MattRounseville
Posts: 29 +0
Windows Vista_32
Thank you for all your help on this. If you ever have questions about a 1983 Toyota Land Cruiser FJ60 I can probably help you. As you can see I have the same problems as many others. I have run the Kapersky 10 rescue fix which found and cleaned several Trojans and Virus but ultimately did not solve the problems. I hope I am doing this right. Here are the Scan data I believe you will need. I am now working from my sons computer since mine is the disabled one.
Thank you for any help you can provide.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 05-08-2012 01
Ran by SYSTEM at 06-08-2012 21:06:11
Running from D:\
Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [PMX Daemon] ICO.EXE [x]
HKLM\...\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM\...\Run: [] [x]
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [137752 2011-02-11] (Intel Corporation)
HKLM\...\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter [206064 2008-10-04] (SupportSoft, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-10-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [935288 2009-09-04] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Matthew\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Matthew\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Matthew\...\Policies\system: [LogonHoursAction] 2
HKU\Matthew\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Matthew\...\Policies\system: [DisableLockWorkstation] 1
HKU\Sage\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Sage\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Sage\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Sage\...\Policies\system: [LogonHoursAction] 2
HKU\Sage\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Skye\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Skye\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Skye\...\Run: [Logitech Vid HD] "C:\Program Files\Logitech\Vid\vid.exe" -bootmode [x]
HKU\Skye\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Skye\...\Policies\system: [LogonHoursAction] 2
HKU\Skye\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Sylvie\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Sylvie\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Sylvie\...\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode [x]
HKU\Sylvie\...\Run: [Google Update] "C:\Users\Sylvie\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-04-15] (Google Inc.)
HKU\Sylvie\...\Run: [Akamai NetSession Interface] "C:\Users\Sylvie\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\Sylvie\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Sylvie\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Sylvie\...\Run: [fervi] rundll32.exe "C:\Users\Sylvie\AppData\Roaming\fervi.dll",StripCRLF [x]
HKU\Sylvie\...\Policies\system: [LogonHoursAction] 2
HKU\Sylvie\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM\...\Winlogon: [Userinit] userinit.exe, [x]
Winlogon\Notify\AutorunsDisabled:
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Matthew\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Sage\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sage\Start Menu\Programs\Startup\IMVU.lnk
ShortcutTarget: IMVU.lnk -> (No File)
Startup: C:\Users\Skye\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sylvie\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sylvie\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 AdobeActiveFileMonitor8.0; C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-10-09] (Adobe Systems Incorporated)
4 AERTFilters; C:\Windows\System32\AERTSrv.exe [73728 2008-07-18] (Andrea Electronics Corporation)
4 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-09-23] (Stardock Corporation)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-20] (Microsoft Corporation)
4 GoogleDesktopManager-092308-165331; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2009-01-19] (Google)
4 GoToAssist; "C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe" Start=service [16936 2009-03-02] (Citrix Online, a division of Citrix Systems, Inc.)
3 QAH; C:\Users\Matthew\AppData\Local\Temp\QAH.exe [449408 2011-12-31] (Sysinternals - www.sysinternals.com)
3 QGXGMK; C:\Users\Matthew\AppData\Local\Temp\QGXGMK.exe [502656 2011-12-31] (Sysinternals - www.sysinternals.com)
2 ScsiAccess; C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe [186760 2010-06-01] ()
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
2 sprtsvc_DellSupportCenter; "C:\Program Files\Dell Support Center\bin\sprtsvc.exe" /service /P DellSupportCenter [201968 2008-10-04] (SupportSoft, Inc.)
3 TIWIA; C:\Users\Matthew\AppData\Local\Temp\TIWIA.exe [535424 2011-12-31] (Sysinternals - www.sysinternals.com)
2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2011-08-19] (Logitech Inc.)
2 Akamai; c:\program files\common files\akamai/netsession_win_4f7fccd.dll [x]
2 hnmsvc; "c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe" [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 MSSQL$MSSMLBIZ; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
========================== Drivers (Whitelisted) =============
3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
3 IntcHdmiAddService; C:\Windows\System32\drivers\IntcHdmi.sys [112128 2008-07-17] (Intel(R) Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-06] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MTDVC2; C:\Windows\System32\DRIVERS\mtdv2ku2.sys [12288 2003-10-15] (Matsushita Electric Industrial Co., Ltd.)
3 MTDVC2_ENUM; C:\Windows\System32\DRIVERS\mtdv2ks2.sys [11648 2003-10-11] (Matsushita Electric Industrial Co., Ltd.)
2 Packet; C:\Windows\System32\DRIVERS\packet.sys [22016 2008-06-17] (SingleClick Systems)
2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2008-07-21] (Windows (R) Codename Longhorn DDK provider)
3 USBCCID; C:\Windows\System32\DRIVERS\Rts5161ccid.sys [40960 2008-03-18] (Realtek Semiconductor Corporation)
4 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x]
3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
4 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 LVRS; C:\Windows\System32\DRIVERS\lvrs.sys [x]
4 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
4 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 Ser2pl; C:\Windows\System32\DRIVERS\ser2pl.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 21:02 - 2012-08-06 21:02 - 00000000 ____D C:\FRST
2012-08-06 11:44 - 2012-08-06 11:44 - 00000066 ____A C:\Users\Sylvie\Documents\.directory
2012-08-06 10:38 - 2012-08-06 10:38 - 03503224 ____A (McAfee, Inc.) C:\Program Files\SecurityScan_Release.exe
2012-08-06 06:06 - 2012-08-06 06:07 - 00000728 ____A C:\Users\Matthew\Desktop\shutdown.lnk
2012-08-05 23:39 - 2012-08-05 23:39 - 00000075 ____A C:\Users\Sylvie\Downloads\.directory
2012-08-05 23:35 - 2012-08-05 23:37 - 141823280 ____A C:\Users\Sylvie\Downloads\setup_11.0.0.1245.x01_2012_08_06_17_10.exe
2012-08-05 15:25 - 2012-08-05 15:26 - 00000728 ____A C:\Users\Sylvie\Desktop\shutdown.lnk
2012-08-05 14:45 - 2012-08-05 14:45 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\qimbvnag.sys
2012-08-05 14:04 - 2012-08-06 06:01 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-05 11:30 - 2012-08-05 11:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-05 11:29 - 2012-08-05 11:29 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(2).exe
2012-08-05 10:55 - 2012-08-05 10:55 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 10:45 - 2012-08-05 10:45 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(1).exe
2012-08-05 10:41 - 2012-08-05 10:41 - 00985600 ____A C:\Users\Matthew\Downloads\MicrosoftFixit50123.msi
2012-08-05 10:01 - 2012-08-05 11:20 - 00000000 ____D C:\Users\All Users\036DFF61031A59BCC8DD8DBA2F3B707C
2012-08-05 09:59 - 2012-08-05 09:59 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(3).zip
2012-08-05 09:04 - 2012-08-05 09:05 - 00000000 ____D C:\Users\Sylvie\AppData\Roaming\.minecraft
2012-08-05 09:03 - 2012-08-05 09:03 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.5-20120331.zip
2012-08-05 09:02 - 2012-08-05 09:02 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(2).zip
2012-08-05 08:57 - 2012-08-05 08:57 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(1).zip
2012-08-05 08:54 - 2012-08-05 08:54 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.4-20120327.zip
2012-08-05 08:53 - 2012-08-05 08:53 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader.zip
2012-08-04 16:58 - 2012-08-04 16:58 - 00022958 ____A C:\Users\Matthew\Desktop\120802 mpr Hip Hop.xlsx
2012-08-04 16:58 - 2012-08-04 16:58 - 00000165 ___AH C:\Users\Matthew\Desktop\~$120802 mpr Hip Hop.xlsx
2012-08-02 16:50 - 2012-08-02 20:10 - 00000000 ____D C:\Users\Sylvie\Desktop\world
2012-08-01 11:27 - 2012-08-01 13:38 - 00000000 ____D C:\Users\Sylvie\Desktop\movie set
2012-08-01 10:15 - 2012-08-04 14:56 - 00000000 ____D C:\Users\Sylvie\Desktop\Minecraft Server
2012-08-01 07:21 - 2012-08-01 07:21 - 00029751 ____A C:\Users\Sylvie\Downloads\Attachments_2012_08_1.zip
2012-07-31 09:23 - 2012-08-01 11:25 - 08667074 ____A C:\Users\Sylvie\Desktop\movie set.zip
2012-07-29 09:32 - 2012-07-29 09:32 - 00001666 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-29 09:30 - 2012-07-29 09:32 - 00000000 ____D C:\Program Files\iTunes
2012-07-29 09:30 - 2012-07-29 09:30 - 00000000 ____D C:\Program Files\iPod
2012-07-29 09:22 - 2012-07-29 09:23 - 77251480 ____A (Apple Inc.) C:\Users\Matthew\Downloads\iTunesSetup.exe
2012-07-25 16:43 - 2012-07-25 16:43 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25(1).zip
2012-07-25 09:03 - 2012-07-25 09:03 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25.zip
2012-07-23 13:42 - 2012-07-29 07:29 - 00000068 ____A C:\Users\Sylvie\Desktop\nexon reciept.txt
2012-07-18 06:18 - 2012-08-06 06:03 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-12 02:07 - 2012-06-13 05:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 06:37 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 06:37 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 06:37 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 06:37 - 2012-06-04 07:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 06:37 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 06:37 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-09 18:59 - 2012-07-09 18:59 - 00051131 ____A C:\Users\Sylvie\Downloads\TooManyItems2012_04_13_1.2.5.zip
============ 3 Months Modified Files ========================
2012-08-06 18:01 - 2011-08-03 11:23 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-06 18:01 - 2009-01-19 10:07 - 00000276 ____A C:\Windows\Tasks\RtlNICDiagVistaStart.job
2012-08-06 18:01 - 2006-11-02 05:01 - 00032544 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-06 18:01 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 18:01 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 18:01 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 17:57 - 2009-08-11 06:51 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-06 17:44 - 2011-04-15 09:06 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2676501248-3947168053-2482511801-1004UA.job
2012-08-06 11:44 - 2012-08-06 11:44 - 00000066 ____A C:\Users\Sylvie\Documents\.directory
2012-08-06 10:38 - 2012-08-06 10:38 - 03503224 ____A (McAfee, Inc.) C:\Program Files\SecurityScan_Release.exe
2012-08-06 06:07 - 2012-08-06 06:06 - 00000728 ____A C:\Users\Matthew\Desktop\shutdown.lnk
2012-08-06 06:03 - 2012-07-18 06:18 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-06 06:01 - 2012-08-05 14:04 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-05 23:39 - 2012-08-05 23:39 - 00000075 ____A C:\Users\Sylvie\Downloads\.directory
2012-08-05 23:37 - 2012-08-05 23:35 - 141823280 ____A C:\Users\Sylvie\Downloads\setup_11.0.0.1245.x01_2012_08_06_17_10.exe
2012-08-05 16:33 - 2011-12-29 17:26 - 00003638 ____A C:\Windows\setupact.log
2012-08-05 15:26 - 2012-08-05 15:25 - 00000728 ____A C:\Users\Sylvie\Desktop\shutdown.lnk
2012-08-05 14:45 - 2012-08-05 14:45 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\qimbvnag.sys
2012-08-05 13:33 - 2011-12-28 16:37 - 00050428 ____A C:\Windows\PFRO.log
2012-08-05 11:31 - 2011-12-30 14:24 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 11:31 - 2009-01-19 03:55 - 01112389 ____A C:\Windows\WindowsUpdate.log
2012-08-05 11:29 - 2012-08-05 11:29 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(2).exe
2012-08-05 11:00 - 2011-08-03 11:23 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-05 10:55 - 2012-08-05 10:55 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 10:45 - 2012-08-05 10:45 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(1).exe
2012-08-05 10:41 - 2012-08-05 10:41 - 00985600 ____A C:\Users\Matthew\Downloads\MicrosoftFixit50123.msi
2012-08-05 10:01 - 2009-03-20 20:38 - 00000437 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2012-08-05 09:59 - 2012-08-05 09:59 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(3).zip
2012-08-05 09:03 - 2012-08-05 09:03 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.5-20120331.zip
2012-08-05 09:02 - 2012-08-05 09:02 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(2).zip
2012-08-05 08:57 - 2012-08-05 08:57 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(1).zip
2012-08-05 08:54 - 2012-08-05 08:54 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.4-20120327.zip
2012-08-05 08:53 - 2012-08-05 08:53 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader.zip
2012-08-04 16:58 - 2012-08-04 16:58 - 00022958 ____A C:\Users\Matthew\Desktop\120802 mpr Hip Hop.xlsx
2012-08-04 16:58 - 2012-08-04 16:58 - 00000165 ___AH C:\Users\Matthew\Desktop\~$120802 mpr Hip Hop.xlsx
2012-08-04 16:44 - 2011-04-15 09:06 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2676501248-3947168053-2482511801-1004Core.job
2012-08-03 08:55 - 2012-06-26 06:00 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 08:55 - 2011-06-20 18:37 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-01 11:25 - 2012-07-31 09:23 - 08667074 ____A C:\Users\Sylvie\Desktop\movie set.zip
2012-08-01 07:21 - 2012-08-01 07:21 - 00029751 ____A C:\Users\Sylvie\Downloads\Attachments_2012_08_1.zip
2012-07-29 09:32 - 2012-07-29 09:32 - 00001666 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-29 09:23 - 2012-07-29 09:22 - 77251480 ____A (Apple Inc.) C:\Users\Matthew\Downloads\iTunesSetup.exe
2012-07-29 07:29 - 2012-07-23 13:42 - 00000068 ____A C:\Users\Sylvie\Desktop\nexon reciept.txt
2012-07-25 16:43 - 2012-07-25 16:43 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25(1).zip
2012-07-25 09:03 - 2012-07-25 09:03 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25.zip
2012-07-23 15:26 - 2012-06-05 18:07 - 00002377 ____A C:\Users\Sylvie\Desktop\Skype.lnk
2012-07-17 19:45 - 2009-03-02 22:17 - 00001356 ____A C:\Users\Sylvie\AppData\Local\d3d9caps.dat
2012-07-12 02:26 - 2006-11-02 04:47 - 00385728 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 02:06 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
2012-07-12 02:02 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-09 18:59 - 2012-07-09 18:59 - 00051131 ____A C:\Users\Sylvie\Downloads\TooManyItems2012_04_13_1.2.5.zip
2012-07-03 18:43 - 2012-06-23 10:42 - 00000134 ____A C:\Users\Sylvie\Desktop\New Text Document.txt
2012-07-03 12:46 - 2011-12-27 10:34 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 08:06 - 2012-07-02 08:06 - 00145531 ____A C:\Users\Sylvie\Downloads\SimpleSpleef(1).jar
2012-07-01 15:25 - 2012-07-01 15:25 - 01275098 ____A C:\Users\Sylvie\Downloads\Essentials-2.9.2(2).zip
2012-07-01 10:33 - 2012-07-01 10:33 - 00025251 ____A C:\Users\Sylvie\Downloads\World_Portal_0.2.4(1).zip
2012-07-01 10:02 - 2012-07-01 10:02 - 00025251 ____A C:\Users\Sylvie\Downloads\World_Portal_0.2.4.zip
2012-07-01 09:04 - 2012-07-01 09:04 - 01275098 ____A C:\Users\Sylvie\Downloads\Essentials-2.9.2(1).zip
2012-06-30 20:01 - 2012-06-30 20:01 - 00014038 ____A C:\Users\Sylvie\Downloads\hs_err_pid1496.log
2012-06-30 18:53 - 2012-06-30 18:53 - 00013933 ____A C:\Users\Sylvie\Downloads\hs_err_pid472.log
2012-06-30 17:35 - 2012-06-30 17:35 - 01275098 ____A C:\Users\Sylvie\Downloads\Essentials-2.9.2.zip
2012-06-30 17:35 - 2012-06-30 17:35 - 00116645 ____A C:\Users\Sylvie\Downloads\Essentials-gm-2.9.2(1).zip
2012-06-29 19:59 - 2012-06-29 19:59 - 00116645 ____A C:\Users\Sylvie\Downloads\Essentials-gm-2.9.2.zip
2012-06-29 19:50 - 2012-06-29 19:50 - 00000866 ____A C:\Users\Sylvie\Desktop\Notepad++.lnk
2012-06-29 19:50 - 2012-06-29 19:50 - 00000866 ____A C:\Users\Skye\Desktop\Notepad++.lnk
2012-06-29 19:50 - 2012-06-29 19:50 - 00000866 ____A C:\Users\Matthew\Desktop\Notepad++.lnk
2012-06-29 19:50 - 2012-02-23 11:01 - 00000866 ____A C:\Users\Sage\Desktop\Notepad++.lnk
2012-06-29 19:49 - 2012-06-29 19:49 - 05808917 ____A C:\Users\Sylvie\Downloads\npp.6.1.4.Installer.exe
2012-06-24 16:26 - 2012-06-24 11:16 - 08688607 ____A C:\Users\Sylvie\Desktop\The Survival Games 2.zip
2012-06-22 22:07 - 2012-06-22 22:06 - 22259528 ____A C:\Users\Matthew\Downloads\vlc-2.0.1-win32.exe
2012-06-22 22:01 - 2012-06-23 08:58 - 13055187 ____A C:\Users\Sylvie\Desktop\TSDC 2012 Jack and Jill Sylvia and Matt.flv
2012-06-22 22:01 - 2012-06-22 22:00 - 13055187 ____A C:\Users\Matthew\Desktop\TSDC 2012 Jack and Jill Sylvia and Matt.flv
2012-06-22 18:41 - 2012-06-22 18:41 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-06-22 18:41 - 2012-06-22 18:41 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-06-22 18:41 - 2012-06-22 18:41 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-06-22 18:41 - 2012-06-22 18:41 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-06-22 18:41 - 2011-11-11 17:37 - 00472840 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-06-20 05:13 - 2009-03-02 21:44 - 00104056 ____A C:\Users\Sylvie\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-19 20:48 - 2011-03-30 19:58 - 00104056 ____A C:\Users\Matthew\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-19 11:02 - 2012-06-19 11:01 - 00000717 ____A C:\Users\Sylvie\Desktop\SinglePlayerCommands-MC1.2.5_V3.2.2.lnk
2012-06-19 11:01 - 2012-06-19 11:01 - 00999771 ____A C:\Users\Sylvie\Downloads\SinglePlayerCommands-MC1.2.5_V3.2.2.jar
2012-06-19 04:56 - 2012-05-08 18:54 - 00002251 ____A C:\Users\Sylvie\Documents\mcedit.ini
2012-06-18 15:51 - 2012-06-18 15:51 - 38686311 ____A C:\Users\Sylvie\Downloads\Goddess of Decay V4.2.zip
2012-06-18 09:59 - 2012-06-18 09:59 - 00042301 ____A C:\Users\Sylvie\Downloads\X-RayMod_v024_WithFly.rar
2012-06-13 05:40 - 2012-07-12 02:07 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 07:59 - 2009-09-22 10:45 - 00093696 ____A C:\Users\Sylvie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-08 09:47 - 2012-07-11 06:37 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-06 19:58 - 2012-04-09 20:04 - 00000968 ____A C:\Users\Matthew\Desktop\Dropbox.lnk
2012-06-06 13:29 - 2012-06-06 13:29 - 02354015 ____A C:\Users\Sylvie\Desktop\4 Pillar Survival v1.1.zip
2012-06-05 20:58 - 2012-06-05 20:57 - 15267728 ____A (Google Inc.) C:\Users\Matthew\Downloads\picasa39-setup.exe
2012-06-05 08:47 - 2012-07-11 06:37 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-11 06:37 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 14:47 - 2009-03-03 18:58 - 00102040 ____A C:\Users\Skye\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-04 14:09 - 2012-06-04 14:09 - 00278561 ____A C:\Users\Skye\Downloads\Minecraft(1).exe
2012-06-04 14:08 - 2012-06-04 14:08 - 00278561 ____A C:\Users\Skye\Desktop\Minecraft.exe
2012-06-04 14:05 - 2012-06-04 14:05 - 00000104 ____A C:\Users\Skye\Desktop\Mozilla FireFox.lnk
2012-06-04 07:26 - 2012-07-11 06:37 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-18 16:00 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 16:00 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 16:00 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 15:59 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 15:59 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-18 15:59 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 16:00 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 15:59 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-18 15:59 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 16:04 - 2012-07-11 06:37 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-11 06:37 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-29 16:34 - 2012-05-29 16:33 - 29262633 ____A C:\Users\Sylvie\Desktop\The Survival Game V.1.4.zip
2012-05-26 11:45 - 2012-06-23 05:07 - 00010478 ____A C:\Users\Sylvie\Documents\New York DC Trip summer 2012.xlsx
2012-05-25 17:07 - 2012-04-29 09:45 - 00000965 ____A C:\Users\Sylvie\Desktop\Dropbox.lnk
2012-05-24 13:18 - 2012-05-24 13:18 - 04472832 ____A (Google Inc.) C:\Windows\System32\GPhotos.scr
2012-05-22 06:27 - 2012-05-22 06:27 - 00050616 ____A C:\Users\Sylvie\Downloads\SDD Report Outline - version 2
2012-05-15 14:04 - 2012-06-18 05:05 - 00834048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-15 14:02 - 2012-06-18 05:05 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
ZeroAccess:
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\@
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\U
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L\00000004.@
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L\201d3dde
ZeroAccess:
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\@
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe C5488EA6408AD0C3CC3E3CB876CBBED4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 4060.26 MB
Available physical RAM: 3678.52 MB
Total Pagefile: 3927.57 MB
Available Pagefile: 3765.75 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.31 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:450.71 GB) (Free:76.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Removable) (Total:0.49 GB) (Free:0.2 GB) FAT
4 Drive x: (RECOVERY) (Fixed) (Total:15 GB) (Free:2.82 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 466 GB 0 B
Disk 1 Online 501 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 32 KB
Partition 2 Primary 15 GB 48 MB
Partition 3 Primary 451 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 15 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 501 MB 0 B
==================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-08-05 12:55
======================= End Of Log ==========================
Thank you for all your help on this. If you ever have questions about a 1983 Toyota Land Cruiser FJ60 I can probably help you. As you can see I have the same problems as many others. I have run the Kapersky 10 rescue fix which found and cleaned several Trojans and Virus but ultimately did not solve the problems. I hope I am doing this right. Here are the Scan data I believe you will need. I am now working from my sons computer since mine is the disabled one.
Thank you for any help you can provide.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 05-08-2012 01
Ran by SYSTEM at 06-08-2012 21:06:11
Running from D:\
Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [PMX Daemon] ICO.EXE [x]
HKLM\...\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM\...\Run: [] [x]
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [137752 2011-02-11] (Intel Corporation)
HKLM\...\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter [206064 2008-10-04] (SupportSoft, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-10-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [935288 2009-09-04] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Matthew\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Matthew\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Matthew\...\Policies\system: [LogonHoursAction] 2
HKU\Matthew\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Matthew\...\Policies\system: [DisableLockWorkstation] 1
HKU\Sage\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Sage\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Sage\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Sage\...\Policies\system: [LogonHoursAction] 2
HKU\Sage\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Skye\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Skye\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Skye\...\Run: [Logitech Vid HD] "C:\Program Files\Logitech\Vid\vid.exe" -bootmode [x]
HKU\Skye\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Skye\...\Policies\system: [LogonHoursAction] 2
HKU\Skye\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Sylvie\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Sylvie\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Sylvie\...\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode [x]
HKU\Sylvie\...\Run: [Google Update] "C:\Users\Sylvie\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-04-15] (Google Inc.)
HKU\Sylvie\...\Run: [Akamai NetSession Interface] "C:\Users\Sylvie\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\Sylvie\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Sylvie\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Sylvie\...\Run: [fervi] rundll32.exe "C:\Users\Sylvie\AppData\Roaming\fervi.dll",StripCRLF [x]
HKU\Sylvie\...\Policies\system: [LogonHoursAction] 2
HKU\Sylvie\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM\...\Winlogon: [Userinit] userinit.exe, [x]
Winlogon\Notify\AutorunsDisabled:
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Matthew\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Sage\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sage\Start Menu\Programs\Startup\IMVU.lnk
ShortcutTarget: IMVU.lnk -> (No File)
Startup: C:\Users\Skye\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sylvie\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sylvie\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 AdobeActiveFileMonitor8.0; C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-10-09] (Adobe Systems Incorporated)
4 AERTFilters; C:\Windows\System32\AERTSrv.exe [73728 2008-07-18] (Andrea Electronics Corporation)
4 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-09-23] (Stardock Corporation)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-20] (Microsoft Corporation)
4 GoogleDesktopManager-092308-165331; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2009-01-19] (Google)
4 GoToAssist; "C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe" Start=service [16936 2009-03-02] (Citrix Online, a division of Citrix Systems, Inc.)
3 QAH; C:\Users\Matthew\AppData\Local\Temp\QAH.exe [449408 2011-12-31] (Sysinternals - www.sysinternals.com)
3 QGXGMK; C:\Users\Matthew\AppData\Local\Temp\QGXGMK.exe [502656 2011-12-31] (Sysinternals - www.sysinternals.com)
2 ScsiAccess; C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe [186760 2010-06-01] ()
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
2 sprtsvc_DellSupportCenter; "C:\Program Files\Dell Support Center\bin\sprtsvc.exe" /service /P DellSupportCenter [201968 2008-10-04] (SupportSoft, Inc.)
3 TIWIA; C:\Users\Matthew\AppData\Local\Temp\TIWIA.exe [535424 2011-12-31] (Sysinternals - www.sysinternals.com)
2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2011-08-19] (Logitech Inc.)
2 Akamai; c:\program files\common files\akamai/netsession_win_4f7fccd.dll [x]
2 hnmsvc; "c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe" [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 MSSQL$MSSMLBIZ; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
========================== Drivers (Whitelisted) =============
3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
3 IntcHdmiAddService; C:\Windows\System32\drivers\IntcHdmi.sys [112128 2008-07-17] (Intel(R) Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-06] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MTDVC2; C:\Windows\System32\DRIVERS\mtdv2ku2.sys [12288 2003-10-15] (Matsushita Electric Industrial Co., Ltd.)
3 MTDVC2_ENUM; C:\Windows\System32\DRIVERS\mtdv2ks2.sys [11648 2003-10-11] (Matsushita Electric Industrial Co., Ltd.)
2 Packet; C:\Windows\System32\DRIVERS\packet.sys [22016 2008-06-17] (SingleClick Systems)
2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2008-07-21] (Windows (R) Codename Longhorn DDK provider)
3 USBCCID; C:\Windows\System32\DRIVERS\Rts5161ccid.sys [40960 2008-03-18] (Realtek Semiconductor Corporation)
4 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x]
3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
4 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 LVRS; C:\Windows\System32\DRIVERS\lvrs.sys [x]
4 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
4 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 Ser2pl; C:\Windows\System32\DRIVERS\ser2pl.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 21:02 - 2012-08-06 21:02 - 00000000 ____D C:\FRST
2012-08-06 11:44 - 2012-08-06 11:44 - 00000066 ____A C:\Users\Sylvie\Documents\.directory
2012-08-06 10:38 - 2012-08-06 10:38 - 03503224 ____A (McAfee, Inc.) C:\Program Files\SecurityScan_Release.exe
2012-08-06 06:06 - 2012-08-06 06:07 - 00000728 ____A C:\Users\Matthew\Desktop\shutdown.lnk
2012-08-05 23:39 - 2012-08-05 23:39 - 00000075 ____A C:\Users\Sylvie\Downloads\.directory
2012-08-05 23:35 - 2012-08-05 23:37 - 141823280 ____A C:\Users\Sylvie\Downloads\setup_11.0.0.1245.x01_2012_08_06_17_10.exe
2012-08-05 15:25 - 2012-08-05 15:26 - 00000728 ____A C:\Users\Sylvie\Desktop\shutdown.lnk
2012-08-05 14:45 - 2012-08-05 14:45 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\qimbvnag.sys
2012-08-05 14:04 - 2012-08-06 06:01 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-05 11:30 - 2012-08-05 11:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-05 11:29 - 2012-08-05 11:29 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(2).exe
2012-08-05 10:55 - 2012-08-05 10:55 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 10:45 - 2012-08-05 10:45 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(1).exe
2012-08-05 10:41 - 2012-08-05 10:41 - 00985600 ____A C:\Users\Matthew\Downloads\MicrosoftFixit50123.msi
2012-08-05 10:01 - 2012-08-05 11:20 - 00000000 ____D C:\Users\All Users\036DFF61031A59BCC8DD8DBA2F3B707C
2012-08-05 09:59 - 2012-08-05 09:59 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(3).zip
2012-08-05 09:04 - 2012-08-05 09:05 - 00000000 ____D C:\Users\Sylvie\AppData\Roaming\.minecraft
2012-08-05 09:03 - 2012-08-05 09:03 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.5-20120331.zip
2012-08-05 09:02 - 2012-08-05 09:02 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(2).zip
2012-08-05 08:57 - 2012-08-05 08:57 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(1).zip
2012-08-05 08:54 - 2012-08-05 08:54 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.4-20120327.zip
2012-08-05 08:53 - 2012-08-05 08:53 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader.zip
2012-08-04 16:58 - 2012-08-04 16:58 - 00022958 ____A C:\Users\Matthew\Desktop\120802 mpr Hip Hop.xlsx
2012-08-04 16:58 - 2012-08-04 16:58 - 00000165 ___AH C:\Users\Matthew\Desktop\~$120802 mpr Hip Hop.xlsx
2012-08-02 16:50 - 2012-08-02 20:10 - 00000000 ____D C:\Users\Sylvie\Desktop\world
2012-08-01 11:27 - 2012-08-01 13:38 - 00000000 ____D C:\Users\Sylvie\Desktop\movie set
2012-08-01 10:15 - 2012-08-04 14:56 - 00000000 ____D C:\Users\Sylvie\Desktop\Minecraft Server
2012-08-01 07:21 - 2012-08-01 07:21 - 00029751 ____A C:\Users\Sylvie\Downloads\Attachments_2012_08_1.zip
2012-07-31 09:23 - 2012-08-01 11:25 - 08667074 ____A C:\Users\Sylvie\Desktop\movie set.zip
2012-07-29 09:32 - 2012-07-29 09:32 - 00001666 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-29 09:30 - 2012-07-29 09:32 - 00000000 ____D C:\Program Files\iTunes
2012-07-29 09:30 - 2012-07-29 09:30 - 00000000 ____D C:\Program Files\iPod
2012-07-29 09:22 - 2012-07-29 09:23 - 77251480 ____A (Apple Inc.) C:\Users\Matthew\Downloads\iTunesSetup.exe
2012-07-25 16:43 - 2012-07-25 16:43 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25(1).zip
2012-07-25 09:03 - 2012-07-25 09:03 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25.zip
2012-07-23 13:42 - 2012-07-29 07:29 - 00000068 ____A C:\Users\Sylvie\Desktop\nexon reciept.txt
2012-07-18 06:18 - 2012-08-06 06:03 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-12 02:07 - 2012-06-13 05:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 06:37 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 06:37 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 06:37 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 06:37 - 2012-06-04 07:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 06:37 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 06:37 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-09 18:59 - 2012-07-09 18:59 - 00051131 ____A C:\Users\Sylvie\Downloads\TooManyItems2012_04_13_1.2.5.zip
============ 3 Months Modified Files ========================
2012-08-06 18:01 - 2011-08-03 11:23 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-06 18:01 - 2009-01-19 10:07 - 00000276 ____A C:\Windows\Tasks\RtlNICDiagVistaStart.job
2012-08-06 18:01 - 2006-11-02 05:01 - 00032544 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-06 18:01 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 18:01 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 18:01 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 17:57 - 2009-08-11 06:51 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-06 17:44 - 2011-04-15 09:06 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2676501248-3947168053-2482511801-1004UA.job
2012-08-06 11:44 - 2012-08-06 11:44 - 00000066 ____A C:\Users\Sylvie\Documents\.directory
2012-08-06 10:38 - 2012-08-06 10:38 - 03503224 ____A (McAfee, Inc.) C:\Program Files\SecurityScan_Release.exe
2012-08-06 06:07 - 2012-08-06 06:06 - 00000728 ____A C:\Users\Matthew\Desktop\shutdown.lnk
2012-08-06 06:03 - 2012-07-18 06:18 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-06 06:01 - 2012-08-05 14:04 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-05 23:39 - 2012-08-05 23:39 - 00000075 ____A C:\Users\Sylvie\Downloads\.directory
2012-08-05 23:37 - 2012-08-05 23:35 - 141823280 ____A C:\Users\Sylvie\Downloads\setup_11.0.0.1245.x01_2012_08_06_17_10.exe
2012-08-05 16:33 - 2011-12-29 17:26 - 00003638 ____A C:\Windows\setupact.log
2012-08-05 15:26 - 2012-08-05 15:25 - 00000728 ____A C:\Users\Sylvie\Desktop\shutdown.lnk
2012-08-05 14:45 - 2012-08-05 14:45 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\qimbvnag.sys
2012-08-05 13:33 - 2011-12-28 16:37 - 00050428 ____A C:\Windows\PFRO.log
2012-08-05 11:31 - 2011-12-30 14:24 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 11:31 - 2009-01-19 03:55 - 01112389 ____A C:\Windows\WindowsUpdate.log
2012-08-05 11:29 - 2012-08-05 11:29 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(2).exe
2012-08-05 11:00 - 2011-08-03 11:23 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-05 10:55 - 2012-08-05 10:55 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 10:45 - 2012-08-05 10:45 - 10288512 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\mseinstall(1).exe
2012-08-05 10:41 - 2012-08-05 10:41 - 00985600 ____A C:\Users\Matthew\Downloads\MicrosoftFixit50123.msi
2012-08-05 10:01 - 2009-03-20 20:38 - 00000437 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2012-08-05 09:59 - 2012-08-05 09:59 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(3).zip
2012-08-05 09:03 - 2012-08-05 09:03 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.5-20120331.zip
2012-08-05 09:02 - 2012-08-05 09:02 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(2).zip
2012-08-05 08:57 - 2012-08-05 08:57 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader(1).zip
2012-08-05 08:54 - 2012-08-05 08:54 - 00022214 ____A C:\Users\Sylvie\Downloads\parachute-1.2.4-20120327.zip
2012-08-05 08:53 - 2012-08-05 08:53 - 00170691 ____A C:\Users\Sylvie\Downloads\ModLoader.zip
2012-08-04 16:58 - 2012-08-04 16:58 - 00022958 ____A C:\Users\Matthew\Desktop\120802 mpr Hip Hop.xlsx
2012-08-04 16:58 - 2012-08-04 16:58 - 00000165 ___AH C:\Users\Matthew\Desktop\~$120802 mpr Hip Hop.xlsx
2012-08-04 16:44 - 2011-04-15 09:06 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2676501248-3947168053-2482511801-1004Core.job
2012-08-03 08:55 - 2012-06-26 06:00 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 08:55 - 2011-06-20 18:37 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-01 11:25 - 2012-07-31 09:23 - 08667074 ____A C:\Users\Sylvie\Desktop\movie set.zip
2012-08-01 07:21 - 2012-08-01 07:21 - 00029751 ____A C:\Users\Sylvie\Downloads\Attachments_2012_08_1.zip
2012-07-29 09:32 - 2012-07-29 09:32 - 00001666 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-29 09:23 - 2012-07-29 09:22 - 77251480 ____A (Apple Inc.) C:\Users\Matthew\Downloads\iTunesSetup.exe
2012-07-29 07:29 - 2012-07-23 13:42 - 00000068 ____A C:\Users\Sylvie\Desktop\nexon reciept.txt
2012-07-25 16:43 - 2012-07-25 16:43 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25(1).zip
2012-07-25 09:03 - 2012-07-25 09:03 - 01599758 ____A C:\Users\Sylvie\Downloads\Attachments_2012_07_25.zip
2012-07-23 15:26 - 2012-06-05 18:07 - 00002377 ____A C:\Users\Sylvie\Desktop\Skype.lnk
2012-07-17 19:45 - 2009-03-02 22:17 - 00001356 ____A C:\Users\Sylvie\AppData\Local\d3d9caps.dat
2012-07-12 02:26 - 2006-11-02 04:47 - 00385728 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 02:06 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
2012-07-12 02:02 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-09 18:59 - 2012-07-09 18:59 - 00051131 ____A C:\Users\Sylvie\Downloads\TooManyItems2012_04_13_1.2.5.zip
2012-07-03 18:43 - 2012-06-23 10:42 - 00000134 ____A C:\Users\Sylvie\Desktop\New Text Document.txt
2012-07-03 12:46 - 2011-12-27 10:34 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 08:06 - 2012-07-02 08:06 - 00145531 ____A C:\Users\Sylvie\Downloads\SimpleSpleef(1).jar
2012-07-01 15:25 - 2012-07-01 15:25 - 01275098 ____A C:\Users\Sylvie\Downloads\Essentials-2.9.2(2).zip
2012-07-01 10:33 - 2012-07-01 10:33 - 00025251 ____A C:\Users\Sylvie\Downloads\World_Portal_0.2.4(1).zip
2012-07-01 10:02 - 2012-07-01 10:02 - 00025251 ____A C:\Users\Sylvie\Downloads\World_Portal_0.2.4.zip
2012-07-01 09:04 - 2012-07-01 09:04 - 01275098 ____A C:\Users\Sylvie\Downloads\Essentials-2.9.2(1).zip
2012-06-30 20:01 - 2012-06-30 20:01 - 00014038 ____A C:\Users\Sylvie\Downloads\hs_err_pid1496.log
2012-06-30 18:53 - 2012-06-30 18:53 - 00013933 ____A C:\Users\Sylvie\Downloads\hs_err_pid472.log
2012-06-30 17:35 - 2012-06-30 17:35 - 01275098 ____A C:\Users\Sylvie\Downloads\Essentials-2.9.2.zip
2012-06-30 17:35 - 2012-06-30 17:35 - 00116645 ____A C:\Users\Sylvie\Downloads\Essentials-gm-2.9.2(1).zip
2012-06-29 19:59 - 2012-06-29 19:59 - 00116645 ____A C:\Users\Sylvie\Downloads\Essentials-gm-2.9.2.zip
2012-06-29 19:50 - 2012-06-29 19:50 - 00000866 ____A C:\Users\Sylvie\Desktop\Notepad++.lnk
2012-06-29 19:50 - 2012-06-29 19:50 - 00000866 ____A C:\Users\Skye\Desktop\Notepad++.lnk
2012-06-29 19:50 - 2012-06-29 19:50 - 00000866 ____A C:\Users\Matthew\Desktop\Notepad++.lnk
2012-06-29 19:50 - 2012-02-23 11:01 - 00000866 ____A C:\Users\Sage\Desktop\Notepad++.lnk
2012-06-29 19:49 - 2012-06-29 19:49 - 05808917 ____A C:\Users\Sylvie\Downloads\npp.6.1.4.Installer.exe
2012-06-24 16:26 - 2012-06-24 11:16 - 08688607 ____A C:\Users\Sylvie\Desktop\The Survival Games 2.zip
2012-06-22 22:07 - 2012-06-22 22:06 - 22259528 ____A C:\Users\Matthew\Downloads\vlc-2.0.1-win32.exe
2012-06-22 22:01 - 2012-06-23 08:58 - 13055187 ____A C:\Users\Sylvie\Desktop\TSDC 2012 Jack and Jill Sylvia and Matt.flv
2012-06-22 22:01 - 2012-06-22 22:00 - 13055187 ____A C:\Users\Matthew\Desktop\TSDC 2012 Jack and Jill Sylvia and Matt.flv
2012-06-22 18:41 - 2012-06-22 18:41 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-06-22 18:41 - 2012-06-22 18:41 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-06-22 18:41 - 2012-06-22 18:41 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-06-22 18:41 - 2012-06-22 18:41 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-06-22 18:41 - 2011-11-11 17:37 - 00472840 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-06-20 05:13 - 2009-03-02 21:44 - 00104056 ____A C:\Users\Sylvie\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-19 20:48 - 2011-03-30 19:58 - 00104056 ____A C:\Users\Matthew\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-19 11:02 - 2012-06-19 11:01 - 00000717 ____A C:\Users\Sylvie\Desktop\SinglePlayerCommands-MC1.2.5_V3.2.2.lnk
2012-06-19 11:01 - 2012-06-19 11:01 - 00999771 ____A C:\Users\Sylvie\Downloads\SinglePlayerCommands-MC1.2.5_V3.2.2.jar
2012-06-19 04:56 - 2012-05-08 18:54 - 00002251 ____A C:\Users\Sylvie\Documents\mcedit.ini
2012-06-18 15:51 - 2012-06-18 15:51 - 38686311 ____A C:\Users\Sylvie\Downloads\Goddess of Decay V4.2.zip
2012-06-18 09:59 - 2012-06-18 09:59 - 00042301 ____A C:\Users\Sylvie\Downloads\X-RayMod_v024_WithFly.rar
2012-06-13 05:40 - 2012-07-12 02:07 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 07:59 - 2009-09-22 10:45 - 00093696 ____A C:\Users\Sylvie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-08 09:47 - 2012-07-11 06:37 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-06 19:58 - 2012-04-09 20:04 - 00000968 ____A C:\Users\Matthew\Desktop\Dropbox.lnk
2012-06-06 13:29 - 2012-06-06 13:29 - 02354015 ____A C:\Users\Sylvie\Desktop\4 Pillar Survival v1.1.zip
2012-06-05 20:58 - 2012-06-05 20:57 - 15267728 ____A (Google Inc.) C:\Users\Matthew\Downloads\picasa39-setup.exe
2012-06-05 08:47 - 2012-07-11 06:37 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-11 06:37 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 14:47 - 2009-03-03 18:58 - 00102040 ____A C:\Users\Skye\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-04 14:09 - 2012-06-04 14:09 - 00278561 ____A C:\Users\Skye\Downloads\Minecraft(1).exe
2012-06-04 14:08 - 2012-06-04 14:08 - 00278561 ____A C:\Users\Skye\Desktop\Minecraft.exe
2012-06-04 14:05 - 2012-06-04 14:05 - 00000104 ____A C:\Users\Skye\Desktop\Mozilla FireFox.lnk
2012-06-04 07:26 - 2012-07-11 06:37 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-18 16:00 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 16:00 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 16:00 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 15:59 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 15:59 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-18 15:59 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 16:00 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 15:59 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-18 15:59 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 16:04 - 2012-07-11 06:37 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-11 06:37 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-29 16:34 - 2012-05-29 16:33 - 29262633 ____A C:\Users\Sylvie\Desktop\The Survival Game V.1.4.zip
2012-05-26 11:45 - 2012-06-23 05:07 - 00010478 ____A C:\Users\Sylvie\Documents\New York DC Trip summer 2012.xlsx
2012-05-25 17:07 - 2012-04-29 09:45 - 00000965 ____A C:\Users\Sylvie\Desktop\Dropbox.lnk
2012-05-24 13:18 - 2012-05-24 13:18 - 04472832 ____A (Google Inc.) C:\Windows\System32\GPhotos.scr
2012-05-22 06:27 - 2012-05-22 06:27 - 00050616 ____A C:\Users\Sylvie\Downloads\SDD Report Outline - version 2
2012-05-15 14:04 - 2012-06-18 05:05 - 00834048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-15 14:02 - 2012-06-18 05:05 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
ZeroAccess:
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\@
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\U
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L\00000004.@
C:\Windows\Installer\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L\201d3dde
ZeroAccess:
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\@
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\L
C:\Users\Sylvie\AppData\Local\{2ecd8a28-aacc-4050-8b42-84617a28e4ae}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe C5488EA6408AD0C3CC3E3CB876CBBED4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 4060.26 MB
Available physical RAM: 3678.52 MB
Total Pagefile: 3927.57 MB
Available Pagefile: 3765.75 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.31 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:450.71 GB) (Free:76.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Removable) (Total:0.49 GB) (Free:0.2 GB) FAT
4 Drive x: (RECOVERY) (Fixed) (Total:15 GB) (Free:2.82 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 466 GB 0 B
Disk 1 Online 501 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 32 KB
Partition 2 Primary 15 GB 48 MB
Partition 3 Primary 451 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 15 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 501 MB 0 B
==================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-08-05 12:55
======================= End Of Log ==========================