oxygendeprived
Posts: 9 +0
Windows 7 32bit on Dell Inspiron 1520
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-08-2012
Ran by SYSTEM at 09-08-2012 20:10:51
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-04-27] (Synaptics, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-09-07] (IDT, Inc.)
HKLM\...\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.)
HKLM\...\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r [180224 2006-11-27] (Creative Technology Ltd)
HKLM\...\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [221184 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Derek\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [460784 2007-03-15] (Gteko Ltd.)
HKU\Derek\...\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKU\Derek\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\Derek\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-16] (Google Inc.)
HKU\Derek\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Derek\...\Policies\system: [LogonHoursAction] 2
HKU\Jenerek\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\Jenerek\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-16] (Google Inc.)
HKU\Jenerek\...\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2012-02-23] (Apple Inc.)
HKU\Jenerek\...\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2012-02-24] (Apple Inc.)
HKU\Jenerek\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Jenerek\...\Policies\system: [LogonHoursAction] 2
HKU\Jenerek\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\Derek\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Jenerek\Start Menu\Programs\Startup\BUFFALO NAS Navigator.lnk
ShortcutTarget: BUFFALO NAS Navigator.lnk -> C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe (BUFFALO INC.)
Startup: C:\Users\Jenerek\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Jenerek\Start Menu\Programs\Startup\NAS Scheduler.lnk
ShortcutTarget: NAS Scheduler.lnk -> C:\Program Files\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.)
================================ Services (Whitelisted) ==================
4 ADVService; "C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe" [25704 2009-09-03] (Amazon.com)
2 Creative Labs Licensing Service; "C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe" [72704 2007-08-22] (Creative Labs)
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2007-03-19] ()
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 gupdate1c9db10f55c84b8; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2009-05-22] (Google Inc.)
2 NasPmService; C:\Program Files\BUFFALO\NASNAVI\nassvc.exe -Service_Execute -dcyc=60 -dto=3 -dluc=0 -dmin=1 -dmax=60 -dflc=0 -apc=0 -log=0 -pm=1 -pall=1 -phttp=0 -pbc=0 -ppro=0 -pcyc=0 -pmin=1 -pmax=60 -pflc=0 [251184 2008-07-11] (BUFFALO INC.)
2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [201968 2008-08-13] (SupportSoft, Inc.)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
3 PS3 Media Server; "C:\Program Files\PS3 Media Server\win32\service\wrapper.exe" -s "C:\Program Files\PS3 Media Server\win32\service\wrapper.conf" [x]
========================== Drivers (Whitelisted) =============
3 dvd43llh; C:\Windows\System32\DRIVERS\dvd43llh.sys [18816 2010-02-19] (RIF)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 19:59 - 2012-08-09 20:00 - 00000000 ____D C:\FRST
2012-08-09 12:53 - 2012-08-09 12:53 - 00002222 ____A C:\Windows\PFRO.log
2012-08-09 12:36 - 2012-08-09 12:36 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Desktop\mseinstall.exe
2012-08-04 15:28 - 2012-08-04 15:28 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall (1).exe
2012-08-04 15:26 - 2012-08-04 15:26 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall.exe
2012-07-14 09:25 - 2012-07-14 09:29 - 131730073 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-core.m4v
2012-07-14 09:22 - 2012-07-14 09:24 - 67062420 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-cardio-tabata.m4v
2012-07-14 08:50 - 2012-07-14 09:22 - 816079684 ____A C:\Users\Jenerek\Desktop\cathe-crossfire.m4v
2012-07-11 06:53 - 2012-07-11 06:55 - 68540212 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-slide-n-glide-tabata.m4v
2012-07-11 06:50 - 2012-07-11 06:52 - 67404408 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-fitness-tabata.m4v
2012-07-11 06:28 - 2012-07-11 06:49 - 792734004 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max.m4v
2012-07-11 05:43 - 2012-07-11 06:27 - 792734004 ____A C:\Users\Jenerek\Downloads\cathe-to-the-max.m4v
2012-07-11 05:39 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 05:39 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 05:39 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 05:39 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 05:38 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 05:38 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 05:38 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 05:38 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 05:38 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 05:38 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 05:38 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 05:38 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 05:38 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 05:38 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 05:35 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 15:15 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 15:15 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 15:15 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 15:15 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 15:15 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 15:15 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 15:15 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 15:15 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 15:15 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 15:15 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-10 15:15 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-10 15:15 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-10 15:15 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
============ 3 Months Modified Files ========================
2012-08-09 17:38 - 2012-06-20 16:20 - 00178137 ____A C:\Windows\setupact.log
2012-08-09 17:38 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 17:35 - 2009-06-30 21:48 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-09 17:32 - 2010-11-13 09:20 - 00000418 _RASH C:\Users\All Users\ntuser.pol
2012-08-09 17:17 - 2010-04-18 20:46 - 00472576 __ASH C:\Users\Jenerek\Desktop\Thumbs.db
2012-08-09 12:53 - 2012-08-09 12:53 - 00002222 ____A C:\Windows\PFRO.log
2012-08-09 12:52 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 12:41 - 2010-11-13 09:15 - 01219819 ____A C:\Windows\WindowsUpdate.log
2012-08-09 12:41 - 2010-11-13 08:19 - 00011952 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 12:41 - 2010-11-13 08:19 - 00011952 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 12:40 - 2011-01-31 16:14 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 12:40 - 2010-11-13 08:21 - 00744406 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 12:36 - 2012-08-09 12:36 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Desktop\mseinstall.exe
2012-08-04 15:28 - 2012-08-04 15:28 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall (1).exe
2012-08-04 15:26 - 2012-08-04 15:26 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall.exe
2012-08-04 15:22 - 2012-04-13 16:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-04 15:22 - 2009-06-30 21:49 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-03 20:30 - 2009-09-05 14:08 - 00000334 ____A C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
2012-08-03 20:00 - 2008-09-07 20:57 - 00000316 ____A C:\Windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
2012-08-02 18:03 - 2012-04-13 16:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 18:03 - 2011-06-10 14:45 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-01 08:31 - 2009-07-13 20:53 - 00032578 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-14 09:29 - 2012-07-14 09:25 - 131730073 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-core.m4v
2012-07-14 09:24 - 2012-07-14 09:22 - 67062420 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-cardio-tabata.m4v
2012-07-14 09:22 - 2012-07-14 08:50 - 816079684 ____A C:\Users\Jenerek\Desktop\cathe-crossfire.m4v
2012-07-11 07:11 - 2009-07-13 20:33 - 00360288 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 06:55 - 2012-07-11 06:53 - 68540212 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-slide-n-glide-tabata.m4v
2012-07-11 06:52 - 2012-07-11 06:50 - 67404408 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-fitness-tabata.m4v
2012-07-11 06:49 - 2012-07-11 06:28 - 792734004 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max.m4v
2012-07-11 06:27 - 2012-07-11 05:43 - 792734004 ____A C:\Users\Jenerek\Downloads\cathe-to-the-max.m4v
2012-07-11 05:35 - 2011-01-10 14:59 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-29 06:38 - 2012-06-29 06:38 - 00109292 ____A C:\Users\Jenerek\Desktop\FIRE 4
2012-06-29 06:38 - 2012-06-29 06:38 - 00072776 ____A C:\Users\Jenerek\Desktop\fire 3
2012-06-29 06:37 - 2012-06-29 06:38 - 00084621 ____A C:\Users\Jenerek\Desktop\FIRE 2
2012-06-29 06:37 - 2012-06-29 06:37 - 00082504 ____A C:\Users\Jenerek\Desktop\Fire 1
2012-06-20 16:20 - 2012-06-20 16:20 - 00000000 ____A C:\Windows\setuperr.log
2012-06-15 20:56 - 2012-06-15 20:56 - 03862112 ____A (Piriform Ltd) C:\Users\Jenerek\Downloads\ccsetup319.exe
2012-06-11 18:40 - 2012-07-11 05:35 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-10 15:15 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-07 17:05 - 2012-01-21 11:42 - 00001029 ____A C:\Users\Jenerek\Desktop\Dropbox.lnk
2012-06-05 21:05 - 2012-07-10 15:15 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 15:15 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 15:15 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 16:25 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 16:25 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 16:25 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 13:19 - 2012-06-20 16:24 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 13:12 - 2012-06-20 16:24 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 05:38 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 05:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 05:38 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 05:38 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 05:38 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 05:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 05:38 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 05:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 05:38 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 05:39 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 05:38 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 05:39 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 05:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 05:39 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:45 - 2012-07-10 15:15 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 15:15 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 15:15 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 15:15 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 15:15 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-20 08:22 - 2011-07-22 18:54 - 00002479 ____A C:\Users\Public\Desktop\Safari.lnk
2012-05-20 08:21 - 2012-05-20 08:21 - 00001866 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
ZeroAccess:
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\@
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\L
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\n
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 21%
Total physical RAM: 2038.19 MB
Available physical RAM: 1601.74 MB
Total Pagefile: 2038.19 MB
Available Pagefile: 1615.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.6 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:136.44 GB) (Free:57.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:5.06 GB) NTFS
4 Drive f: () (Removable) (Total:1.86 GB) (Free:1.85 GB) FAT32
5 Drive g: (M-S325) (Removable) (Total:7.45 GB) (Free:3.46 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 1024 KB
Disk 1 Online 1908 MB 0 B
Disk 2 Online 7648 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 109 MB 31 KB
Partition 2 Primary 10 GB 110 MB
Partition 3 Primary 136 GB 10 GB
Partition 0 Extended 2560 MB 146 GB
Partition 4 Logical 2559 MB 146 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 109 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D RECOVERY NTFS Partition 10 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 136 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : DD
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1908 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 1908 MB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7647 MB 40 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G M-S325 FAT32 Removable 7647 MB Healthy
==================================================================================
Last Boot: 2012-07-28 15:26
======================= End Of Log ==========================
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-08-2012
Ran by SYSTEM at 09-08-2012 20:10:51
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-04-27] (Synaptics, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-09-07] (IDT, Inc.)
HKLM\...\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.)
HKLM\...\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r [180224 2006-11-27] (Creative Technology Ltd)
HKLM\...\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [221184 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Derek\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [460784 2007-03-15] (Gteko Ltd.)
HKU\Derek\...\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKU\Derek\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\Derek\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-16] (Google Inc.)
HKU\Derek\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Derek\...\Policies\system: [LogonHoursAction] 2
HKU\Jenerek\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\Jenerek\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-04-16] (Google Inc.)
HKU\Jenerek\...\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2012-02-23] (Apple Inc.)
HKU\Jenerek\...\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2012-02-24] (Apple Inc.)
HKU\Jenerek\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Jenerek\...\Policies\system: [LogonHoursAction] 2
HKU\Jenerek\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\Derek\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Jenerek\Start Menu\Programs\Startup\BUFFALO NAS Navigator.lnk
ShortcutTarget: BUFFALO NAS Navigator.lnk -> C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe (BUFFALO INC.)
Startup: C:\Users\Jenerek\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Jenerek\Start Menu\Programs\Startup\NAS Scheduler.lnk
ShortcutTarget: NAS Scheduler.lnk -> C:\Program Files\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.)
================================ Services (Whitelisted) ==================
4 ADVService; "C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe" [25704 2009-09-03] (Amazon.com)
2 Creative Labs Licensing Service; "C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe" [72704 2007-08-22] (Creative Labs)
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2007-03-19] ()
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 gupdate1c9db10f55c84b8; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2009-05-22] (Google Inc.)
2 NasPmService; C:\Program Files\BUFFALO\NASNAVI\nassvc.exe -Service_Execute -dcyc=60 -dto=3 -dluc=0 -dmin=1 -dmax=60 -dflc=0 -apc=0 -log=0 -pm=1 -pall=1 -phttp=0 -pbc=0 -ppro=0 -pcyc=0 -pmin=1 -pmax=60 -pflc=0 [251184 2008-07-11] (BUFFALO INC.)
2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [201968 2008-08-13] (SupportSoft, Inc.)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
3 PS3 Media Server; "C:\Program Files\PS3 Media Server\win32\service\wrapper.exe" -s "C:\Program Files\PS3 Media Server\win32\service\wrapper.conf" [x]
========================== Drivers (Whitelisted) =============
3 dvd43llh; C:\Windows\System32\DRIVERS\dvd43llh.sys [18816 2010-02-19] (RIF)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 19:59 - 2012-08-09 20:00 - 00000000 ____D C:\FRST
2012-08-09 12:53 - 2012-08-09 12:53 - 00002222 ____A C:\Windows\PFRO.log
2012-08-09 12:36 - 2012-08-09 12:36 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Desktop\mseinstall.exe
2012-08-04 15:28 - 2012-08-04 15:28 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall (1).exe
2012-08-04 15:26 - 2012-08-04 15:26 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall.exe
2012-07-14 09:25 - 2012-07-14 09:29 - 131730073 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-core.m4v
2012-07-14 09:22 - 2012-07-14 09:24 - 67062420 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-cardio-tabata.m4v
2012-07-14 08:50 - 2012-07-14 09:22 - 816079684 ____A C:\Users\Jenerek\Desktop\cathe-crossfire.m4v
2012-07-11 06:53 - 2012-07-11 06:55 - 68540212 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-slide-n-glide-tabata.m4v
2012-07-11 06:50 - 2012-07-11 06:52 - 67404408 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-fitness-tabata.m4v
2012-07-11 06:28 - 2012-07-11 06:49 - 792734004 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max.m4v
2012-07-11 05:43 - 2012-07-11 06:27 - 792734004 ____A C:\Users\Jenerek\Downloads\cathe-to-the-max.m4v
2012-07-11 05:39 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 05:39 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 05:39 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 05:39 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 05:38 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 05:38 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 05:38 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 05:38 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 05:38 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 05:38 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 05:38 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 05:38 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 05:38 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 05:38 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 05:35 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 15:15 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 15:15 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 15:15 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 15:15 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 15:15 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 15:15 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 15:15 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 15:15 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 15:15 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 15:15 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-10 15:15 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-10 15:15 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-10 15:15 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
============ 3 Months Modified Files ========================
2012-08-09 17:38 - 2012-06-20 16:20 - 00178137 ____A C:\Windows\setupact.log
2012-08-09 17:38 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 17:35 - 2009-06-30 21:48 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-09 17:32 - 2010-11-13 09:20 - 00000418 _RASH C:\Users\All Users\ntuser.pol
2012-08-09 17:17 - 2010-04-18 20:46 - 00472576 __ASH C:\Users\Jenerek\Desktop\Thumbs.db
2012-08-09 12:53 - 2012-08-09 12:53 - 00002222 ____A C:\Windows\PFRO.log
2012-08-09 12:52 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 12:41 - 2010-11-13 09:15 - 01219819 ____A C:\Windows\WindowsUpdate.log
2012-08-09 12:41 - 2010-11-13 08:19 - 00011952 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 12:41 - 2010-11-13 08:19 - 00011952 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 12:40 - 2011-01-31 16:14 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 12:40 - 2010-11-13 08:21 - 00744406 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 12:36 - 2012-08-09 12:36 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Desktop\mseinstall.exe
2012-08-04 15:28 - 2012-08-04 15:28 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall (1).exe
2012-08-04 15:26 - 2012-08-04 15:26 - 10288512 ____A (Microsoft Corporation) C:\Users\Jenerek\Downloads\mseinstall.exe
2012-08-04 15:22 - 2012-04-13 16:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-04 15:22 - 2009-06-30 21:49 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-03 20:30 - 2009-09-05 14:08 - 00000334 ____A C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
2012-08-03 20:00 - 2008-09-07 20:57 - 00000316 ____A C:\Windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
2012-08-02 18:03 - 2012-04-13 16:58 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 18:03 - 2011-06-10 14:45 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-01 08:31 - 2009-07-13 20:53 - 00032578 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-14 09:29 - 2012-07-14 09:25 - 131730073 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-core.m4v
2012-07-14 09:24 - 2012-07-14 09:22 - 67062420 ____A C:\Users\Jenerek\Desktop\cathe-crossfire-bonus-cardio-tabata.m4v
2012-07-14 09:22 - 2012-07-14 08:50 - 816079684 ____A C:\Users\Jenerek\Desktop\cathe-crossfire.m4v
2012-07-11 07:11 - 2009-07-13 20:33 - 00360288 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 06:55 - 2012-07-11 06:53 - 68540212 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-slide-n-glide-tabata.m4v
2012-07-11 06:52 - 2012-07-11 06:50 - 67404408 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max-bonus-fitness-tabata.m4v
2012-07-11 06:49 - 2012-07-11 06:28 - 792734004 ____A C:\Users\Jenerek\Desktop\cathe-to-the-max.m4v
2012-07-11 06:27 - 2012-07-11 05:43 - 792734004 ____A C:\Users\Jenerek\Downloads\cathe-to-the-max.m4v
2012-07-11 05:35 - 2011-01-10 14:59 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-29 06:38 - 2012-06-29 06:38 - 00109292 ____A C:\Users\Jenerek\Desktop\FIRE 4
2012-06-29 06:38 - 2012-06-29 06:38 - 00072776 ____A C:\Users\Jenerek\Desktop\fire 3
2012-06-29 06:37 - 2012-06-29 06:38 - 00084621 ____A C:\Users\Jenerek\Desktop\FIRE 2
2012-06-29 06:37 - 2012-06-29 06:37 - 00082504 ____A C:\Users\Jenerek\Desktop\Fire 1
2012-06-20 16:20 - 2012-06-20 16:20 - 00000000 ____A C:\Windows\setuperr.log
2012-06-15 20:56 - 2012-06-15 20:56 - 03862112 ____A (Piriform Ltd) C:\Users\Jenerek\Downloads\ccsetup319.exe
2012-06-11 18:40 - 2012-07-11 05:35 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-10 15:15 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-07 17:05 - 2012-01-21 11:42 - 00001029 ____A C:\Users\Jenerek\Desktop\Dropbox.lnk
2012-06-05 21:05 - 2012-07-10 15:15 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 15:15 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 15:15 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 16:25 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 16:25 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 16:25 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 16:25 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 13:19 - 2012-06-20 16:24 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 13:12 - 2012-06-20 16:24 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 05:38 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 05:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 05:38 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 05:38 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 05:38 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 05:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 05:38 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 05:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 05:38 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 05:39 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 05:38 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 05:39 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 05:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 05:39 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:45 - 2012-07-10 15:15 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 15:15 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 15:15 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 15:15 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 15:15 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-20 08:22 - 2011-07-22 18:54 - 00002479 ____A C:\Users\Public\Desktop\Safari.lnk
2012-05-20 08:21 - 2012-05-20 08:21 - 00001866 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
ZeroAccess:
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\@
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\L
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\n
C:\Windows\Installer\{59944ef7-5072-d7c8-acee-ac85cd4f94db}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 21%
Total physical RAM: 2038.19 MB
Available physical RAM: 1601.74 MB
Total Pagefile: 2038.19 MB
Available Pagefile: 1615.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.6 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:136.44 GB) (Free:57.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:5.06 GB) NTFS
4 Drive f: () (Removable) (Total:1.86 GB) (Free:1.85 GB) FAT32
5 Drive g: (M-S325) (Removable) (Total:7.45 GB) (Free:3.46 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 1024 KB
Disk 1 Online 1908 MB 0 B
Disk 2 Online 7648 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 109 MB 31 KB
Partition 2 Primary 10 GB 110 MB
Partition 3 Primary 136 GB 10 GB
Partition 0 Extended 2560 MB 146 GB
Partition 4 Logical 2559 MB 146 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 109 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D RECOVERY NTFS Partition 10 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 136 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : DD
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1908 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 1908 MB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7647 MB 40 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G M-S325 FAT32 Removable 7647 MB Healthy
==================================================================================
Last Boot: 2012-07-28 15:26
======================= End Of Log ==========================