Chicagoflyski
Posts: 16 +0
Sadly, my machine got infected with the sirfef virus this morning, just before a 10-day trip to Europe. As a result, the laptop won't be making the trip with me but I'd like to get started on fixing the problem today and tomorrow so I can be closer to a working machine when I get back. So, if you don't hear from me for about 10 days, please forgive me and please keep the thread open as I want to jump on this first thing when I'm back on July 23. My FRST scan is posted below. Many thanks in advance for your help with this.
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 11-07-2012 16:26:43
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [318464 2009-05-14] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [610872 2009-07-21] ()
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [165912 2009-12-22] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [387608 2009-12-22] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [365592 2009-12-22] (Intel Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1612880 2010-01-27] (Logitech, Inc.)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [stlaml] rundll32.exe "C:\Users\Barry Bloom\AppData\Roaming\stlaml.dll",RicheditStreamOut [140800 2012-07-11] (DT Soft Ltd)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam" [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [500792 2010-05-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKU\Barry Bloom\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2736128 2010-06-16] (Hewlett-Packard Company)
HKU\Barry Bloom\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Barry Bloom\...\Run: [Spotify Web Helper] "C:\Users\Barry Bloom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [932528 2012-05-25] ()
HKU\Barry Bloom\...\Policies\system: [WallpaperStyle] 2
HKU\Barry Bloom.V2\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2736128 2010-06-16] (Hewlett-Packard Company)
HKU\Barry Bloom.V2\...\Run: [RCUI] "C:\Program Files (x86)\RingCentral\RingCentral Call Controller\RCUI.exe" [x]
HKU\Barry Bloom.V2\...\Run: [RCHotKey] "C:\Program Files (x86)\RingCentral\RingCentral Call Controller\RCHotKey.exe" [x]
HKU\Barry Bloom.V2\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background [4283256 2011-05-13] (Microsoft Corporation)
HKU\Barry Bloom.V2\...\Policies\system: [WallpaperStyle] 2
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1689144 2010-06-29] (Hewlett-Packard)
HKU\Default\...\Policies\system: [WallpaperStyle] 2
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1689144 2010-06-29] (Hewlett-Packard)
HKU\Default User\...\Policies\system: [WallpaperStyle] 2
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 208.59.247.45 208.59.247.46
Startup: C:\Users\All Users\Start Menu\Programs\Startup\CardMinder Viewer.lnk
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Barry Bloom\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [247152 2009-01-21] ()
2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [993848 2011-04-18] (Secunia)
2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service [399416 2011-04-18] (Secunia)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
2 Updater Service for StartNow Toolbar; C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [210144 2011-05-20] ()
========================== Drivers (Whitelisted) =============
3 SMSIVZAM5X64; \??\C:\PROGRA~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS [43032 2009-03-20] (Smith Micro Inc.)
4 eabfiltr; [x]
3 iscFlash; \??\C:\Users\BARRYB~1\AppData\Local\Temp\iscflashx64.sys [x]
3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-11 12:10 - 2012-07-11 12:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB57A93AB8D2FBBC
2012-07-11 12:05 - 2012-07-11 12:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214887FE27D1CCB3
2012-07-11 12:02 - 2012-07-11 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94C000235E939FB8
2012-07-11 11:57 - 2012-07-11 11:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2DE011F37F873D
2012-07-11 11:51 - 2012-07-11 11:51 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Barry Bloom\Downloads\tdsskiller.exe
2012-07-11 11:50 - 2012-07-11 11:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C5E9C520DFCA49D
2012-07-11 11:41 - 2012-07-11 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1D18CE78614CD9B3
2012-07-11 11:38 - 2012-07-11 11:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28886E99021B4DDC
2012-07-11 11:34 - 2012-07-11 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169E773A8420F57
2012-07-11 11:31 - 2012-07-11 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A9FED504373D24B
2012-07-11 11:28 - 2012-07-11 11:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA7236CA51C5A522
2012-07-11 11:24 - 2012-07-11 11:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E127CB94BBFE404E
2012-07-11 11:19 - 2012-07-11 11:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18039F551D19EA94
2012-07-11 11:16 - 2012-07-11 11:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E3A68B00C0B32C69
2012-07-11 11:10 - 2012-07-11 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BAE8885DCAEE29E
2012-07-11 11:07 - 2012-07-11 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E50DB400F05CC49
2012-07-11 11:04 - 2012-07-11 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E45AB5EF16A4F5B1
2012-07-11 10:57 - 2012-07-11 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D321DB3A0AACA8F4
2012-07-11 10:52 - 2012-07-11 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C053C16FB801F3AC
2012-07-11 10:43 - 2012-07-11 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C621B04502ECF3
2012-07-11 10:35 - 2012-07-11 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4544198BB216FCDC
2012-07-11 10:32 - 2012-07-11 10:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29D644316F3FEEA7
2012-07-11 10:29 - 2012-07-11 10:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.45008E5B51034A7E
2012-07-11 10:24 - 2012-07-11 10:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37AD25DECF0E1BA2
2012-07-11 10:06 - 2012-07-11 10:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD87C1993475FFB8
2012-07-11 09:46 - 2012-07-11 09:46 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-11 09:46 - 2012-07-11 09:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-11 09:38 - 2012-07-11 09:38 - 12621696 ____A (Microsoft Corporation) C:\Users\Barry Bloom\Downloads\mseinstall(1).exe
2012-07-11 09:31 - 2012-07-11 09:31 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-11 09:29 - 2012-07-11 09:29 - 00372736 ____A C:\Users\Barry Bloom\AppData\Roaming\mdeat.dll
2012-07-11 09:29 - 2012-07-11 09:29 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\{DDAF3A5A-CB7D-11E1-8270-B8AC6F996F26}
2012-07-11 09:28 - 2012-07-11 09:36 - 00000000 ____D C:\Users\All Users\F4D55F3B03B4DE2D09A16979B4EB2331
2012-07-11 09:28 - 2012-07-11 09:28 - 00055808 ___AH (FRISK Software International) C:\Windows\SysWOW64\cmmoance.dll
2012-07-11 09:28 - 2012-07-11 09:27 - 00140800 __ASH (DT Soft Ltd) C:\Users\Barry Bloom\AppData\Roaming\stlaml.dll
2012-07-11 02:50 - 2012-07-11 02:50 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\visi_coupon
2012-07-11 00:44 - 2012-07-11 00:56 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\FileTypeAssistant
2012-07-11 00:43 - 2012-07-11 09:08 - 00000284 ____A C:\Windows\Tasks\RGames Updater.job
2012-07-11 00:43 - 2012-07-11 02:53 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2012-07-11 00:43 - 2012-07-11 00:43 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\RivalGaming
2012-07-11 00:43 - 2012-07-11 00:43 - 00000000 ____D C:\Users\All Users\Yahoo!
2012-07-11 00:43 - 2012-07-11 00:43 - 00000000 ____D C:\Program Files (x86)\Free Offers from Freeze.com
2012-06-25 05:14 - 2012-07-11 11:03 - 00337920 __ASH C:\Users\Barry Bloom\Desktop\Thumbs.db
2012-06-24 16:54 - 2012-06-24 16:54 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\Macromedia
2012-06-21 17:57 - 2012-06-21 17:57 - 00000000 ____D C:\Users\Barry Bloom\Documents\CardMinder
2012-06-21 13:51 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 13:51 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 13:51 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 13:51 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 13:50 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 13:50 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 13:50 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 13:50 - 2012-06-02 11:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 13:50 - 2012-06-02 11:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-16 07:16 - 2012-06-16 07:16 - 00000000 ____D C:\Windows\Hewlett-Packard
2012-06-14 03:45 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 03:45 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 03:45 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 03:45 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 03:45 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 03:45 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 03:45 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 03:45 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 03:44 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 03:44 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 03:44 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 03:44 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 03:44 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 03:44 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 03:44 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 03:44 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 03:44 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 03:44 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 03:44 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 03:44 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 03:44 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 03:44 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 03:44 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 03:44 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 03:44 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 03:44 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 03:44 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 03:44 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 17:19 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 17:19 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 17:19 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 17:19 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 17:19 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 17:19 - 2012-04-27 21:32 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-06-13 17:19 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 17:19 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 17:19 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 17:19 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 17:19 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 17:19 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 17:19 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 17:19 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 17:19 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 17:19 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 17:19 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 17:19 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
============ 3 Months Modified Files ========================
2012-07-11 12:17 - 2009-07-13 21:13 - 00736408 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-11 12:15 - 2009-12-23 18:03 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-11 12:14 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-11 12:12 - 2011-10-19 17:18 - 00009618 ____A C:\Windows\setupact.log
2012-07-11 12:12 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-11 12:10 - 2012-07-11 12:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB57A93AB8D2FBBC
2012-07-11 12:05 - 2012-07-11 12:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214887FE27D1CCB3
2012-07-11 12:04 - 2009-07-13 21:08 - 00032652 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-11 12:02 - 2012-07-11 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94C000235E939FB8
2012-07-11 11:57 - 2012-07-11 11:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2DE011F37F873D
2012-07-11 11:51 - 2012-07-11 11:51 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Barry Bloom\Downloads\tdsskiller.exe
2012-07-11 11:50 - 2012-07-11 11:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C5E9C520DFCA49D
2012-07-11 11:41 - 2012-07-11 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1D18CE78614CD9B3
2012-07-11 11:38 - 2012-07-11 11:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28886E99021B4DDC
2012-07-11 11:34 - 2012-07-11 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169E773A8420F57
2012-07-11 11:31 - 2012-07-11 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A9FED504373D24B
2012-07-11 11:28 - 2012-07-11 11:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA7236CA51C5A522
2012-07-11 11:24 - 2012-07-11 11:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E127CB94BBFE404E
2012-07-11 11:19 - 2012-07-11 11:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18039F551D19EA94
2012-07-11 11:16 - 2012-07-11 11:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E3A68B00C0B32C69
2012-07-11 11:10 - 2012-07-11 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BAE8885DCAEE29E
2012-07-11 11:07 - 2012-07-11 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E50DB400F05CC49
2012-07-11 11:04 - 2012-07-11 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E45AB5EF16A4F5B1
2012-07-11 11:03 - 2012-06-25 05:14 - 00337920 __ASH C:\Users\Barry Bloom\Desktop\Thumbs.db
2012-07-11 10:57 - 2012-07-11 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D321DB3A0AACA8F4
2012-07-11 10:52 - 2012-07-11 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C053C16FB801F3AC
2012-07-11 10:48 - 2012-05-06 16:55 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-11 10:43 - 2012-07-11 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C621B04502ECF3
2012-07-11 10:35 - 2012-07-11 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4544198BB216FCDC
2012-07-11 10:32 - 2012-07-11 10:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29D644316F3FEEA7
2012-07-11 10:29 - 2012-07-11 10:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.45008E5B51034A7E
2012-07-11 10:24 - 2012-07-11 10:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37AD25DECF0E1BA2
2012-07-11 10:23 - 2009-07-13 20:45 - 00028704 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-11 10:23 - 2009-07-13 20:45 - 00028704 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-11 10:12 - 2009-12-23 18:03 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-11 10:06 - 2012-07-11 10:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD87C1993475FFB8
2012-07-11 09:47 - 2012-01-12 16:21 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-11 09:47 - 2009-10-12 18:29 - 01160767 ____A C:\Windows\WindowsUpdate.log
2012-07-11 09:46 - 2010-04-05 08:14 - 00750558 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-11 09:41 - 2011-11-11 01:23 - 00024080 ____A C:\Windows\PFRO.log
2012-07-11 09:41 - 2011-07-19 07:40 - 00000356 ____A C:\Windows\Tasks\HPCeeScheduleForBarry Bloom.job
2012-07-11 09:38 - 2012-07-11 09:38 - 12621696 ____A (Microsoft Corporation) C:\Users\Barry Bloom\Downloads\mseinstall(1).exe
2012-07-11 09:29 - 2012-07-11 09:29 - 00372736 ____A C:\Users\Barry Bloom\AppData\Roaming\mdeat.dll
2012-07-11 09:28 - 2012-07-11 09:28 - 00055808 ___AH (FRISK Software International) C:\Windows\SysWOW64\cmmoance.dll
2012-07-11 09:27 - 2012-07-11 09:28 - 00140800 __ASH (DT Soft Ltd) C:\Users\Barry Bloom\AppData\Roaming\stlaml.dll
2012-07-11 09:08 - 2012-07-11 00:43 - 00000284 ____A C:\Windows\Tasks\RGames Updater.job
2012-07-07 07:59 - 2011-10-15 12:18 - 00001893 ____A C:\Users\Public\Desktop\Defraggler.lnk
2012-07-07 07:59 - 2011-10-15 11:55 - 00000991 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-07-07 07:59 - 2010-11-20 07:12 - 00002129 ____A C:\Users\Barry Bloom\Desktop\SAS 9.2 (English).lnk
2012-07-07 07:59 - 2010-01-03 17:24 - 00001097 ____A C:\Users\Barry Bloom\Desktop\PDF-Viewer.lnk
2012-07-07 07:59 - 2009-12-23 18:11 - 00001019 ____A C:\Users\Barry Bloom\Desktop\Bullzip PDF Printer.lnk
2012-06-29 11:55 - 2012-05-06 16:54 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-29 11:55 - 2011-05-18 03:45 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-23 20:08 - 2012-05-06 17:48 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-06-14 04:21 - 2009-07-13 20:45 - 00521592 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 03:54 - 2009-12-19 13:45 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-05 19:13 - 2010-04-04 10:08 - 00001040 ____A C:\Users\Barry Bloom\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-21 13:51 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 13:51 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 13:51 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 13:50 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 13:50 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 13:51 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 13:50 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 13:50 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-21 13:50 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-17 18:47 - 2012-06-14 03:44 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 03:44 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 03:44 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 03:45 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:59 - 2012-06-14 03:44 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:58 - 2012-06-14 03:45 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:58 - 2012-06-14 03:44 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:56 - 2012-06-14 03:44 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 03:44 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 03:44 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 03:44 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 03:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 03:45 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 03:44 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 03:44 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 03:44 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 03:44 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 03:45 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 03:44 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 03:44 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 03:45 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 03:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 03:44 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 03:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 03:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 03:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 03:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 03:44 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 17:19 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 13:36 - 2011-10-31 08:00 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-05-11 13:36 - 2009-12-20 19:20 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-05-06 18:06 - 2010-05-24 08:01 - 00001007 ____A C:\Users\Barry Bloom.V2\Desktop\Bullzip PDF Printer.lnk
2012-05-04 03:06 - 2012-06-13 17:19 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 17:19 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 17:19 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 17:19 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-29 18:15 - 2012-04-29 18:15 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-04-27 21:32 - 2012-06-13 17:19 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-04-27 19:55 - 2012-06-13 17:19 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 18:22 - 2012-04-27 18:22 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-27 18:22 - 2012-04-27 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-27 18:22 - 2012-04-27 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-27 18:22 - 2011-09-21 08:15 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-27 18:20 - 2012-04-27 18:19 - 00908576 ____A (Sun Microsystems, Inc.) C:\Users\Barry Bloom\Downloads\jxpiinstall(1).exe
2012-04-25 21:41 - 2012-06-13 17:19 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 17:19 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 17:19 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 17:19 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 17:19 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 17:19 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 17:19 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 17:19 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 17:19 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-16 10:23 - 2012-02-17 15:04 - 00002044 ____A C:\Users\Public\Desktop\Adobe Acrobat X Standard.lnk
2012-04-15 15:03 - 2012-04-15 15:03 - 00001840 ____A C:\Users\Barry Bloom\Desktop\Spotify.lnk
2012-04-15 15:02 - 2012-04-15 15:02 - 00085272 ____A (Spotify Ltd) C:\Users\Barry Bloom\Downloads\SpotifySetup.exe
ZeroAccess:
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\@
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\L
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\n
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U\00000001.@
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U\800000cb.@
ZeroAccess:
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\@
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\L
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3998.96 MB
Available physical RAM: 3253.5 MB
Total Pagefile: 3997.11 MB
Available Pagefile: 3253.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:282.08 GB) (Free:39.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:15.82 GB) (Free:2.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: () (Removable) (Total:0.94 GB) (Free:0.89 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 966 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 282 GB 200 MB
Partition 3 Primary 15 GB 282 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 282 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 15 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 965 MB 508 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 965 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-11 05:06
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 11-07-2012 16:26:43
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [318464 2009-05-14] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [610872 2009-07-21] ()
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [165912 2009-12-22] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [387608 2009-12-22] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [365592 2009-12-22] (Intel Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1612880 2010-01-27] (Logitech, Inc.)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [stlaml] rundll32.exe "C:\Users\Barry Bloom\AppData\Roaming\stlaml.dll",RicheditStreamOut [140800 2012-07-11] (DT Soft Ltd)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam" [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [500792 2010-05-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKU\Barry Bloom\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2736128 2010-06-16] (Hewlett-Packard Company)
HKU\Barry Bloom\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Barry Bloom\...\Run: [Spotify Web Helper] "C:\Users\Barry Bloom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [932528 2012-05-25] ()
HKU\Barry Bloom\...\Policies\system: [WallpaperStyle] 2
HKU\Barry Bloom.V2\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2736128 2010-06-16] (Hewlett-Packard Company)
HKU\Barry Bloom.V2\...\Run: [RCUI] "C:\Program Files (x86)\RingCentral\RingCentral Call Controller\RCUI.exe" [x]
HKU\Barry Bloom.V2\...\Run: [RCHotKey] "C:\Program Files (x86)\RingCentral\RingCentral Call Controller\RCHotKey.exe" [x]
HKU\Barry Bloom.V2\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background [4283256 2011-05-13] (Microsoft Corporation)
HKU\Barry Bloom.V2\...\Policies\system: [WallpaperStyle] 2
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1689144 2010-06-29] (Hewlett-Packard)
HKU\Default\...\Policies\system: [WallpaperStyle] 2
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1689144 2010-06-29] (Hewlett-Packard)
HKU\Default User\...\Policies\system: [WallpaperStyle] 2
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 208.59.247.45 208.59.247.46
Startup: C:\Users\All Users\Start Menu\Programs\Startup\CardMinder Viewer.lnk
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Barry Bloom\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [247152 2009-01-21] ()
2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [993848 2011-04-18] (Secunia)
2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service [399416 2011-04-18] (Secunia)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
2 Updater Service for StartNow Toolbar; C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [210144 2011-05-20] ()
========================== Drivers (Whitelisted) =============
3 SMSIVZAM5X64; \??\C:\PROGRA~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS [43032 2009-03-20] (Smith Micro Inc.)
4 eabfiltr; [x]
3 iscFlash; \??\C:\Users\BARRYB~1\AppData\Local\Temp\iscflashx64.sys [x]
3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-11 12:10 - 2012-07-11 12:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB57A93AB8D2FBBC
2012-07-11 12:05 - 2012-07-11 12:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214887FE27D1CCB3
2012-07-11 12:02 - 2012-07-11 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94C000235E939FB8
2012-07-11 11:57 - 2012-07-11 11:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2DE011F37F873D
2012-07-11 11:51 - 2012-07-11 11:51 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Barry Bloom\Downloads\tdsskiller.exe
2012-07-11 11:50 - 2012-07-11 11:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C5E9C520DFCA49D
2012-07-11 11:41 - 2012-07-11 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1D18CE78614CD9B3
2012-07-11 11:38 - 2012-07-11 11:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28886E99021B4DDC
2012-07-11 11:34 - 2012-07-11 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169E773A8420F57
2012-07-11 11:31 - 2012-07-11 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A9FED504373D24B
2012-07-11 11:28 - 2012-07-11 11:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA7236CA51C5A522
2012-07-11 11:24 - 2012-07-11 11:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E127CB94BBFE404E
2012-07-11 11:19 - 2012-07-11 11:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18039F551D19EA94
2012-07-11 11:16 - 2012-07-11 11:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E3A68B00C0B32C69
2012-07-11 11:10 - 2012-07-11 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BAE8885DCAEE29E
2012-07-11 11:07 - 2012-07-11 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E50DB400F05CC49
2012-07-11 11:04 - 2012-07-11 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E45AB5EF16A4F5B1
2012-07-11 10:57 - 2012-07-11 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D321DB3A0AACA8F4
2012-07-11 10:52 - 2012-07-11 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C053C16FB801F3AC
2012-07-11 10:43 - 2012-07-11 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C621B04502ECF3
2012-07-11 10:35 - 2012-07-11 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4544198BB216FCDC
2012-07-11 10:32 - 2012-07-11 10:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29D644316F3FEEA7
2012-07-11 10:29 - 2012-07-11 10:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.45008E5B51034A7E
2012-07-11 10:24 - 2012-07-11 10:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37AD25DECF0E1BA2
2012-07-11 10:06 - 2012-07-11 10:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD87C1993475FFB8
2012-07-11 09:46 - 2012-07-11 09:46 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-11 09:46 - 2012-07-11 09:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-11 09:38 - 2012-07-11 09:38 - 12621696 ____A (Microsoft Corporation) C:\Users\Barry Bloom\Downloads\mseinstall(1).exe
2012-07-11 09:31 - 2012-07-11 09:31 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-11 09:29 - 2012-07-11 09:29 - 00372736 ____A C:\Users\Barry Bloom\AppData\Roaming\mdeat.dll
2012-07-11 09:29 - 2012-07-11 09:29 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\{DDAF3A5A-CB7D-11E1-8270-B8AC6F996F26}
2012-07-11 09:28 - 2012-07-11 09:36 - 00000000 ____D C:\Users\All Users\F4D55F3B03B4DE2D09A16979B4EB2331
2012-07-11 09:28 - 2012-07-11 09:28 - 00055808 ___AH (FRISK Software International) C:\Windows\SysWOW64\cmmoance.dll
2012-07-11 09:28 - 2012-07-11 09:27 - 00140800 __ASH (DT Soft Ltd) C:\Users\Barry Bloom\AppData\Roaming\stlaml.dll
2012-07-11 02:50 - 2012-07-11 02:50 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\visi_coupon
2012-07-11 00:44 - 2012-07-11 00:56 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\FileTypeAssistant
2012-07-11 00:43 - 2012-07-11 09:08 - 00000284 ____A C:\Windows\Tasks\RGames Updater.job
2012-07-11 00:43 - 2012-07-11 02:53 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2012-07-11 00:43 - 2012-07-11 00:43 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\RivalGaming
2012-07-11 00:43 - 2012-07-11 00:43 - 00000000 ____D C:\Users\All Users\Yahoo!
2012-07-11 00:43 - 2012-07-11 00:43 - 00000000 ____D C:\Program Files (x86)\Free Offers from Freeze.com
2012-06-25 05:14 - 2012-07-11 11:03 - 00337920 __ASH C:\Users\Barry Bloom\Desktop\Thumbs.db
2012-06-24 16:54 - 2012-06-24 16:54 - 00000000 ____D C:\Users\Barry Bloom\AppData\Local\Macromedia
2012-06-21 17:57 - 2012-06-21 17:57 - 00000000 ____D C:\Users\Barry Bloom\Documents\CardMinder
2012-06-21 13:51 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 13:51 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 13:51 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 13:51 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 13:50 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 13:50 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 13:50 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 13:50 - 2012-06-02 11:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 13:50 - 2012-06-02 11:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-16 07:16 - 2012-06-16 07:16 - 00000000 ____D C:\Windows\Hewlett-Packard
2012-06-14 03:45 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 03:45 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 03:45 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 03:45 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 03:45 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 03:45 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 03:45 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 03:45 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 03:44 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 03:44 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 03:44 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 03:44 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 03:44 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 03:44 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 03:44 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 03:44 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 03:44 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 03:44 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 03:44 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 03:44 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 03:44 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 03:44 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 03:44 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 03:44 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 03:44 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 03:44 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 03:44 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 03:44 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 17:19 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 17:19 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 17:19 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 17:19 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 17:19 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 17:19 - 2012-04-27 21:32 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-06-13 17:19 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 17:19 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 17:19 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 17:19 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 17:19 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 17:19 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 17:19 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 17:19 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 17:19 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 17:19 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 17:19 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 17:19 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
============ 3 Months Modified Files ========================
2012-07-11 12:17 - 2009-07-13 21:13 - 00736408 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-11 12:15 - 2009-12-23 18:03 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-11 12:14 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-11 12:12 - 2011-10-19 17:18 - 00009618 ____A C:\Windows\setupact.log
2012-07-11 12:12 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-11 12:10 - 2012-07-11 12:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB57A93AB8D2FBBC
2012-07-11 12:05 - 2012-07-11 12:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214887FE27D1CCB3
2012-07-11 12:04 - 2009-07-13 21:08 - 00032652 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-11 12:02 - 2012-07-11 12:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94C000235E939FB8
2012-07-11 11:57 - 2012-07-11 11:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC2DE011F37F873D
2012-07-11 11:51 - 2012-07-11 11:51 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Barry Bloom\Downloads\tdsskiller.exe
2012-07-11 11:50 - 2012-07-11 11:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3C5E9C520DFCA49D
2012-07-11 11:41 - 2012-07-11 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1D18CE78614CD9B3
2012-07-11 11:38 - 2012-07-11 11:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28886E99021B4DDC
2012-07-11 11:34 - 2012-07-11 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169E773A8420F57
2012-07-11 11:31 - 2012-07-11 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A9FED504373D24B
2012-07-11 11:28 - 2012-07-11 11:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA7236CA51C5A522
2012-07-11 11:24 - 2012-07-11 11:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E127CB94BBFE404E
2012-07-11 11:19 - 2012-07-11 11:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18039F551D19EA94
2012-07-11 11:16 - 2012-07-11 11:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E3A68B00C0B32C69
2012-07-11 11:10 - 2012-07-11 11:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BAE8885DCAEE29E
2012-07-11 11:07 - 2012-07-11 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E50DB400F05CC49
2012-07-11 11:04 - 2012-07-11 11:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E45AB5EF16A4F5B1
2012-07-11 11:03 - 2012-06-25 05:14 - 00337920 __ASH C:\Users\Barry Bloom\Desktop\Thumbs.db
2012-07-11 10:57 - 2012-07-11 10:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D321DB3A0AACA8F4
2012-07-11 10:52 - 2012-07-11 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C053C16FB801F3AC
2012-07-11 10:48 - 2012-05-06 16:55 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-11 10:43 - 2012-07-11 10:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C621B04502ECF3
2012-07-11 10:35 - 2012-07-11 10:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4544198BB216FCDC
2012-07-11 10:32 - 2012-07-11 10:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.29D644316F3FEEA7
2012-07-11 10:29 - 2012-07-11 10:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.45008E5B51034A7E
2012-07-11 10:24 - 2012-07-11 10:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37AD25DECF0E1BA2
2012-07-11 10:23 - 2009-07-13 20:45 - 00028704 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-11 10:23 - 2009-07-13 20:45 - 00028704 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-11 10:12 - 2009-12-23 18:03 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-11 10:06 - 2012-07-11 10:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD87C1993475FFB8
2012-07-11 09:47 - 2012-01-12 16:21 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-11 09:47 - 2009-10-12 18:29 - 01160767 ____A C:\Windows\WindowsUpdate.log
2012-07-11 09:46 - 2010-04-05 08:14 - 00750558 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-11 09:41 - 2011-11-11 01:23 - 00024080 ____A C:\Windows\PFRO.log
2012-07-11 09:41 - 2011-07-19 07:40 - 00000356 ____A C:\Windows\Tasks\HPCeeScheduleForBarry Bloom.job
2012-07-11 09:38 - 2012-07-11 09:38 - 12621696 ____A (Microsoft Corporation) C:\Users\Barry Bloom\Downloads\mseinstall(1).exe
2012-07-11 09:29 - 2012-07-11 09:29 - 00372736 ____A C:\Users\Barry Bloom\AppData\Roaming\mdeat.dll
2012-07-11 09:28 - 2012-07-11 09:28 - 00055808 ___AH (FRISK Software International) C:\Windows\SysWOW64\cmmoance.dll
2012-07-11 09:27 - 2012-07-11 09:28 - 00140800 __ASH (DT Soft Ltd) C:\Users\Barry Bloom\AppData\Roaming\stlaml.dll
2012-07-11 09:08 - 2012-07-11 00:43 - 00000284 ____A C:\Windows\Tasks\RGames Updater.job
2012-07-07 07:59 - 2011-10-15 12:18 - 00001893 ____A C:\Users\Public\Desktop\Defraggler.lnk
2012-07-07 07:59 - 2011-10-15 11:55 - 00000991 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-07-07 07:59 - 2010-11-20 07:12 - 00002129 ____A C:\Users\Barry Bloom\Desktop\SAS 9.2 (English).lnk
2012-07-07 07:59 - 2010-01-03 17:24 - 00001097 ____A C:\Users\Barry Bloom\Desktop\PDF-Viewer.lnk
2012-07-07 07:59 - 2009-12-23 18:11 - 00001019 ____A C:\Users\Barry Bloom\Desktop\Bullzip PDF Printer.lnk
2012-06-29 11:55 - 2012-05-06 16:54 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-29 11:55 - 2011-05-18 03:45 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-23 20:08 - 2012-05-06 17:48 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-06-14 04:21 - 2009-07-13 20:45 - 00521592 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 03:54 - 2009-12-19 13:45 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-05 19:13 - 2010-04-04 10:08 - 00001040 ____A C:\Users\Barry Bloom\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-21 13:51 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 13:51 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 13:51 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 13:50 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 13:50 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 13:51 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 13:50 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 13:50 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-21 13:50 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-17 18:47 - 2012-06-14 03:44 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 03:44 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 03:44 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 03:45 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:59 - 2012-06-14 03:44 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:58 - 2012-06-14 03:45 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:58 - 2012-06-14 03:44 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:56 - 2012-06-14 03:44 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 03:44 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 03:44 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 03:44 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 03:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 03:45 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 03:44 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 03:44 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 03:44 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 03:44 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 03:45 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 03:44 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 03:44 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 03:45 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 03:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 03:44 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 03:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 03:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 03:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 03:45 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 03:44 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 17:19 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 13:36 - 2011-10-31 08:00 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-05-11 13:36 - 2009-12-20 19:20 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-05-06 18:06 - 2010-05-24 08:01 - 00001007 ____A C:\Users\Barry Bloom.V2\Desktop\Bullzip PDF Printer.lnk
2012-05-04 03:06 - 2012-06-13 17:19 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 17:19 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 17:19 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 17:19 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-29 18:15 - 2012-04-29 18:15 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-04-27 21:32 - 2012-06-13 17:19 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-04-27 19:55 - 2012-06-13 17:19 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 18:22 - 2012-04-27 18:22 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-27 18:22 - 2012-04-27 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-27 18:22 - 2012-04-27 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-27 18:22 - 2011-09-21 08:15 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-27 18:20 - 2012-04-27 18:19 - 00908576 ____A (Sun Microsystems, Inc.) C:\Users\Barry Bloom\Downloads\jxpiinstall(1).exe
2012-04-25 21:41 - 2012-06-13 17:19 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 17:19 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 17:19 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 17:19 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 17:19 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 17:19 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 17:19 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 17:19 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 17:19 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-16 10:23 - 2012-02-17 15:04 - 00002044 ____A C:\Users\Public\Desktop\Adobe Acrobat X Standard.lnk
2012-04-15 15:03 - 2012-04-15 15:03 - 00001840 ____A C:\Users\Barry Bloom\Desktop\Spotify.lnk
2012-04-15 15:02 - 2012-04-15 15:02 - 00085272 ____A (Spotify Ltd) C:\Users\Barry Bloom\Downloads\SpotifySetup.exe
ZeroAccess:
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\@
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\L
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\n
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U\00000001.@
C:\Windows\Installer\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U\800000cb.@
ZeroAccess:
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\@
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\L
C:\Users\Barry Bloom\AppData\Local\{ac191d7a-bcc7-9b88-29df-07ad7d2ba41b}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3998.96 MB
Available physical RAM: 3253.5 MB
Total Pagefile: 3997.11 MB
Available Pagefile: 3253.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:282.08 GB) (Free:39.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:15.82 GB) (Free:2.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: () (Removable) (Total:0.94 GB) (Free:0.89 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 966 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 282 GB 200 MB
Partition 3 Primary 15 GB 282 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 282 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E RECOVERY NTFS Partition 15 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 965 MB 508 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 965 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-11 05:06
======================= End Of Log ==========================