Frederick8
Posts: 20 +0
Seems like many of us are getting the same infection.
I have read a few threads and noticed that a farbar scan result is required. Please take a look
Thank you for your help!
Scan result of Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 16-07-2012 01:10:21
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [4030008 2011-08-09] (ESET)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1680976 2010-10-28] (Logitech, Inc.)
HKLM-x32\...\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [101888 2011-01-11] (Leadtek Research Inc.)
HKLM-x32\...\Run: [T Probe] "C:\Program Files (x86)\ASUS\T Probe\TProbe.exe" -b [4010496 2009-10-19] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe [228352 2010-04-28] ()
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ISTray] "C:\Program Files (x86)\Spyware Doctor\pctsGui.exe" /hideGUI [2659768 2012-02-23] (PC Tools)
HKU\Frederick\...\Run: [Device Detection] C:\Program Files (x86)\FUJIFILM\MyFinePix Studio\dd.exe [787640 2011-07-27] ()
HKU\Patrick\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
==================== Services (Whitelisted) ======
2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-17] (ArcSoft Inc.)
2 Ad-Aware Service; "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe" [1226096 2012-05-03] (Lavasoft Limited)
2 Browser Defender Update Service; "C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe" [550864 2012-02-16] (Threat Expert Ltd.)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [974944 2011-08-09] (ESET)
2 FXNADB; C:\Program Files (x86)\Fuji Xerox\DocuPrint SSW2\SimpleMonitor for AP\fxksmdb.exe [86528 2010-10-19] ()
2 FXSMAPPWD; C:\Program Files\Fuji Xerox\SimpleMonitor for AP\FXAPPWDN.EXE [150016 2010-05-26] (Fuji Xerox Co., Ltd.)
2 FXSMAPSDB; C:\Program Files\Fuji Xerox\SimpleMonitor for AP\FXAPSDBN.EXE [338944 2010-05-26] (Fuji Xerox Co., Ltd.)
2 NetPipeActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
2 NetTcpActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
2 SBAMSvc; "C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe" [3289032 2011-12-18] (GFI Software)
2 sdAuxService; C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe [402336 2012-02-23] (PC Tools)
2 sdCoreService; C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe [1117624 2012-02-23] (PC Tools)
2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe" [1974080 2010-10-27] (TuneUp Software)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2009-08-03] ()
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-08] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-03] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [137144 2011-08-03] (ESET)
3 Linksys_adapter_H; C:\Windows\System32\DRIVERS\AE1200w764.sys [1254464 2011-03-28] (Broadcom Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-15] ()
3 PCTBD; C:\Windows\System32\Drivers\PCTBD64.sys [70760 2011-09-27] (PC Tools)
0 PCTCore; C:\Windows\System32\drivers\PCTCore64.sys [367912 2011-11-13] (PC Tools)
0 pctDS; C:\Windows\System32\drivers\pctDS64.sys [453896 2011-12-01] (PC Tools)
0 pctEFA; C:\Windows\System32\drivers\pctEFA64.sys [1096688 2011-12-01] (PC Tools)
1 PCTSD; C:\Windows\System32\Drivers\PCTSD64.sys [230952 2012-02-23] (PC Tools)
3 Razerlow; C:\Windows\System32\drivers\DB3G.sys [21120 2005-11-06] (Razer (Asia-Pacific) Pte Ltd)
1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [57976 2011-10-25] (GFI Software)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-11-23] (Duplex Secure Ltd.)
3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2010-10-06] (TuneUp Software)
3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-15 08:55 - 2012-07-15 08:55 - 01436595 ____A (Farbar) C:\Users\Frederick\Desktop\FRST64.exe
2012-07-15 06:07 - 2012-07-15 06:07 - 00000952 ____A C:\Windows\Tasks\Ad-Aware Antivirus Scheduled Scan.job
2012-07-14 19:42 - 2012-07-14 19:43 - 00000000 ____D C:\Users\All Users\SecTaskMan
2012-07-14 19:42 - 2012-07-14 19:42 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2012-07-14 19:20 - 2012-07-14 19:20 - 00000012 ____A C:\Users\Frederick\Desktop\FSSC.dat
2012-07-14 19:20 - 2012-07-14 19:20 - 00000000 ____D C:\Users\Frederick\AppData\Local\adaware
2012-07-14 19:19 - 2012-07-15 06:07 - 00001868 ____A C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2012-07-14 19:19 - 2012-07-15 05:59 - 00000000 ____D C:\Users\All Users\Ad-Aware Browsing Protection
2012-07-14 19:19 - 2012-07-14 19:31 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2012-07-14 19:19 - 2011-12-18 21:21 - 00045936 ____A (GFI Software) C:\Windows\System32\sbbd.exe
2012-07-14 19:19 - 2011-12-18 20:44 - 00256632 ____A (GFI Software) C:\Windows\System32\Drivers\SbFw.sys
2012-07-14 19:19 - 2011-12-18 20:44 - 00060536 ____A (GFI Software) C:\Windows\System32\Drivers\sbhips.sys
2012-07-14 19:19 - 2011-09-28 20:16 - 00119416 ____A (GFI Software) C:\Windows\System32\Drivers\SbFwIm.sys
2012-07-14 19:18 - 2012-07-15 02:50 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Ad-Aware Antivirus
2012-07-14 19:17 - 2012-07-14 19:17 - 06236280 ____A (Lavasoft Limited) C:\Users\Frederick\Desktop\Adaware_Installer.exe
2012-07-14 18:57 - 2012-07-14 19:19 - 02029804 ____A C:\Windows\System32\Drivers\Cat.DB
2012-07-14 18:57 - 2012-02-23 18:36 - 00230952 ____A (PC Tools) C:\Windows\System32\Drivers\PCTSD64.sys
2012-07-14 18:57 - 2012-02-23 18:35 - 00014776 ____A (PC Tools) C:\Windows\System32\Drivers\pctBTFix64.sys
2012-07-14 18:57 - 2012-02-16 23:08 - 02250704 ____A (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll
2012-07-14 18:57 - 2012-02-16 23:08 - 01681360 ____A (Threat Expert Ltd.) C:\Windows\PCTBDRes.dll
2012-07-14 18:57 - 2012-02-16 23:08 - 00767952 ____A C:\Windows\BDTSupport.dll
2012-07-14 18:57 - 2012-02-16 23:08 - 00149456 ____A (PC Tools) C:\Windows\SGDetectionTool.dll
2012-07-14 18:57 - 2011-12-01 00:07 - 01096688 ____A (PC Tools) C:\Windows\System32\Drivers\pctEFA64.sys
2012-07-14 18:57 - 2011-12-01 00:07 - 00453896 ____A (PC Tools) C:\Windows\System32\Drivers\pctDS64.sys
2012-07-14 18:57 - 2011-09-27 21:14 - 00070760 ____A (PC Tools) C:\Windows\System32\Drivers\PCTBD64.sys
2012-07-14 18:57 - 2011-05-16 23:47 - 00003488 ____A C:\Windows\UDB.zip
2012-07-14 18:57 - 2010-08-19 18:50 - 00000882 ____A C:\Windows\RegSDImport.xml
2012-07-14 18:57 - 2010-01-21 17:44 - 00000879 ____A C:\Windows\RegISSImport.xml
2012-07-14 18:57 - 2008-11-25 20:08 - 00000131 ____A C:\Windows\IDB.zip
2012-07-14 18:44 - 2012-07-14 18:53 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\GetRightToGo
2012-07-14 07:37 - 2012-07-14 07:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0AED4141-A6DF-4E36-8616-43BD92B65CFC}
2012-07-14 07:36 - 2012-07-14 07:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{2CD78501-5450-46D1-8151-31321D4D28D3}
2012-07-13 19:36 - 2012-07-13 19:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{DBBB6581-6E21-46DC-B8DE-44A684499E55}
2012-07-13 19:36 - 2012-07-13 19:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C268871C-B0D3-41FF-9C5B-5073568F091A}
2012-07-12 20:49 - 2012-07-12 20:49 - 00000000 ____D C:\Users\Frederick\AppData\Local\{AFCAC9C6-9170-4E40-858E-4EB7A160A10C}
2012-07-12 20:49 - 2012-07-12 20:49 - 00000000 ____D C:\Users\Frederick\AppData\Local\{5D5B2CED-3CE8-4C3A-A585-C06AC82D644F}
2012-07-12 08:07 - 2012-07-12 08:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{E1C5D2D2-C2C6-4439-8A88-348126D9C074}
2012-07-12 08:07 - 2012-07-12 08:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{76DF4FCF-39C5-4D39-A3A4-11D84CA9B7A5}
2012-07-12 04:12 - 2012-07-12 04:12 - 00000000 ____D C:\Users\Patrick\AppData\Local\{DDE7C2A0-7ABB-4B5F-AD69-6BD8B6214A24}
2012-07-12 04:12 - 2012-07-12 04:12 - 00000000 ____D C:\Users\Patrick\AppData\Local\{44233D42-19E5-4C54-B0E4-026A01E6E591}
2012-07-11 19:54 - 2012-07-11 19:54 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C9BA0AAA-9FCC-467B-B42C-1C5F2A692DA3}
2012-07-11 19:54 - 2012-07-11 19:54 - 00000000 ____D C:\Users\Frederick\AppData\Local\{7F42D0FD-9882-49F3-BDDC-341528146EAC}
2012-07-11 00:09 - 2012-07-11 00:09 - 00000000 ____D C:\Users\Frederick\AppData\Local\{50BF93AA-D183-4661-8883-B73AD8C9550D}
2012-07-11 00:09 - 2012-07-11 00:09 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0ACBF48C-990C-413A-8F10-A03115033BED}
2012-07-09 19:45 - 2012-07-09 19:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{45EA8CA0-78A2-4FA8-998E-980592FA5BA5}
2012-07-09 19:44 - 2012-07-09 19:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{99D21CA8-7A44-4AEA-9480-A681424008FC}
2012-07-09 07:44 - 2012-07-09 07:44 - 00000000 ____D C:\Users\Frederick\AppData\Local\{4622B4E7-9ED9-42F9-AA49-DFD8D323009D}
2012-07-09 07:44 - 2012-07-09 07:44 - 00000000 ____D C:\Users\Frederick\AppData\Local\{1AC6AB99-F576-4C87-ABA9-BCDFA6FB3A36}
2012-07-08 21:46 - 2012-07-08 21:46 - 00000000 ____D C:\Users\Patrick\AppData\Local\Macromedia
2012-07-08 21:42 - 2012-07-08 21:42 - 00000000 ____D C:\Users\Patrick\AppData\Local\{61B1C3F0-2B47-4E44-9B5B-BCDE6A84EE89}
2012-07-08 21:41 - 2012-07-08 21:42 - 00000000 ____D C:\Users\Patrick\AppData\Local\{AFF8CD8E-E766-4EA7-8BA8-D7F296357FFE}
2012-07-08 08:18 - 2012-07-08 08:18 - 00000000 ____D C:\Users\Frederick\AppData\Local\{3FC08BB6-4932-411E-B90F-EF5C0220585C}
2012-07-08 08:18 - 2012-07-08 08:18 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0BB678DF-7A32-4163-A83F-DED7A1376788}
2012-07-07 18:24 - 2012-07-07 18:24 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B9F3618F-B74E-41B4-B1FF-0A6673F52875}
2012-07-07 18:24 - 2012-07-07 18:24 - 00000000 ____D C:\Users\Frederick\AppData\Local\{67296BCD-A18A-48DD-86BC-E26A3426DB5F}
2012-07-07 07:07 - 2012-07-07 20:47 - 00000000 ____D C:\Users\Frederick\Desktop\John.Carter.2012.PAL.Retail.DVDR.Multi.Subs
2012-07-07 06:40 - 2012-07-07 06:40 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-07 06:25 - 2012-07-14 18:39 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Bafo
2012-07-07 06:25 - 2012-07-14 18:35 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Puiqyp
2012-07-07 06:25 - 2012-07-07 06:25 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Xyihgy
2012-07-06 22:45 - 2012-07-06 22:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FCA0228F-E493-4744-B81F-FB438BB42C92}
2012-07-06 22:45 - 2012-07-06 22:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B2B7F6D0-2E15-436A-B446-7A8C1BA56307}
2012-07-05 08:39 - 2012-07-05 08:39 - 00000000 ____D C:\Users\Frederick\AppData\Local\{67E45C36-5503-4A50-9681-3257DC6455DD}
2012-07-05 08:39 - 2012-07-05 08:39 - 00000000 ____D C:\Users\Frederick\AppData\Local\{5058D7D7-EA0D-4B1B-9F09-C87AABE6B75B}
2012-07-05 01:39 - 2012-07-05 01:39 - 00000037 ____A C:\Users\Frederick\Desktop\helen new units.txt
2012-07-04 21:59 - 2012-07-04 21:59 - 00000821 ____A C:\Users\Frederick\Desktop\New Leads.xlsx.lnk
2012-07-04 20:38 - 2012-07-04 20:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{96399D33-C40C-49DE-81F4-C9C74815FD6B}
2012-07-04 20:38 - 2012-07-04 20:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{030E1E9E-8DBA-4053-A129-FA9D7FD28771}
2012-07-04 08:38 - 2012-07-04 08:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{4DC4F536-DFB2-41FD-A327-9D3B4ADF3FDF}
2012-07-04 08:37 - 2012-07-04 08:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{ACF288DA-F1D2-4AAB-85EB-3C9F8E8DDA8F}
2012-07-03 20:37 - 2012-07-03 20:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{84B1B61B-80D7-4144-8455-67AFF1655591}
2012-07-03 20:37 - 2012-07-03 20:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{54CB378D-4A20-483F-B691-0317AAA04079}
2012-07-03 08:36 - 2012-07-03 08:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{3675A661-7485-4B0C-9F43-970EFCAEDCD9}
2012-07-03 08:36 - 2012-07-03 08:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{23BFDE15-4924-45B3-825C-18FC43C66F52}
2012-07-03 02:59 - 2012-07-02 21:33 - 00000000 ____D C:\Users\Frederick\Desktop\__MACOSX
2012-07-02 20:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{EC6C99D0-55EA-4935-BD35-94BCBA8A702F}
2012-07-02 20:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{00F632AD-CC6F-40E1-94CC-D295ECB76CF8}
2012-07-02 00:32 - 2012-07-02 00:32 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C1191710-394C-467E-BC9B-CBA022404786}
2012-07-02 00:32 - 2012-07-02 00:32 - 00000000 ____D C:\Users\Frederick\AppData\Local\{4AC87162-C055-4189-B585-09A891A3DE9B}
2012-07-01 21:21 - 2012-07-01 21:22 - 00000000 ____D C:\Users\Frederick\Desktop\Blk108 Bedok North Picture 1st July 2012
2012-07-01 21:20 - 2012-07-01 21:24 - 00000000 ____D C:\Users\Frederick\Desktop\Melvin Wedding
2012-07-01 02:35 - 2012-07-01 02:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{734F8C1E-C091-4451-8926-0942542D282C}
2012-07-01 02:35 - 2012-07-01 02:35 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B47CF5FF-0A8A-4859-BD9B-9F3C21C8895F}
2012-06-30 01:21 - 2012-06-30 01:21 - 00000000 ____D C:\Users\Frederick\AppData\Local\{BAF223F7-0BE5-4974-A1A6-166F7806C64A}
2012-06-30 01:21 - 2012-06-30 01:21 - 00000000 ____D C:\Users\Frederick\AppData\Local\{AF84DBA5-B023-4E6D-B527-FCAEC6E96D4E}
2012-06-28 11:26 - 2012-06-28 11:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{6905AB74-1F42-4169-80C5-3340E70B6001}
2012-06-28 11:26 - 2012-06-28 11:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{521A56CD-2EF1-45E2-A808-93EED72D355A}
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Frederick\AppData\Local\{DA1BA184-D73E-4919-A682-CF1E84B62943}
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Frederick\AppData\Local\{353652EB-0280-4ED6-9CC5-843052795C59}
2012-06-27 01:35 - 2012-06-27 01:35 - 00000000 ____D C:\Users\Frederick\AppData\Local\{99C0D0A5-8BC8-4A51-83EF-2C3E6511E23C}
2012-06-27 01:35 - 2012-06-27 01:35 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0A2B0687-2197-4D05-93B7-21EEAF0FB3D6}
2012-06-26 09:18 - 2012-06-27 18:16 - 00011438 ____A C:\Users\Frederick\Desktop\AMK 3RM.xlsx
2012-06-26 01:43 - 2012-06-26 01:44 - 00000000 ____D C:\Users\Frederick\AppData\Local\{483A5240-B54D-4441-B6CB-A9BBDA522791}
2012-06-26 01:43 - 2012-06-26 01:43 - 00000000 ____D C:\Users\Frederick\AppData\Local\{464629E8-1842-4B6C-8F00-6E30C257BA53}
2012-06-25 00:06 - 2012-06-25 00:06 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FB3688DF-C973-4A1F-8498-DB226C14ED17}
2012-06-25 00:06 - 2012-06-25 00:06 - 00000000 ____D C:\Users\Frederick\AppData\Local\{3CF09A68-5DFC-4073-85A8-F92647B94314}
2012-06-24 12:05 - 2012-06-24 12:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{A6AC8BC1-EB41-40D7-A7DE-5972DA50AA58}
2012-06-24 12:05 - 2012-06-24 12:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{058428A1-397D-41C4-9610-E371771566D3}
2012-06-24 00:05 - 2012-06-24 00:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B60AE591-763B-40CC-AB2B-99EB6EB570EB}
2012-06-24 00:04 - 2012-06-24 00:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{CCF591B1-2A1D-4B44-AD49-A6BA62D8A714}
2012-06-23 12:04 - 2012-06-23 12:04 - 00000000 ____D C:\Users\Frederick\AppData\Local\{974E243D-737F-4316-9390-A59331A2224C}
2012-06-23 12:04 - 2012-06-23 12:04 - 00000000 ____D C:\Users\Frederick\AppData\Local\{28BF708E-4992-41FF-88E5-F82B3FFA6506}
2012-06-23 00:03 - 2012-06-23 00:04 - 00000000 ____D C:\Users\Frederick\AppData\Local\{D2E953FF-9D92-4E71-926D-A4B7D992A513}
2012-06-23 00:03 - 2012-06-23 00:03 - 00000000 ____D C:\Users\Frederick\AppData\Local\{7FE06E0C-E02E-446A-8B4E-F0CA0948D9C2}
2012-06-22 20:28 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-22 20:28 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-22 20:28 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-22 20:28 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-22 20:28 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-22 20:28 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-22 20:28 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-22 20:28 - 2012-06-01 23:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-22 20:28 - 2012-06-01 23:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-22 08:08 - 2012-06-22 08:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FB40060C-6043-4C72-8173-135ED343111E}
2012-06-22 08:08 - 2012-06-22 08:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0D51EB9A-558C-4324-9B8F-649ADB06A8BC}
2012-06-21 20:08 - 2012-06-21 20:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B3AAC429-BF78-45BB-AFF9-997B5C50AC87}
2012-06-21 20:07 - 2012-06-21 20:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{E502D257-A56C-4852-9B35-9275F9F43CD8}
2012-06-21 05:26 - 2012-06-21 05:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C769905B-6E7B-4994-BD8F-4CBE3DED710D}
2012-06-21 05:25 - 2012-06-21 05:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{E15B1950-0DA2-428A-B87E-7AB76F9A5450}
2012-06-20 02:52 - 2012-06-20 02:52 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C792A012-7C88-49BF-B2CE-948B025D8B77}
2012-06-20 02:52 - 2012-06-20 02:52 - 00000000 ____D C:\Users\Frederick\AppData\Local\{1D4B5977-5EAF-483A-B423-78A2632C9F8E}
2012-06-19 19:06 - 2012-06-21 01:01 - 00000000 ____D C:\Users\Frederick\Desktop\Leslie & Sansan Loan
2012-06-19 08:07 - 2012-06-19 08:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{1B6D0857-E1DA-424C-AAE5-39C2163E0451}
2012-06-19 08:07 - 2012-06-19 08:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{88867921-89D7-4C1F-BE3B-83A9FFF34EAD}
2012-06-19 05:10 - 2012-06-21 08:43 - 00000287 ____A C:\Users\Frederick\Desktop\thurs.txt
2012-06-18 20:07 - 2012-06-18 20:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FFAE1013-500D-4DA8-BC59-2E82D6963BF4}
2012-06-18 20:07 - 2012-06-18 20:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{25452EA8-25FD-4A72-B6C1-3BFCA4773AA0}
2012-06-17 23:39 - 2012-06-17 23:39 - 00000000 ____D C:\Users\Frederick\AppData\Local\{EBF1FB6F-AC28-475A-9CB0-0D5F23A55011}
============ 3 Months Modified Files ========================
2012-07-15 09:05 - 2011-08-08 18:20 - 00011747 ____A C:\Windows\setupact.log
2012-07-15 09:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-15 09:02 - 2010-12-25 20:26 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-15 08:58 - 2011-09-04 08:32 - 00000000 ____A C:\sparkraw.log
2012-07-15 08:55 - 2012-07-15 08:55 - 01436595 ____A (Farbar) C:\Users\Frederick\Desktop\FRST64.exe
2012-07-15 08:52 - 2009-07-13 20:45 - 00014272 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-15 08:52 - 2009-07-13 20:45 - 00014272 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-15 08:49 - 2009-07-13 21:13 - 00848306 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-15 08:46 - 2012-06-12 05:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-15 06:07 - 2012-07-15 06:07 - 00000952 ____A C:\Windows\Tasks\Ad-Aware Antivirus Scheduled Scan.job
2012-07-15 06:07 - 2012-07-14 19:19 - 00001868 ____A C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2012-07-14 22:20 - 2010-12-25 20:26 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-14 19:20 - 2012-07-14 19:20 - 00000012 ____A C:\Users\Frederick\Desktop\FSSC.dat
2012-07-14 19:19 - 2012-07-14 18:57 - 02029804 ____A C:\Windows\System32\Drivers\Cat.DB
2012-07-14 19:17 - 2012-07-14 19:17 - 06236280 ____A (Lavasoft Limited) C:\Users\Frederick\Desktop\Adaware_Installer.exe
2012-07-11 21:46 - 2012-04-02 18:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 21:46 - 2011-05-19 18:43 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-07 06:27 - 2010-11-23 01:55 - 01555177 ____A C:\Windows\WindowsUpdate.log
2012-07-05 01:39 - 2012-07-05 01:39 - 00000037 ____A C:\Users\Frederick\Desktop\helen new units.txt
2012-07-04 21:59 - 2012-07-04 21:59 - 00000821 ____A C:\Users\Frederick\Desktop\New Leads.xlsx.lnk
2012-06-27 18:16 - 2012-06-26 09:18 - 00011438 ____A C:\Users\Frederick\Desktop\AMK 3RM.xlsx
2012-06-26 09:54 - 2012-06-08 11:23 - 00031086 ____A C:\Users\Frederick\Desktop\dh_damage_calculation_v1.22.xlsx
2012-06-21 08:43 - 2012-06-19 05:10 - 00000287 ____A C:\Users\Frederick\Desktop\thurs.txt
2012-06-15 22:54 - 2012-06-15 22:44 - 00000433 ____A C:\Users\Frederick\Desktop\123.txt
2012-06-14 07:05 - 2009-07-13 21:08 - 00032566 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-11 22:29 - 2012-06-11 22:29 - 00000016 ____A C:\Users\Frederick\Desktop\New leads1.txt
2012-06-10 07:57 - 2010-11-23 02:03 - 00109232 ____A C:\Users\Frederick\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-10 07:52 - 2011-08-09 04:12 - 00003706 ____A C:\Windows\PFRO.log
2012-06-10 07:52 - 2009-07-13 20:45 - 02343288 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-10 07:51 - 2011-04-25 07:16 - 00006932 ____A C:\Users\All Users\hpzinstall.log
2012-06-10 07:37 - 2011-04-25 07:16 - 00208133 ____A C:\Windows\hpoins47.dat
2012-06-10 07:26 - 2012-06-10 07:26 - 00002194 ____A C:\Users\Public\Desktop\HP Officejet 4610 series.lnk
2012-06-10 07:25 - 2012-06-10 07:25 - 00000057 ____A C:\Users\All Users\Ament.ini
2012-06-06 23:50 - 2012-06-06 21:00 - 00000211 ____A C:\Users\Frederick\Desktop\New Leads.txt
2012-06-04 06:20 - 2011-08-08 05:35 - 00425984 ____A C:\Users\Frederick\Desktop\SCB Repayment calculator_pv1 0.xls
2012-06-02 14:19 - 2012-06-22 20:28 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 20:28 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 20:28 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 20:28 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 20:28 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 20:28 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 20:28 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-01 23:19 - 2012-06-22 20:28 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 23:15 - 2012-06-22 20:28 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-22 22:09 - 2012-05-22 21:59 - 00000243 ____A C:\Users\Frederick\Desktop\Guilin View For our reference.txt
2012-05-18 19:06 - 2012-05-18 19:06 - 00000047 ____A C:\Users\Frederick\Desktop\hdb.txt
2012-05-17 20:30 - 2012-05-17 20:30 - 00000030 ____A C:\Users\Frederick\Desktop\Mark US Number.txt
2012-05-14 10:24 - 2012-05-14 10:09 - 00001193 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-13 20:32 - 2012-05-13 20:30 - 00002284 ____A C:\Windows\logboot_14.05.2012.tureg.log
2012-05-13 20:32 - 2009-07-13 18:34 - 74448896 ____A C:\Windows\System32\config\SOFTWARE_tureg_old
2012-05-13 20:32 - 2009-07-13 18:34 - 19398656 ____A C:\Windows\System32\config\SYSTEM_tureg_old
2012-05-13 20:32 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SECURITY_tureg_old
2012-05-13 10:59 - 2009-07-13 18:34 - 00524288 ____A C:\Windows\System32\config\DEFAULT_tureg_old
2012-05-13 10:59 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SAM_tureg_old
2012-05-12 11:24 - 2011-02-20 20:55 - 00002592 ____A C:\Users\Frederick\Desktop\How to Qualify your customers.txt
2012-05-12 08:27 - 2012-05-12 08:27 - 00001908 ____A C:\Windows\diagwrn.xml
2012-05-12 08:27 - 2012-05-12 08:27 - 00001908 ____A C:\Windows\diagerr.xml
2012-05-12 08:27 - 2009-07-13 20:51 - 00000000 ____A C:\Windows\setuperr.log
2012-05-10 09:54 - 2010-11-23 03:39 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-06 04:55 - 2012-05-06 04:55 - 00029191 ____A C:\formatter.log
2012-04-20 10:30 - 2012-04-19 22:23 - 00000431 ____A C:\Users\Frederick\Desktop\Sat Viewing.txt
2012-04-19 10:42 - 2012-04-01 21:40 - 00000605 ____A C:\Users\Frederick\Desktop\Rybi.txt
ZeroAccess:
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}\@
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}\L
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}\U
ZeroAccess:
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}\@
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}\L
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8190.05 MB
Available physical RAM: 7379.52 MB
Total Pagefile: 8188.2 MB
Available Pagefile: 7381.94 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:74.43 GB) (Free:7.18 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:465.76 GB) (Free:6.71 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (GRMCHPXFRER_EN_DVD) (CDROM) (Total:3 GB) (Free:0 GB) UDF
5 Drive h: (KINGSTON) (Removable) (Total:0.48 GB) (Free:0.44 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: () (Fixed) (Total:465.75 GB) (Free:23.4 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 7168 KB
Disk 1 Online 74 GB 0 B
Disk 2 Online 465 GB 1024 KB
Disk 3 Online 490 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 74 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 74 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 1024 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 489 MB 16 KB
==================================================================================
Disk: 3
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT32 Removable 489 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 08:38
======================= End Of Log ==========================
I have read a few threads and noticed that a farbar scan result is required. Please take a look
Thank you for your help!
Scan result of Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 16-07-2012 01:10:21
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [4030008 2011-08-09] (ESET)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1680976 2010-10-28] (Logitech, Inc.)
HKLM-x32\...\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [101888 2011-01-11] (Leadtek Research Inc.)
HKLM-x32\...\Run: [T Probe] "C:\Program Files (x86)\ASUS\T Probe\TProbe.exe" -b [4010496 2009-10-19] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe [228352 2010-04-28] ()
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ISTray] "C:\Program Files (x86)\Spyware Doctor\pctsGui.exe" /hideGUI [2659768 2012-02-23] (PC Tools)
HKU\Frederick\...\Run: [Device Detection] C:\Program Files (x86)\FUJIFILM\MyFinePix Studio\dd.exe [787640 2011-07-27] ()
HKU\Patrick\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
==================== Services (Whitelisted) ======
2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-17] (ArcSoft Inc.)
2 Ad-Aware Service; "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe" [1226096 2012-05-03] (Lavasoft Limited)
2 Browser Defender Update Service; "C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe" [550864 2012-02-16] (Threat Expert Ltd.)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [974944 2011-08-09] (ESET)
2 FXNADB; C:\Program Files (x86)\Fuji Xerox\DocuPrint SSW2\SimpleMonitor for AP\fxksmdb.exe [86528 2010-10-19] ()
2 FXSMAPPWD; C:\Program Files\Fuji Xerox\SimpleMonitor for AP\FXAPPWDN.EXE [150016 2010-05-26] (Fuji Xerox Co., Ltd.)
2 FXSMAPSDB; C:\Program Files\Fuji Xerox\SimpleMonitor for AP\FXAPSDBN.EXE [338944 2010-05-26] (Fuji Xerox Co., Ltd.)
2 NetPipeActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
2 NetTcpActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
2 SBAMSvc; "C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe" [3289032 2011-12-18] (GFI Software)
2 sdAuxService; C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe [402336 2012-02-23] (PC Tools)
2 sdCoreService; C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe [1117624 2012-02-23] (PC Tools)
2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe" [1974080 2010-10-27] (TuneUp Software)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2009-08-03] ()
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-08] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-03] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [137144 2011-08-03] (ESET)
3 Linksys_adapter_H; C:\Windows\System32\DRIVERS\AE1200w764.sys [1254464 2011-03-28] (Broadcom Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-15] ()
3 PCTBD; C:\Windows\System32\Drivers\PCTBD64.sys [70760 2011-09-27] (PC Tools)
0 PCTCore; C:\Windows\System32\drivers\PCTCore64.sys [367912 2011-11-13] (PC Tools)
0 pctDS; C:\Windows\System32\drivers\pctDS64.sys [453896 2011-12-01] (PC Tools)
0 pctEFA; C:\Windows\System32\drivers\pctEFA64.sys [1096688 2011-12-01] (PC Tools)
1 PCTSD; C:\Windows\System32\Drivers\PCTSD64.sys [230952 2012-02-23] (PC Tools)
3 Razerlow; C:\Windows\System32\drivers\DB3G.sys [21120 2005-11-06] (Razer (Asia-Pacific) Pte Ltd)
1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [57976 2011-10-25] (GFI Software)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-11-23] (Duplex Secure Ltd.)
3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2010-10-06] (TuneUp Software)
3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-15 08:55 - 2012-07-15 08:55 - 01436595 ____A (Farbar) C:\Users\Frederick\Desktop\FRST64.exe
2012-07-15 06:07 - 2012-07-15 06:07 - 00000952 ____A C:\Windows\Tasks\Ad-Aware Antivirus Scheduled Scan.job
2012-07-14 19:42 - 2012-07-14 19:43 - 00000000 ____D C:\Users\All Users\SecTaskMan
2012-07-14 19:42 - 2012-07-14 19:42 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2012-07-14 19:20 - 2012-07-14 19:20 - 00000012 ____A C:\Users\Frederick\Desktop\FSSC.dat
2012-07-14 19:20 - 2012-07-14 19:20 - 00000000 ____D C:\Users\Frederick\AppData\Local\adaware
2012-07-14 19:19 - 2012-07-15 06:07 - 00001868 ____A C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2012-07-14 19:19 - 2012-07-15 05:59 - 00000000 ____D C:\Users\All Users\Ad-Aware Browsing Protection
2012-07-14 19:19 - 2012-07-14 19:31 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus
2012-07-14 19:19 - 2011-12-18 21:21 - 00045936 ____A (GFI Software) C:\Windows\System32\sbbd.exe
2012-07-14 19:19 - 2011-12-18 20:44 - 00256632 ____A (GFI Software) C:\Windows\System32\Drivers\SbFw.sys
2012-07-14 19:19 - 2011-12-18 20:44 - 00060536 ____A (GFI Software) C:\Windows\System32\Drivers\sbhips.sys
2012-07-14 19:19 - 2011-09-28 20:16 - 00119416 ____A (GFI Software) C:\Windows\System32\Drivers\SbFwIm.sys
2012-07-14 19:18 - 2012-07-15 02:50 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Ad-Aware Antivirus
2012-07-14 19:17 - 2012-07-14 19:17 - 06236280 ____A (Lavasoft Limited) C:\Users\Frederick\Desktop\Adaware_Installer.exe
2012-07-14 18:57 - 2012-07-14 19:19 - 02029804 ____A C:\Windows\System32\Drivers\Cat.DB
2012-07-14 18:57 - 2012-02-23 18:36 - 00230952 ____A (PC Tools) C:\Windows\System32\Drivers\PCTSD64.sys
2012-07-14 18:57 - 2012-02-23 18:35 - 00014776 ____A (PC Tools) C:\Windows\System32\Drivers\pctBTFix64.sys
2012-07-14 18:57 - 2012-02-16 23:08 - 02250704 ____A (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll
2012-07-14 18:57 - 2012-02-16 23:08 - 01681360 ____A (Threat Expert Ltd.) C:\Windows\PCTBDRes.dll
2012-07-14 18:57 - 2012-02-16 23:08 - 00767952 ____A C:\Windows\BDTSupport.dll
2012-07-14 18:57 - 2012-02-16 23:08 - 00149456 ____A (PC Tools) C:\Windows\SGDetectionTool.dll
2012-07-14 18:57 - 2011-12-01 00:07 - 01096688 ____A (PC Tools) C:\Windows\System32\Drivers\pctEFA64.sys
2012-07-14 18:57 - 2011-12-01 00:07 - 00453896 ____A (PC Tools) C:\Windows\System32\Drivers\pctDS64.sys
2012-07-14 18:57 - 2011-09-27 21:14 - 00070760 ____A (PC Tools) C:\Windows\System32\Drivers\PCTBD64.sys
2012-07-14 18:57 - 2011-05-16 23:47 - 00003488 ____A C:\Windows\UDB.zip
2012-07-14 18:57 - 2010-08-19 18:50 - 00000882 ____A C:\Windows\RegSDImport.xml
2012-07-14 18:57 - 2010-01-21 17:44 - 00000879 ____A C:\Windows\RegISSImport.xml
2012-07-14 18:57 - 2008-11-25 20:08 - 00000131 ____A C:\Windows\IDB.zip
2012-07-14 18:44 - 2012-07-14 18:53 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\GetRightToGo
2012-07-14 07:37 - 2012-07-14 07:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0AED4141-A6DF-4E36-8616-43BD92B65CFC}
2012-07-14 07:36 - 2012-07-14 07:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{2CD78501-5450-46D1-8151-31321D4D28D3}
2012-07-13 19:36 - 2012-07-13 19:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{DBBB6581-6E21-46DC-B8DE-44A684499E55}
2012-07-13 19:36 - 2012-07-13 19:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C268871C-B0D3-41FF-9C5B-5073568F091A}
2012-07-12 20:49 - 2012-07-12 20:49 - 00000000 ____D C:\Users\Frederick\AppData\Local\{AFCAC9C6-9170-4E40-858E-4EB7A160A10C}
2012-07-12 20:49 - 2012-07-12 20:49 - 00000000 ____D C:\Users\Frederick\AppData\Local\{5D5B2CED-3CE8-4C3A-A585-C06AC82D644F}
2012-07-12 08:07 - 2012-07-12 08:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{E1C5D2D2-C2C6-4439-8A88-348126D9C074}
2012-07-12 08:07 - 2012-07-12 08:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{76DF4FCF-39C5-4D39-A3A4-11D84CA9B7A5}
2012-07-12 04:12 - 2012-07-12 04:12 - 00000000 ____D C:\Users\Patrick\AppData\Local\{DDE7C2A0-7ABB-4B5F-AD69-6BD8B6214A24}
2012-07-12 04:12 - 2012-07-12 04:12 - 00000000 ____D C:\Users\Patrick\AppData\Local\{44233D42-19E5-4C54-B0E4-026A01E6E591}
2012-07-11 19:54 - 2012-07-11 19:54 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C9BA0AAA-9FCC-467B-B42C-1C5F2A692DA3}
2012-07-11 19:54 - 2012-07-11 19:54 - 00000000 ____D C:\Users\Frederick\AppData\Local\{7F42D0FD-9882-49F3-BDDC-341528146EAC}
2012-07-11 00:09 - 2012-07-11 00:09 - 00000000 ____D C:\Users\Frederick\AppData\Local\{50BF93AA-D183-4661-8883-B73AD8C9550D}
2012-07-11 00:09 - 2012-07-11 00:09 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0ACBF48C-990C-413A-8F10-A03115033BED}
2012-07-09 19:45 - 2012-07-09 19:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{45EA8CA0-78A2-4FA8-998E-980592FA5BA5}
2012-07-09 19:44 - 2012-07-09 19:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{99D21CA8-7A44-4AEA-9480-A681424008FC}
2012-07-09 07:44 - 2012-07-09 07:44 - 00000000 ____D C:\Users\Frederick\AppData\Local\{4622B4E7-9ED9-42F9-AA49-DFD8D323009D}
2012-07-09 07:44 - 2012-07-09 07:44 - 00000000 ____D C:\Users\Frederick\AppData\Local\{1AC6AB99-F576-4C87-ABA9-BCDFA6FB3A36}
2012-07-08 21:46 - 2012-07-08 21:46 - 00000000 ____D C:\Users\Patrick\AppData\Local\Macromedia
2012-07-08 21:42 - 2012-07-08 21:42 - 00000000 ____D C:\Users\Patrick\AppData\Local\{61B1C3F0-2B47-4E44-9B5B-BCDE6A84EE89}
2012-07-08 21:41 - 2012-07-08 21:42 - 00000000 ____D C:\Users\Patrick\AppData\Local\{AFF8CD8E-E766-4EA7-8BA8-D7F296357FFE}
2012-07-08 08:18 - 2012-07-08 08:18 - 00000000 ____D C:\Users\Frederick\AppData\Local\{3FC08BB6-4932-411E-B90F-EF5C0220585C}
2012-07-08 08:18 - 2012-07-08 08:18 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0BB678DF-7A32-4163-A83F-DED7A1376788}
2012-07-07 18:24 - 2012-07-07 18:24 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B9F3618F-B74E-41B4-B1FF-0A6673F52875}
2012-07-07 18:24 - 2012-07-07 18:24 - 00000000 ____D C:\Users\Frederick\AppData\Local\{67296BCD-A18A-48DD-86BC-E26A3426DB5F}
2012-07-07 07:07 - 2012-07-07 20:47 - 00000000 ____D C:\Users\Frederick\Desktop\John.Carter.2012.PAL.Retail.DVDR.Multi.Subs
2012-07-07 06:40 - 2012-07-07 06:40 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-07 06:25 - 2012-07-14 18:39 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Bafo
2012-07-07 06:25 - 2012-07-14 18:35 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Puiqyp
2012-07-07 06:25 - 2012-07-07 06:25 - 00000000 ____D C:\Users\Frederick\AppData\Roaming\Xyihgy
2012-07-06 22:45 - 2012-07-06 22:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FCA0228F-E493-4744-B81F-FB438BB42C92}
2012-07-06 22:45 - 2012-07-06 22:45 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B2B7F6D0-2E15-436A-B446-7A8C1BA56307}
2012-07-05 08:39 - 2012-07-05 08:39 - 00000000 ____D C:\Users\Frederick\AppData\Local\{67E45C36-5503-4A50-9681-3257DC6455DD}
2012-07-05 08:39 - 2012-07-05 08:39 - 00000000 ____D C:\Users\Frederick\AppData\Local\{5058D7D7-EA0D-4B1B-9F09-C87AABE6B75B}
2012-07-05 01:39 - 2012-07-05 01:39 - 00000037 ____A C:\Users\Frederick\Desktop\helen new units.txt
2012-07-04 21:59 - 2012-07-04 21:59 - 00000821 ____A C:\Users\Frederick\Desktop\New Leads.xlsx.lnk
2012-07-04 20:38 - 2012-07-04 20:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{96399D33-C40C-49DE-81F4-C9C74815FD6B}
2012-07-04 20:38 - 2012-07-04 20:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{030E1E9E-8DBA-4053-A129-FA9D7FD28771}
2012-07-04 08:38 - 2012-07-04 08:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{4DC4F536-DFB2-41FD-A327-9D3B4ADF3FDF}
2012-07-04 08:37 - 2012-07-04 08:38 - 00000000 ____D C:\Users\Frederick\AppData\Local\{ACF288DA-F1D2-4AAB-85EB-3C9F8E8DDA8F}
2012-07-03 20:37 - 2012-07-03 20:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{84B1B61B-80D7-4144-8455-67AFF1655591}
2012-07-03 20:37 - 2012-07-03 20:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{54CB378D-4A20-483F-B691-0317AAA04079}
2012-07-03 08:36 - 2012-07-03 08:37 - 00000000 ____D C:\Users\Frederick\AppData\Local\{3675A661-7485-4B0C-9F43-970EFCAEDCD9}
2012-07-03 08:36 - 2012-07-03 08:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{23BFDE15-4924-45B3-825C-18FC43C66F52}
2012-07-03 02:59 - 2012-07-02 21:33 - 00000000 ____D C:\Users\Frederick\Desktop\__MACOSX
2012-07-02 20:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{EC6C99D0-55EA-4935-BD35-94BCBA8A702F}
2012-07-02 20:36 - 2012-07-02 20:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{00F632AD-CC6F-40E1-94CC-D295ECB76CF8}
2012-07-02 00:32 - 2012-07-02 00:32 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C1191710-394C-467E-BC9B-CBA022404786}
2012-07-02 00:32 - 2012-07-02 00:32 - 00000000 ____D C:\Users\Frederick\AppData\Local\{4AC87162-C055-4189-B585-09A891A3DE9B}
2012-07-01 21:21 - 2012-07-01 21:22 - 00000000 ____D C:\Users\Frederick\Desktop\Blk108 Bedok North Picture 1st July 2012
2012-07-01 21:20 - 2012-07-01 21:24 - 00000000 ____D C:\Users\Frederick\Desktop\Melvin Wedding
2012-07-01 02:35 - 2012-07-01 02:36 - 00000000 ____D C:\Users\Frederick\AppData\Local\{734F8C1E-C091-4451-8926-0942542D282C}
2012-07-01 02:35 - 2012-07-01 02:35 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B47CF5FF-0A8A-4859-BD9B-9F3C21C8895F}
2012-06-30 01:21 - 2012-06-30 01:21 - 00000000 ____D C:\Users\Frederick\AppData\Local\{BAF223F7-0BE5-4974-A1A6-166F7806C64A}
2012-06-30 01:21 - 2012-06-30 01:21 - 00000000 ____D C:\Users\Frederick\AppData\Local\{AF84DBA5-B023-4E6D-B527-FCAEC6E96D4E}
2012-06-28 11:26 - 2012-06-28 11:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{6905AB74-1F42-4169-80C5-3340E70B6001}
2012-06-28 11:26 - 2012-06-28 11:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{521A56CD-2EF1-45E2-A808-93EED72D355A}
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Frederick\AppData\Local\{DA1BA184-D73E-4919-A682-CF1E84B62943}
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Frederick\AppData\Local\{353652EB-0280-4ED6-9CC5-843052795C59}
2012-06-27 01:35 - 2012-06-27 01:35 - 00000000 ____D C:\Users\Frederick\AppData\Local\{99C0D0A5-8BC8-4A51-83EF-2C3E6511E23C}
2012-06-27 01:35 - 2012-06-27 01:35 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0A2B0687-2197-4D05-93B7-21EEAF0FB3D6}
2012-06-26 09:18 - 2012-06-27 18:16 - 00011438 ____A C:\Users\Frederick\Desktop\AMK 3RM.xlsx
2012-06-26 01:43 - 2012-06-26 01:44 - 00000000 ____D C:\Users\Frederick\AppData\Local\{483A5240-B54D-4441-B6CB-A9BBDA522791}
2012-06-26 01:43 - 2012-06-26 01:43 - 00000000 ____D C:\Users\Frederick\AppData\Local\{464629E8-1842-4B6C-8F00-6E30C257BA53}
2012-06-25 00:06 - 2012-06-25 00:06 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FB3688DF-C973-4A1F-8498-DB226C14ED17}
2012-06-25 00:06 - 2012-06-25 00:06 - 00000000 ____D C:\Users\Frederick\AppData\Local\{3CF09A68-5DFC-4073-85A8-F92647B94314}
2012-06-24 12:05 - 2012-06-24 12:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{A6AC8BC1-EB41-40D7-A7DE-5972DA50AA58}
2012-06-24 12:05 - 2012-06-24 12:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{058428A1-397D-41C4-9610-E371771566D3}
2012-06-24 00:05 - 2012-06-24 00:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B60AE591-763B-40CC-AB2B-99EB6EB570EB}
2012-06-24 00:04 - 2012-06-24 00:05 - 00000000 ____D C:\Users\Frederick\AppData\Local\{CCF591B1-2A1D-4B44-AD49-A6BA62D8A714}
2012-06-23 12:04 - 2012-06-23 12:04 - 00000000 ____D C:\Users\Frederick\AppData\Local\{974E243D-737F-4316-9390-A59331A2224C}
2012-06-23 12:04 - 2012-06-23 12:04 - 00000000 ____D C:\Users\Frederick\AppData\Local\{28BF708E-4992-41FF-88E5-F82B3FFA6506}
2012-06-23 00:03 - 2012-06-23 00:04 - 00000000 ____D C:\Users\Frederick\AppData\Local\{D2E953FF-9D92-4E71-926D-A4B7D992A513}
2012-06-23 00:03 - 2012-06-23 00:03 - 00000000 ____D C:\Users\Frederick\AppData\Local\{7FE06E0C-E02E-446A-8B4E-F0CA0948D9C2}
2012-06-22 20:28 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-22 20:28 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-22 20:28 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-22 20:28 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-22 20:28 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-22 20:28 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-22 20:28 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-22 20:28 - 2012-06-01 23:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-22 20:28 - 2012-06-01 23:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-22 08:08 - 2012-06-22 08:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FB40060C-6043-4C72-8173-135ED343111E}
2012-06-22 08:08 - 2012-06-22 08:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{0D51EB9A-558C-4324-9B8F-649ADB06A8BC}
2012-06-21 20:08 - 2012-06-21 20:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{B3AAC429-BF78-45BB-AFF9-997B5C50AC87}
2012-06-21 20:07 - 2012-06-21 20:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{E502D257-A56C-4852-9B35-9275F9F43CD8}
2012-06-21 05:26 - 2012-06-21 05:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C769905B-6E7B-4994-BD8F-4CBE3DED710D}
2012-06-21 05:25 - 2012-06-21 05:26 - 00000000 ____D C:\Users\Frederick\AppData\Local\{E15B1950-0DA2-428A-B87E-7AB76F9A5450}
2012-06-20 02:52 - 2012-06-20 02:52 - 00000000 ____D C:\Users\Frederick\AppData\Local\{C792A012-7C88-49BF-B2CE-948B025D8B77}
2012-06-20 02:52 - 2012-06-20 02:52 - 00000000 ____D C:\Users\Frederick\AppData\Local\{1D4B5977-5EAF-483A-B423-78A2632C9F8E}
2012-06-19 19:06 - 2012-06-21 01:01 - 00000000 ____D C:\Users\Frederick\Desktop\Leslie & Sansan Loan
2012-06-19 08:07 - 2012-06-19 08:08 - 00000000 ____D C:\Users\Frederick\AppData\Local\{1B6D0857-E1DA-424C-AAE5-39C2163E0451}
2012-06-19 08:07 - 2012-06-19 08:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{88867921-89D7-4C1F-BE3B-83A9FFF34EAD}
2012-06-19 05:10 - 2012-06-21 08:43 - 00000287 ____A C:\Users\Frederick\Desktop\thurs.txt
2012-06-18 20:07 - 2012-06-18 20:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{FFAE1013-500D-4DA8-BC59-2E82D6963BF4}
2012-06-18 20:07 - 2012-06-18 20:07 - 00000000 ____D C:\Users\Frederick\AppData\Local\{25452EA8-25FD-4A72-B6C1-3BFCA4773AA0}
2012-06-17 23:39 - 2012-06-17 23:39 - 00000000 ____D C:\Users\Frederick\AppData\Local\{EBF1FB6F-AC28-475A-9CB0-0D5F23A55011}
============ 3 Months Modified Files ========================
2012-07-15 09:05 - 2011-08-08 18:20 - 00011747 ____A C:\Windows\setupact.log
2012-07-15 09:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-15 09:02 - 2010-12-25 20:26 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-15 08:58 - 2011-09-04 08:32 - 00000000 ____A C:\sparkraw.log
2012-07-15 08:55 - 2012-07-15 08:55 - 01436595 ____A (Farbar) C:\Users\Frederick\Desktop\FRST64.exe
2012-07-15 08:52 - 2009-07-13 20:45 - 00014272 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-15 08:52 - 2009-07-13 20:45 - 00014272 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-15 08:49 - 2009-07-13 21:13 - 00848306 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-15 08:46 - 2012-06-12 05:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-15 06:07 - 2012-07-15 06:07 - 00000952 ____A C:\Windows\Tasks\Ad-Aware Antivirus Scheduled Scan.job
2012-07-15 06:07 - 2012-07-14 19:19 - 00001868 ____A C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2012-07-14 22:20 - 2010-12-25 20:26 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-14 19:20 - 2012-07-14 19:20 - 00000012 ____A C:\Users\Frederick\Desktop\FSSC.dat
2012-07-14 19:19 - 2012-07-14 18:57 - 02029804 ____A C:\Windows\System32\Drivers\Cat.DB
2012-07-14 19:17 - 2012-07-14 19:17 - 06236280 ____A (Lavasoft Limited) C:\Users\Frederick\Desktop\Adaware_Installer.exe
2012-07-11 21:46 - 2012-04-02 18:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-11 21:46 - 2011-05-19 18:43 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-07 06:27 - 2010-11-23 01:55 - 01555177 ____A C:\Windows\WindowsUpdate.log
2012-07-05 01:39 - 2012-07-05 01:39 - 00000037 ____A C:\Users\Frederick\Desktop\helen new units.txt
2012-07-04 21:59 - 2012-07-04 21:59 - 00000821 ____A C:\Users\Frederick\Desktop\New Leads.xlsx.lnk
2012-06-27 18:16 - 2012-06-26 09:18 - 00011438 ____A C:\Users\Frederick\Desktop\AMK 3RM.xlsx
2012-06-26 09:54 - 2012-06-08 11:23 - 00031086 ____A C:\Users\Frederick\Desktop\dh_damage_calculation_v1.22.xlsx
2012-06-21 08:43 - 2012-06-19 05:10 - 00000287 ____A C:\Users\Frederick\Desktop\thurs.txt
2012-06-15 22:54 - 2012-06-15 22:44 - 00000433 ____A C:\Users\Frederick\Desktop\123.txt
2012-06-14 07:05 - 2009-07-13 21:08 - 00032566 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-11 22:29 - 2012-06-11 22:29 - 00000016 ____A C:\Users\Frederick\Desktop\New leads1.txt
2012-06-10 07:57 - 2010-11-23 02:03 - 00109232 ____A C:\Users\Frederick\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-10 07:52 - 2011-08-09 04:12 - 00003706 ____A C:\Windows\PFRO.log
2012-06-10 07:52 - 2009-07-13 20:45 - 02343288 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-10 07:51 - 2011-04-25 07:16 - 00006932 ____A C:\Users\All Users\hpzinstall.log
2012-06-10 07:37 - 2011-04-25 07:16 - 00208133 ____A C:\Windows\hpoins47.dat
2012-06-10 07:26 - 2012-06-10 07:26 - 00002194 ____A C:\Users\Public\Desktop\HP Officejet 4610 series.lnk
2012-06-10 07:25 - 2012-06-10 07:25 - 00000057 ____A C:\Users\All Users\Ament.ini
2012-06-06 23:50 - 2012-06-06 21:00 - 00000211 ____A C:\Users\Frederick\Desktop\New Leads.txt
2012-06-04 06:20 - 2011-08-08 05:35 - 00425984 ____A C:\Users\Frederick\Desktop\SCB Repayment calculator_pv1 0.xls
2012-06-02 14:19 - 2012-06-22 20:28 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 20:28 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 20:28 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 20:28 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 20:28 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 20:28 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 20:28 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-01 23:19 - 2012-06-22 20:28 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 23:15 - 2012-06-22 20:28 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-22 22:09 - 2012-05-22 21:59 - 00000243 ____A C:\Users\Frederick\Desktop\Guilin View For our reference.txt
2012-05-18 19:06 - 2012-05-18 19:06 - 00000047 ____A C:\Users\Frederick\Desktop\hdb.txt
2012-05-17 20:30 - 2012-05-17 20:30 - 00000030 ____A C:\Users\Frederick\Desktop\Mark US Number.txt
2012-05-14 10:24 - 2012-05-14 10:09 - 00001193 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-13 20:32 - 2012-05-13 20:30 - 00002284 ____A C:\Windows\logboot_14.05.2012.tureg.log
2012-05-13 20:32 - 2009-07-13 18:34 - 74448896 ____A C:\Windows\System32\config\SOFTWARE_tureg_old
2012-05-13 20:32 - 2009-07-13 18:34 - 19398656 ____A C:\Windows\System32\config\SYSTEM_tureg_old
2012-05-13 20:32 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SECURITY_tureg_old
2012-05-13 10:59 - 2009-07-13 18:34 - 00524288 ____A C:\Windows\System32\config\DEFAULT_tureg_old
2012-05-13 10:59 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SAM_tureg_old
2012-05-12 11:24 - 2011-02-20 20:55 - 00002592 ____A C:\Users\Frederick\Desktop\How to Qualify your customers.txt
2012-05-12 08:27 - 2012-05-12 08:27 - 00001908 ____A C:\Windows\diagwrn.xml
2012-05-12 08:27 - 2012-05-12 08:27 - 00001908 ____A C:\Windows\diagerr.xml
2012-05-12 08:27 - 2009-07-13 20:51 - 00000000 ____A C:\Windows\setuperr.log
2012-05-10 09:54 - 2010-11-23 03:39 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-06 04:55 - 2012-05-06 04:55 - 00029191 ____A C:\formatter.log
2012-04-20 10:30 - 2012-04-19 22:23 - 00000431 ____A C:\Users\Frederick\Desktop\Sat Viewing.txt
2012-04-19 10:42 - 2012-04-01 21:40 - 00000605 ____A C:\Users\Frederick\Desktop\Rybi.txt
ZeroAccess:
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}\@
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}\L
C:\Windows\Installer\{8e39dd68-a100-1622-ebd0-27061a621c76}\U
ZeroAccess:
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}\@
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}\L
C:\Users\Frederick\AppData\Local\{8e39dd68-a100-1622-ebd0-27061a621c76}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8190.05 MB
Available physical RAM: 7379.52 MB
Total Pagefile: 8188.2 MB
Available Pagefile: 7381.94 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:74.43 GB) (Free:7.18 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:465.76 GB) (Free:6.71 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (GRMCHPXFRER_EN_DVD) (CDROM) (Total:3 GB) (Free:0 GB) UDF
5 Drive h: (KINGSTON) (Removable) (Total:0.48 GB) (Free:0.44 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: () (Fixed) (Total:465.75 GB) (Free:23.4 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 7168 KB
Disk 1 Online 74 GB 0 B
Disk 2 Online 465 GB 1024 KB
Disk 3 Online 490 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 74 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 74 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 1024 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 489 MB 16 KB
==================================================================================
Disk: 3
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT32 Removable 489 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 08:38
======================= End Of Log ==========================