Hi,
I have trojan Win 64 Sirefef on my Windows Vista.
It keeps rebooting avec 2-3 minutes after it starts, even after I deleted MSE.
I can't run any program to remove the trojan because my pc reboot before.
I would greatly appreciate help....
Frédérique
My log :
Scan result of Farbar Recovery Scan Tool Version: 21-06-2012 02
Ran by SYSTEM at 21-06-2012 08:12:07
Running from G:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: French Standard
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1216808 2007-11-29] (Synaptics, Inc.)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [431968 2008-01-17] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [584568 2008-04-23] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [865280 2008-03-19] (TOSHIBA Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Annie\...\Run: [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe [542136 2008-12-02] (Druide informatique inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
Tcpip\Parameters: [DhcpNameServer] 24.48.19.13 24.202.72.13 24.53.0.2
AppInit_DLLs: C:\PROGRA~2\WI371A~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI371A~1\Datamngr\x64\IEBHO.dll acaptuser64.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Services (Whitelisted) ======
2 AcronisOSSReinstallSvc; "C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe" [2217416 2007-02-22] ()
2 Ati External Event Utility; C:\Windows\System32\Ati2evxx.exe [870400 2008-04-07] (ATI Technologies Inc.)
3 FLEXnet Licensing Service; "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [651720 2010-02-12] (Macrovision Europe Ltd.)
3 Lavasoft Ad-Aware Service; "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe" [2152152 2011-09-02] (Lavasoft Limited)
2 lxdiCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxdiserv.exe [33712 2007-06-11] (Lexmark International, Inc.)
2 lxdi_device; C:\Windows\system32\lxdicoms.exe -service [876976 2007-06-11] ( )
2 lxdi_device; C:\Windows\SysWow64\lxdicoms.exe -service [517040 2007-06-11] ( )
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 TNaviSrv; C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312 2008-07-18] (TOSHIBA Corporation)
========================== Drivers (Whitelisted) =============
3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [19968 2008-01-20] (Microsoft Corporation)
0 Lbd; C:\Windows\System32\Drivers\Lbd.sys [69152 2010-08-12] (Lavasoft AB)
3 O2MDRDR; C:\Windows\System32\DRIVERS\o2mdx64.sys [62040 2008-04-14] (O2Micro )
3 QIOMem; C:\Windows\System32\Drivers\QIOMem.sys [9728 2007-04-09] (TOSHIBA)
0 snapman; C:\Windows\System32\Drivers\snapman.sys [198944 2010-12-14] (Acronis)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [871408 2009-09-10] (Duplex Secure Ltd.)
3 tosporte; C:\Windows\System32\Drivers\tosporte.sys [49152 2008-03-25] (TOSHIBA Corporation)
3 tosrfbd; C:\Windows\System32\Drivers\tosrfbd.sys [165888 2008-04-23] (TOSHIBA CORPORATION)
3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [44800 2007-11-29] (TOSHIBA Corporation)
1 Tosrfcom; C:\Windows\System32\Drivers\Tosrfcom.sys [76160 2007-10-02] (TOSHIBA Corporation)
3 tosrfec; C:\Windows\System32\Drivers\tosrfec.sys [18944 2006-10-23] (TOSHIBA Corporation)
3 Tosrfhid; C:\Windows\System32\Drivers\Tosrfhid.sys [88192 2008-03-19] (TOSHIBA Corporation.)
3 tosrfnds; C:\Windows\System32\Drivers\tosrfnds.sys [28160 2005-07-13] (TOSHIBA Corporation.)
3 TosRfSnd; C:\Windows\System32\Drivers\TosRfSnd.sys [56320 2008-01-22] (TOSHIBA Corporation)
0 TVALZ; C:\Windows\System32\DRIVERS\TVALZ_O.SYS [26968 2007-11-09] (TOSHIBA Corporation)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 WPRO_40_1340; C:\Windows\System32\drivers\WPRO_40_1340.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-21 08:11 - 2012-06-21 08:11 - 00000000 ____D C:\FRST
2012-06-20 16:41 - 2012-06-20 16:41 - 00015844 ____A C:\FixitRegBackup.reg
2012-06-20 15:55 - 2012-06-20 15:55 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-20 13:20 - 2012-06-20 16:40 - 00000000 ____D C:\sh4ldr
2012-06-20 13:20 - 2012-06-20 13:20 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-06-20 13:17 - 2012-06-21 00:49 - 00000000 ____D C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-06-20 12:02 - 2012-06-20 12:02 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6519815EF186CF6A
2012-06-20 11:52 - 2012-06-20 11:52 - 00000000 ____D C:\Windows\pss
2012-06-20 10:44 - 2012-06-20 10:44 - 00000422 ____A C:\Windows\BitsRepairTool.log
2012-06-20 10:36 - 2012-06-20 15:20 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-20 10:33 - 2012-06-20 10:33 - 01527300 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-20 10:33 - 2012-06-20 10:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 10:31 - 2012-06-20 10:34 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-19 06:20 - 2012-06-02 18:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-19 06:20 - 2012-06-02 18:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-19 06:20 - 2012-06-02 18:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-19 06:20 - 2012-06-02 18:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-19 06:19 - 2012-06-02 18:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-19 06:19 - 2012-06-02 18:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-19 06:19 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-19 06:19 - 2012-06-02 15:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-19 06:19 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 06:19 - 2012-06-02 15:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-14 06:54 - 2012-05-17 21:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 06:54 - 2012-05-17 18:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 06:53 - 2012-05-17 22:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 06:53 - 2012-05-17 22:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 06:53 - 2012-05-17 22:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 06:53 - 2012-05-17 21:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 06:53 - 2012-05-17 21:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 06:53 - 2012-05-17 21:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 06:53 - 2012-05-17 21:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 06:53 - 2012-05-17 21:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 06:53 - 2012-05-17 21:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 06:53 - 2012-05-17 21:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 06:53 - 2012-05-17 21:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 06:53 - 2012-05-17 21:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 06:53 - 2012-05-17 21:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 06:53 - 2012-05-17 19:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 06:53 - 2012-05-17 18:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 06:53 - 2012-05-17 18:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 06:53 - 2012-05-17 18:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 06:53 - 2012-05-17 18:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 06:53 - 2012-05-17 18:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 06:53 - 2012-05-17 18:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 06:53 - 2012-05-17 18:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 06:53 - 2012-05-17 18:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 06:53 - 2012-05-17 18:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 06:53 - 2012-05-17 18:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 06:53 - 2012-05-17 18:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 06:53 - 2012-05-17 18:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 20:29 - 2012-05-15 16:15 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 20:29 - 2012-05-01 10:29 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 20:29 - 2012-04-23 12:25 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 20:29 - 2012-04-23 12:25 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 20:29 - 2012-04-23 12:25 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 20:29 - 2012-04-23 12:00 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 20:29 - 2012-04-23 12:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 20:29 - 2012-04-23 12:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-08 19:07 - 2012-06-08 19:07 - 00001727 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-08 19:06 - 2012-06-08 19:07 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-08 18:51 - 2012-06-08 18:51 - 00001665 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-08 18:49 - 2012-06-08 18:51 - 00000000 ____D C:\Program Files\iTunes
2012-06-08 18:49 - 2012-06-08 18:51 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-08 18:49 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files\iPod
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files\Bonjour
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files (x86)\Bonjour
2012-05-31 20:22 - 2012-06-21 00:31 - 00001078 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000UA.job
2012-05-31 20:22 - 2012-06-19 20:27 - 00001026 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000Core.job
2012-05-25 15:12 - 2012-05-25 15:12 - 00000000 ____D C:\Program Files (x86)\Cisco Systems
2012-05-25 15:11 - 2012-05-25 15:11 - 00000000 ____D C:\Users\All Users\Cisco Systems
============ 3 Months Modified Files and Folders =============
2012-06-21 08:11 - 2012-06-21 08:11 - 00000000 ____D C:\FRST
2012-06-21 00:59 - 2009-08-08 12:26 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-06-21 00:53 - 2009-12-03 11:08 - 00325898 ____A C:\aaw7boot.log
2012-06-21 00:49 - 2012-06-20 13:17 - 00000000 ____D C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-06-21 00:42 - 2012-03-25 16:11 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Dropbox
2012-06-21 00:41 - 2012-03-25 16:13 - 00000000 ___RD C:\Users\Annie\Dropbox
2012-06-21 00:39 - 2010-02-26 15:44 - 00001064 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-21 00:39 - 2009-05-21 18:14 - 00000224 ____A C:\Windows\Tasks\PAV.job
2012-06-21 00:39 - 2006-11-02 11:22 - 00003344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-21 00:39 - 2006-11-02 11:22 - 00003344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-21 00:38 - 2006-11-02 11:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-21 00:31 - 2012-05-31 20:22 - 00001078 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000UA.job
2012-06-21 00:23 - 2010-02-26 15:44 - 00001068 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-20 19:34 - 2009-04-21 22:05 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Azureus
2012-06-20 17:18 - 2006-11-02 09:34 - 00000000 ____D C:\Windows\tracing
2012-06-20 16:41 - 2012-06-20 16:41 - 00015844 ____A C:\FixitRegBackup.reg
2012-06-20 16:40 - 2012-06-20 13:20 - 00000000 ____D C:\sh4ldr
2012-06-20 16:32 - 2008-12-22 23:42 - 00001356 ____A C:\Users\Annie\AppData\Local\d3d9caps.dat
2012-06-20 15:55 - 2012-06-20 15:55 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-20 15:20 - 2012-06-20 10:36 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-20 13:20 - 2012-06-20 13:20 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-06-20 13:07 - 2008-01-21 06:01 - 01502832 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-20 13:07 - 2008-01-21 06:00 - 00680406 ____A C:\Windows\System32\perfh00C.dat
2012-06-20 13:07 - 2008-01-21 06:00 - 00127292 ____A C:\Windows\System32\perfc00C.dat
2012-06-20 12:17 - 2008-12-22 23:34 - 00000732 ____A C:\Users\Annie\AppData\Local\d3d9caps64.dat
2012-06-20 12:02 - 2012-06-20 12:02 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6519815EF186CF6A
2012-06-20 11:52 - 2012-06-20 11:52 - 00000000 ____D C:\Windows\pss
2012-06-20 11:19 - 2006-11-02 11:42 - 00032616 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-20 10:54 - 2012-05-10 06:31 - 00001002 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-20 10:45 - 2008-12-22 19:16 - 01552521 ____A C:\Windows\WindowsUpdate.log
2012-06-20 10:44 - 2012-06-20 10:44 - 00000422 ____A C:\Windows\BitsRepairTool.log
2012-06-20 10:34 - 2012-06-20 10:31 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-20 10:33 - 2012-06-20 10:33 - 01527300 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-20 10:33 - 2012-06-20 10:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 10:20 - 2011-09-16 18:00 - 00056984 ____A C:\Windows\PFRO.log
2012-06-20 10:19 - 2011-11-15 11:11 - 00000000 ____D C:\Users\All Users\MFAData
2012-06-20 10:19 - 2008-12-22 19:17 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-06-20 10:17 - 2006-11-02 11:07 - 00000000 ____D C:\Program Files\Windows Sidebar
2012-06-19 20:27 - 2012-05-31 20:22 - 00001026 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000Core.job
2012-06-19 18:22 - 2006-11-02 09:33 - 00000000 ____D C:\Windows\rescache
2012-06-17 07:14 - 2012-05-02 19:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-16 21:35 - 2011-05-11 21:36 - 00000064 ____A C:\Windows\SysWOW64\rp_stats.dat
2012-06-16 21:35 - 2011-05-11 21:36 - 00000044 ____A C:\Windows\SysWOW64\rp_rules.dat
2012-06-16 15:32 - 2009-04-21 22:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-14 07:19 - 2006-11-02 11:21 - 00334376 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 06:39 - 2006-11-02 08:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-08 19:07 - 2012-06-08 19:07 - 00001727 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-08 19:07 - 2012-06-08 19:06 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-08 18:51 - 2012-06-08 18:51 - 00001665 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-08 18:51 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files\iTunes
2012-06-08 18:51 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-08 18:49 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files\iPod
2012-06-08 18:39 - 2008-12-22 23:34 - 00000000 ____D C:\users\Annie
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files\Bonjour
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files (x86)\Bonjour
2012-06-02 18:19 - 2012-06-19 06:20 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 18:19 - 2012-06-19 06:20 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 18:19 - 2012-06-19 06:20 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 18:15 - 2012-06-19 06:20 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 18:15 - 2012-06-19 06:19 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 18:12 - 2012-06-19 06:19 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 15:19 - 2012-06-19 06:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:19 - 2012-06-19 06:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 15:15 - 2012-06-19 06:19 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 15:12 - 2012-06-19 06:19 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-05-31 20:53 - 2010-09-23 19:05 - 00000000 ____D C:\Program Files (x86)\Raptr
2012-05-31 20:22 - 2008-12-23 01:10 - 00000000 ____D C:\Users\Annie\AppData\Local\Google
2012-05-27 22:17 - 2009-01-09 12:08 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Skype
2012-05-25 15:12 - 2012-05-25 15:12 - 00000000 ____D C:\Program Files (x86)\Cisco Systems
2012-05-25 15:11 - 2012-05-25 15:11 - 00000000 ____D C:\Users\All Users\Cisco Systems
2012-05-25 15:11 - 2011-09-28 18:02 - 00002780 ____A C:\Windows\setupact.log
2012-05-17 22:47 - 2012-06-14 06:53 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 22:16 - 2012-06-14 06:53 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 22:06 - 2012-06-14 06:53 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 21:59 - 2012-06-14 06:53 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 21:59 - 2012-06-14 06:53 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 21:58 - 2012-06-14 06:53 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 21:58 - 2012-06-14 06:53 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 21:56 - 2012-06-14 06:53 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 21:55 - 2012-06-14 06:53 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 21:55 - 2012-06-14 06:53 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 21:54 - 2012-06-14 06:53 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 21:51 - 2012-06-14 06:54 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 21:51 - 2012-06-14 06:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 21:47 - 2012-06-14 06:53 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 19:11 - 2012-06-14 06:53 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 18:48 - 2012-06-14 06:53 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 18:45 - 2012-06-14 06:53 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 18:36 - 2012-06-14 06:53 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 18:35 - 2012-06-14 06:53 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 18:35 - 2012-06-14 06:53 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 18:33 - 2012-06-14 06:53 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 18:31 - 2012-06-14 06:53 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 18:29 - 2012-06-14 06:53 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 18:29 - 2012-06-14 06:53 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 18:27 - 2012-06-14 06:53 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 18:25 - 2012-06-14 06:53 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 18:24 - 2012-06-14 06:54 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 18:20 - 2012-06-14 06:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 16:15 - 2012-06-13 20:29 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 22:45 - 2011-09-16 15:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-13 22:35 - 2012-05-13 22:34 - 00000000 ____D C:\Users\Annie\AppData\Local\{DC51E5D8-22C1-4FAB-A1A2-25D0F47003BE}
2012-05-13 22:34 - 2012-05-13 22:34 - 00000000 ____D C:\Users\Annie\AppData\Local\{DDB67882-F74D-4497-8D23-D0CE141ECBF8}
2012-05-13 22:34 - 2009-08-10 11:25 - 00000000 ____D C:\Users\Annie\Tracing
2012-05-11 13:19 - 2006-11-02 11:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2012-05-11 13:19 - 2006-11-02 11:07 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-11 08:54 - 2008-06-13 20:34 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-10 06:31 - 2012-05-10 06:31 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-10 06:31 - 2011-09-06 07:28 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-02 19:56 - 2012-05-02 19:56 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-02 17:10 - 2011-02-14 20:08 - 00000448 ___AH C:\Windows\Tasks\Norton Security Scan for Annie.job
2012-05-01 10:29 - 2012-06-13 20:29 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-23 12:25 - 2012-06-13 20:29 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 12:25 - 2012-06-13 20:29 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 12:25 - 2012-06-13 20:29 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 12:00 - 2012-06-13 20:29 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 12:00 - 2012-06-13 20:29 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 12:00 - 2012-06-13 20:29 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 20:56 - 2012-04-18 20:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 20:56 - 2012-04-18 20:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-14 10:00 - 2009-01-09 12:07 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-04-14 09:59 - 2009-01-09 12:07 - 00000000 ____D C:\Users\All Users\Skype
2012-04-14 09:16 - 2011-06-16 15:48 - 00000000 ____D C:\Users\All Users\Skype Extras
2012-04-14 09:06 - 2009-01-09 12:12 - 00000000 ____D C:\Users\Annie\AppData\Roaming\skypePM
2012-04-03 04:22 - 2012-05-10 22:07 - 04699520 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-31 16:17 - 2011-01-28 19:36 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Apple Computer
2012-03-31 15:19 - 2010-12-23 07:20 - 00000000 ____D C:\Users\Annie\AppData\Local\Apple Computer
2012-03-31 15:17 - 2012-03-31 15:16 - 00000000 ____D C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-03-31 15:16 - 2012-03-31 15:14 - 00000000 ____D C:\Users\All Users\Apple Computer
2012-03-31 15:12 - 2012-03-31 15:12 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2012-03-30 08:45 - 2012-05-10 22:09 - 01423744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
ZeroAccess:
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\@
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\L
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\n
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\U
ZeroAccess:
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\@
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\L
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe BC81150939BD52DBC7A08C245F1FB229 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4059.93 MB
Available physical RAM: 3502.61 MB
Total Pagefile: 3807.07 MB
Available Pagefile: 3475.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (S3A6831D004) (Fixed) (Total:126.64 GB) (Free:73.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Annie) (Fixed) (Total:98.05 GB) (Free:4.62 GB) NTFS
4 Drive f: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.29 GB) NTFS
5 Drive g: () (Removable) (Total:0.48 GB) (Free:0.06 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
N¯ disque Statut Taille Libre Dyn GPT
---------- ------------- ------- ------------ --- ---
Disque 0 En ligne 233 G octets 0 octets
Disque 1 En ligne 491 M octets 0 octets
Partitions of Disk 0:
===============
N¯ partition Type Taille DÇcalage
------------- ---------------- ------- --------
Partition 1 OEM 1500 M 1024 K
Partition 2 Principale 127 G 1501 M
Partition 3 Principale 98 G 128 G
Partition 4 Principale 6893 M 226 G
======================================================================================================
Disk: 0
Partition 1
Type : 27
MasquÇ : Oui
Active : Non
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F TOSHIBA SYS NTFS Partition 1500 M Sain MasquÇ
======================================================================================================
Disk: 0
Partition 2
Type : 07
MasquÇ : Non
Active : Oui
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C S3A6831D004 NTFS Partition 127 G Sain
======================================================================================================
Disk: 0
Partition 3
Type : 07
MasquÇ : Non
Active : Non
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Annie NTFS Partition 98 G Sain
======================================================================================================
Disk: 0
Partition 4
Type : 17
MasquÇ : Oui
Active : Non
Il n'y a pas de volume associÇ avec cette partition.
======================================================================================================
Partitions of Disk 1:
===============
N¯ partition Type Taille DÇcalage
------------- ---------------- ------- --------
Partition 1 Principale 491 M 16 K
======================================================================================================
Disk: 1
Partition 1
Type : 0E
MasquÇ : Non
Active : Oui
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 G FAT Amovible 491 M Sain
======================================================================================================
==========================================================
Last Boot: 2012-06-20 16:51
======================= End Of Log ==========================
I have trojan Win 64 Sirefef on my Windows Vista.
It keeps rebooting avec 2-3 minutes after it starts, even after I deleted MSE.
I can't run any program to remove the trojan because my pc reboot before.
I would greatly appreciate help....
Frédérique
My log :
Scan result of Farbar Recovery Scan Tool Version: 21-06-2012 02
Ran by SYSTEM at 21-06-2012 08:12:07
Running from G:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: French Standard
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1216808 2007-11-29] (Synaptics, Inc.)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [431968 2008-01-17] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [584568 2008-04-23] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [865280 2008-03-19] (TOSHIBA Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Annie\...\Run: [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe [542136 2008-12-02] (Druide informatique inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
Tcpip\Parameters: [DhcpNameServer] 24.48.19.13 24.202.72.13 24.53.0.2
AppInit_DLLs: C:\PROGRA~2\WI371A~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI371A~1\Datamngr\x64\IEBHO.dll acaptuser64.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Services (Whitelisted) ======
2 AcronisOSSReinstallSvc; "C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe" [2217416 2007-02-22] ()
2 Ati External Event Utility; C:\Windows\System32\Ati2evxx.exe [870400 2008-04-07] (ATI Technologies Inc.)
3 FLEXnet Licensing Service; "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [651720 2010-02-12] (Macrovision Europe Ltd.)
3 Lavasoft Ad-Aware Service; "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe" [2152152 2011-09-02] (Lavasoft Limited)
2 lxdiCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxdiserv.exe [33712 2007-06-11] (Lexmark International, Inc.)
2 lxdi_device; C:\Windows\system32\lxdicoms.exe -service [876976 2007-06-11] ( )
2 lxdi_device; C:\Windows\SysWow64\lxdicoms.exe -service [517040 2007-06-11] ( )
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 TNaviSrv; C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312 2008-07-18] (TOSHIBA Corporation)
========================== Drivers (Whitelisted) =============
3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [19968 2008-01-20] (Microsoft Corporation)
0 Lbd; C:\Windows\System32\Drivers\Lbd.sys [69152 2010-08-12] (Lavasoft AB)
3 O2MDRDR; C:\Windows\System32\DRIVERS\o2mdx64.sys [62040 2008-04-14] (O2Micro )
3 QIOMem; C:\Windows\System32\Drivers\QIOMem.sys [9728 2007-04-09] (TOSHIBA)
0 snapman; C:\Windows\System32\Drivers\snapman.sys [198944 2010-12-14] (Acronis)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [871408 2009-09-10] (Duplex Secure Ltd.)
3 tosporte; C:\Windows\System32\Drivers\tosporte.sys [49152 2008-03-25] (TOSHIBA Corporation)
3 tosrfbd; C:\Windows\System32\Drivers\tosrfbd.sys [165888 2008-04-23] (TOSHIBA CORPORATION)
3 tosrfbnp; C:\Windows\System32\Drivers\tosrfbnp.sys [44800 2007-11-29] (TOSHIBA Corporation)
1 Tosrfcom; C:\Windows\System32\Drivers\Tosrfcom.sys [76160 2007-10-02] (TOSHIBA Corporation)
3 tosrfec; C:\Windows\System32\Drivers\tosrfec.sys [18944 2006-10-23] (TOSHIBA Corporation)
3 Tosrfhid; C:\Windows\System32\Drivers\Tosrfhid.sys [88192 2008-03-19] (TOSHIBA Corporation.)
3 tosrfnds; C:\Windows\System32\Drivers\tosrfnds.sys [28160 2005-07-13] (TOSHIBA Corporation.)
3 TosRfSnd; C:\Windows\System32\Drivers\TosRfSnd.sys [56320 2008-01-22] (TOSHIBA Corporation)
0 TVALZ; C:\Windows\System32\DRIVERS\TVALZ_O.SYS [26968 2007-11-09] (TOSHIBA Corporation)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 WPRO_40_1340; C:\Windows\System32\drivers\WPRO_40_1340.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-21 08:11 - 2012-06-21 08:11 - 00000000 ____D C:\FRST
2012-06-20 16:41 - 2012-06-20 16:41 - 00015844 ____A C:\FixitRegBackup.reg
2012-06-20 15:55 - 2012-06-20 15:55 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-20 13:20 - 2012-06-20 16:40 - 00000000 ____D C:\sh4ldr
2012-06-20 13:20 - 2012-06-20 13:20 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-06-20 13:17 - 2012-06-21 00:49 - 00000000 ____D C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-06-20 12:02 - 2012-06-20 12:02 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6519815EF186CF6A
2012-06-20 11:52 - 2012-06-20 11:52 - 00000000 ____D C:\Windows\pss
2012-06-20 10:44 - 2012-06-20 10:44 - 00000422 ____A C:\Windows\BitsRepairTool.log
2012-06-20 10:36 - 2012-06-20 15:20 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-20 10:33 - 2012-06-20 10:33 - 01527300 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-20 10:33 - 2012-06-20 10:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 10:31 - 2012-06-20 10:34 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-19 06:20 - 2012-06-02 18:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-19 06:20 - 2012-06-02 18:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-19 06:20 - 2012-06-02 18:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-19 06:20 - 2012-06-02 18:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-19 06:19 - 2012-06-02 18:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-19 06:19 - 2012-06-02 18:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-19 06:19 - 2012-06-02 18:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-19 06:19 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-19 06:19 - 2012-06-02 15:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-19 06:19 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 06:19 - 2012-06-02 15:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-14 06:54 - 2012-05-17 21:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 06:54 - 2012-05-17 18:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 06:53 - 2012-05-17 22:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 06:53 - 2012-05-17 22:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 06:53 - 2012-05-17 22:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 06:53 - 2012-05-17 21:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 06:53 - 2012-05-17 21:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 06:53 - 2012-05-17 21:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 06:53 - 2012-05-17 21:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 06:53 - 2012-05-17 21:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 06:53 - 2012-05-17 21:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 06:53 - 2012-05-17 21:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 06:53 - 2012-05-17 21:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 06:53 - 2012-05-17 21:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 06:53 - 2012-05-17 21:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 06:53 - 2012-05-17 19:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 06:53 - 2012-05-17 18:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 06:53 - 2012-05-17 18:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 06:53 - 2012-05-17 18:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 06:53 - 2012-05-17 18:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 06:53 - 2012-05-17 18:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 06:53 - 2012-05-17 18:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 06:53 - 2012-05-17 18:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 06:53 - 2012-05-17 18:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 06:53 - 2012-05-17 18:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 06:53 - 2012-05-17 18:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 06:53 - 2012-05-17 18:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 06:53 - 2012-05-17 18:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 20:29 - 2012-05-15 16:15 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 20:29 - 2012-05-01 10:29 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 20:29 - 2012-04-23 12:25 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 20:29 - 2012-04-23 12:25 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 20:29 - 2012-04-23 12:25 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 20:29 - 2012-04-23 12:00 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 20:29 - 2012-04-23 12:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 20:29 - 2012-04-23 12:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-08 19:07 - 2012-06-08 19:07 - 00001727 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-08 19:06 - 2012-06-08 19:07 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-08 18:51 - 2012-06-08 18:51 - 00001665 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-08 18:49 - 2012-06-08 18:51 - 00000000 ____D C:\Program Files\iTunes
2012-06-08 18:49 - 2012-06-08 18:51 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-08 18:49 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files\iPod
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files\Bonjour
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files (x86)\Bonjour
2012-05-31 20:22 - 2012-06-21 00:31 - 00001078 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000UA.job
2012-05-31 20:22 - 2012-06-19 20:27 - 00001026 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000Core.job
2012-05-25 15:12 - 2012-05-25 15:12 - 00000000 ____D C:\Program Files (x86)\Cisco Systems
2012-05-25 15:11 - 2012-05-25 15:11 - 00000000 ____D C:\Users\All Users\Cisco Systems
============ 3 Months Modified Files and Folders =============
2012-06-21 08:11 - 2012-06-21 08:11 - 00000000 ____D C:\FRST
2012-06-21 00:59 - 2009-08-08 12:26 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-06-21 00:53 - 2009-12-03 11:08 - 00325898 ____A C:\aaw7boot.log
2012-06-21 00:49 - 2012-06-20 13:17 - 00000000 ____D C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-06-21 00:42 - 2012-03-25 16:11 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Dropbox
2012-06-21 00:41 - 2012-03-25 16:13 - 00000000 ___RD C:\Users\Annie\Dropbox
2012-06-21 00:39 - 2010-02-26 15:44 - 00001064 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-21 00:39 - 2009-05-21 18:14 - 00000224 ____A C:\Windows\Tasks\PAV.job
2012-06-21 00:39 - 2006-11-02 11:22 - 00003344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-21 00:39 - 2006-11-02 11:22 - 00003344 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-21 00:38 - 2006-11-02 11:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-21 00:31 - 2012-05-31 20:22 - 00001078 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000UA.job
2012-06-21 00:23 - 2010-02-26 15:44 - 00001068 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-20 19:34 - 2009-04-21 22:05 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Azureus
2012-06-20 17:18 - 2006-11-02 09:34 - 00000000 ____D C:\Windows\tracing
2012-06-20 16:41 - 2012-06-20 16:41 - 00015844 ____A C:\FixitRegBackup.reg
2012-06-20 16:40 - 2012-06-20 13:20 - 00000000 ____D C:\sh4ldr
2012-06-20 16:32 - 2008-12-22 23:42 - 00001356 ____A C:\Users\Annie\AppData\Local\d3d9caps.dat
2012-06-20 15:55 - 2012-06-20 15:55 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-20 15:20 - 2012-06-20 10:36 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-20 13:20 - 2012-06-20 13:20 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-06-20 13:07 - 2008-01-21 06:01 - 01502832 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-20 13:07 - 2008-01-21 06:00 - 00680406 ____A C:\Windows\System32\perfh00C.dat
2012-06-20 13:07 - 2008-01-21 06:00 - 00127292 ____A C:\Windows\System32\perfc00C.dat
2012-06-20 12:17 - 2008-12-22 23:34 - 00000732 ____A C:\Users\Annie\AppData\Local\d3d9caps64.dat
2012-06-20 12:02 - 2012-06-20 12:02 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6519815EF186CF6A
2012-06-20 11:52 - 2012-06-20 11:52 - 00000000 ____D C:\Windows\pss
2012-06-20 11:19 - 2006-11-02 11:42 - 00032616 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-20 10:54 - 2012-05-10 06:31 - 00001002 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-20 10:45 - 2008-12-22 19:16 - 01552521 ____A C:\Windows\WindowsUpdate.log
2012-06-20 10:44 - 2012-06-20 10:44 - 00000422 ____A C:\Windows\BitsRepairTool.log
2012-06-20 10:34 - 2012-06-20 10:31 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-20 10:33 - 2012-06-20 10:33 - 01527300 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-20 10:33 - 2012-06-20 10:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-20 10:20 - 2011-09-16 18:00 - 00056984 ____A C:\Windows\PFRO.log
2012-06-20 10:19 - 2011-11-15 11:11 - 00000000 ____D C:\Users\All Users\MFAData
2012-06-20 10:19 - 2008-12-22 19:17 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-06-20 10:17 - 2006-11-02 11:07 - 00000000 ____D C:\Program Files\Windows Sidebar
2012-06-19 20:27 - 2012-05-31 20:22 - 00001026 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3065547687-1470503384-3735164326-1000Core.job
2012-06-19 18:22 - 2006-11-02 09:33 - 00000000 ____D C:\Windows\rescache
2012-06-17 07:14 - 2012-05-02 19:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-16 21:35 - 2011-05-11 21:36 - 00000064 ____A C:\Windows\SysWOW64\rp_stats.dat
2012-06-16 21:35 - 2011-05-11 21:36 - 00000044 ____A C:\Windows\SysWOW64\rp_rules.dat
2012-06-16 15:32 - 2009-04-21 22:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-14 07:19 - 2006-11-02 11:21 - 00334376 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 06:39 - 2006-11-02 08:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-08 19:07 - 2012-06-08 19:07 - 00001727 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-08 19:07 - 2012-06-08 19:06 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-08 18:51 - 2012-06-08 18:51 - 00001665 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-08 18:51 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files\iTunes
2012-06-08 18:51 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-08 18:49 - 2012-06-08 18:49 - 00000000 ____D C:\Program Files\iPod
2012-06-08 18:39 - 2008-12-22 23:34 - 00000000 ____D C:\users\Annie
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files\Bonjour
2012-06-08 18:37 - 2012-06-08 18:37 - 00000000 ____D C:\Program Files (x86)\Bonjour
2012-06-02 18:19 - 2012-06-19 06:20 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 18:19 - 2012-06-19 06:20 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 18:19 - 2012-06-19 06:20 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 18:19 - 2012-06-19 06:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 18:15 - 2012-06-19 06:20 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 18:15 - 2012-06-19 06:19 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 18:12 - 2012-06-19 06:19 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 15:19 - 2012-06-19 06:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:19 - 2012-06-19 06:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 15:15 - 2012-06-19 06:19 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 15:12 - 2012-06-19 06:19 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-05-31 20:53 - 2010-09-23 19:05 - 00000000 ____D C:\Program Files (x86)\Raptr
2012-05-31 20:22 - 2008-12-23 01:10 - 00000000 ____D C:\Users\Annie\AppData\Local\Google
2012-05-27 22:17 - 2009-01-09 12:08 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Skype
2012-05-25 15:12 - 2012-05-25 15:12 - 00000000 ____D C:\Program Files (x86)\Cisco Systems
2012-05-25 15:11 - 2012-05-25 15:11 - 00000000 ____D C:\Users\All Users\Cisco Systems
2012-05-25 15:11 - 2011-09-28 18:02 - 00002780 ____A C:\Windows\setupact.log
2012-05-17 22:47 - 2012-06-14 06:53 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 22:16 - 2012-06-14 06:53 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 22:06 - 2012-06-14 06:53 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 21:59 - 2012-06-14 06:53 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 21:59 - 2012-06-14 06:53 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 21:58 - 2012-06-14 06:53 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 21:58 - 2012-06-14 06:53 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 21:56 - 2012-06-14 06:53 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 21:55 - 2012-06-14 06:53 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 21:55 - 2012-06-14 06:53 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 21:54 - 2012-06-14 06:53 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 21:51 - 2012-06-14 06:54 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 21:51 - 2012-06-14 06:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 21:47 - 2012-06-14 06:53 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 19:11 - 2012-06-14 06:53 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 18:48 - 2012-06-14 06:53 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 18:45 - 2012-06-14 06:53 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 18:36 - 2012-06-14 06:53 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 18:35 - 2012-06-14 06:53 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 18:35 - 2012-06-14 06:53 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 18:33 - 2012-06-14 06:53 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 18:31 - 2012-06-14 06:53 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 18:29 - 2012-06-14 06:53 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 18:29 - 2012-06-14 06:53 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 18:27 - 2012-06-14 06:53 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 18:25 - 2012-06-14 06:53 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 18:24 - 2012-06-14 06:54 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 18:20 - 2012-06-14 06:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 16:15 - 2012-06-13 20:29 - 02767360 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 22:45 - 2011-09-16 15:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-13 22:35 - 2012-05-13 22:34 - 00000000 ____D C:\Users\Annie\AppData\Local\{DC51E5D8-22C1-4FAB-A1A2-25D0F47003BE}
2012-05-13 22:34 - 2012-05-13 22:34 - 00000000 ____D C:\Users\Annie\AppData\Local\{DDB67882-F74D-4497-8D23-D0CE141ECBF8}
2012-05-13 22:34 - 2009-08-10 11:25 - 00000000 ____D C:\Users\Annie\Tracing
2012-05-11 13:19 - 2006-11-02 11:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2012-05-11 13:19 - 2006-11-02 11:07 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-11 08:54 - 2008-06-13 20:34 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-10 06:31 - 2012-05-10 06:31 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-10 06:31 - 2011-09-06 07:28 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-02 19:56 - 2012-05-02 19:56 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-02 17:10 - 2011-02-14 20:08 - 00000448 ___AH C:\Windows\Tasks\Norton Security Scan for Annie.job
2012-05-01 10:29 - 2012-06-13 20:29 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-23 12:25 - 2012-06-13 20:29 - 01267200 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 12:25 - 2012-06-13 20:29 - 00174592 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 12:25 - 2012-06-13 20:29 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 12:00 - 2012-06-13 20:29 - 00984064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 12:00 - 2012-06-13 20:29 - 00133120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 12:00 - 2012-06-13 20:29 - 00098304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 20:56 - 2012-04-18 20:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 20:56 - 2012-04-18 20:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-14 10:00 - 2009-01-09 12:07 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-04-14 09:59 - 2009-01-09 12:07 - 00000000 ____D C:\Users\All Users\Skype
2012-04-14 09:16 - 2011-06-16 15:48 - 00000000 ____D C:\Users\All Users\Skype Extras
2012-04-14 09:06 - 2009-01-09 12:12 - 00000000 ____D C:\Users\Annie\AppData\Roaming\skypePM
2012-04-03 04:22 - 2012-05-10 22:07 - 04699520 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-31 16:17 - 2011-01-28 19:36 - 00000000 ____D C:\Users\Annie\AppData\Roaming\Apple Computer
2012-03-31 15:19 - 2010-12-23 07:20 - 00000000 ____D C:\Users\Annie\AppData\Local\Apple Computer
2012-03-31 15:17 - 2012-03-31 15:16 - 00000000 ____D C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-03-31 15:16 - 2012-03-31 15:14 - 00000000 ____D C:\Users\All Users\Apple Computer
2012-03-31 15:12 - 2012-03-31 15:12 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2012-03-30 08:45 - 2012-05-10 22:09 - 01423744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
ZeroAccess:
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\@
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\L
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\n
C:\Windows\Installer\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\U
ZeroAccess:
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\@
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\L
C:\Users\Annie\AppData\Local\{e2f8cece-1c65-f720-ecfc-b956de1d4728}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe BC81150939BD52DBC7A08C245F1FB229 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4059.93 MB
Available physical RAM: 3502.61 MB
Total Pagefile: 3807.07 MB
Available Pagefile: 3475.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (S3A6831D004) (Fixed) (Total:126.64 GB) (Free:73.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Annie) (Fixed) (Total:98.05 GB) (Free:4.62 GB) NTFS
4 Drive f: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.29 GB) NTFS
5 Drive g: () (Removable) (Total:0.48 GB) (Free:0.06 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
N¯ disque Statut Taille Libre Dyn GPT
---------- ------------- ------- ------------ --- ---
Disque 0 En ligne 233 G octets 0 octets
Disque 1 En ligne 491 M octets 0 octets
Partitions of Disk 0:
===============
N¯ partition Type Taille DÇcalage
------------- ---------------- ------- --------
Partition 1 OEM 1500 M 1024 K
Partition 2 Principale 127 G 1501 M
Partition 3 Principale 98 G 128 G
Partition 4 Principale 6893 M 226 G
======================================================================================================
Disk: 0
Partition 1
Type : 27
MasquÇ : Oui
Active : Non
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F TOSHIBA SYS NTFS Partition 1500 M Sain MasquÇ
======================================================================================================
Disk: 0
Partition 2
Type : 07
MasquÇ : Non
Active : Oui
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C S3A6831D004 NTFS Partition 127 G Sain
======================================================================================================
Disk: 0
Partition 3
Type : 07
MasquÇ : Non
Active : Non
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Annie NTFS Partition 98 G Sain
======================================================================================================
Disk: 0
Partition 4
Type : 17
MasquÇ : Oui
Active : Non
Il n'y a pas de volume associÇ avec cette partition.
======================================================================================================
Partitions of Disk 1:
===============
N¯ partition Type Taille DÇcalage
------------- ---------------- ------- --------
Partition 1 Principale 491 M 16 K
======================================================================================================
Disk: 1
Partition 1
Type : 0E
MasquÇ : Non
Active : Oui
N¯ volume Ltr Nom Fs Type Taille Statut Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 G FAT Amovible 491 M Sain
======================================================================================================
==========================================================
Last Boot: 2012-06-20 16:51
======================= End Of Log ==========================