprdin.dll
2012-05-27 18:09 - 2012-05-27 18:09 - 00000395 ____A C:\Windows\SysWOW64\mprdin.ocx
============ 3 Months Modified Files and Folders =============
2012-06-18 22:31 - 2012-06-18 22:31 - 00000000 ____D C:\FRST
2012-06-18 19:20 - 2012-03-13 19:53 - 4294107136 __ASH C:\pagefile.sys
2012-06-18 19:20 - 2012-03-13 19:53 - 3220578304 __ASH C:\hiberfil.sys
2012-06-18 19:20 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-18 19:20 - 2009-07-13 20:51 - 00025459 ____A C:\Windows\setupact.log
2012-06-18 19:19 - 2012-06-17 17:25 - 00832286 ____A C:\Windows\ntbtlog.txt
2012-06-17 20:07 - 2012-06-17 19:57 - 00218563 ____A C:\Users\Anthony\Downloads\yorkyt.exe.log
2012-06-17 20:06 - 2012-03-13 19:53 - 00000000 __SHD C:\System Volume Information
2012-06-17 19:57 - 2009-07-13 19:20 - 00000000 ____D C:\Windows
2012-06-17 19:55 - 2012-06-17 19:55 - 01415784 ____A C:\Users\Anthony\Downloads\yorkyt.exe
2012-06-17 17:57 - 2012-06-17 17:57 - 00000036 ____A C:\Users\Anthony\AppData\Local\housecall.guid.cache
2012-06-17 17:57 - 2012-06-17 17:57 - 00000000 ____D C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019
2012-06-17 17:50 - 2012-06-17 17:50 - 04731392 ____A (AVAST Software) C:\Users\Anthony\Downloads\aswMBR.exe
2012-06-17 17:49 - 2012-06-17 17:49 - 02048818 ____A C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019.zip
2012-06-17 17:31 - 2012-03-14 15:02 - 00000000 __SHD C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}
2012-06-17 17:22 - 2012-05-03 16:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-17 17:22 - 2012-03-20 18:43 - 00000000 ___HD C:\Config.Msi
2012-06-17 17:21 - 2012-03-13 20:44 - 00000000 ____D C:\Program Files\PeerBlock
2012-06-17 17:20 - 2012-03-13 20:41 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\uTorrent
2012-06-17 17:18 - 2012-06-17 17:18 - 00000000 ____D C:\Users\Anthony\AppData\Local\ElevatedDiagnostics
2012-06-17 17:17 - 2012-06-17 17:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\MicrosoftFixit.WindowsFirewall.RNP.81263412915320082.4.1.Run.exe
2012-06-17 17:16 - 2012-03-13 19:57 - 01300696 ____A C:\Windows\WindowsUpdate.log
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-17 17:14 - 2012-03-13 19:19 - 00743538 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-17 17:14 - 2012-03-13 19:19 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-17 17:14 - 2009-07-13 19:20 - 00000000 ___RD C:\Program Files (x86)
2012-06-17 17:14 - 2009-07-13 19:20 - 00000000 ___RD C:\Program Files
2012-06-17 17:11 - 2012-06-17 17:11 - 12621696 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\mseinstall.exe
2012-06-17 17:11 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-17 17:11 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-17 17:08 - 2009-07-13 21:13 - 00729816 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-17 17:06 - 2012-06-17 17:06 - 00000000 ____D C:\Users\Anthony\Downloads\NBA TV
2012-06-17 17:05 - 2012-03-13 19:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-17 17:01 - 2012-06-17 17:01 - 00229548 ____A C:\Users\Anthony\Downloads\1055.BFE.reg
2012-06-17 17:01 - 2012-06-17 17:01 - 00006396 ____A C:\Users\Anthony\Downloads\0677.mpssvc.reg
2012-06-17 16:56 - 2012-06-17 16:56 - 00012168 ____A C:\Users\Anthony\Downloads\+-Demonoid.me-+_NBA_TV_The_Dream_Team_Documentary_720p_HD_x264_590534.5606.torrent
2012-06-17 16:49 - 2012-04-03 19:18 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-15 20:40 - 2012-03-13 20:57 - 00000000 ____D C:\Users\Anthony\Downloads\1417 16th ST S
2012-06-14 19:23 - 2012-06-14 19:22 - 00000000 ____D C:\Users\Anthony\Downloads\A Brief History of Thought
2012-06-14 19:21 - 2012-06-14 19:21 - 00006962 ____A C:\Users\Anthony\Downloads\[[Demonoid.me]]-A_Brief_History_of_Thought_A_Philosophical_Guide_to_Living_(2011)_epub_mobi_590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00026709 ____A C:\Users\Anthony\Downloads\NY_Times_Bestseller_Combined_Print_and_Ebook_Fiction_Top_15_for_June_17th-_=Demonoid.me=__590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00000000 ____D C:\Users\Anthony\Downloads\Fiction
2012-06-13 00:59 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-06-13 00:22 - 2009-07-13 20:45 - 04973160 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 00:06 - 2012-03-13 20:17 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-13 00:03 - 2012-03-14 20:04 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-09 19:15 - 2012-06-09 18:39 - 00000000 ____D C:\Users\Anthony\Downloads\30 Life changing books
2012-06-09 18:36 - 2012-06-09 18:36 - 00015084 ____A C:\Users\Anthony\Downloads\_=Demonoid.me=_-30_life_changing_books_(sex_relationships_money_fitness_bdsm_music_travel_spirituality_cooking_drawing_etc)_590534.5606.torrent
2012-06-07 18:04 - 2012-04-03 20:51 - 00000000 ____D C:\Users\Anthony\My Music 2
2012-06-07 17:35 - 2012-06-07 16:44 - 00000000 ____D C:\Users\Anthony\Downloads\Arrested Development
2012-06-07 16:50 - 2012-06-05 17:24 - 00000000 ____D C:\Users\Anthony\Downloads\PBS EMPIRES Medici Godfathers
2012-06-07 16:41 - 2012-06-07 16:41 - 00054312 ____A C:\Users\Anthony\Downloads\Arrested_Development_[Season_1_3]_Full-[[Demonoid.me]]_590534.5606.torrent
2012-06-07 16:39 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-06-04 18:38 - 2012-03-14 20:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-05-30 18:20 - 2012-05-30 18:20 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-27 18:09 - 2012-05-27 18:09 - 01725952 ____A C:\Windows\SysWOW64\mprdin.dll
2012-05-27 18:09 - 2012-05-27 18:09 - 00000395 ____A C:\Windows\SysWOW64\mprdin.ocx
2012-05-20 15:53 - 2012-04-07 19:16 - 00214016 ____A C:\Users\Anthony\AppData\Roaming\SharedSettings.ccs
2012-05-19 18:20 - 2012-03-13 20:41 - 00000000 ____D C:\Program Files (x86)\uTorrent
2012-05-17 18:47 - 2012-06-13 00:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 00:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 00:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 00:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 00:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 00:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 00:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 00:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 00:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 00:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 00:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 00:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 00:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 00:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 00:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 00:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 00:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 00:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 00:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 00:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 00:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 00:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 00:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 00:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 00:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 00:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-12 14:03 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-10 00:00 - 2009-07-13 23:46 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-04 21:49 - 2012-04-03 19:49 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 21:49 - 2012-04-03 19:18 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-04 21:49 - 2012-03-13 20:48 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-04 03:06 - 2012-06-12 14:03 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 14:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 14:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 18:17 - 2012-05-03 17:48 - 191910591 ____A C:\Users\Anthony\Downloads\Money, Power and Wall Street- Part Two - Watch FRONTLINE - PBS Video.flv
2012-05-03 16:53 - 2012-05-03 16:53 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-03 16:53 - 2009-07-13 19:20 - 00000000 ___HD C:\ProgramData
2012-04-30 21:40 - 2012-06-12 14:03 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 21:32 - 2012-06-12 14:03 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-04-27 19:55 - 2012-06-12 14:03 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 14:03 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 14:03 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 14:03 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 14:02 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 14:02 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 14:02 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 14:02 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 14:02 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 14:02 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-16 07:03 - 2012-04-16 07:03 - 00010675 ____A C:\Users\Anthony\Documents\Dear Mrs.docx
2012-04-13 18:53 - 2012-04-13 18:53 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\Xilisoft
2012-04-13 18:53 - 2012-04-13 18:53 - 00000000 ____D C:\Users\All Users\Xilisoft
2012-04-13 18:53 - 2012-04-13 18:53 - 00000000 ____D C:\Program Files (x86)\Xilisoft
2012-04-13 18:53 - 2009-07-13 18:34 - 00001543 ____A C:\Windows\System32\Drivers\etc\hosts
2012-04-11 19:14 - 2012-03-13 21:25 - 00000000 ____D C:\Users\Anthony\Documents\Taxes
2012-04-09 17:08 - 2012-03-16 18:55 - 00009768 ____A C:\Windows\DPINST.LOG
2012-04-09 17:07 - 2012-04-09 17:07 - 00000000 ____D C:\Users\All Users\Cisco Systems
2012-04-09 17:06 - 2012-03-13 19:58 - 00005026 ____A C:\Windows\PFRO.log
2012-04-07 19:19 - 2012-04-07 19:16 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\CoffeeCup Software
2012-04-07 19:16 - 2012-04-07 19:16 - 00000000 ____D C:\Users\Public\Documents\CoffeeCup Software
2012-04-07 19:16 - 2012-04-07 19:16 - 00000000 ____D C:\Users\All Users\CoffeeCup Software
2012-04-07 18:45 - 2012-04-07 18:45 - 00000000 ____D C:\Program Files (x86)\CoffeeCup Software
2012-04-07 17:23 - 2012-03-13 21:11 - 00000000 ____D C:\Users\Anthony\Books
2012-04-07 04:31 - 2012-06-12 14:03 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 14:03 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 12:56 - 2012-03-14 20:06 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-03 20:51 - 2012-03-13 18:01 - 00000000 ____D C:\users\Anthony
2012-04-03 19:19 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2012-04-02 16:35 - 2012-04-02 11:07 - 00000866 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2012-04-02 14:03 - 2012-03-13 19:07 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\Apple Computer
2012-04-02 11:18 - 2012-04-02 11:06 - 00000000 ____D C:\Program Files (x86)\1ClickDownload
2012-04-02 11:07 - 2012-04-02 11:07 - 00000000 ____D C:\Program Files (x86)\IMinent Toolbar
2012-04-02 11:06 - 2012-04-02 11:06 - 00000000 ____D C:\Users\All Users\Tarma Installer
2012-04-02 11:06 - 2012-04-02 11:06 - 00000000 ____D C:\Program Files (x86)\Yontoo
2012-04-02 11:06 - 2012-04-02 11:06 - 00000000 ____D C:\Program Files (x86)\fbphotozoom
2012-03-30 16:51 - 2012-03-30 16:51 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\WinAVI
2012-03-30 16:51 - 2012-03-30 16:51 - 00000000 ____D C:\Users\Anthony\AppData\Local\WinAVI
2012-03-30 16:51 - 2012-03-30 16:51 - 00000000 ____D C:\Program Files (x86)\All in One Converter
2012-03-30 03:35 - 2012-05-09 17:28 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-24 00:00 - 2012-03-24 00:00 - 00286008 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-03-21 14:34 - 2012-03-21 14:34 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2012-03-21 14:34 - 2012-03-21 14:33 - 00290592 ____A C:\Windows\msxml4-KB954430-enu.LOG
ZeroAccess:
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\@
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\L
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U\00000001.@
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U\800000cb.@
ZeroAccess:
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\@
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\L
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 4095.18 MB
Available physical RAM: 3474.4 MB
Total Pagefile: 4093.33 MB
Available Pagefile: 3465.67 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:931.41 GB) (Free:527.95 GB) NTFS
2 Drive d: (Backup) (Fixed) (Total:74.53 GB) (Free:9.58 GB) NTFS
5 Drive h: (MSSS_Media64) (Removable) (Total:0.97 GB) (Free:0.93 GB) NTFS
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 74 GB 1024 KB
Disk 2 No Media 0 B 0 B
Disk 3 Online 991 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 74 GB 31 KB
======================================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Backup NTFS Partition 74 GB Healthy
======================================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 991 MB 16 KB
======================================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H MSSS_Media6 NTFS Removable 991 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-07 21:54
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 17-06-2012 04
Ran by SYSTEM at 18-06-2012 22:31:28
Running from H:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 24.177.176.38 71.92.29.130
HKLM\...\InprocServer32: [Default-wbemess] \\.\globalroot\systemroot\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\n. ATTENTION! ====> ZeroAccess
==================== Services (Whitelisted) ======
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 RemoteAccess; C:\Windows\SysWOW64\mprdin.dll [1725952 2012-05-27] ()
4 Mcx2Svc; C:\Windows\SysWOW64\Mcx2Svc.dll [x]
========================== Drivers (Whitelisted) =============
3 AE1000; C:\Windows\System32\DRIVERS\ae1000w7.sys [1101600 2010-02-12] (Ralink Technology Corp.)
3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [19968 2011-02-23] (Microsoft Corporation)
3 epmntdrv; \??\C:\Windows\system32\epmntdrv.sys [16776 2010-07-15] ()
3 EuGdiDrv; \??\C:\Windows\system32\EuGdiDrv.sys [9096 2010-07-15] ()
3 pbfilter; \??\C:\Program Files\PeerBlock\pbfilter.sys [24176 2010-11-06] ()
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
NETSVCx32: Mcx2Svc -> C:\Windows\SysWOW64\Mcx2Svc.dll ==> No File.
============ One Month Created Files and Folders ==============
2012-06-18 22:31 - 2012-06-18 22:31 - 00000000 ____D C:\FRST
2012-06-17 19:57 - 2012-06-17 20:07 - 00218563 ____A C:\Users\Anthony\Downloads\yorkyt.exe.log
2012-06-17 19:55 - 2012-06-17 19:55 - 01415784 ____A C:\Users\Anthony\Downloads\yorkyt.exe
2012-06-17 17:57 - 2012-06-17 17:57 - 00000036 ____A C:\Users\Anthony\AppData\Local\housecall.guid.cache
2012-06-17 17:57 - 2012-06-17 17:57 - 00000000 ____D C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019
2012-06-17 17:50 - 2012-06-17 17:50 - 04731392 ____A (AVAST Software) C:\Users\Anthony\Downloads\aswMBR.exe
2012-06-17 17:49 - 2012-06-17 17:49 - 02048818 ____A C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019.zip
2012-06-17 17:25 - 2012-06-18 19:19 - 00832286 ____A C:\Windows\ntbtlog.txt
2012-06-17 17:18 - 2012-06-17 17:18 - 00000000 ____D C:\Users\Anthony\AppData\Local\ElevatedDiagnostics
2012-06-17 17:17 - 2012-06-17 17:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\MicrosoftFixit.WindowsFirewall.RNP.81263412915320082.4.1.Run.exe
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-17 17:11 - 2012-06-17 17:11 - 12621696 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\mseinstall.exe
2012-06-17 17:06 - 2012-06-17 17:06 - 00000000 ____D C:\Users\Anthony\Downloads\NBA TV
2012-06-17 17:01 - 2012-06-17 17:01 - 00229548 ____A C:\Users\Anthony\Downloads\1055.BFE.reg
2012-06-17 17:01 - 2012-06-17 17:01 - 00006396 ____A C:\Users\Anthony\Downloads\0677.mpssvc.reg
2012-06-17 16:56 - 2012-06-17 16:56 - 00012168 ____A C:\Users\Anthony\Downloads\+-Demonoid.me-+_NBA_TV_The_Dream_Team_Documentary_720p_HD_x264_590534.5606.torrent
2012-06-14 19:22 - 2012-06-14 19:23 - 00000000 ____D C:\Users\Anthony\Downloads\A Brief History of Thought
2012-06-14 19:21 - 2012-06-14 19:21 - 00006962 ____A C:\Users\Anthony\Downloads\[[Demonoid.me]]-A_Brief_History_of_Thought_A_Philosophical_Guide_to_Living_(2011)_epub_mobi_590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00026709 ____A C:\Users\Anthony\Downloads\NY_Times_Bestseller_Combined_Print_and_Ebook_Fiction_Top_15_for_June_17th-_=Demonoid.me=__590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00000000 ____D C:\Users\Anthony\Downloads\Fiction
2012-06-13 00:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 00:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 00:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 00:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 00:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 00:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 00:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 00:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 00:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 00:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 00:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 00:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 00:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 00:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 00:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 00:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 00:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 00:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 00:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 00:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 00:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 00:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 00:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 00:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 00:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 00:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 00:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 00:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 14:03 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 14:03 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 14:03 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 14:03 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 14:03 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 14:03 - 2012-04-27 21:32 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-06-12 14:03 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 14:03 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 14:03 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 14:03 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 14:03 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 14:03 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-12 14:02 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 14:02 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 14:02 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 14:02 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 14:02 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 14:02 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-09 18:39 - 2012-06-09 19:15 - 00000000 ____D C:\Users\Anthony\Downloads\30 Life changing books
2012-06-09 18:36 - 2012-06-09 18:36 - 00015084 ____A C:\Users\Anthony\Downloads\_=Demonoid.me=_-30_life_changing_books_(sex_relationships_money_fitness_bdsm_music_travel_spirituality_cooking_drawing_etc)_590534.5606.torrent
2012-06-07 16:44 - 2012-06-07 17:35 - 00000000 ____D C:\Users\Anthony\Downloads\Arrested Development
2012-06-07 16:41 - 2012-06-07 16:41 - 00054312 ____A C:\Users\Anthony\Downloads\Arrested_Development_[Season_1_3]_Full-[[Demonoid.me]]_590534.5606.torrent
2012-06-05 17:24 - 2012-06-07 16:50 - 00000000 ____D C:\Users\Anthony\Downloads\PBS EMPIRES Medici Godfathers
2012-05-30 18:20 - 2012-05-30 18:20 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-27 18:09 - 2012-05-27 18:09 - 01725952 ____A C:\Windows\SysWOW64\mprdin.dll
2012-05-27 18:09 - 2012-05-27 18:09 - 00000395 ____A C:\Windows\SysWOW64\mprdin.ocx
============ 3 Months Modified Files and Folders =============
2012-06-18 22:31 - 2012-06-18 22:31 - 00000000 ____D C:\FRST
2012-06-18 19:20 - 2012-03-13 19:53 - 4294107136 __ASH C:\pagefile.sys
2012-06-18 19:20 - 2012-03-13 19:53 - 3220578304 __ASH C:\hiberfil.sys
2012-06-18 19:20 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-18 19:20 - 2009-07-13 20:51 - 00025459 ____A C:\Windows\setupact.log
2012-06-18 19:19 - 2012-06-17 17:25 - 00832286 ____A C:\Windows\ntbtlog.txt
2012-06-17 20:07 - 2012-06-17 19:57 - 00218563 ____A C:\Users\Anthony\Downloads\yorkyt.exe.log
2012-06-17 20:06 - 2012-03-13 19:53 - 00000000 __SHD C:\System Volume Information
2012-06-17 19:57 - 2009-07-13 19:20 - 00000000 ____D C:\Windows
2012-06-17 19:55 - 2012-06-17 19:55 - 01415784 ____A C:\Users\Anthony\Downloads\yorkyt.exe
2012-06-17 17:57 - 2012-06-17 17:57 - 00000036 ____A C:\Users\Anthony\AppData\Local\housecall.guid.cache
2012-06-17 17:57 - 2012-06-17 17:57 - 00000000 ____D C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019
2012-06-17 17:50 - 2012-06-17 17:50 - 04731392 ____A (AVAST Software) C:\Users\Anthony\Downloads\aswMBR.exe
2012-06-17 17:49 - 2012-06-17 17:49 - 02048818 ____A C:\Users\Anthony\Downloads\FakeAVRemover_1.0.0.1019.zip
2012-06-17 17:31 - 2012-03-14 15:02 - 00000000 __SHD C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}
2012-06-17 17:22 - 2012-05-03 16:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-17 17:22 - 2012-03-20 18:43 - 00000000 ___HD C:\Config.Msi
2012-06-17 17:21 - 2012-03-13 20:44 - 00000000 ____D C:\Program Files\PeerBlock
2012-06-17 17:20 - 2012-03-13 20:41 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\uTorrent
2012-06-17 17:18 - 2012-06-17 17:18 - 00000000 ____D C:\Users\Anthony\AppData\Local\ElevatedDiagnostics
2012-06-17 17:17 - 2012-06-17 17:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\MicrosoftFixit.WindowsFirewall.RNP.81263412915320082.4.1.Run.exe
2012-06-17 17:16 - 2012-03-13 19:57 - 01300696 ____A C:\Windows\WindowsUpdate.log
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-17 17:14 - 2012-06-17 17:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-17 17:14 - 2012-03-13 19:19 - 00743538 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-17 17:14 - 2012-03-13 19:19 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-17 17:14 - 2009-07-13 19:20 - 00000000 ___RD C:\Program Files (x86)
2012-06-17 17:14 - 2009-07-13 19:20 - 00000000 ___RD C:\Program Files
2012-06-17 17:11 - 2012-06-17 17:11 - 12621696 ____A (Microsoft Corporation) C:\Users\Anthony\Downloads\mseinstall.exe
2012-06-17 17:11 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-17 17:11 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-17 17:08 - 2009-07-13 21:13 - 00729816 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-17 17:06 - 2012-06-17 17:06 - 00000000 ____D C:\Users\Anthony\Downloads\NBA TV
2012-06-17 17:05 - 2012-03-13 19:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-17 17:01 - 2012-06-17 17:01 - 00229548 ____A C:\Users\Anthony\Downloads\1055.BFE.reg
2012-06-17 17:01 - 2012-06-17 17:01 - 00006396 ____A C:\Users\Anthony\Downloads\0677.mpssvc.reg
2012-06-17 16:56 - 2012-06-17 16:56 - 00012168 ____A C:\Users\Anthony\Downloads\+-Demonoid.me-+_NBA_TV_The_Dream_Team_Documentary_720p_HD_x264_590534.5606.torrent
2012-06-17 16:49 - 2012-04-03 19:18 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-15 20:40 - 2012-03-13 20:57 - 00000000 ____D C:\Users\Anthony\Downloads\1417 16th ST S
2012-06-14 19:23 - 2012-06-14 19:22 - 00000000 ____D C:\Users\Anthony\Downloads\A Brief History of Thought
2012-06-14 19:21 - 2012-06-14 19:21 - 00006962 ____A C:\Users\Anthony\Downloads\[[Demonoid.me]]-A_Brief_History_of_Thought_A_Philosophical_Guide_to_Living_(2011)_epub_mobi_590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00026709 ____A C:\Users\Anthony\Downloads\NY_Times_Bestseller_Combined_Print_and_Ebook_Fiction_Top_15_for_June_17th-_=Demonoid.me=__590534.5606.torrent
2012-06-13 20:05 - 2012-06-13 20:05 - 00000000 ____D C:\Users\Anthony\Downloads\Fiction
2012-06-13 00:59 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-06-13 00:22 - 2009-07-13 20:45 - 04973160 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 00:06 - 2012-03-13 20:17 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-13 00:03 - 2012-03-14 20:04 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-09 19:15 - 2012-06-09 18:39 - 00000000 ____D C:\Users\Anthony\Downloads\30 Life changing books
2012-06-09 18:36 - 2012-06-09 18:36 - 00015084 ____A C:\Users\Anthony\Downloads\_=Demonoid.me=_-30_life_changing_books_(sex_relationships_money_fitness_bdsm_music_travel_spirituality_cooking_drawing_etc)_590534.5606.torrent
2012-06-07 18:04 - 2012-04-03 20:51 - 00000000 ____D C:\Users\Anthony\My Music 2
2012-06-07 17:35 - 2012-06-07 16:44 - 00000000 ____D C:\Users\Anthony\Downloads\Arrested Development
2012-06-07 16:50 - 2012-06-05 17:24 - 00000000 ____D C:\Users\Anthony\Downloads\PBS EMPIRES Medici Godfathers
2012-06-07 16:41 - 2012-06-07 16:41 - 00054312 ____A C:\Users\Anthony\Downloads\Arrested_Development_[Season_1_3]_Full-[[Demonoid.me]]_590534.5606.torrent
2012-06-07 16:39 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-06-04 18:38 - 2012-03-14 20:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-05-30 18:20 - 2012-05-30 18:20 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-27 18:09 - 2012-05-27 18:09 - 01725952 ____A C:\Windows\SysWOW64\mprdin.dll
2012-05-27 18:09 - 2012-05-27 18:09 - 00000395 ____A C:\Windows\SysWOW64\mprdin.ocx
2012-05-20 15:53 - 2012-04-07 19:16 - 00214016 ____A C:\Users\Anthony\AppData\Roaming\SharedSettings.ccs
2012-05-19 18:20 - 2012-03-13 20:41 - 00000000 ____D C:\Program Files (x86)\uTorrent
2012-05-17 18:47 - 2012-06-13 00:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 00:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 00:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 00:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 00:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 00:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 00:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 00:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 00:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 00:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 00:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 00:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 00:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 00:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 00:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 00:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 00:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 00:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 00:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 00:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 00:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 00:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 00:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 00:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 00:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 00:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 00:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-12 14:03 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-10 00:00 - 2009-07-13 23:46 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-04 21:49 - 2012-04-03 19:49 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 21:49 - 2012-04-03 19:18 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-04 21:49 - 2012-03-13 20:48 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-04 03:06 - 2012-06-12 14:03 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 14:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 14:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 18:17 - 2012-05-03 17:48 - 191910591 ____A C:\Users\Anthony\Downloads\Money, Power and Wall Street- Part Two - Watch FRONTLINE - PBS Video.flv
2012-05-03 16:53 - 2012-05-03 16:53 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-03 16:53 - 2009-07-13 19:20 - 00000000 ___HD C:\ProgramData
2012-04-30 21:40 - 2012-06-12 14:03 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 21:32 - 2012-06-12 14:03 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-04-27 19:55 - 2012-06-12 14:03 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 14:03 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 14:03 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 14:03 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 14:02 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 14:02 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 14:02 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 14:02 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 14:02 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 14:02 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-16 07:03 - 2012-04-16 07:03 - 00010675 ____A C:\Users\Anthony\Documents\Dear Mrs.docx
2012-04-13 18:53 - 2012-04-13 18:53 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\Xilisoft
2012-04-13 18:53 - 2012-04-13 18:53 - 00000000 ____D C:\Users\All Users\Xilisoft
2012-04-13 18:53 - 2012-04-13 18:53 - 00000000 ____D C:\Program Files (x86)\Xilisoft
2012-04-13 18:53 - 2009-07-13 18:34 - 00001543 ____A C:\Windows\System32\Drivers\etc\hosts
2012-04-11 19:14 - 2012-03-13 21:25 - 00000000 ____D C:\Users\Anthony\Documents\Taxes
2012-04-09 17:08 - 2012-03-16 18:55 - 00009768 ____A C:\Windows\DPINST.LOG
2012-04-09 17:07 - 2012-04-09 17:07 - 00000000 ____D C:\Users\All Users\Cisco Systems
2012-04-09 17:06 - 2012-03-13 19:58 - 00005026 ____A C:\Windows\PFRO.log
2012-04-07 19:19 - 2012-04-07 19:16 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\CoffeeCup Software
2012-04-07 19:16 - 2012-04-07 19:16 - 00000000 ____D C:\Users\Public\Documents\CoffeeCup Software
2012-04-07 19:16 - 2012-04-07 19:16 - 00000000 ____D C:\Users\All Users\CoffeeCup Software
2012-04-07 18:45 - 2012-04-07 18:45 - 00000000 ____D C:\Program Files (x86)\CoffeeCup Software
2012-04-07 17:23 - 2012-03-13 21:11 - 00000000 ____D C:\Users\Anthony\Books
2012-04-07 04:31 - 2012-06-12 14:03 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 14:03 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 12:56 - 2012-03-14 20:06 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-03 20:51 - 2012-03-13 18:01 - 00000000 ____D C:\users\Anthony
2012-04-03 19:19 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2012-04-02 16:35 - 2012-04-02 11:07 - 00000866 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog
2012-04-02 14:03 - 2012-03-13 19:07 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\Apple Computer
2012-04-02 11:18 - 2012-04-02 11:06 - 00000000 ____D C:\Program Files (x86)\1ClickDownload
2012-04-02 11:07 - 2012-04-02 11:07 - 00000000 ____D C:\Program Files (x86)\IMinent Toolbar
2012-04-02 11:06 - 2012-04-02 11:06 - 00000000 ____D C:\Users\All Users\Tarma Installer
2012-04-02 11:06 - 2012-04-02 11:06 - 00000000 ____D C:\Program Files (x86)\Yontoo
2012-04-02 11:06 - 2012-04-02 11:06 - 00000000 ____D C:\Program Files (x86)\fbphotozoom
2012-03-30 16:51 - 2012-03-30 16:51 - 00000000 ____D C:\Users\Anthony\AppData\Roaming\WinAVI
2012-03-30 16:51 - 2012-03-30 16:51 - 00000000 ____D C:\Users\Anthony\AppData\Local\WinAVI
2012-03-30 16:51 - 2012-03-30 16:51 - 00000000 ____D C:\Program Files (x86)\All in One Converter
2012-03-30 03:35 - 2012-05-09 17:28 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-24 00:00 - 2012-03-24 00:00 - 00286008 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-03-21 14:34 - 2012-03-21 14:34 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2012-03-21 14:34 - 2012-03-21 14:33 - 00290592 ____A C:\Windows\msxml4-KB954430-enu.LOG
ZeroAccess:
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\@
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\L
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U\00000001.@
C:\Windows\Installer\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U\800000cb.@
ZeroAccess:
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\@
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\L
C:\Users\Anthony\AppData\Local\{2e4c143a-2f42-42be-f9f1-2c50ab818d1f}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 4095.18 MB
Available physical RAM: 3474.4 MB
Total Pagefile: 4093.33 MB
Available Pagefile: 3465.67 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:931.41 GB) (Free:527.95 GB) NTFS
2 Drive d: (Backup) (Fixed) (Total:74.53 GB) (Free:9.58 GB) NTFS
5 Drive h: (MSSS_Media64) (Removable) (Total:0.97 GB) (Free:0.93 GB) NTFS
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 74 GB 1024 KB
Disk 2 No Media 0 B 0 B
Disk 3 Online 991 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 74 GB 31 KB
======================================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Backup NTFS Partition 74 GB Healthy
======================================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 991 MB 16 KB
======================================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H MSSS_Media6 NTFS Removable 991 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-07 21:54
======================= End Of Log ==========================