Hello,
It seems I am one of the many having this problem. I have run FRST and pasted the log file and if somebody could assist it would be greatly appreciated.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 18-06-2012 02
Ran by SYSTEM at 19-06-2012 10:49:37
Running from F:\
Windows 7 Professional Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [292208 2010-06-03] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [487562 2010-08-19] (Creative Technology Ltd)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [136216 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [171032 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [170520 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [5954296 2011-12-16] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [403104 2011-12-16] (Acronis)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Docking Otter\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-03-30] (Google Inc.)
HKU\Docking Otter\...\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [218032 2006-09-10] (Macrovision Corporation)
HKU\Docking Otter\...\Run: [Spotify Web Helper] "C:\Users\Docking Otter\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [932528 2012-05-05] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.2
Startup: C:\Users\Docking Otter\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [812808 2011-12-16] (Acronis)
2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3450832 2012-01-13] (Acronis)
2 Atheros Bt&Wlan Coex Agent; C:\Program Files\Dell Wireless\Ath_CoexAgent.exe [151552 2010-05-24] (Atheros)
2 AtherosSvc; C:\Program Files\Dell Wireless\Bluetooth Suite\adminservice.exe [56480 2010-09-01] (Atheros Commnucations)
2 BBSvc; C:\Program Files\Microsoft\BingBar\7.1.362.0\BBSvc.exe [193816 2012-02-13] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files\Microsoft\BingBar\7.1.362.0\SeaPort.exe [240408 2012-02-13] (Microsoft Corporation.)
2 EFS; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [556544 2010-11-20] (Microsoft Corporation)
3 ehSched; C:\Windows\ehome\ehsched.exe [94720 2009-07-13] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 Fax; C:\Windows\System32\fxssvc.exe [523264 2010-11-20] (Microsoft Corporation)
2 HsfXAudioService; C:\Windows\system32\XAudio32.dll [417336 2010-05-10] (Conexant Systems, Inc.)
3 KeyIso; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [134144 2009-07-13] (Microsoft Corporation)
3 msiserver; C:\Windows\System32\msiexec.exe /V [73216 2010-11-20] (Microsoft Corporation)
3 Netlogon; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 RoxMediaDB12OEM; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe" [1116656 2010-09-03] (Sonic Solutions)
2 RoxWatch12; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-09-03] (Sonic Solutions)
3 RpcLocator; C:\Windows\System32\locator.exe [9216 2009-07-13] (Microsoft Corporation)
2 SamSs; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-05-02] (Skype Technologies)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2009-07-13] (Microsoft Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [317440 2010-11-20] (Microsoft Corporation)
2 sppsvc; C:\Windows\System32\sppsvc.exe [3179520 2010-11-20] (Microsoft Corporation)
3 StorSvc; C:\Windows\System32\storsvc.dll [16384 2009-07-13] (Microsoft Corporation)
2 syncagentsrv; "C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe" [5881968 2011-12-16] (Acronis)
4 TlntSvr; C:\Windows\System32\tlntsvr.exe [71680 2009-07-13] (Microsoft Corporation)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2009-07-13] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 vds; C:\Windows\System32\vds.exe [453632 2010-11-20] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1025536 2010-11-20] (Microsoft Corporation)
3 wbengine; "C:\Windows\system32\wbengine.exe" [1203200 2010-11-20] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
========================== Drivers (Whitelisted) =============
3 afcdp; C:\Windows\System32\DRIVERS\afcdp.sys [234752 2012-01-13] (Acronis)
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-07-07] (Atheros)
3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [257896 2010-07-07] (Atheros)
3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [26984 2010-07-07] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [178024 2010-07-07] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [47976 2010-09-01] (Atheros)
3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143336 2010-07-07] (Atheros)
3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [237416 2010-08-30] (Atheros)
0 fltsrv; C:\Windows\System32\DRIVERS\fltsrv.sys [77696 2012-01-13] (Acronis)
3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [988728 2010-05-09] (Conexant Systems, Inc.)
3 iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [41040 2009-07-13] (Intel Corp./ICP vortex GmbH)
2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [19384 2010-05-10] (Conexant)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
2 rimspci; C:\Windows\System32\DRIVERS\rimspe86.sys [47104 2009-07-01] (REDC)
2 risdpcie; C:\Windows\System32\DRIVERS\risdpe86.sys [49152 2009-06-30] (REDC)
3 rixdpcie; C:\Windows\system32\DRIVERS\rixdpe86.sys [38400 2009-07-04] (REDC)
3 ROOTMODEM; C:\Windows\System32\Drivers\RootMdm.sys [8192 2009-07-13] (Microsoft Corporation)
0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [766496 2012-01-13] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [609760 2012-01-13] (Acronis)
0 vididr; C:\Windows\System32\DRIVERS\vididr.sys [126144 2012-01-13] (Acronis)
0 vidsflt61; C:\Windows\System32\DRIVERS\vsflt61.sys [84544 2012-01-13] (Acronis)
2 XAudio; C:\Windows\System32\DRIVERS\XAudio32.sys [15416 2010-05-10] (Conexant Systems, Inc.)
3 PCDSRVC{E9D79540-57D5953E-06020101}_0; \??\c:\program files\dell support center\pcdsrvc.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-19 10:38 - 2012-06-19 10:49 - 00000000 ____D C:\FRST
2012-06-18 03:00 - 2012-06-18 03:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 02:55 - 2012-06-18 03:11 - 00000000 __SHD C:\Config.Msi
2012-06-18 02:39 - 2012-06-18 02:39 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-18 02:38 - 2012-06-18 02:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-17 09:21 - 2012-06-17 09:21 - 00000000 ____D C:\Users\All Users\F4D55F3B22BFB52F5A9914E5B4EB238B
2012-06-17 07:01 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-17 07:01 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-17 07:01 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-17 07:01 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-17 07:01 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-17 07:01 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-17 07:01 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-17 07:01 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-17 07:01 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-17 07:01 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-17 07:01 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-17 07:01 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-17 07:01 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-17 07:01 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-17 05:24 - 2012-05-14 17:05 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-17 05:24 - 2012-04-30 20:44 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-17 05:24 - 2012-04-27 19:17 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-17 05:24 - 2012-04-25 20:45 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-17 05:24 - 2012-04-25 20:45 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-17 05:24 - 2012-04-25 20:41 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-17 05:24 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-17 05:24 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-17 05:24 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-17 05:24 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-11 05:17 - 2012-06-11 05:17 - 00284727 ____N C:\Users\Docking Otter\Desktop\reason for transfer return Nick Zoll.jpeg
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2012-06-09 11:08 - 2012-06-09 13:41 - 00000000 ____D C:\Users\Docking Otter\Desktop\Mexico Esencia June 2012
2012-06-07 10:29 - 2012-06-07 10:29 - 00100352 ____N C:\Users\Docking Otter\Desktop\#28 - Des Soutar 2012.doc
2012-06-04 04:28 - 2012-06-04 04:28 - 00037461 ____A C:\Users\Docking Otter\Desktop\536048_10151890858273538_896670023_n.jpg
2012-06-01 09:06 - 2012-06-01 09:06 - 00000000 ____D C:\Users\Docking Otter\Desktop\AHAlife
2012-05-30 03:14 - 2012-05-30 03:14 - 00122396 ____A C:\Users\Docking Otter\Desktop\Invoice-168.pdf
2012-05-30 03:13 - 2012-05-30 03:14 - 00120329 ____A C:\Users\Docking Otter\Downloads\Invoice-168.pdf
2012-05-25 12:36 - 2012-05-25 12:44 - 00000000 ____D C:\Users\Docking Otter\Desktop\Steelhead Direct
============ 3 Months Modified Files and Folders ===============
2012-06-19 00:35 - 2011-03-07 06:24 - 00032156 ____A C:\Windows\setupact.log
2012-06-19 00:35 - 2011-01-26 20:30 - 2387890176 __ASH C:\hiberfil.sys
2012-06-19 00:35 - 2011-01-26 19:56 - 3183857664 __ASH C:\pagefile.sys
2012-06-19 00:35 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-19 00:33 - 2011-03-30 07:41 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-19 00:33 - 2011-02-15 05:40 - 00000000 ___RD C:\Users\Docking Otter\Dropbox
2012-06-19 00:33 - 2011-02-15 05:33 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Dropbox
2012-06-19 00:20 - 2011-03-15 06:00 - 02394432 ____A C:\Windows\ntbtlog.txt
2012-06-18 07:27 - 2012-01-10 15:31 - 00000000 __SHD C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}
2012-06-18 03:30 - 2011-02-02 02:58 - 00000422 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-06-18 03:11 - 2012-06-18 02:55 - 00000000 __SHD C:\Config.Msi
2012-06-18 03:08 - 2009-07-13 20:55 - 01215225 ____A C:\Windows\WindowsUpdate.log
2012-06-18 03:04 - 2011-03-07 04:37 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-18 03:00 - 2012-06-18 03:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 03:00 - 2011-01-26 18:45 - 00769174 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-18 03:00 - 2009-07-13 18:37 - 00000000 ___RD C:\Program Files
2012-06-18 02:56 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-18 02:56 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-18 02:51 - 2011-01-26 19:03 - 00000000 ____D C:\Users\All Users\Sonic
2012-06-18 02:48 - 2011-03-07 06:24 - 00009148 ____A C:\Windows\PFRO.log
2012-06-18 02:39 - 2012-06-18 02:39 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-18 02:39 - 2011-03-15 06:11 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-06-18 02:38 - 2012-06-18 02:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-18 01:34 - 2011-02-02 10:55 - 00000000 ____D C:\Users\Docking Otter\Documents\Outlook Files
2012-06-18 01:21 - 2011-03-30 07:41 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-17 09:35 - 2012-04-09 01:13 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-17 09:23 - 2012-04-09 01:13 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-06-17 09:23 - 2011-07-07 03:10 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-06-17 09:21 - 2012-06-17 09:21 - 00000000 ____D C:\Users\All Users\F4D55F3B22BFB52F5A9914E5B4EB238B
2012-06-17 09:21 - 2009-07-13 18:37 - 00000000 ___HD C:\ProgramData
2012-06-17 08:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2012-06-17 07:48 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
2012-06-17 07:23 - 2009-07-13 20:33 - 00461336 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-17 07:07 - 2011-02-02 03:02 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-17 07:03 - 2011-02-08 01:12 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-11 05:17 - 2012-06-11 05:17 - 00284727 ____N C:\Users\Docking Otter\Desktop\reason for transfer return Nick Zoll.jpeg
2012-06-09 13:41 - 2012-06-09 11:08 - 00000000 ____D C:\Users\Docking Otter\Desktop\Mexico Esencia June 2012
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2012-06-07 10:29 - 2012-06-07 10:29 - 00100352 ____N C:\Users\Docking Otter\Desktop\#28 - Des Soutar 2012.doc
2012-06-04 04:28 - 2012-06-04 04:28 - 00037461 ____A C:\Users\Docking Otter\Desktop\536048_10151890858273538_896670023_n.jpg
2012-06-04 00:10 - 2011-02-03 02:40 - 00000000 ____D C:\Users\Docking Otter\Desktop\Desktop stuff
2012-06-02 14:29 - 2011-02-09 08:46 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Skype
2012-06-01 09:06 - 2012-06-01 09:06 - 00000000 ____D C:\Users\Docking Otter\Desktop\AHAlife
2012-06-01 01:07 - 2012-02-29 05:17 - 00000000 ____D C:\Users\Docking Otter\Desktop\Hunting
2012-05-30 03:14 - 2012-05-30 03:14 - 00122396 ____A C:\Users\Docking Otter\Desktop\Invoice-168.pdf
2012-05-30 03:14 - 2012-05-30 03:13 - 00120329 ____A C:\Users\Docking Otter\Downloads\Invoice-168.pdf
2012-05-29 02:19 - 2012-02-20 09:26 - 00000000 ____D C:\Users\Docking Otter\Desktop\Alta Baby
2012-05-29 02:14 - 2011-02-02 11:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Spotify
2012-05-29 02:14 - 2011-02-02 11:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\Spotify
2012-05-25 12:44 - 2012-05-25 12:36 - 00000000 ____D C:\Users\Docking Otter\Desktop\Steelhead Direct
2012-05-17 15:11 - 2012-06-17 07:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-06-17 07:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-06-17 07:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-06-17 07:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-06-17 07:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-06-17 07:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-06-17 07:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-06-17 07:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-06-17 07:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:29 - 2012-06-17 07:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:27 - 2012-06-17 07:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-06-17 07:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-06-17 07:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-06-17 07:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-16 10:38 - 2011-02-02 10:12 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\Windows Live
2012-05-16 10:37 - 2012-05-16 10:37 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{AC501644-4945-4F39-8E11-0F35143A6BF8}
2012-05-16 10:37 - 2012-05-16 10:37 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{5BEEACE8-D917-47CF-97BE-6CC6845797F1}
2012-05-15 09:05 - 2012-05-15 09:05 - 02070873 ____A C:\Users\Docking Otter\Downloads\Egg Box Study 2012.docx
2012-05-15 04:04 - 2012-05-15 04:04 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{66D2ABC3-E4E6-4CFF-9E9D-EA2786AF86ED}
2012-05-15 04:04 - 2012-05-15 04:04 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{1E3F12FD-786D-4225-84D8-08650D306B1F}
2012-05-15 03:54 - 2009-07-13 18:37 - 00000000 ____D C:\Windows
2012-05-15 03:52 - 2011-01-26 19:11 - 00000000 ____D C:\Program Files\Windows Live
2012-05-15 03:40 - 2012-05-15 03:40 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{B59BFB71-7F7C-41B1-93FB-249E607C3B3F}
2012-05-14 17:05 - 2012-06-17 05:24 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-12 12:50 - 2012-05-12 12:50 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{43973BED-81A6-4C35-9939-305D1E120CC1}
2012-05-12 00:49 - 2011-02-02 02:58 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-05-11 07:25 - 2011-01-26 19:09 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-11 07:24 - 2009-07-13 23:50 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-07 07:12 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\NDF
2012-05-03 23:20 - 2009-07-13 20:53 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-04-30 20:44 - 2012-06-17 05:24 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:17 - 2012-06-17 05:24 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 10:34 - 2012-04-27 10:34 - 00000000 ____D C:\Program Files\Common Files\Skype
2012-04-27 10:34 - 2011-02-09 08:46 - 00000000 ___RD C:\Program Files\Skype
2012-04-27 10:34 - 2011-02-09 08:46 - 00000000 ____D C:\Users\All Users\Skype
2012-04-27 10:16 - 2011-03-30 07:41 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\Google
2012-04-27 10:15 - 2011-03-30 07:41 - 00000000 ____D C:\Program Files\Google
2012-04-25 20:45 - 2012-06-17 05:24 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-17 05:24 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-17 05:24 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 20:36 - 2012-06-17 05:24 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-06-17 05:24 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-06-17 05:24 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-20 03:34 - 2012-04-20 03:34 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{68FE5A7F-749D-42D9-8835-58F548C2BCE3}
2012-04-20 03:32 - 2012-04-20 03:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{6AE3FFF7-93E1-491E-8AC6-B4E387F93823}
2012-04-20 03:32 - 2012-04-20 03:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{28769253-8247-4D85-8439-F2475D73645D}
2012-04-20 03:28 - 2012-04-20 03:27 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{1D78714C-CD98-4548-BF3D-EE91E150C4DE}
2012-04-12 02:18 - 2011-06-20 06:56 - 00000000 ____D C:\Program Files\Common Files\Adobe
2012-04-11 07:06 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-04-10 00:52 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\LiveKernelReports
2012-04-07 03:26 - 2012-06-17 05:24 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-04 06:56 - 2011-03-15 06:11 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-30 20:39 - 2012-05-10 20:06 - 03968368 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-10 20:06 - 03913072 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 02:23 - 2012-05-10 20:06 - 01291632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 07:49 - 2012-03-28 07:49 - 00145920 ____A C:\Users\Docking Otter\Desktop\2013-calendar.doc
2012-03-23 10:16 - 2012-03-23 10:16 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Sonic Solutions
2012-03-22 06:17 - 2011-02-02 05:08 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\TeamViewer
ZeroAccess:
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\@
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\L
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\U
ZeroAccess:
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\@
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\L
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3036.36 MB
Available physical RAM: 2579.46 MB
Total Pagefile: 3034.65 MB
Available Pagefile: 2592.57 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.61 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:451.1 GB) (Free:375.01 GB) NTFS
3 Drive f: (NEW VOLUME) (Removable) (Total:0.47 GB) (Free:0.46 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:14.66 GB) (Free:8.83 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 1024 KB
Disk 1 Online 478 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
Partition 2 Primary 451 GB 14 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 14 GB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 477 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F NEW VOLUME FAT32 Removable 477 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-09 16:28
======================= End Of Log ==========================
It seems I am one of the many having this problem. I have run FRST and pasted the log file and if somebody could assist it would be greatly appreciated.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 18-06-2012 02
Ran by SYSTEM at 19-06-2012 10:49:37
Running from F:\
Windows 7 Professional Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [292208 2010-06-03] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM\...\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [487562 2010-08-19] (Creative Technology Ltd)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [136216 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [171032 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [170520 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [5954296 2011-12-16] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [403104 2011-12-16] (Acronis)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Docking Otter\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-03-30] (Google Inc.)
HKU\Docking Otter\...\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [218032 2006-09-10] (Macrovision Corporation)
HKU\Docking Otter\...\Run: [Spotify Web Helper] "C:\Users\Docking Otter\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [932528 2012-05-05] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.2
Startup: C:\Users\Docking Otter\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [812808 2011-12-16] (Acronis)
2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3450832 2012-01-13] (Acronis)
2 Atheros Bt&Wlan Coex Agent; C:\Program Files\Dell Wireless\Ath_CoexAgent.exe [151552 2010-05-24] (Atheros)
2 AtherosSvc; C:\Program Files\Dell Wireless\Bluetooth Suite\adminservice.exe [56480 2010-09-01] (Atheros Commnucations)
2 BBSvc; C:\Program Files\Microsoft\BingBar\7.1.362.0\BBSvc.exe [193816 2012-02-13] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files\Microsoft\BingBar\7.1.362.0\SeaPort.exe [240408 2012-02-13] (Microsoft Corporation.)
2 EFS; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [556544 2010-11-20] (Microsoft Corporation)
3 ehSched; C:\Windows\ehome\ehsched.exe [94720 2009-07-13] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 Fax; C:\Windows\System32\fxssvc.exe [523264 2010-11-20] (Microsoft Corporation)
2 HsfXAudioService; C:\Windows\system32\XAudio32.dll [417336 2010-05-10] (Conexant Systems, Inc.)
3 KeyIso; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [134144 2009-07-13] (Microsoft Corporation)
3 msiserver; C:\Windows\System32\msiexec.exe /V [73216 2010-11-20] (Microsoft Corporation)
3 Netlogon; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 RoxMediaDB12OEM; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe" [1116656 2010-09-03] (Sonic Solutions)
2 RoxWatch12; "C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe" [219632 2010-09-03] (Sonic Solutions)
3 RpcLocator; C:\Windows\System32\locator.exe [9216 2009-07-13] (Microsoft Corporation)
2 SamSs; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-05-02] (Skype Technologies)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2009-07-13] (Microsoft Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [317440 2010-11-20] (Microsoft Corporation)
2 sppsvc; C:\Windows\System32\sppsvc.exe [3179520 2010-11-20] (Microsoft Corporation)
3 StorSvc; C:\Windows\System32\storsvc.dll [16384 2009-07-13] (Microsoft Corporation)
2 syncagentsrv; "C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe" [5881968 2011-12-16] (Acronis)
4 TlntSvr; C:\Windows\System32\tlntsvr.exe [71680 2009-07-13] (Microsoft Corporation)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2009-07-13] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 vds; C:\Windows\System32\vds.exe [453632 2010-11-20] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1025536 2010-11-20] (Microsoft Corporation)
3 wbengine; "C:\Windows\system32\wbengine.exe" [1203200 2010-11-20] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
========================== Drivers (Whitelisted) =============
3 afcdp; C:\Windows\System32\DRIVERS\afcdp.sys [234752 2012-01-13] (Acronis)
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [37224 2010-07-07] (Atheros)
3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [257896 2010-07-07] (Atheros)
3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [26984 2010-07-07] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [178024 2010-07-07] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [47976 2010-09-01] (Atheros)
3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143336 2010-07-07] (Atheros)
3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [237416 2010-08-30] (Atheros)
0 fltsrv; C:\Windows\System32\DRIVERS\fltsrv.sys [77696 2012-01-13] (Acronis)
3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [988728 2010-05-09] (Conexant Systems, Inc.)
3 iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [41040 2009-07-13] (Intel Corp./ICP vortex GmbH)
2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [19384 2010-05-10] (Conexant)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
2 rimspci; C:\Windows\System32\DRIVERS\rimspe86.sys [47104 2009-07-01] (REDC)
2 risdpcie; C:\Windows\System32\DRIVERS\risdpe86.sys [49152 2009-06-30] (REDC)
3 rixdpcie; C:\Windows\system32\DRIVERS\rixdpe86.sys [38400 2009-07-04] (REDC)
3 ROOTMODEM; C:\Windows\System32\Drivers\RootMdm.sys [8192 2009-07-13] (Microsoft Corporation)
0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [766496 2012-01-13] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [609760 2012-01-13] (Acronis)
0 vididr; C:\Windows\System32\DRIVERS\vididr.sys [126144 2012-01-13] (Acronis)
0 vidsflt61; C:\Windows\System32\DRIVERS\vsflt61.sys [84544 2012-01-13] (Acronis)
2 XAudio; C:\Windows\System32\DRIVERS\XAudio32.sys [15416 2010-05-10] (Conexant Systems, Inc.)
3 PCDSRVC{E9D79540-57D5953E-06020101}_0; \??\c:\program files\dell support center\pcdsrvc.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-19 10:38 - 2012-06-19 10:49 - 00000000 ____D C:\FRST
2012-06-18 03:00 - 2012-06-18 03:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 02:55 - 2012-06-18 03:11 - 00000000 __SHD C:\Config.Msi
2012-06-18 02:39 - 2012-06-18 02:39 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-18 02:38 - 2012-06-18 02:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-17 09:21 - 2012-06-17 09:21 - 00000000 ____D C:\Users\All Users\F4D55F3B22BFB52F5A9914E5B4EB238B
2012-06-17 07:01 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-17 07:01 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-17 07:01 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-17 07:01 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-17 07:01 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-17 07:01 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-17 07:01 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-17 07:01 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-17 07:01 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-17 07:01 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-17 07:01 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-17 07:01 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-17 07:01 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-17 07:01 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-17 05:24 - 2012-05-14 17:05 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-17 05:24 - 2012-04-30 20:44 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-17 05:24 - 2012-04-27 19:17 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-17 05:24 - 2012-04-25 20:45 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-17 05:24 - 2012-04-25 20:45 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-17 05:24 - 2012-04-25 20:41 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-17 05:24 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-17 05:24 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-17 05:24 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-17 05:24 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-11 05:17 - 2012-06-11 05:17 - 00284727 ____N C:\Users\Docking Otter\Desktop\reason for transfer return Nick Zoll.jpeg
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2012-06-09 11:08 - 2012-06-09 13:41 - 00000000 ____D C:\Users\Docking Otter\Desktop\Mexico Esencia June 2012
2012-06-07 10:29 - 2012-06-07 10:29 - 00100352 ____N C:\Users\Docking Otter\Desktop\#28 - Des Soutar 2012.doc
2012-06-04 04:28 - 2012-06-04 04:28 - 00037461 ____A C:\Users\Docking Otter\Desktop\536048_10151890858273538_896670023_n.jpg
2012-06-01 09:06 - 2012-06-01 09:06 - 00000000 ____D C:\Users\Docking Otter\Desktop\AHAlife
2012-05-30 03:14 - 2012-05-30 03:14 - 00122396 ____A C:\Users\Docking Otter\Desktop\Invoice-168.pdf
2012-05-30 03:13 - 2012-05-30 03:14 - 00120329 ____A C:\Users\Docking Otter\Downloads\Invoice-168.pdf
2012-05-25 12:36 - 2012-05-25 12:44 - 00000000 ____D C:\Users\Docking Otter\Desktop\Steelhead Direct
============ 3 Months Modified Files and Folders ===============
2012-06-19 00:35 - 2011-03-07 06:24 - 00032156 ____A C:\Windows\setupact.log
2012-06-19 00:35 - 2011-01-26 20:30 - 2387890176 __ASH C:\hiberfil.sys
2012-06-19 00:35 - 2011-01-26 19:56 - 3183857664 __ASH C:\pagefile.sys
2012-06-19 00:35 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-19 00:33 - 2011-03-30 07:41 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-19 00:33 - 2011-02-15 05:40 - 00000000 ___RD C:\Users\Docking Otter\Dropbox
2012-06-19 00:33 - 2011-02-15 05:33 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Dropbox
2012-06-19 00:20 - 2011-03-15 06:00 - 02394432 ____A C:\Windows\ntbtlog.txt
2012-06-18 07:27 - 2012-01-10 15:31 - 00000000 __SHD C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}
2012-06-18 03:30 - 2011-02-02 02:58 - 00000422 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-06-18 03:11 - 2012-06-18 02:55 - 00000000 __SHD C:\Config.Msi
2012-06-18 03:08 - 2009-07-13 20:55 - 01215225 ____A C:\Windows\WindowsUpdate.log
2012-06-18 03:04 - 2011-03-07 04:37 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-18 03:00 - 2012-06-18 03:00 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 03:00 - 2011-01-26 18:45 - 00769174 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-18 03:00 - 2009-07-13 18:37 - 00000000 ___RD C:\Program Files
2012-06-18 02:56 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-18 02:56 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-18 02:51 - 2011-01-26 19:03 - 00000000 ____D C:\Users\All Users\Sonic
2012-06-18 02:48 - 2011-03-07 06:24 - 00009148 ____A C:\Windows\PFRO.log
2012-06-18 02:39 - 2012-06-18 02:39 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-18 02:39 - 2011-03-15 06:11 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-06-18 02:38 - 2012-06-18 02:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-18 01:34 - 2011-02-02 10:55 - 00000000 ____D C:\Users\Docking Otter\Documents\Outlook Files
2012-06-18 01:21 - 2011-03-30 07:41 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-17 09:35 - 2012-04-09 01:13 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-17 09:23 - 2012-04-09 01:13 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-06-17 09:23 - 2011-07-07 03:10 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-06-17 09:21 - 2012-06-17 09:21 - 00000000 ____D C:\Users\All Users\F4D55F3B22BFB52F5A9914E5B4EB238B
2012-06-17 09:21 - 2009-07-13 18:37 - 00000000 ___HD C:\ProgramData
2012-06-17 08:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2012-06-17 07:48 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
2012-06-17 07:23 - 2009-07-13 20:33 - 00461336 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-17 07:07 - 2011-02-02 03:02 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-17 07:03 - 2011-02-08 01:12 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-11 05:17 - 2012-06-11 05:17 - 00284727 ____N C:\Users\Docking Otter\Desktop\reason for transfer return Nick Zoll.jpeg
2012-06-09 13:41 - 2012-06-09 11:08 - 00000000 ____D C:\Users\Docking Otter\Desktop\Mexico Esencia June 2012
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2012-06-09 11:23 - 2012-06-09 11:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2012-06-07 10:29 - 2012-06-07 10:29 - 00100352 ____N C:\Users\Docking Otter\Desktop\#28 - Des Soutar 2012.doc
2012-06-04 04:28 - 2012-06-04 04:28 - 00037461 ____A C:\Users\Docking Otter\Desktop\536048_10151890858273538_896670023_n.jpg
2012-06-04 00:10 - 2011-02-03 02:40 - 00000000 ____D C:\Users\Docking Otter\Desktop\Desktop stuff
2012-06-02 14:29 - 2011-02-09 08:46 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Skype
2012-06-01 09:06 - 2012-06-01 09:06 - 00000000 ____D C:\Users\Docking Otter\Desktop\AHAlife
2012-06-01 01:07 - 2012-02-29 05:17 - 00000000 ____D C:\Users\Docking Otter\Desktop\Hunting
2012-05-30 03:14 - 2012-05-30 03:14 - 00122396 ____A C:\Users\Docking Otter\Desktop\Invoice-168.pdf
2012-05-30 03:14 - 2012-05-30 03:13 - 00120329 ____A C:\Users\Docking Otter\Downloads\Invoice-168.pdf
2012-05-29 02:19 - 2012-02-20 09:26 - 00000000 ____D C:\Users\Docking Otter\Desktop\Alta Baby
2012-05-29 02:14 - 2011-02-02 11:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Spotify
2012-05-29 02:14 - 2011-02-02 11:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\Spotify
2012-05-25 12:44 - 2012-05-25 12:36 - 00000000 ____D C:\Users\Docking Otter\Desktop\Steelhead Direct
2012-05-17 15:11 - 2012-06-17 07:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-06-17 07:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-06-17 07:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-06-17 07:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-06-17 07:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-06-17 07:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-06-17 07:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-06-17 07:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-06-17 07:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:29 - 2012-06-17 07:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:27 - 2012-06-17 07:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-06-17 07:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-06-17 07:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-06-17 07:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-16 10:38 - 2011-02-02 10:12 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\Windows Live
2012-05-16 10:37 - 2012-05-16 10:37 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{AC501644-4945-4F39-8E11-0F35143A6BF8}
2012-05-16 10:37 - 2012-05-16 10:37 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{5BEEACE8-D917-47CF-97BE-6CC6845797F1}
2012-05-15 09:05 - 2012-05-15 09:05 - 02070873 ____A C:\Users\Docking Otter\Downloads\Egg Box Study 2012.docx
2012-05-15 04:04 - 2012-05-15 04:04 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{66D2ABC3-E4E6-4CFF-9E9D-EA2786AF86ED}
2012-05-15 04:04 - 2012-05-15 04:04 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{1E3F12FD-786D-4225-84D8-08650D306B1F}
2012-05-15 03:54 - 2009-07-13 18:37 - 00000000 ____D C:\Windows
2012-05-15 03:52 - 2011-01-26 19:11 - 00000000 ____D C:\Program Files\Windows Live
2012-05-15 03:40 - 2012-05-15 03:40 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{B59BFB71-7F7C-41B1-93FB-249E607C3B3F}
2012-05-14 17:05 - 2012-06-17 05:24 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-12 12:50 - 2012-05-12 12:50 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{43973BED-81A6-4C35-9939-305D1E120CC1}
2012-05-12 00:49 - 2011-02-02 02:58 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-05-11 07:25 - 2011-01-26 19:09 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-11 07:24 - 2009-07-13 23:50 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-07 07:12 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\NDF
2012-05-03 23:20 - 2009-07-13 20:53 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-04-30 20:44 - 2012-06-17 05:24 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:17 - 2012-06-17 05:24 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 10:34 - 2012-04-27 10:34 - 00000000 ____D C:\Program Files\Common Files\Skype
2012-04-27 10:34 - 2011-02-09 08:46 - 00000000 ___RD C:\Program Files\Skype
2012-04-27 10:34 - 2011-02-09 08:46 - 00000000 ____D C:\Users\All Users\Skype
2012-04-27 10:16 - 2011-03-30 07:41 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\Google
2012-04-27 10:15 - 2011-03-30 07:41 - 00000000 ____D C:\Program Files\Google
2012-04-25 20:45 - 2012-06-17 05:24 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-17 05:24 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-17 05:24 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 20:36 - 2012-06-17 05:24 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-06-17 05:24 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-06-17 05:24 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-20 03:34 - 2012-04-20 03:34 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{68FE5A7F-749D-42D9-8835-58F548C2BCE3}
2012-04-20 03:32 - 2012-04-20 03:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{6AE3FFF7-93E1-491E-8AC6-B4E387F93823}
2012-04-20 03:32 - 2012-04-20 03:32 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{28769253-8247-4D85-8439-F2475D73645D}
2012-04-20 03:28 - 2012-04-20 03:27 - 00000000 ____D C:\Users\Docking Otter\AppData\Local\{1D78714C-CD98-4548-BF3D-EE91E150C4DE}
2012-04-12 02:18 - 2011-06-20 06:56 - 00000000 ____D C:\Program Files\Common Files\Adobe
2012-04-11 07:06 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-04-10 00:52 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\LiveKernelReports
2012-04-07 03:26 - 2012-06-17 05:24 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-04 06:56 - 2011-03-15 06:11 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-30 20:39 - 2012-05-10 20:06 - 03968368 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-10 20:06 - 03913072 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 02:23 - 2012-05-10 20:06 - 01291632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 07:49 - 2012-03-28 07:49 - 00145920 ____A C:\Users\Docking Otter\Desktop\2013-calendar.doc
2012-03-23 10:16 - 2012-03-23 10:16 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\Sonic Solutions
2012-03-22 06:17 - 2011-02-02 05:08 - 00000000 ____D C:\Users\Docking Otter\AppData\Roaming\TeamViewer
ZeroAccess:
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\@
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\L
C:\Windows\Installer\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\U
ZeroAccess:
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\@
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\L
C:\Users\Docking Otter\AppData\Local\{ae04cdd7-f7d8-50d2-cba8-af40938542a9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3036.36 MB
Available physical RAM: 2579.46 MB
Total Pagefile: 3034.65 MB
Available Pagefile: 2592.57 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.61 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:451.1 GB) (Free:375.01 GB) NTFS
3 Drive f: (NEW VOLUME) (Removable) (Total:0.47 GB) (Free:0.46 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:14.66 GB) (Free:8.83 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 1024 KB
Disk 1 Online 478 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
Partition 2 Primary 451 GB 14 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 14 GB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 477 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F NEW VOLUME FAT32 Removable 477 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-09 16:28
======================= End Of Log ==========================