Mark Baron
Posts: 16 +1
Howdy helpful techie folk! Two things I hate - uninvited house guests and computer viruses, especially when the former leads to my computer being infected with the latter.
Like many others, I am getting the "Critical Error" leading to a rolling restart.
Farbar scan results below:
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 08-08-2012 16:04:00
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8060960 2009-08-05] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [200704 2009-11-20] ()
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-06-23] (Logitech, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2009-07-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Baron\...\Run: [Facebook Update] "C:\Users\Baron\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\Baron\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Baron\Start Menu\Programs\Startup\Launch Utility Application.lnk
ShortcutTarget: Launch Utility Application.lnk -> (No File)
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [869672 2007-12-03] (Nero AG)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
4 NMIndexingService; "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe" [447784 2007-12-13] (Nero AG)
2 RichVideo; "C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe" [244904 2010-06-08] ()
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 McAfee SiteAdvisor Service; C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]
========================== Drivers (Whitelisted) =============
2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; \??\C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [146928 2010-03-13] (CyberLink Corp.)
2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [146928 2009-10-05] (CyberLink Corp.)
3 PTSimBus; C:\Windows\System32\DRIVERS\PTSimBus.sys [x]
3 PTSimHid; C:\Windows\System32\DRIVERS\PTSimHid.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-08 16:03 - 2012-08-08 16:04 - 00000000 ____D C:\FRST
2012-08-07 20:00 - 2012-08-07 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9332A8001FE63C52
2012-08-07 19:49 - 2012-08-07 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A3F153B8401B3F5
2012-08-07 19:22 - 2012-08-07 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8025361BB421D056
2012-08-07 18:55 - 2012-08-07 18:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FA90DB8C2E9D330
2012-08-07 18:49 - 2012-08-07 18:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37F9CA91FD414ADE
2012-08-07 18:43 - 2012-08-07 18:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68B311C1FA4BFF50
2012-08-07 18:23 - 2012-08-07 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.254328009C9786B5
2012-08-07 18:16 - 2012-08-07 18:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\MicrosoftFixit.WindowsFirewall.RNP.132267822619476349.1.1.Run.exe
2012-08-07 18:08 - 2012-08-07 18:08 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-07 18:08 - 2012-08-07 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-07 16:49 - 2012-08-07 16:49 - 00005490 ____A C:\Windows\wininit.ini
2012-08-07 15:34 - 2012-08-07 15:34 - 12621696 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\mseinstall.exe
2012-08-05 19:33 - 2012-08-05 19:33 - 00000083 ____A C:\Users\Baron\Documents\Marks Costume Costs.txt
2012-08-04 21:23 - 2012-08-04 21:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-30 15:15 - 2012-07-30 15:15 - 00001849 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-30 15:14 - 2012-07-30 15:15 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-26 13:28 - 2012-08-04 21:30 - 00000000 ____D C:\Users\Baron\Documents\story
2012-07-24 11:09 - 2012-07-24 13:40 - 00000000 ____D C:\Users\Baron\Desktop\07_20_12SummerTampaCaleighWedding
2012-07-13 14:04 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-13 13:55 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-13 13:55 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-13 13:55 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-13 13:55 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-13 13:55 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-13 13:55 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-13 13:55 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-13 13:55 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-13 13:55 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-13 13:55 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-13 13:55 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-13 13:55 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-13 13:55 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-13 13:55 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-13 13:55 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-13 13:55 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-13 13:55 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-13 13:55 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-13 13:55 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-13 13:55 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-13 13:55 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-13 13:55 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-13 13:55 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-13 13:55 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-13 13:55 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-13 13:55 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-13 13:55 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-13 13:55 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-13 13:53 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-13 13:53 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-13 13:53 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-13 13:53 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-13 13:53 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-13 13:53 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-13 13:53 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-13 13:53 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-13 13:53 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-13 13:53 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-13 13:53 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-13 13:53 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-13 13:53 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-13 13:53 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-13 13:53 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-13 13:53 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-13 13:53 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-13 13:53 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-13 13:53 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-09 17:40 - 2012-07-21 08:02 - 00000000 ____D C:\Users\Baron\Desktop\iphone7_9_12
2012-07-09 16:23 - 2012-07-09 16:23 - 00000000 ____D C:\Users\Baron\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
============ 3 Months Modified Files ========================
2012-08-07 20:10 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-07 20:08 - 2012-06-22 07:45 - 00006348 ____A C:\Windows\setupact.log
2012-08-07 20:08 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 20:02 - 2009-07-13 21:08 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-07 20:00 - 2012-08-07 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9332A8001FE63C52
2012-08-07 19:49 - 2012-08-07 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A3F153B8401B3F5
2012-08-07 19:22 - 2012-08-07 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8025361BB421D056
2012-08-07 18:55 - 2012-08-07 18:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FA90DB8C2E9D330
2012-08-07 18:55 - 2012-04-04 19:31 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-07 18:49 - 2012-08-07 18:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37F9CA91FD414ADE
2012-08-07 18:47 - 2011-11-22 17:33 - 00000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1008123640-2362147214-3341983321-1001UA.job
2012-08-07 18:43 - 2012-08-07 18:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68B311C1FA4BFF50
2012-08-07 18:37 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-07 18:37 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-07 18:23 - 2012-08-07 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.254328009C9786B5
2012-08-07 18:17 - 2012-08-07 18:16 - 00347424 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\MicrosoftFixit.WindowsFirewall.RNP.132267822619476349.1.1.Run.exe
2012-08-07 18:09 - 2011-03-01 14:56 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-07 18:09 - 2010-03-18 21:53 - 01541788 ____A C:\Windows\WindowsUpdate.log
2012-08-07 18:08 - 2011-03-01 14:55 - 00747944 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-07 17:52 - 2009-10-30 12:31 - 00775992 ____A C:\Windows\PFRO.log
2012-08-07 16:49 - 2012-08-07 16:49 - 00005490 ____A C:\Windows\wininit.ini
2012-08-07 15:34 - 2012-08-07 15:34 - 12621696 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\mseinstall.exe
2012-08-07 12:47 - 2011-11-22 17:33 - 00000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1008123640-2362147214-3341983321-1001Core.job
2012-08-05 19:33 - 2012-08-05 19:33 - 00000083 ____A C:\Users\Baron\Documents\Marks Costume Costs.txt
2012-08-02 09:55 - 2012-04-04 19:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-02 09:55 - 2011-06-07 08:05 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-30 15:15 - 2012-07-30 15:15 - 00001849 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-26 06:05 - 2009-07-13 21:13 - 00733968 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-13 14:27 - 2009-07-13 20:45 - 05552736 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-13 14:03 - 2009-07-13 18:34 - 00000510 ____A C:\Windows\win.ini
2012-07-13 13:57 - 2010-07-24 22:19 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 18:19 - 2010-10-15 18:35 - 00001223 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-01 07:45 - 2012-02-17 19:08 - 00001008 ____A C:\Users\Public\Desktop\Hero Lab.lnk
2012-06-24 11:16 - 2011-12-30 07:50 - 00000132 ____A C:\Users\Baron\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-06-22 12:09 - 2012-06-22 12:09 - 530816055 ____A C:\Windows\MEMORY.DMP
2012-06-22 12:09 - 2012-06-22 12:09 - 00279048 ____A C:\Windows\Minidump\062212-53508-01.dmp
2012-06-22 11:24 - 2011-12-18 19:26 - 00393216 __ASH C:\Users\Baron\Documents\Thumbs.db
2012-06-22 11:22 - 2012-06-22 11:22 - 00001787 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-22 11:17 - 2012-06-22 11:16 - 79225752 ____A (Apple Inc.) C:\Users\Baron\Documents\iTunes64Setup.exe
2012-06-22 07:45 - 2012-06-22 07:45 - 00000000 ____A C:\Windows\setuperr.log
2012-06-20 10:30 - 2011-07-13 18:54 - 04873197 ____A C:\Users\Baron\Downloads\iTunes64Setup.exe
2012-06-19 14:56 - 2012-06-19 14:56 - 00001036 ____A C:\Users\Baron\Documents\Fate - Shortcut.lnk
2012-06-19 14:56 - 2012-06-07 16:31 - 00001015 ____A C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2012-06-19 14:56 - 2011-07-02 19:50 - 00000971 ____A C:\Users\Baron\Desktop\DS3 Tool.lnk
2012-06-19 14:56 - 2011-07-02 19:39 - 00000971 ____A C:\Users\Public\Desktop\DS3 Tool.lnk
2012-06-19 05:57 - 2012-06-18 15:26 - 00063488 ____A C:\Users\Baron\xobglu16.dll
2012-06-19 05:57 - 2012-06-18 15:26 - 00023552 ____A C:\Users\Baron\xobglu32.dll
2012-06-18 15:23 - 2012-06-18 15:22 - 00000247 ____A C:\Windows\SIERRA.INI
2012-06-18 15:23 - 2012-06-18 15:22 - 00000233 ____A C:\Windows\KA.INI
2012-06-11 19:08 - 2012-07-13 14:04 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-13 13:53 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-13 13:53 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 16:29 - 2012-06-07 16:28 - 32112904 ____A (TeamSpeak Systems GmbH) C:\Users\Baron\Downloads\TeamSpeak3-Client-win64-3.0.6.exe
2012-06-07 16:27 - 2012-06-07 16:26 - 04813018 ____A C:\Users\Baron\Downloads\teamspeak3-server_win64-3.0.5.zip
2012-06-05 22:06 - 2012-07-13 13:53 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-13 13:53 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-13 13:53 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-13 13:53 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-13 13:53 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-13 13:53 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-24 10:22 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-24 10:22 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-24 10:22 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-24 10:22 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-24 10:22 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-13 13:55 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-13 13:55 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-13 13:55 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-13 13:55 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-13 13:55 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-13 13:55 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-13 13:55 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-13 13:55 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-13 13:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-13 13:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-13 13:55 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-13 13:55 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-13 13:55 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-13 13:55 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-13 13:55 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-13 13:55 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-13 13:55 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-13 13:55 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-13 13:55 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-13 13:55 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-13 13:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-13 13:55 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-13 13:55 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-13 13:55 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-13 13:55 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-13 13:55 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-13 13:55 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-13 13:55 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-13 13:53 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-13 13:53 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-13 13:53 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-13 13:53 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-13 13:53 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-13 13:53 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-13 13:53 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-13 13:53 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-13 13:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 05:01 - 2010-07-22 00:40 - 00000069 ____A C:\Windows\NeroDigital.ini
2012-05-26 11:16 - 2012-05-26 11:16 - 00000921 ____A C:\Users\Baron\Desktop\Ventrilo.lnk
2012-05-26 11:16 - 2012-05-26 11:16 - 00000262 ____A C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
2012-05-26 11:14 - 2012-05-26 11:14 - 04135696 ____A C:\Users\Baron\Downloads\ventrilo-3.0.8-Windows-x64.exe
2012-05-14 15:13 - 2012-04-24 05:57 - 00005632 ____A C:\Users\Baron\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-13 16:47 - 2012-05-14 15:13 - 11260713 ____A C:\Users\Baron\Documents\Jimi Hendrix - Star spangled banner (live at woodstock) 1969.mp4
ZeroAccess:
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\@
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\L
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\n
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\00000001.@
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\80000000.@
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\800000cb.@
ZeroAccess:
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\@
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\L
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3838.36 MB
Available physical RAM: 3125.07 MB
Total Pagefile: 3836.51 MB
Available Pagefile: 3118.89 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (ACER) (Fixed) (Total:453.94 GB) (Free:178.49 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:11.72 GB) (Free:1.45 GB) NTFS
4 Drive g: () (Removable) (Total:15.05 GB) (Free:15.05 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 11 GB 1024 KB
Partition 2 Primary 100 MB 11 GB
Partition 3 Primary 453 GB 11 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 11 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C ACER NTFS Partition 453 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-07 03:41
======================= End Of Log ==========================
Like many others, I am getting the "Critical Error" leading to a rolling restart.
Farbar scan results below:
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 08-08-2012 16:04:00
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8060960 2009-08-05] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [200704 2009-11-20] ()
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-06-23] (Logitech, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2009-07-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Baron\...\Run: [Facebook Update] "C:\Users\Baron\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\Baron\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Baron\Start Menu\Programs\Startup\Launch Utility Application.lnk
ShortcutTarget: Launch Utility Application.lnk -> (No File)
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [869672 2007-12-03] (Nero AG)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
4 NMIndexingService; "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe" [447784 2007-12-13] (Nero AG)
2 RichVideo; "C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe" [244904 2010-06-08] ()
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 McAfee SiteAdvisor Service; C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]
========================== Drivers (Whitelisted) =============
2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; \??\C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [146928 2010-03-13] (CyberLink Corp.)
2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [146928 2009-10-05] (CyberLink Corp.)
3 PTSimBus; C:\Windows\System32\DRIVERS\PTSimBus.sys [x]
3 PTSimHid; C:\Windows\System32\DRIVERS\PTSimHid.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-08 16:03 - 2012-08-08 16:04 - 00000000 ____D C:\FRST
2012-08-07 20:00 - 2012-08-07 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9332A8001FE63C52
2012-08-07 19:49 - 2012-08-07 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A3F153B8401B3F5
2012-08-07 19:22 - 2012-08-07 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8025361BB421D056
2012-08-07 18:55 - 2012-08-07 18:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FA90DB8C2E9D330
2012-08-07 18:49 - 2012-08-07 18:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37F9CA91FD414ADE
2012-08-07 18:43 - 2012-08-07 18:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68B311C1FA4BFF50
2012-08-07 18:23 - 2012-08-07 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.254328009C9786B5
2012-08-07 18:16 - 2012-08-07 18:17 - 00347424 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\MicrosoftFixit.WindowsFirewall.RNP.132267822619476349.1.1.Run.exe
2012-08-07 18:08 - 2012-08-07 18:08 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-07 18:08 - 2012-08-07 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-07 16:49 - 2012-08-07 16:49 - 00005490 ____A C:\Windows\wininit.ini
2012-08-07 15:34 - 2012-08-07 15:34 - 12621696 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\mseinstall.exe
2012-08-05 19:33 - 2012-08-05 19:33 - 00000083 ____A C:\Users\Baron\Documents\Marks Costume Costs.txt
2012-08-04 21:23 - 2012-08-04 21:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-30 15:15 - 2012-07-30 15:15 - 00001849 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-30 15:14 - 2012-07-30 15:15 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-26 13:28 - 2012-08-04 21:30 - 00000000 ____D C:\Users\Baron\Documents\story
2012-07-24 11:09 - 2012-07-24 13:40 - 00000000 ____D C:\Users\Baron\Desktop\07_20_12SummerTampaCaleighWedding
2012-07-13 14:04 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-13 13:55 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-13 13:55 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-13 13:55 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-13 13:55 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-13 13:55 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-13 13:55 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-13 13:55 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-13 13:55 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-13 13:55 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-13 13:55 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-13 13:55 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-13 13:55 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-13 13:55 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-13 13:55 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-13 13:55 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-13 13:55 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-13 13:55 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-13 13:55 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-13 13:55 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-13 13:55 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-13 13:55 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-13 13:55 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-13 13:55 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-13 13:55 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-13 13:55 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-13 13:55 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-13 13:55 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-13 13:55 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-13 13:53 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-13 13:53 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-13 13:53 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-13 13:53 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-13 13:53 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-13 13:53 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-13 13:53 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-13 13:53 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-13 13:53 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-13 13:53 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-13 13:53 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-13 13:53 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-13 13:53 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-13 13:53 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-13 13:53 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-13 13:53 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-13 13:53 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-13 13:53 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-13 13:53 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-09 17:40 - 2012-07-21 08:02 - 00000000 ____D C:\Users\Baron\Desktop\iphone7_9_12
2012-07-09 16:23 - 2012-07-09 16:23 - 00000000 ____D C:\Users\Baron\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
============ 3 Months Modified Files ========================
2012-08-07 20:10 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-07 20:08 - 2012-06-22 07:45 - 00006348 ____A C:\Windows\setupact.log
2012-08-07 20:08 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 20:02 - 2009-07-13 21:08 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-07 20:00 - 2012-08-07 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9332A8001FE63C52
2012-08-07 19:49 - 2012-08-07 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A3F153B8401B3F5
2012-08-07 19:22 - 2012-08-07 19:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8025361BB421D056
2012-08-07 18:55 - 2012-08-07 18:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FA90DB8C2E9D330
2012-08-07 18:55 - 2012-04-04 19:31 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-07 18:49 - 2012-08-07 18:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37F9CA91FD414ADE
2012-08-07 18:47 - 2011-11-22 17:33 - 00000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1008123640-2362147214-3341983321-1001UA.job
2012-08-07 18:43 - 2012-08-07 18:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.68B311C1FA4BFF50
2012-08-07 18:37 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-07 18:37 - 2009-07-13 20:45 - 00017600 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-07 18:23 - 2012-08-07 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.254328009C9786B5
2012-08-07 18:17 - 2012-08-07 18:16 - 00347424 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\MicrosoftFixit.WindowsFirewall.RNP.132267822619476349.1.1.Run.exe
2012-08-07 18:09 - 2011-03-01 14:56 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-07 18:09 - 2010-03-18 21:53 - 01541788 ____A C:\Windows\WindowsUpdate.log
2012-08-07 18:08 - 2011-03-01 14:55 - 00747944 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-07 17:52 - 2009-10-30 12:31 - 00775992 ____A C:\Windows\PFRO.log
2012-08-07 16:49 - 2012-08-07 16:49 - 00005490 ____A C:\Windows\wininit.ini
2012-08-07 15:34 - 2012-08-07 15:34 - 12621696 ____A (Microsoft Corporation) C:\Users\Baron\Downloads\mseinstall.exe
2012-08-07 12:47 - 2011-11-22 17:33 - 00000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1008123640-2362147214-3341983321-1001Core.job
2012-08-05 19:33 - 2012-08-05 19:33 - 00000083 ____A C:\Users\Baron\Documents\Marks Costume Costs.txt
2012-08-02 09:55 - 2012-04-04 19:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-02 09:55 - 2011-06-07 08:05 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-30 15:15 - 2012-07-30 15:15 - 00001849 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-26 06:05 - 2009-07-13 21:13 - 00733968 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-13 14:27 - 2009-07-13 20:45 - 05552736 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-13 14:03 - 2009-07-13 18:34 - 00000510 ____A C:\Windows\win.ini
2012-07-13 13:57 - 2010-07-24 22:19 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 18:19 - 2010-10-15 18:35 - 00001223 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-01 07:45 - 2012-02-17 19:08 - 00001008 ____A C:\Users\Public\Desktop\Hero Lab.lnk
2012-06-24 11:16 - 2011-12-30 07:50 - 00000132 ____A C:\Users\Baron\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-06-22 12:09 - 2012-06-22 12:09 - 530816055 ____A C:\Windows\MEMORY.DMP
2012-06-22 12:09 - 2012-06-22 12:09 - 00279048 ____A C:\Windows\Minidump\062212-53508-01.dmp
2012-06-22 11:24 - 2011-12-18 19:26 - 00393216 __ASH C:\Users\Baron\Documents\Thumbs.db
2012-06-22 11:22 - 2012-06-22 11:22 - 00001787 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-22 11:17 - 2012-06-22 11:16 - 79225752 ____A (Apple Inc.) C:\Users\Baron\Documents\iTunes64Setup.exe
2012-06-22 07:45 - 2012-06-22 07:45 - 00000000 ____A C:\Windows\setuperr.log
2012-06-20 10:30 - 2011-07-13 18:54 - 04873197 ____A C:\Users\Baron\Downloads\iTunes64Setup.exe
2012-06-19 14:56 - 2012-06-19 14:56 - 00001036 ____A C:\Users\Baron\Documents\Fate - Shortcut.lnk
2012-06-19 14:56 - 2012-06-07 16:31 - 00001015 ____A C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2012-06-19 14:56 - 2011-07-02 19:50 - 00000971 ____A C:\Users\Baron\Desktop\DS3 Tool.lnk
2012-06-19 14:56 - 2011-07-02 19:39 - 00000971 ____A C:\Users\Public\Desktop\DS3 Tool.lnk
2012-06-19 05:57 - 2012-06-18 15:26 - 00063488 ____A C:\Users\Baron\xobglu16.dll
2012-06-19 05:57 - 2012-06-18 15:26 - 00023552 ____A C:\Users\Baron\xobglu32.dll
2012-06-18 15:23 - 2012-06-18 15:22 - 00000247 ____A C:\Windows\SIERRA.INI
2012-06-18 15:23 - 2012-06-18 15:22 - 00000233 ____A C:\Windows\KA.INI
2012-06-11 19:08 - 2012-07-13 14:04 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-13 13:53 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-13 13:53 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 16:29 - 2012-06-07 16:28 - 32112904 ____A (TeamSpeak Systems GmbH) C:\Users\Baron\Downloads\TeamSpeak3-Client-win64-3.0.6.exe
2012-06-07 16:27 - 2012-06-07 16:26 - 04813018 ____A C:\Users\Baron\Downloads\teamspeak3-server_win64-3.0.5.zip
2012-06-05 22:06 - 2012-07-13 13:53 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-13 13:53 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-13 13:53 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-13 13:53 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-13 13:53 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-13 13:53 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-24 10:22 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-24 10:22 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-24 10:22 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-24 10:22 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-24 10:22 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-24 10:22 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-13 13:55 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-13 13:55 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-13 13:55 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-13 13:55 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-13 13:55 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-13 13:55 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-13 13:55 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-13 13:55 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-13 13:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-13 13:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-13 13:55 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-13 13:55 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-13 13:55 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-13 13:55 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-13 13:55 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-13 13:55 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-13 13:55 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-13 13:55 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-13 13:55 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-13 13:55 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-13 13:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-13 13:55 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-13 13:55 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-13 13:55 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-13 13:55 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-13 13:55 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-13 13:55 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-13 13:55 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-13 13:53 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-13 13:53 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-13 13:53 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-13 13:53 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-13 13:53 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-13 13:53 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-13 13:53 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-13 13:53 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-13 13:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 05:01 - 2010-07-22 00:40 - 00000069 ____A C:\Windows\NeroDigital.ini
2012-05-26 11:16 - 2012-05-26 11:16 - 00000921 ____A C:\Users\Baron\Desktop\Ventrilo.lnk
2012-05-26 11:16 - 2012-05-26 11:16 - 00000262 ____A C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
2012-05-26 11:14 - 2012-05-26 11:14 - 04135696 ____A C:\Users\Baron\Downloads\ventrilo-3.0.8-Windows-x64.exe
2012-05-14 15:13 - 2012-04-24 05:57 - 00005632 ____A C:\Users\Baron\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-13 16:47 - 2012-05-14 15:13 - 11260713 ____A C:\Users\Baron\Documents\Jimi Hendrix - Star spangled banner (live at woodstock) 1969.mp4
ZeroAccess:
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\@
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\L
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\n
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\00000001.@
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\80000000.@
C:\Windows\Installer\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\800000cb.@
ZeroAccess:
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\@
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\L
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U
C:\Users\Baron\AppData\Local\{fd89cca5-afe4-e2a6-7a33-b3ed3e6b79f0}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3838.36 MB
Available physical RAM: 3125.07 MB
Total Pagefile: 3836.51 MB
Available Pagefile: 3118.89 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (ACER) (Fixed) (Total:453.94 GB) (Free:178.49 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:11.72 GB) (Free:1.45 GB) NTFS
4 Drive g: () (Removable) (Total:15.05 GB) (Free:15.05 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 11 GB 1024 KB
Partition 2 Primary 100 MB 11 GB
Partition 3 Primary 453 GB 11 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 11 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C ACER NTFS Partition 453 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-07 03:41
======================= End Of Log ==========================