Bob Appendown
Posts: 49 +0
Hi.
New to the forum and new to viruses and I wonder if anyone could help me please.
I'm running Win7 x64 and all of a sudden, my PC will not stay on. Either in Windows or Safe Mode, it always shuts down within a minute (With a warning when in windows). It will not stay on long enough for me to do anything but I can't see anything "Unusual" in the process list.
I've seen a similar post, so heve downloaded and run Farbar Recovery Scan Tool (frst64.exe) according to the instructions on that post and here is the log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-05-2013 01
Ran by SYSTEM on 23-05-2013 11:24:32
Running from L:\
Windows 7 Ultimate (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ACPW06EN] "C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe" /pid ACPW06EN [1231992 2012-08-31] (ACD Systems)
HKLM-x32\...\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [356376 2012-11-13] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [ACPW05EN] "C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe" /pid ACPW05EN [822384 2011-09-19] (ACD Systems)
HKLM-x32\...\Run: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKU\FRAZ\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" [267056 2011-10-08] (BitTorrent, Inc.)
HKU\FRAZ\...\Run: [EPSON Stylus Photo R220 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIAIA.EXE /FU "C:\Windows\TEMP\E_S6681.tmp" /EF "HKCU" [148 2012-12-16] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\iReboot 1.1.1.lnk
ShortcutTarget: iReboot 1.1.1.lnk -> C:\Program Files (x86)\NeoSmart Technologies\iReboot\iReboot.exe (NeoSmart Technologies)
==================== Services (Whitelisted) =================
S2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [891432 2009-09-12] (Acronis)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-09-15] ()
S2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2326920 2011-10-09] (Acronis)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2012-11-13] (Kaspersky Lab ZAO)
S2 BITS; C:\Windows\System32\qmgr.dll [848384 2009-07-13] ()
S2 BrowserProtect; C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2787280 2013-03-22] ()
S2 iReboot; C:\Program Files (x86)\NeoSmart Technologies\iReboot\iRebootd.exe [17408 2009-09-15] ()
S3 Macromedia Licensing Service; C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [68096 2012-09-15] ()
S2 PCLEPCI; C:\Windows\SysWOW64\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH)
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [60288 2009-07-13] (Microsoft Corporation)
S0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620128 2013-04-22] (Kaspersky Lab ZAO)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-09-17] (Kaspersky Lab)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-09-17] (Kaspersky Lab)
S1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55056 2013-04-22] (Kaspersky Lab ZAO)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-22] (Kaspersky Lab ZAO)
S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
S3 WimFltr; C:\Windows\SysWow64\DRIVERS\wimfltr.sys [128104 2006-11-01] (Microsoft Corporation)
S4 Gpstetexysm; No ImagePath
S0 snapman; system32\DRIVERS\snapman.sys [x]
S0 tdrpman251; system32\DRIVERS\tdrpm251.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-05-23 10:40 - 2013-05-23 10:40 - 00000000 ____D C:\FRST
2013-05-17 10:11 - 2013-05-17 10:11 - 00000000 __SHD C:\found.000
2013-05-16 05:21 - 2013-05-16 10:10 - 00000000 ____D C:\Users\FRAZ\Desktop\family photos spain
2013-05-14 22:28 - 2013-05-14 22:28 - 00300768 ____A C:\Windows\Minidump\051513-27908-01.dmp
2013-05-12 15:03 - 2013-05-12 15:04 - 00000000 ____D C:\Users\FRAZ\Desktop\Panasonic Camcorder photo test
2013-05-12 14:54 - 2013-05-12 14:55 - 00000000 ____D C:\Users\FRAZ\Desktop\FashionRingtones
2013-05-12 07:04 - 2013-05-12 07:04 - 00000952 ____A C:\Users\FRAZ\Desktop\HD Tune.lnk
2013-05-12 07:04 - 2013-05-12 07:04 - 00000000 ____D C:\Program Files (x86)\HD Tune
2013-05-11 03:29 - 2013-05-11 03:34 - 00000000 ____D C:\Users\FRAZ\Desktop\moby northern
2013-05-11 03:29 - 2013-05-03 14:58 - 09093237 ____N C:\Users\FRAZ\Desktop\20130503_235820.mp4
2013-05-11 03:29 - 2013-05-03 14:05 - 245591627 ____N C:\Users\FRAZ\Desktop\20130503_230306.mp4
2013-05-11 03:29 - 2013-05-03 14:02 - 71031828 ____N C:\Users\FRAZ\Desktop\20130503_230220.mp4
2013-05-11 01:16 - 2013-05-11 01:16 - 00000000 ___HD C:\Users\Public\[Originals]
2013-05-11 00:54 - 2013-05-11 00:54 - 00000000 ____D C:\Users\FRAZ\Documents\Adobe
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\Users\Public\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\ProgramData\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:36 - 2013-05-11 00:36 - 00000000 ____D C:\Users\FRAZ\Desktop\Adobe
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\Users\Public\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\ProgramData\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\YTD YouTube Downloader & Converter
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\Application Data\YTD YouTube Downloader & Converter
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\ProgramData\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\ProgramData\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\Application Data\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
==================== One Month Modified Files and Folders =======
2013-05-23 10:40 - 2013-05-23 10:40 - 00000000 ____D C:\FRST
2013-05-23 01:54 - 2011-10-09 00:44 - 00000000 ____D C:\Users\FRAZ\AppData\Local\ACD Systems
2013-05-23 01:50 - 2011-10-08 15:31 - 00000000 ____D C:\Users\FRAZ\Application Data\uTorrent
2013-05-23 01:50 - 2011-10-08 15:31 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\uTorrent
2013-05-23 01:49 - 2012-09-15 00:17 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-05-23 01:49 - 2012-09-15 00:17 - 00000000 ____D C:\ProgramData\Application Data\Kaspersky Lab
2013-05-23 01:48 - 2011-10-08 14:59 - 00000000 ____D C:\ProgramData\NVIDIA
2013-05-23 01:48 - 2011-10-08 14:59 - 00000000 ____D C:\ProgramData\Application Data\NVIDIA
2013-05-23 01:48 - 2009-07-13 21:08 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-05-23 01:48 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-23 01:48 - 2003-12-01 04:31 - 00070328 ____A C:\Windows\setupact.log
2013-05-17 10:30 - 2009-07-13 15:38 - 00129024 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\videoprt.sys
2013-05-17 10:28 - 2009-07-13 16:10 - 00845824 ____A (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-05-17 10:27 - 2009-07-13 15:28 - 01162240 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-05-17 10:25 - 2009-07-13 15:49 - 01065984 ____A (Microsoft Corporation) C:\Windows\System32\cryptui.dll
2013-05-17 10:14 - 2009-07-13 15:25 - 01898576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-05-17 10:13 - 2009-07-13 15:20 - 01659984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-05-17 10:11 - 2013-05-17 10:11 - 00000000 __SHD C:\found.000
2013-05-17 01:03 - 2011-10-08 13:41 - 02059676 ____A C:\Windows\WindowsUpdate.log
2013-05-17 00:57 - 2009-07-13 20:45 - 00015504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-05-17 00:57 - 2009-07-13 20:45 - 00015504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-05-17 00:47 - 2012-09-15 07:19 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-16 10:51 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports
2013-05-16 10:42 - 2011-10-08 15:03 - 00000000 ____D C:\Users\FRAZ\Application Data\Adobe
2013-05-16 10:42 - 2011-10-08 15:03 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\Adobe
2013-05-16 10:10 - 2013-05-16 05:21 - 00000000 ____D C:\Users\FRAZ\Desktop\family photos spain
2013-05-15 08:47 - 2012-09-15 07:19 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-15 08:47 - 2012-09-15 07:19 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-14 22:28 - 2013-05-14 22:28 - 00300768 ____A C:\Windows\Minidump\051513-27908-01.dmp
2013-05-14 22:28 - 2012-11-19 03:00 - 00000000 ____D C:\Windows\Minidump
2013-05-12 22:50 - 2009-07-13 21:13 - 00726316 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-12 15:04 - 2013-05-12 15:03 - 00000000 ____D C:\Users\FRAZ\Desktop\Panasonic Camcorder photo test
2013-05-12 14:55 - 2013-05-12 14:54 - 00000000 ____D C:\Users\FRAZ\Desktop\FashionRingtones
2013-05-12 07:04 - 2013-05-12 07:04 - 00000952 ____A C:\Users\FRAZ\Desktop\HD Tune.lnk
2013-05-12 07:04 - 2013-05-12 07:04 - 00000000 ____D C:\Program Files (x86)\HD Tune
2013-05-11 03:34 - 2013-05-11 03:29 - 00000000 ____D C:\Users\FRAZ\Desktop\moby northern
2013-05-11 01:16 - 2013-05-11 01:16 - 00000000 ___HD C:\Users\Public\[Originals]
2013-05-11 00:54 - 2013-05-11 00:54 - 00000000 ____D C:\Users\FRAZ\Documents\Adobe
2013-05-11 00:54 - 2011-10-09 03:54 - 00000000 ____D C:\Users\FRAZ\AppData\Local\Adobe
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\Users\Public\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\ProgramData\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:48 - 2011-10-09 03:59 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-05-11 00:48 - 2011-10-08 15:54 - 00000000 ____D C:\ProgramData\Application Data\Adobe
2013-05-11 00:48 - 2011-10-08 15:54 - 00000000 ____D C:\ProgramData\Adobe
2013-05-11 00:47 - 2011-10-09 04:00 - 00000000 ____D C:\Program Files\Adobe
2013-05-11 00:36 - 2013-05-11 00:36 - 00000000 ____D C:\Users\FRAZ\Desktop\Adobe
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\Users\Public\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\ProgramData\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\YTD YouTube Downloader & Converter
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\Application Data\YTD YouTube Downloader & Converter
2013-05-07 05:30 - 2011-10-09 00:37 - 00000000 ____D C:\Program Files (x86)\YouTube Downloader
2013-05-03 14:58 - 2013-05-11 03:29 - 09093237 ____N C:\Users\FRAZ\Desktop\20130503_235820.mp4
2013-05-03 14:05 - 2013-05-11 03:29 - 245591627 ____N C:\Users\FRAZ\Desktop\20130503_230306.mp4
2013-05-03 14:02 - 2013-05-11 03:29 - 71031828 ____N C:\Users\FRAZ\Desktop\20130503_230220.mp4
2013-04-30 21:51 - 2003-12-01 04:31 - 00030206 ____A C:\Windows\PFRO.log
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\ProgramData\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\ProgramData\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\Application Data\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-04-30 01:44 - 2011-10-09 06:29 - 00000000 ____D C:\Users\FRAZ\Documents\DVDVideoSoft
2013-04-30 01:22 - 2011-10-09 06:34 - 00000349 ____A C:\Users\Public\Documents\PCLECHAL.INI
2013-04-30 01:22 - 2011-10-09 06:34 - 00000349 ____A C:\ProgramData\Documents\PCLECHAL.INI
2013-04-30 01:21 - 2011-10-09 06:34 - 00000000 ____D C:\Users\Public\Documents\Pinnacle
2013-04-30 01:21 - 2011-10-09 06:34 - 00000000 ____D C:\ProgramData\Documents\Pinnacle
2013-04-30 01:21 - 2011-10-09 03:06 - 00000000 ____D C:\Users\FRAZ\Documents\Pinnacle Studio
2013-04-23 23:37 - 2011-10-08 15:23 - 00270560 ____A C:\Users\FRAZ\AppData\Local\GDIPFONTCACHEV1.DAT
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2009-07-13 15:56] - [2009-07-13 17:39] - 2868224 ____A (Microsoft Corporation) 22424AE68280D6FDE95CD40F2D238049
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 9%
Total physical RAM: 8190.05 MB
Available physical RAM: 7400.41 MB
Total Pagefile: 8188.2 MB
Available Pagefile: 7392.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Drives ================================
Drive c: (130 GIG - SAT1 - WIN 7) (Fixed) (Total:136.72 GB) (Free:10.65 GB) NTFS (Disk=0 Partition=1)
Drive l: (8 GIG STICK) (Removable) (Total:7.55 GB) (Free:0.53 GB) FAT32 (Disk=7 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (96 gig ) (Fixed) (Total:96.16 GB) (Free:4.5 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 233 GB) (Disk ID: 2D531A81)
Partition 1: (Not Active) - (Size=137 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=96 GB) - (Type=07 NTFS)
========================================================
Disk: 7 (MBR Code: Windows XP) (Size: 8 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=8 GB) - (Type=0C)
Last Boot: 2013-05-14 05:58
==================== End Of Log ============================
Can anyone advise or provide the fix log please.
Many thanks in advance
Fraz
New to the forum and new to viruses and I wonder if anyone could help me please.
I'm running Win7 x64 and all of a sudden, my PC will not stay on. Either in Windows or Safe Mode, it always shuts down within a minute (With a warning when in windows). It will not stay on long enough for me to do anything but I can't see anything "Unusual" in the process list.
I've seen a similar post, so heve downloaded and run Farbar Recovery Scan Tool (frst64.exe) according to the instructions on that post and here is the log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-05-2013 01
Ran by SYSTEM on 23-05-2013 11:24:32
Running from L:\
Windows 7 Ultimate (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ACPW06EN] "C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe" /pid ACPW06EN [1231992 2012-08-31] (ACD Systems)
HKLM-x32\...\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [356376 2012-11-13] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [ACPW05EN] "C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe" /pid ACPW05EN [822384 2011-09-19] (ACD Systems)
HKLM-x32\...\Run: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKU\FRAZ\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" [267056 2011-10-08] (BitTorrent, Inc.)
HKU\FRAZ\...\Run: [EPSON Stylus Photo R220 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIAIA.EXE /FU "C:\Windows\TEMP\E_S6681.tmp" /EF "HKCU" [148 2012-12-16] ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\iReboot 1.1.1.lnk
ShortcutTarget: iReboot 1.1.1.lnk -> C:\Program Files (x86)\NeoSmart Technologies\iReboot\iReboot.exe (NeoSmart Technologies)
==================== Services (Whitelisted) =================
S2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [891432 2009-09-12] (Acronis)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-09-15] ()
S2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2326920 2011-10-09] (Acronis)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2012-11-13] (Kaspersky Lab ZAO)
S2 BITS; C:\Windows\System32\qmgr.dll [848384 2009-07-13] ()
S2 BrowserProtect; C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2787280 2013-03-22] ()
S2 iReboot; C:\Program Files (x86)\NeoSmart Technologies\iReboot\iRebootd.exe [17408 2009-09-15] ()
S3 Macromedia Licensing Service; C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [68096 2012-09-15] ()
S2 PCLEPCI; C:\Windows\SysWOW64\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH)
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [60288 2009-07-13] (Microsoft Corporation)
S0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620128 2013-04-22] (Kaspersky Lab ZAO)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-09-17] (Kaspersky Lab)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-09-17] (Kaspersky Lab)
S1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55056 2013-04-22] (Kaspersky Lab ZAO)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-22] (Kaspersky Lab ZAO)
S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
S3 WimFltr; C:\Windows\SysWow64\DRIVERS\wimfltr.sys [128104 2006-11-01] (Microsoft Corporation)
S4 Gpstetexysm; No ImagePath
S0 snapman; system32\DRIVERS\snapman.sys [x]
S0 tdrpman251; system32\DRIVERS\tdrpm251.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-05-23 10:40 - 2013-05-23 10:40 - 00000000 ____D C:\FRST
2013-05-17 10:11 - 2013-05-17 10:11 - 00000000 __SHD C:\found.000
2013-05-16 05:21 - 2013-05-16 10:10 - 00000000 ____D C:\Users\FRAZ\Desktop\family photos spain
2013-05-14 22:28 - 2013-05-14 22:28 - 00300768 ____A C:\Windows\Minidump\051513-27908-01.dmp
2013-05-12 15:03 - 2013-05-12 15:04 - 00000000 ____D C:\Users\FRAZ\Desktop\Panasonic Camcorder photo test
2013-05-12 14:54 - 2013-05-12 14:55 - 00000000 ____D C:\Users\FRAZ\Desktop\FashionRingtones
2013-05-12 07:04 - 2013-05-12 07:04 - 00000952 ____A C:\Users\FRAZ\Desktop\HD Tune.lnk
2013-05-12 07:04 - 2013-05-12 07:04 - 00000000 ____D C:\Program Files (x86)\HD Tune
2013-05-11 03:29 - 2013-05-11 03:34 - 00000000 ____D C:\Users\FRAZ\Desktop\moby northern
2013-05-11 03:29 - 2013-05-03 14:58 - 09093237 ____N C:\Users\FRAZ\Desktop\20130503_235820.mp4
2013-05-11 03:29 - 2013-05-03 14:05 - 245591627 ____N C:\Users\FRAZ\Desktop\20130503_230306.mp4
2013-05-11 03:29 - 2013-05-03 14:02 - 71031828 ____N C:\Users\FRAZ\Desktop\20130503_230220.mp4
2013-05-11 01:16 - 2013-05-11 01:16 - 00000000 ___HD C:\Users\Public\[Originals]
2013-05-11 00:54 - 2013-05-11 00:54 - 00000000 ____D C:\Users\FRAZ\Documents\Adobe
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\Users\Public\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\ProgramData\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:36 - 2013-05-11 00:36 - 00000000 ____D C:\Users\FRAZ\Desktop\Adobe
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\Users\Public\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\ProgramData\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\YTD YouTube Downloader & Converter
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\Application Data\YTD YouTube Downloader & Converter
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\ProgramData\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\ProgramData\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\Application Data\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
==================== One Month Modified Files and Folders =======
2013-05-23 10:40 - 2013-05-23 10:40 - 00000000 ____D C:\FRST
2013-05-23 01:54 - 2011-10-09 00:44 - 00000000 ____D C:\Users\FRAZ\AppData\Local\ACD Systems
2013-05-23 01:50 - 2011-10-08 15:31 - 00000000 ____D C:\Users\FRAZ\Application Data\uTorrent
2013-05-23 01:50 - 2011-10-08 15:31 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\uTorrent
2013-05-23 01:49 - 2012-09-15 00:17 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-05-23 01:49 - 2012-09-15 00:17 - 00000000 ____D C:\ProgramData\Application Data\Kaspersky Lab
2013-05-23 01:48 - 2011-10-08 14:59 - 00000000 ____D C:\ProgramData\NVIDIA
2013-05-23 01:48 - 2011-10-08 14:59 - 00000000 ____D C:\ProgramData\Application Data\NVIDIA
2013-05-23 01:48 - 2009-07-13 21:08 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-05-23 01:48 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-23 01:48 - 2003-12-01 04:31 - 00070328 ____A C:\Windows\setupact.log
2013-05-17 10:30 - 2009-07-13 15:38 - 00129024 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\videoprt.sys
2013-05-17 10:28 - 2009-07-13 16:10 - 00845824 ____A (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-05-17 10:27 - 2009-07-13 15:28 - 01162240 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-05-17 10:25 - 2009-07-13 15:49 - 01065984 ____A (Microsoft Corporation) C:\Windows\System32\cryptui.dll
2013-05-17 10:14 - 2009-07-13 15:25 - 01898576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-05-17 10:13 - 2009-07-13 15:20 - 01659984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-05-17 10:11 - 2013-05-17 10:11 - 00000000 __SHD C:\found.000
2013-05-17 01:03 - 2011-10-08 13:41 - 02059676 ____A C:\Windows\WindowsUpdate.log
2013-05-17 00:57 - 2009-07-13 20:45 - 00015504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-05-17 00:57 - 2009-07-13 20:45 - 00015504 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-05-17 00:47 - 2012-09-15 07:19 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-16 10:51 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports
2013-05-16 10:42 - 2011-10-08 15:03 - 00000000 ____D C:\Users\FRAZ\Application Data\Adobe
2013-05-16 10:42 - 2011-10-08 15:03 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\Adobe
2013-05-16 10:10 - 2013-05-16 05:21 - 00000000 ____D C:\Users\FRAZ\Desktop\family photos spain
2013-05-15 08:47 - 2012-09-15 07:19 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-15 08:47 - 2012-09-15 07:19 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-14 22:28 - 2013-05-14 22:28 - 00300768 ____A C:\Windows\Minidump\051513-27908-01.dmp
2013-05-14 22:28 - 2012-11-19 03:00 - 00000000 ____D C:\Windows\Minidump
2013-05-12 22:50 - 2009-07-13 21:13 - 00726316 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-12 15:04 - 2013-05-12 15:03 - 00000000 ____D C:\Users\FRAZ\Desktop\Panasonic Camcorder photo test
2013-05-12 14:55 - 2013-05-12 14:54 - 00000000 ____D C:\Users\FRAZ\Desktop\FashionRingtones
2013-05-12 07:04 - 2013-05-12 07:04 - 00000952 ____A C:\Users\FRAZ\Desktop\HD Tune.lnk
2013-05-12 07:04 - 2013-05-12 07:04 - 00000000 ____D C:\Program Files (x86)\HD Tune
2013-05-11 03:34 - 2013-05-11 03:29 - 00000000 ____D C:\Users\FRAZ\Desktop\moby northern
2013-05-11 01:16 - 2013-05-11 01:16 - 00000000 ___HD C:\Users\Public\[Originals]
2013-05-11 00:54 - 2013-05-11 00:54 - 00000000 ____D C:\Users\FRAZ\Documents\Adobe
2013-05-11 00:54 - 2011-10-09 03:54 - 00000000 ____D C:\Users\FRAZ\AppData\Local\Adobe
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\Users\Public\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:48 - 2013-05-11 00:48 - 00002077 ____A C:\ProgramData\Desktop\Lightroom 4.3 64-bit.lnk
2013-05-11 00:48 - 2011-10-09 03:59 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-05-11 00:48 - 2011-10-08 15:54 - 00000000 ____D C:\ProgramData\Application Data\Adobe
2013-05-11 00:48 - 2011-10-08 15:54 - 00000000 ____D C:\ProgramData\Adobe
2013-05-11 00:47 - 2011-10-09 04:00 - 00000000 ____D C:\Program Files\Adobe
2013-05-11 00:36 - 2013-05-11 00:36 - 00000000 ____D C:\Users\FRAZ\Desktop\Adobe
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-05-08 23:17 - 2013-05-08 23:17 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\Users\Public\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00001072 ____A C:\ProgramData\Desktop\YTD YouTube Downloader & Converter.lnk
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\YTD YouTube Downloader & Converter
2013-05-07 05:30 - 2013-05-07 05:30 - 00000000 ____D C:\ProgramData\Application Data\YTD YouTube Downloader & Converter
2013-05-07 05:30 - 2011-10-09 00:37 - 00000000 ____D C:\Program Files (x86)\YouTube Downloader
2013-05-03 14:58 - 2013-05-11 03:29 - 09093237 ____N C:\Users\FRAZ\Desktop\20130503_235820.mp4
2013-05-03 14:05 - 2013-05-11 03:29 - 245591627 ____N C:\Users\FRAZ\Desktop\20130503_230306.mp4
2013-05-03 14:02 - 2013-05-11 03:29 - 71031828 ____N C:\Users\FRAZ\Desktop\20130503_230220.mp4
2013-04-30 21:51 - 2003-12-01 04:31 - 00030206 ____A C:\Windows\PFRO.log
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001388 ____A C:\ProgramData\Desktop\Free Video Flip and Rotate.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00001265 ____A C:\ProgramData\Desktop\DVDVideoSoft Free Studio.lnk
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\Application Data\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Users\FRAZ\AppData\Roaming\DVDVideoSoft
2013-04-30 01:44 - 2013-04-30 01:44 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-04-30 01:44 - 2011-10-09 06:29 - 00000000 ____D C:\Users\FRAZ\Documents\DVDVideoSoft
2013-04-30 01:22 - 2011-10-09 06:34 - 00000349 ____A C:\Users\Public\Documents\PCLECHAL.INI
2013-04-30 01:22 - 2011-10-09 06:34 - 00000349 ____A C:\ProgramData\Documents\PCLECHAL.INI
2013-04-30 01:21 - 2011-10-09 06:34 - 00000000 ____D C:\Users\Public\Documents\Pinnacle
2013-04-30 01:21 - 2011-10-09 06:34 - 00000000 ____D C:\ProgramData\Documents\Pinnacle
2013-04-30 01:21 - 2011-10-09 03:06 - 00000000 ____D C:\Users\FRAZ\Documents\Pinnacle Studio
2013-04-23 23:37 - 2011-10-08 15:23 - 00270560 ____A C:\Users\FRAZ\AppData\Local\GDIPFONTCACHEV1.DAT
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2009-07-13 15:56] - [2009-07-13 17:39] - 2868224 ____A (Microsoft Corporation) 22424AE68280D6FDE95CD40F2D238049
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 9%
Total physical RAM: 8190.05 MB
Available physical RAM: 7400.41 MB
Total Pagefile: 8188.2 MB
Available Pagefile: 7392.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Drives ================================
Drive c: (130 GIG - SAT1 - WIN 7) (Fixed) (Total:136.72 GB) (Free:10.65 GB) NTFS (Disk=0 Partition=1)
Drive l: (8 GIG STICK) (Removable) (Total:7.55 GB) (Free:0.53 GB) FAT32 (Disk=7 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (96 gig ) (Fixed) (Total:96.16 GB) (Free:4.5 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 233 GB) (Disk ID: 2D531A81)
Partition 1: (Not Active) - (Size=137 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=96 GB) - (Type=07 NTFS)
========================================================
Disk: 7 (MBR Code: Windows XP) (Size: 8 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=8 GB) - (Type=0C)
Last Boot: 2013-05-14 05:58
==================== End Of Log ============================
Can anyone advise or provide the fix log please.
Many thanks in advance
Fraz