Windows 7 startup repair loop virus?

Inactive
By KristenLeto
Oct 14, 2012
  1. Recently my Samsung laptop just kept freezing randomly after maybe 5 or 10 minutes of use. Nothing would move and music would keep playing in the background. I turned it off by pressing the power button and after trying to solve that by trying system recoveries I've gotten to the windows startup repair. This has gotten me no where since it loops on and off saying it found nothing. So far I have done some research and figured out about the FRST64 and gotten the document. Please help!! The txt file is attached, and below is the report.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-10-2012
    Ran by SYSTEM at 14-10-2012 12:37:26
    Running from I:\
    Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ==================== Registry (Whitelisted) ===================

    HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12666984 2011-08-09] (Realtek Semiconductor)
    HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [x]
    HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [791200 2011-07-15] (Atheros Commnucations)
    HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-07-15] (Atheros Commnucations)
    HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2011-10-13] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe" [87336 2010-09-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-01] (CyberLink)
    HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
    HKLM-x32\...\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646232 2011-09-26] ()
    HKLM-x32\...\Run: [Immunet Protect] "C:\Program Files\Suze Orman SecureScan\3.0.5\iptray.exe" [3555104 2012-04-05] (Immunet)
    HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot [296056 2012-04-08] (RealNetworks, Inc.)
    HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [x]
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1996200 2012-08-29] (LogMeIn Inc.)
    HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.)
    HKU\Jceee\...\Run: [Google Update] "C:\Users\Jceee\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-01-24] (Google Inc.)
    HKU\Jceee\...\Run: [Facebook Update] "C:\Users\Jceee\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
    HKU\Jceee\...\Run: [DW6] "C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe" [x]
    HKU\Jceee\...\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent [x]
    HKU\Jceee\...\Run: [Spotify Web Helper] "C:\Users\Jceee\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1193176 2012-08-22] ()
    HKU\Jceee\...\Policies\system: [DisableCMD] 0
    HKU\Jceee\...\Policies\system: [NoDispAppearancePage] 0
    HKU\Jceee\...\Policies\system: [NoDispBackgroundPage] 0
    HKU\Jceee\...\Policies\system: [NoDispSettingsPage] 0
    HKU\Kristen\...\Run: [Google Update] "C:\Users\Kristen\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-02-12] (Google Inc.)
    HKU\Kristen\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [x]
    HKLM\...\RunOnce: [SRS5] C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\InstallManager.exe [1441280 2011-06-24] (SEC)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 4.2.2.2
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
    Startup: C:\Users\Jceee\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

    ==================== Services (Whitelisted) ===================

    2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-07-15] (Atheros)
    2 ImmunetProtect; C:\Program Files\Suze Orman SecureScan\3.0.5\agent.exe [402600 2012-04-05] (Sourcefire, Inc.)
    3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe" [237008 2011-06-17] (McAfee, Inc.)
    2 NSL; "C:\Program Files (x86)\Norton Safe Web Lite\Engine\2.0.0.16\ccSvcHst.exe" /s "NSL" /m "C:\Program Files (x86)\Norton Safe Web Lite\Engine\2.0.0.16\diMaster.dll" /prefetch:1 [303544 2011-10-11] (Symantec Corporation)
    2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [244904 2009-11-30] ()
    3 scan; C:\Program Files\Suze Orman SecureScan\tetra\scan.dll [411648 2012-04-05] (S.C. BitDefender S.R.L)
    2 AdobeARMservice; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [x]

    ==================== Drivers (Whitelisted) =====================

    1 ccSet_NST; C:\Windows\system32\drivers\NSTx64\0200000.010\ccSetx64.sys [167048 2011-08-08] (Symantec Corporation)
    1 ImmunetProtectDriver; C:\Windows\System32\DRIVERS\ImmunetProtect.sys [57120 2012-04-05] (Windows (R) Win 7 DDK provider)
    1 ImmunetSelfProtectDriver; C:\Windows\System32\DRIVERS\ImmunetSelfProtect.sys [32544 2012-04-05] (Windows (R) Win 7 DDK provider)
    2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)
    3 Trufos; C:\Windows\System32\Drivers\Trufos.sys [284232 2012-04-05] (BitDefender S.R.L.)
    3 dump_wmimmc; \??\C:\Program Files (x86)\Flyff\GameGuard\dump_wmimmc.sys [x]
    3 NPPTNT2; \??\C:\windows\system32\npptNT2.sys [x]
    3 X6va001; \??\C:\Users\Jceee\AppData\Local\Temp\0014C3E.tmp [x]
    3 X6va008; \??\C:\windows\SysWOW64\Drivers\X6va008 [x]

    ==================== NetSvcs (Whitelisted) ====================


    ==================== One Month Created Files and Folders ========

    2012-10-14 10:13 - 2011-11-16 03:39 - 00174640 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
    2012-10-14 10:13 - 2011-11-16 03:39 - 00007440 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
    2012-10-14 10:13 - 2008-11-08 14:09 - 00428544 ____A (Samsung Electronics) C:\Windows\AutoReseal.exe
    2012-10-14 10:13 - 2007-11-14 17:13 - 00423936 ____A (TODO: <Company name>) C:\Windows\Reseal64.exe
    2012-09-29 22:06 - 2012-09-29 22:09 - 00001028 ____A C:\Users\Jceee\Downloads\Slender $20 Mode Unlocker (1).reg
    2012-09-29 21:59 - 2012-09-29 22:00 - 00001028 ____A C:\Users\Jceee\Downloads\Slender $20 Mode Unlocker.reg
    2012-09-29 21:59 - 2012-09-29 21:59 - 01517376 ____A C:\Users\Jceee\Downloads\wrar420.exe
    2012-09-29 07:43 - 2012-09-29 07:43 - 00176000 ____A C:\Users\Jceee\Downloads\Adventure Club Feat. Krewella - Rise & Fall (Krewella Remix).mp3.sfk
    2012-09-25 14:44 - 2012-08-21 13:01 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe
    2012-09-23 08:46 - 2012-09-23 08:46 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
    2012-09-23 08:46 - 2012-08-21 12:01 - 00033240 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
    2012-09-23 08:45 - 2012-09-23 08:46 - 00000000 ____D C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69
    2012-09-23 08:45 - 2012-09-23 08:46 - 00000000 ____D C:\Program Files\iTunes
    2012-09-23 08:45 - 2012-09-23 08:46 - 00000000 ____D C:\Program Files (x86)\iTunes
    2012-09-23 08:45 - 2012-09-23 08:45 - 00000000 ____D C:\Program Files\iPod
    2012-09-23 08:31 - 2012-08-24 03:15 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-09-23 08:31 - 2012-08-24 02:39 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-09-23 08:31 - 2012-08-24 02:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-09-23 08:31 - 2012-08-24 02:22 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-09-23 08:31 - 2012-08-24 02:21 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-09-23 08:31 - 2012-08-24 02:20 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-09-23 08:31 - 2012-08-24 02:18 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-09-23 08:31 - 2012-08-24 02:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-09-23 08:31 - 2012-08-24 02:14 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-09-23 08:31 - 2012-08-24 02:14 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-09-23 08:31 - 2012-08-24 02:13 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2012-09-23 08:31 - 2012-08-24 02:12 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-09-23 08:31 - 2012-08-24 02:11 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-09-23 08:31 - 2012-08-24 02:10 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-09-23 08:31 - 2012-08-24 02:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-09-23 08:31 - 2012-08-24 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-09-23 08:31 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-09-23 08:31 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-09-23 08:31 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-09-23 08:31 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-09-23 08:31 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-09-23 08:31 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-09-23 08:31 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-09-23 08:31 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-09-23 08:31 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-09-23 08:31 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2012-09-23 08:31 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-09-23 08:31 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2012-09-23 08:31 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-09-23 08:31 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-09-23 08:31 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-09-23 08:31 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-09-22 14:27 - 2012-09-22 14:27 - 00369736 ____A C:\Users\Jceee\Downloads\The Vampire Diaries Soundtrack S1x17 - All You Wanted - Sounds Under Radio.mp3.sfk
    2012-09-21 23:00 - 2012-10-10 18:06 - 00000376 ____A C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Jceee.job
    2012-09-21 20:11 - 2012-10-09 18:57 - 00000366 ____A C:\Windows\Tasks\ReclaimerUpdateXML_Jceee.job
    2012-09-21 20:11 - 2012-10-08 17:09 - 00000370 ____A C:\Windows\Tasks\ReclaimerUpdateFiles_Jceee.job
    2012-09-19 06:37 - 2012-09-19 06:37 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
    2012-09-19 06:37 - 2009-03-18 16:35 - 00033856 ___AH (LogMeIn, Inc.) C:\Windows\System32\hamachi.sys
    2012-09-16 12:37 - 2012-09-16 12:37 - 01664268 ____A C:\Users\Jceee\Downloads\mcpatcher-2.4.2_03.exe
    2012-09-15 13:55 - 2012-09-15 13:55 - 00000082 ____A C:\Users\Jceee\Desktop\Stuuf.txt


    ==================== 3 Months Modified Files ==================

    2012-10-10 18:10 - 2012-07-25 19:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-10-10 18:10 - 2011-11-16 20:07 - 01267467 ____A C:\Windows\WindowsUpdate.log
    2012-10-10 18:06 - 2012-09-21 23:00 - 00000376 ____A C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Jceee.job
    2012-10-10 18:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-10-10 18:05 - 2009-07-13 20:51 - 00100641 ____A C:\Windows\setupact.log
    2012-10-09 21:27 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-10-09 21:27 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-10-09 21:25 - 2012-02-12 19:00 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1000UA.job
    2012-10-09 20:32 - 2012-03-03 12:27 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1004UA.job
    2012-10-09 20:13 - 2012-01-24 19:51 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1003UA.job
    2012-10-09 19:54 - 2012-03-06 17:02 - 00000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1003UA.job
    2012-10-09 18:57 - 2012-09-21 20:11 - 00000366 ____A C:\Windows\Tasks\ReclaimerUpdateXML_Jceee.job
    2012-10-09 14:58 - 2012-01-24 19:51 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1003Core.job
    2012-10-09 14:50 - 2012-03-03 12:27 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1004Core.job
    2012-10-08 23:25 - 2012-02-12 19:00 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1000Core.job
    2012-10-08 23:00 - 2012-06-19 02:03 - 00000354 ____A C:\Windows\Tasks\Immunet Scan 1839423.job
    2012-10-08 22:54 - 2012-03-06 17:02 - 00000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1833043278-1489670560-2515665415-1003Core.job
    2012-10-08 22:16 - 2012-01-24 19:53 - 00002485 ____A C:\Users\Jceee\Desktop\Google Chrome.lnk
    2012-10-08 17:09 - 2012-09-21 20:11 - 00000370 ____A C:\Windows\Tasks\ReclaimerUpdateFiles_Jceee.job
    2012-10-08 17:09 - 2012-07-25 19:06 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-10-08 17:09 - 2012-07-25 19:06 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-09-29 22:09 - 2012-09-29 22:06 - 00001028 ____A C:\Users\Jceee\Downloads\Slender $20 Mode Unlocker (1).reg
    2012-09-29 22:00 - 2012-09-29 21:59 - 00001028 ____A C:\Users\Jceee\Downloads\Slender $20 Mode Unlocker.reg
    2012-09-29 21:59 - 2012-09-29 21:59 - 01517376 ____A C:\Users\Jceee\Downloads\wrar420.exe
    2012-09-29 07:43 - 2012-09-29 07:43 - 00176000 ____A C:\Users\Jceee\Downloads\Adventure Club Feat. Krewella - Rise & Fall (Krewella Remix).mp3.sfk
    2012-09-25 18:59 - 2009-07-13 21:13 - 00778834 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-09-25 16:36 - 2012-07-09 19:12 - 00054389 ____A C:\Users\Jceee\Downloads\server.log
    2012-09-25 15:57 - 2012-07-09 19:12 - 00000496 ____A C:\Users\Jceee\Downloads\server.properties
    2012-09-25 15:57 - 2012-07-09 19:12 - 00000110 ____A C:\Users\Jceee\Downloads\banned-players.txt
    2012-09-25 15:57 - 2012-07-09 19:12 - 00000110 ____A C:\Users\Jceee\Downloads\banned-ips.txt
    2012-09-25 15:57 - 2012-07-09 19:12 - 00000000 ____A C:\Users\Jceee\Downloads\white-list.txt
    2012-09-25 15:57 - 2012-07-09 19:12 - 00000000 ____A C:\Users\Jceee\Downloads\ops.txt
    2012-09-23 08:46 - 2012-09-23 08:46 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
    2012-09-22 14:27 - 2012-09-22 14:27 - 00369736 ____A C:\Users\Jceee\Downloads\The Vampire Diaries Soundtrack S1x17 - All You Wanted - Sounds Under Radio.mp3.sfk
    2012-09-19 06:37 - 2012-07-13 23:25 - 00000926 ____A C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
    2012-09-16 12:37 - 2012-09-16 12:37 - 01664268 ____A C:\Users\Jceee\Downloads\mcpatcher-2.4.2_03.exe
    2012-09-15 13:55 - 2012-09-15 13:55 - 00000082 ____A C:\Users\Jceee\Desktop\Stuuf.txt
    2012-09-12 02:01 - 2012-02-02 06:44 - 64462936 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-09-10 17:21 - 2012-09-10 17:18 - 60849927 ____A C:\Users\Jceee\Downloads\Slendy.zip
    2012-09-08 21:06 - 2012-09-08 21:06 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-09-08 21:06 - 2012-09-08 21:06 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-09-08 21:06 - 2012-09-08 21:06 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-09-08 21:06 - 2012-09-08 21:06 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2012-09-08 21:06 - 2012-06-22 20:27 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-09-08 21:06 - 2012-06-22 20:27 - 00746984 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-09-04 18:41 - 2012-09-04 18:41 - 00090624 ____A C:\Users\Jceee\Downloads\Essay Grading Form.xls
    2012-09-04 10:30 - 2012-02-12 19:03 - 00002461 ____A C:\Users\Kristen\Desktop\Google Chrome.lnk
    2012-09-04 10:22 - 2012-01-23 21:38 - 00099000 ____A C:\Users\Kristen\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-08-28 22:15 - 2012-08-28 22:14 - 00152544 ____A C:\Users\Jceee\Downloads\Kelly Clarkson - -Dark Side-.mp3.sfk
    2012-08-28 22:15 - 2012-08-28 22:13 - 00162208 ____A C:\Users\Jceee\Downloads\---------------}---------}------ - CANDY CANDY.mp3.sfk
    2012-08-28 22:13 - 2012-08-28 22:09 - 00220872 ____A C:\Users\Jceee\Downloads\Dubstep - Adventure Club ft Krewella - Rise & Fall (KDrew Remix).mp3.sfk
    2012-08-24 03:15 - 2012-09-23 08:31 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-08-24 02:39 - 2012-09-23 08:31 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-08-24 02:31 - 2012-09-23 08:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-08-24 02:22 - 2012-09-23 08:31 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-08-24 02:21 - 2012-09-23 08:31 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-08-24 02:20 - 2012-09-23 08:31 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-08-24 02:18 - 2012-09-23 08:31 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-08-24 02:17 - 2012-09-23 08:31 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-08-24 02:14 - 2012-09-23 08:31 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-08-24 02:14 - 2012-09-23 08:31 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-08-24 02:13 - 2012-09-23 08:31 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2012-08-24 02:12 - 2012-09-23 08:31 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-08-24 02:11 - 2012-09-23 08:31 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-08-24 02:10 - 2012-09-23 08:31 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-08-24 02:09 - 2012-09-23 08:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-08-24 02:04 - 2012-09-23 08:31 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-08-23 23:27 - 2012-09-23 08:31 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-08-23 23:03 - 2012-09-23 08:31 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-08-23 22:59 - 2012-09-23 08:31 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-08-23 22:51 - 2012-09-23 08:31 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-08-23 22:51 - 2012-09-23 08:31 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-08-23 22:51 - 2012-09-23 08:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-08-23 22:49 - 2012-09-23 08:31 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-08-23 22:48 - 2012-09-23 08:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-08-23 22:47 - 2012-09-23 08:31 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-08-23 22:47 - 2012-09-23 08:31 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2012-08-23 22:47 - 2012-09-23 08:31 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-08-23 22:45 - 2012-09-23 08:31 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2012-08-23 22:44 - 2012-09-23 08:31 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-08-23 22:44 - 2012-09-23 08:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-08-23 22:43 - 2012-09-23 08:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-08-23 22:40 - 2012-09-23 08:31 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-08-22 20:08 - 2012-08-22 20:07 - 06149120 ____A C:\Users\Jceee\Downloads\FontPack1000_ko_KR.msi
    2012-08-22 10:12 - 2012-09-11 20:21 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
    2012-08-22 10:12 - 2012-09-11 20:21 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
    2012-08-22 10:12 - 2012-09-11 20:21 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
    2012-08-22 10:12 - 2012-09-11 20:21 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
    2012-08-21 13:01 - 2012-09-25 14:44 - 00245760 ____A (Microsoft Corporation) C:\Windows\System32\OxpsConverter.exe
    2012-08-21 12:01 - 2012-09-23 08:46 - 00033240 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
    2012-08-21 12:01 - 2012-01-24 21:07 - 00125872 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi64.dll
    2012-08-21 12:01 - 2012-01-24 21:07 - 00106928 ____A (GEAR Software Inc.) C:\Windows\SysWOW64\GEARAspi.dll
    2012-08-20 21:56 - 2012-08-20 21:55 - 00278704 ____A C:\Users\Jceee\Downloads\One Direction - What Makes You Beautiful (Lyric Video).mp3.sfk
    2012-08-20 21:55 - 2012-08-20 21:54 - 00250552 ____A C:\Users\Jceee\Downloads\Adventure Club ft. Krewella - Rise & Fall.mp3.sfk
    2012-08-20 21:53 - 2012-08-20 21:52 - 00149344 ____A C:\Users\Jceee\Downloads\Natalia Kills - Wonderland ( with lyrics ).mp3.sfk
    2012-08-20 21:43 - 2012-08-20 21:43 - 00148152 ____A C:\Users\Jceee\Downloads\2NE1 - HATE YOU M_V.mp3.sfk
    2012-08-20 14:27 - 2009-07-13 20:45 - 00367104 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-08-19 18:16 - 2012-01-23 21:57 - 00099000 ____A C:\Users\Jceee\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-08-19 16:55 - 2012-08-19 16:57 - 00016933 ____A C:\Users\Jceee\Downloads\zodiac_hellron.zip
    2012-08-09 19:43 - 2012-08-09 19:43 - 00001302 ____A C:\Users\Public\Desktop\Fa├žade.lnk
    2012-08-09 19:40 - 2012-08-09 19:40 - 00001239 ____A C:\Users\Public\Desktop\Minecraft Note Block Studio.lnk
    2012-08-09 19:39 - 2012-08-09 19:39 - 03769361 ____A (David Norgren ) C:\Users\Jceee\Downloads\mcnbs_setup.exe
    2012-08-09 17:22 - 2012-08-09 16:57 - 175523943 ____A (Procedural Arts) C:\Users\Jceee\Downloads\FacadeInstaller1.1b.exe
    2012-08-07 01:09 - 2012-08-07 01:09 - 00001164 ____A C:\Users\Public\Desktop\1776-Kanji.lnk
    2012-08-07 01:09 - 2012-08-07 01:08 - 03827143 ____A (1776kanji.com ) C:\Users\Jceee\Downloads\1776KanjiSetup.exe
    2012-08-06 19:20 - 2012-08-06 19:20 - 02401888 ____A (Conduit) C:\Users\Jceee\Downloads\Swag_Bucks.exe
    2012-08-05 11:45 - 2012-08-05 11:40 - 01981138 ____A C:\Users\Jceee\Downloads\Minecraft_Server (1).exe
    2012-08-03 00:27 - 2012-08-03 00:27 - 01624358 ____A C:\Users\Jceee\Downloads\mcpatcher-2.4.1_01.exe
    2012-08-03 00:16 - 2012-08-03 00:17 - 00051748 ____A C:\Users\Jceee\Downloads\TooManyItems2012_08_01_1.3.1.zip
    2012-08-02 09:58 - 2012-09-11 20:21 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
    2012-08-02 08:57 - 2012-09-11 20:21 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
    2012-08-02 00:56 - 2012-06-17 15:36 - 00000000 ____A C:\Windows\ka.ini
    2012-08-01 13:58 - 2012-08-01 13:58 - 00145000 ____A C:\Users\Jceee\Downloads\Anarbor - You and I (Official Music Video).mp3.sfk
    2012-07-30 22:21 - 2012-07-30 22:21 - 00269548 ____A C:\Users\Jceee\Downloads\My_Sims_176x208.zip
    2012-07-30 21:57 - 2012-07-30 21:57 - 00014418 ____A C:\Users\Jceee\Downloads\MySims.PC-FULL.rar.torrent
    2012-07-30 14:40 - 2012-07-23 11:51 - 00002094 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
    2012-07-30 14:38 - 2009-07-13 21:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-07-28 14:21 - 2010-11-20 19:47 - 00312160 ____A C:\Windows\PFRO.log
    2012-07-27 13:12 - 2012-07-27 12:08 - 819101929 ____A (Procedural Arts) C:\Users\Jceee\Downloads\FacadeInstaller.exe
    2012-07-27 11:36 - 2012-07-27 11:36 - 00000949 ____A C:\Users\Kristen\Desktop\ABC.lnk
    2012-07-27 11:36 - 2012-07-27 11:36 - 00000949 ____A C:\Users\Guest\Desktop\ABC.lnk
    2012-07-27 11:36 - 2012-07-27 11:35 - 03791729 ____A C:\Users\Jceee\Downloads\ABC-win32-v3.0.1b.exe
    2012-07-27 10:24 - 2012-07-27 10:23 - 07058987 ____A C:\Users\Jceee\Documents\WesterosCraft 26 July 2012.zip
    2012-07-27 10:24 - 2012-07-27 10:22 - 09190938 ____A C:\Users\Jceee\Documents\kingslanding.rar
    2012-07-27 10:22 - 2012-07-27 10:22 - 02148363 ____A C:\Users\Jceee\Documents\winterfell.rar
    2012-07-26 22:20 - 2012-05-17 16:50 - 00001400 ____A C:\Windows\SysWOW64\debug.log
    2012-07-23 11:50 - 2012-07-23 11:50 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
    2012-07-22 18:24 - 2012-07-22 18:24 - 00004504 ____A C:\Users\Jceee\Downloads\Death Chest.zip
    2012-07-22 17:53 - 2012-07-22 17:53 - 00273452 ____A C:\Users\Jceee\Downloads\littleMaidMob-1_2_5-5c.zip
    2012-07-22 17:52 - 2012-07-22 17:52 - 00064555 ____A C:\Users\Jceee\Downloads\MC 1.2.5 - Player API server 1.3.zip
    2012-07-22 17:50 - 2012-07-22 17:51 - 00004050 ____A C:\Users\Jceee\Downloads\CreativeAPI_1.2.5.zip
    2012-07-22 17:49 - 2012-07-22 17:49 - 00046737 ____A C:\Users\Jceee\Downloads\AudioMod.zip
    2012-07-22 17:47 - 2012-07-22 17:47 - 00103347 ____A C:\Users\Jceee\Downloads\ModLoader.zip
    2012-07-21 15:55 - 2012-07-21 15:55 - 01560685 ____A C:\Users\Jceee\Downloads\Defend The House.zip
    2012-07-18 10:15 - 2012-08-15 15:23 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

    ==================== Known DLLs (Whitelisted) =================


    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================


    ==================== Memory info ===========================

    Percentage of memory in use: 16%
    Total physical RAM: 3563.8 MB
    Available physical RAM: 2964.99 MB
    Total Pagefile: 3562 MB
    Available Pagefile: 2957.16 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB

    ==================== Partitions =============================

    1 Drive c: () (Fixed) (Total:179 GB) (Free:87.55 GB) NTFS
    2 Drive d: () (Fixed) (Total:267.1 GB) (Free:265.76 GB) NTFS
    3 Drive f: (SAMSUNG_REC) (Fixed) (Total:19.56 GB) (Free:0.94 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    5 Drive h: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
    6 Drive I: (JCEELETO) (Removable) (Total:3.74 GB) (Free:3.27 GB) FAT32
    7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    8 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 465 GB 1024 KB
    Disk 1 Online 3835 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 179 GB 101 MB
    Partition 0 Extended 267 GB 179 GB
    Partition 4 Logical 267 GB 179 GB
    Partition 3 Recovery 19 GB 446 GB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 Y SYSTEM NTFS Partition 100 MB Healthy

    =========================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 C NTFS Partition 179 GB Healthy

    =========================================================

    Disk: 0
    Partition 4
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 D NTFS Partition 267 GB Healthy

    =========================================================

    Disk: 0
    Partition 3
    Type : 27
    Hidden: Yes
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 F SAMSUNG_REC NTFS Partition 19 GB Healthy Hidden

    =========================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    * Partition 1 Primary 3835 MB 0 B

    ==================================================================================

    Disk: 1
    There is no partition selected.

    There is no partition selected.
    Please select a partition and try again.

    =========================================================

    Last Boot: 2012-10-06 22:00

    ==================== End Of Log =============================

    Attached Files:

  2. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Welcome aboard [​IMG]

    Actually I don't see anything malicious.

    I suggest you start new topic in Windows forum.
  3. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Welcome aboard [​IMG]

    Actually I don't see anything malicious.

    I suggest you start new topic in Windows forum.
  4. KristenLeto

    KristenLeto Newcomer, in training Topic Starter

    Did I post this in the wrong thread? :-O if so sorry!!!
    But I still have no idea what's wrong with my computer.
  5. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    You didn't do anything wrong.
    You wanted to see if your problem is possibly caused by some kind of infection but....


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.