Here we go...Logs, logs and more logs.
First the AdwCleaner[R1].txt log:
# AdwCleaner v1.801 - Logfile created 08/24/2012 at 13:03:50
# Updated 14/08/2012 by Xplode
# Operating system : Windows (TM) Vista Ultimate Service Pack 2 (64 bits)
# User : Main - COREI7
# Boot Mode : Normal
# Running from : J:\VI_TOOLS\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
Folder Found : C:\Users\Main\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Folder Found : C:\Users\Main\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Main\AppData\Roaming\Babylon
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\ProgramData\Premium
File Found : C:\Users\Main\AppData\Local\funmoods.crx
File Found : C:\Users\Main\AppData\Local\funmoods-speeddial.crx
File Found : C:\Users\Main\AppData\Roaming\Mozilla\Firefox\Profiles\ux83yb1u.default\searchplugins\Askcom.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Found : C:\user.js
***** [Registry] *****
Key Found : HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Babylon
Key Found : HKLM\SOFTWARE\bflixtoolbar
Key Found : HKLM\SOFTWARE\Classes\f
Key Found : HKLM\SOFTWARE\Classes\funmoodsApp.appCore
Key Found : HKLM\SOFTWARE\Classes\funmoodsApp.appCore.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Key Found : HKLM\SOFTWARE\Iminent
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
[x64] Key Found : HKCU\Software\Conduit
[x64] Key Found : HKLM\SOFTWARE\Classes\f
[x64] Key Found : HKLM\SOFTWARE\Classes\funmoodsApp.appCore
[x64] Key Found : HKLM\SOFTWARE\Classes\funmoodsApp.appCore.1
[x64] Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\funmoods
***** [Registre - GUID] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Found : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Found : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
[x64] Key Found : HKLM\SOFTWARE\Classes\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}
[x64] Key Found : HKLM\SOFTWARE\Classes\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0AtC0Fzz0B0FzytCyEyCyCtN0D0Tzu0CtBtCtCtN1L2XzutBtFtCtFtDtFtAtDtC&cr=604335370
-\\ Mozilla Firefox v14.0.1 (en-US)
Profile name : default
File : C:\Users\Main\AppData\Roaming\Mozilla\Firefox\Profiles\ux83yb1u.default\prefs.js
Found : user_pref("backup.old.browser.startup.homepage", "hxxp://search.babylon.com/?affID=110796&tt=3312_2&[...]
Found : user_pref("browser.babylon.HPOnNewTab", "");
Found : user_pref("browser.newtab.url", "hxxp://search.babylon.com/?affID=110796&tt=3312_2&babsrc=NT_ss&mntr[...]
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultenginename", "Search the web (Babylon)");
Found : user_pref("browser.search.order.1", "Search the web (Babylon)");
Found : user_pref("browser.search.selectedEngine", "Search the web (Babylon)");
Found : user_pref("extensions.BabylonToolbar.admin", false);
Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Found : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Found : user_pref("extensions.BabylonToolbar.excTlbr", false);
Found : user_pref("extensions.BabylonToolbar.id", "9e7f146600000000000090e6ba1f8bf8");
Found : user_pref("extensions.BabylonToolbar.instlDay", "15568");
Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Found : user_pref("extensions.BabylonToolbar.tlbrId", "tb9");
Found : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://
www.google.com/search?babsrc=TB_ggl&q=");
Found : user_pref("extensions.BabylonToolbar.vrsn", "1.6.4.6");
Found : user_pref("extensions.BabylonToolbar.vrsni", "1.6.4.6");
Found : user_pref("extensions.BabylonToolbar_i.babExt", "");
Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110796&tt=3312_2");
Found : user_pref("extensions.BabylonToolbar_i.newTab", true);
Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=110796&tt=3312_[...]
Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.4.610:54:30");
Found : user_pref("extensions.funmoods.aflt", "nv1");
Found : user_pref("extensions.funmoods.autoRvrt", false);
Found : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Found : user_pref("extensions.funmoods.cntry", "US");
Found : user_pref("extensions.funmoods.cv", "cv5");
Found : user_pref("extensions.funmoods.dfltLng", "");
Found : user_pref("extensions.funmoods.dfltSrch", true);
Found : user_pref("extensions.funmoods.dfltlng", "en");
Found : user_pref("extensions.funmoods.dfltsrch", true);
Found : user_pref("extensions.funmoods.dnsErr", true);
Found : user_pref("extensions.funmoods.envrmnt", "production");
Found : user_pref("extensions.funmoods.excTlbr", false);
Found : user_pref("extensions.funmoods.hdrMd5", "F3C2ADFE15F591416430C001CC606ACF");
Found : user_pref("extensions.funmoods.hmpg", true);
Found : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzuyEtN2[...]
Found : user_pref("extensions.funmoods.hrdid", "90E6BA1F8BF91466");
Found : user_pref("extensions.funmoods.id", "90E6BA1F8BF91466");
Found : user_pref("extensions.funmoods.instlDay", "15551");
Found : user_pref("extensions.funmoods.instlRef", "nv1");
Found : user_pref("extensions.funmoods.instlday", "15551");
Found : user_pref("extensions.funmoods.instlref", "nv1");
Found : user_pref("extensions.funmoods.isdcmntcmplt", true);
Found : user_pref("extensions.funmoods.keywordurl", "");
Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2210:12:23");
Found : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Found : user_pref("extensions.funmoods.newTab", true);
Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=nv1&chnl=nv1&cd=2XzuyEt[...]
Found : user_pref("extensions.funmoods.newtab", true);
Found : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=nv1&chnl=nv1&cd=2XzuyEt[...]
Found : user_pref("extensions.funmoods.prdct", "funmoods");
Found : user_pref("extensions.funmoods.prtnrId", "funmoods");
Found : user_pref("extensions.funmoods.prtnrid", "funmoods");
Found : user_pref("extensions.funmoods.savedVrsnTs", "1");
Found : user_pref("extensions.funmoods.sg", "none");
Found : user_pref("extensions.funmoods.smplGrp", "none");
Found : user_pref("extensions.funmoods.smplgrp", "none");
Found : user_pref("extensions.funmoods.srch", "");
Found : user_pref("extensions.funmoods.srchPrvdr", "Search");
Found : user_pref("extensions.funmoods.srchprvdr", "Search");
Found : user_pref("extensions.funmoods.tlbrId", "base");
Found : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=nv1&chnl=nv1&cd=2Xzuy[...]
Found : user_pref("extensions.funmoods.tlbrid", "base");
Found : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/?f=3&a=nv1&chnl=nv1&cd=2Xzuy[...]
Found : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
Found : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2210:12:23");
Found : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
Found : user_pref("extensions.funmoods.vrsnts", "1.5.23.2210:12:23");
Found : user_pref("extensions.funmoods.xpestat\\xpereportdata", "30-6-2012");
Found : user_pref("extensions.funmoods_i.newTab", true);
Found : user_pref("extensions.funmoods_i.smplGrp", "none");
Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2210:12:23");
Found : user_pref("keyword.URL", "hxxp://search.babylon.com/?affID=110796&tt=3312_2&babsrc=KW_ss&mntrId=9e7f[...]
-\\ Google Chrome v21.0.1180.83
File : C:\Users\Main\AppData\Local\Google\Chrome\User Data\Default\Preferences
Found : "homepage": "hxxp://search.babylon.com/?affID=110796&tt=3312_2&babsrc=HP_ss&mntrId=9e7f1466000[...]
Found : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=110796&tt=3312_2&babsrc=H[...]
Found : "name": "Funmoods",
Found : "update_url": "hxxp://funmoods.com/public/download/chrome/update.xml",
Found : "baseUrl": "hxxp://start.funmoods.com/results.php?",
Found : "update_url": "hxxp://update.funmoods.com/speeddial/update.xml?bu=st",
Found : "homepage": "hxxp://search.babylon.com/?affID=110796&tt=3312_2&babsrc=HP_ss&mntrId=9e7f1466000000[...]
Found : "urls_to_restore_on_startup": [ "hxxp://search.babylon.com/?affID=110796&tt=3312_2&babsrc=HP_s[...]
*************************
AdwCleaner[R1].txt - [13767 octets] - [24/08/2012 13:03:50]
########## EOF - C:\AdwCleaner[R1].txt - [13896 octets] ##########
Next the FRST.txt
Scan result of Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 24-08-2012 13:17:00
Running from F:\VI_TOOLS
Windows Vista (TM) Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM-x32\...\Run: [TurboV] "C:\Program Files\ASUS\TurboV\TurboV.exe" [5391872 2009-05-25] ()
HKLM-x32\...\Run: [PlexUtilities] "C:\Program Files (x86)\Plextor\PlexUTILITIES\PlexRadar.exe" [1746944 2009-05-15] ()
HKLM-x32\...\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1310720 2008-04-15] (Analog Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-03-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [296096 2012-07-21] (RealNetworks, Inc.)
HKLM-x32\...\Run: [combofix] C:\ComboFix\CF14863.3XE /c C:\ComboFix\Combobatch.bat [8272 2012-08-22] ()
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Main\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2009-11-20] (Hewlett-Packard Company)
HKU\Main\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Main\...\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\Main\...\Run: [HydraVisionMDEngine] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD.exe" [569344 2010-08-03] (AMD)
HKU\Main\...\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [393216 2010-08-03] (AMD)
HKU\Main\...\Run: [Grid] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe" [401408 2010-08-03] ()
HKLM-x32\...\Runonce: [combofix] C:\ComboFix\CF14863.3XE /c C:\ComboFixCombobatch.bat [x]
HKLM-x32\...\runonceex: [flags] 8
HKLM\...\Winlogon: [Userinit] C:\Windows\explorer.exe, [3079168 2009-04-10] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
AppInit_DLLs: C:\Windows\System32\guard64.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files (x86)\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
Startup: C:\Users\Main\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Main\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 AEADIFilters; C:\Windows\System32\AEADISRV.EXE [111616 2008-07-14] (Andrea Electronics Corporation)
2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-04-01] ()
2 MDES; C:\ASUS.SYS\CONFIG\DVMExportService.exe [315392 2009-02-18] (DeviceVM)
2 Net Driver HPZ12; C:\Windows\System32\svchost.exe -k HPZ12 [27648 2008-01-20] (Microsoft Corporation)
2 Net Driver HPZ12; C:\Windows\SysWow64\svchost.exe -k HPZ12 [21504 2008-01-20] (Microsoft Corporation)
3 NtmsSvc; C:\Windows\System32\ntmssvc.dll [521216 2008-01-20] (Microsoft Corporation)
2 Pml Driver HPZ12; C:\Windows\System32\svchost.exe -k HPZ12 [27648 2008-01-20] (Microsoft Corporation)
2 Pml Driver HPZ12; C:\Windows\SysWow64\svchost.exe -k HPZ12 [21504 2008-01-20] (Microsoft Corporation)
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
3 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]
========================== Drivers (Whitelisted) =============
3 ADIHdAudAddService; C:\Windows\System32\drivers\ADIHdAud.sys [472576 2008-08-20] (Analog Devices, Inc.)
1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))
3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13368 2009-04-05] ()
0 mrdd; C:\Windows\System32\Drivers\mrdd.sys [22568 2008-11-11] (Marvell Semiconductor, Inc.)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-10-31] ()
0 mv61xx; C:\Windows\System32\Drivers\mv61xx.sys [176680 2009-02-08] (Marvell Semiconductor, Inc.)
1 Beep; [x]
3 catchme; [x]
2 cpuz132; [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
1 isjarjoc; [x]
3 MozillaMaintenance; [x]
3 NAVENG; [x]
3 NAVEX15; [x]
2 Norton Internet Security; [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
1 SRTSP; [x]
1 SRTSPX; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-24 11:03 - 2012-08-24 11:03 - 00013836 ____A C:\AdwCleaner[R1].txt
2012-08-23 06:21 - 2012-08-23 06:21 - 00000000 ____D C:\Program Files (x86)\ESET
2012-08-22 13:55 - 2012-08-24 07:06 - 00000000 ___SD C:\ComboFix
2012-08-22 12:10 - 2012-08-22 12:10 - 00000000 ____D C:\Program Files\COMODO
2012-08-21 07:21 - 2012-08-21 07:21 - 00020606 ____A C:\HitmanPro_20120821_0921.log
2012-08-21 07:14 - 2012-08-21 07:14 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-08-17 09:17 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-08-17 09:17 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-08-17 09:17 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-08-17 09:17 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-08-17 09:17 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-08-17 09:17 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-08-17 09:17 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-08-17 09:17 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-08-17 08:43 - 2012-08-22 12:06 - 00000000 ____D C:\Users\All Users\CPA_VA
2012-08-17 08:42 - 2012-08-17 08:42 - 00000000 ____D C:\Users\Public\Documents\COMODO
2012-08-17 08:40 - 2012-08-17 09:11 - 00505232 ____A C:\Windows\System32\Drivers\sfi.dat
2012-08-17 07:36 - 2012-08-17 07:36 - 01700352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2012-08-17 07:36 - 2012-08-17 07:36 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2012-08-16 09:34 - 2012-08-16 09:34 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eumxhleh.sys
2012-08-16 09:29 - 2012-08-16 09:29 - 00000000 ____D C:\$WINDOWS.~BT
2012-08-16 09:28 - 2012-08-16 09:28 - 00001887 ____A C:\Windows\diagwrn.xml
2012-08-16 09:28 - 2012-08-16 09:28 - 00001887 ____A C:\Windows\diagerr.xml
2012-08-16 09:24 - 2012-08-16 09:24 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\gugoewef.sys
2012-08-16 09:19 - 2012-08-16 09:19 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2012-08-16 09:13 - 2012-08-16 09:13 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\earqytlr.sys
2012-08-16 09:08 - 2012-08-16 09:44 - 00000000 ____D C:\FRST
2012-08-16 08:54 - 2012-08-16 08:54 - 00000304 ____A C:\user.js
2012-08-16 08:41 - 2012-08-16 08:41 - 00000000 ____D C:\Users\Main\AppData\Roaming\Babylon
2012-08-16 08:41 - 2012-08-16 08:41 - 00000000 ____D C:\Users\All Users\Babylon
2012-08-15 07:16 - 2012-08-17 09:09 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 13:50 - 2012-08-20 05:14 - 00000000 ____D C:\Users\Main\Documents\My Digital Editions
2012-08-09 13:48 - 2012-08-09 13:48 - 00001784 ____A C:\Users\Main\Desktop\RawFoodQuickandEasyOver100HealthyReci9781578263479.acsm
2012-08-06 15:03 - 2012-08-06 15:09 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-08-06 15:03 - 2012-08-06 15:03 - 00000000 ____D C:\Users\Main\AppData\Roaming\SpeedyPC Software
2012-08-06 15:03 - 2012-08-06 15:03 - 00000000 ____D C:\Users\Main\AppData\Roaming\DriverCure
2012-08-05 16:29 - 2012-08-22 14:00 - 00000000 ____D C:\Qoobox
2012-08-05 16:29 - 2012-08-18 10:12 - 00000000 ____D C:\Windows\erdnt
2012-08-05 14:12 - 2012-08-05 14:12 - 00000000 ____D C:\Windows\pss
2012-08-01 09:41 - 2012-08-01 09:41 - 00000043 ____A C:\Windows\DAOCONV.T2C
2012-08-01 09:29 - 2012-08-01 09:41 - 00000000 ____D C:\Program Files (x86)\HT Audio
2012-08-01 09:29 - 2012-08-01 09:29 - 00000043 ____A C:\Windows\DAOCONV.T1C
2012-08-01 09:29 - 1998-08-26 13:26 - 01045776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msjet35.dll
2012-08-01 09:29 - 1998-08-11 15:28 - 00407312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrepl35.dll
2012-08-01 09:29 - 1997-08-29 12:14 - 00270344 ____A () C:\Windows\SysWOW64\Btn32x10.ocx
2012-08-01 09:29 - 1997-07-19 14:55 - 01347344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSVBVM50.DLL
2012-08-01 09:29 - 1997-07-19 14:01 - 00196880 ____N (Microsoft Corporation) C:\Windows\SysWOW64\RICHTX32.OCX
2012-08-01 09:29 - 1997-07-19 14:01 - 00192784 ____N (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX
2012-08-01 09:29 - 1997-01-23 22:00 - 00078608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\VB5DB.DLL
2012-08-01 09:29 - 1997-01-13 15:18 - 00037136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSJINT35.DLL
2012-08-01 09:29 - 1996-12-04 22:00 - 00077824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ODBCTL32.DLL
2012-08-01 09:29 - 1996-12-02 16:44 - 00251664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSRD2X35.DLL
2012-08-01 09:29 - 1996-12-02 16:44 - 00024336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSJTER35.DLL
2012-08-01 09:29 - 1996-01-11 22:00 - 00200704 ____R (Sheridan Software Systems, Inc.) C:\Windows\SysWOW64\THREED32.OCX
2012-08-01 08:15 - 2012-08-01 08:15 - 00000000 ____D C:\Users\Main\AppData\Roaming\YourFileDownloader
2012-07-30 09:42 - 2012-08-16 09:28 - 00001155 ____A C:\Windows\setupact.log
2012-07-30 09:42 - 2012-08-16 09:28 - 00000000 ____A C:\Windows\setuperr.log
2012-07-30 09:03 - 2012-07-30 09:03 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-30 08:43 - 2012-07-30 08:43 - 00000000 ____D C:\Users\Main\AppData\Roaming\WinZip
2012-07-30 08:38 - 2012-07-30 08:39 - 00000000 ____D C:\Users\Main\AppData\Local\WinZip
2012-07-30 08:12 - 2012-07-30 08:12 - 00384844 ____A C:\Users\Main\AppData\Local\funmoods-speeddial.crx
2012-07-30 08:12 - 2012-07-30 08:12 - 00031465 ____A C:\Users\Main\AppData\Local\funmoods.crx
2012-07-27 17:38 - 2012-07-31 12:57 - 00000000 ____D C:\Woodworking
2012-07-26 08:12 - 2012-07-26 08:12 - 04064688 ____A C:\Users\Main\Desktop\Beginning_Game_Level_Design.rar
============ 3 Months Modified Files ========================
2012-08-24 11:05 - 2008-01-20 17:53 - 01874307 ____A C:\Windows\WindowsUpdate.log
2012-08-24 11:05 - 2006-11-02 07:40 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-24 11:05 - 2006-11-02 07:40 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-24 11:05 - 2006-11-02 07:21 - 00003712 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-24 11:05 - 2006-11-02 07:21 - 00003712 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-24 11:05 - 2006-11-02 04:46 - 00707430 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-24 11:03 - 2012-08-24 11:03 - 00013836 ____A C:\AdwCleaner[R1].txt
2012-08-24 10:37 - 2012-07-24 10:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-24 10:23 - 2010-02-11 14:04 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-24 10:22 - 2010-02-11 14:04 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-24 08:45 - 2010-03-30 03:24 - 00000426 _RASH C:\Users\Main\ntuser.pol
2012-08-23 12:43 - 2009-05-13 08:53 - 00001194 ____A C:\Windows\WINSET32.INI
2012-08-23 11:00 - 2010-01-10 11:52 - 00029184 ____A C:\Users\Main\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-22 14:19 - 2009-12-05 18:54 - 00000177 ____H C:\dvmexp.idx
2012-08-22 14:09 - 2006-11-02 07:39 - 00193006 ____A C:\Windows\PFRO.log
2012-08-21 07:21 - 2012-08-21 07:21 - 00020606 ____A C:\HitmanPro_20120821_0921.log
2012-08-17 10:25 - 2006-11-02 04:34 - 00000215 ____A C:\Windows\system.ini
2012-08-17 09:11 - 2012-08-17 08:40 - 00505232 ____A C:\Windows\System32\Drivers\sfi.dat
2012-08-17 09:09 - 2012-08-15 07:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-17 07:36 - 2012-08-17 07:36 - 01700352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2012-08-17 07:36 - 2012-08-17 07:36 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2012-08-16 09:34 - 2012-08-16 09:34 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eumxhleh.sys
2012-08-16 09:28 - 2012-08-16 09:28 - 00001887 ____A C:\Windows\diagwrn.xml
2012-08-16 09:28 - 2012-08-16 09:28 - 00001887 ____A C:\Windows\diagerr.xml
2012-08-16 09:28 - 2012-07-30 09:42 - 00001155 ____A C:\Windows\setupact.log
2012-08-16 09:28 - 2012-07-30 09:42 - 00000000 ____A C:\Windows\setuperr.log
2012-08-16 09:24 - 2012-08-16 09:24 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\gugoewef.sys
2012-08-16 09:13 - 2012-08-16 09:13 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\earqytlr.sys
2012-08-16 08:54 - 2012-08-16 08:54 - 00000304 ____A C:\user.js
2012-08-15 07:14 - 2012-02-16 20:15 - 00725714 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-14 22:38 - 2012-04-01 16:15 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-14 22:38 - 2011-05-24 10:50 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-09 13:48 - 2012-08-09 13:48 - 00001784 ____A C:\Users\Main\Desktop\RawFoodQuickandEasyOver100HealthyReci9781578263479.acsm
2012-08-06 15:04 - 2010-12-02 08:19 - 00000539 ____A C:\Users\Main\AppData\Roaming\Rim.Desktop.Exception.log
2012-08-06 07:07 - 2012-03-30 07:53 - 00000069 ____A C:\Windows\NeroDigital.ini
2012-08-06 07:07 - 2011-11-02 03:48 - 00000145 ____A C:\Users\Main\AppData\Roaming\default.rss
2012-08-01 14:42 - 2009-12-05 18:11 - 00099904 ____A C:\Users\Main\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-01 14:42 - 2006-11-02 07:21 - 00379200 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-01 09:41 - 2012-08-01 09:41 - 00000043 ____A C:\Windows\DAOCONV.T2C
2012-08-01 09:29 - 2012-08-01 09:29 - 00000043 ____A C:\Windows\DAOCONV.T1C
2012-08-01 08:01 - 2010-01-24 06:00 - 00000680 ____A C:\Users\Main\AppData\Local\d3d9caps.dat
2012-07-30 09:42 - 2009-12-05 18:11 - 00001460 ____A C:\Users\Main\AppData\Local\d3d9caps64.dat
2012-07-30 08:12 - 2012-07-30 08:12 - 00384844 ____A C:\Users\Main\AppData\Local\funmoods-speeddial.crx
2012-07-30 08:12 - 2012-07-30 08:12 - 00031465 ____A C:\Users\Main\AppData\Local\funmoods.crx
2012-07-26 08:12 - 2012-07-26 08:12 - 04064688 ____A C:\Users\Main\Desktop\Beginning_Game_Level_Design.rar
2012-07-21 12:27 - 2012-07-21 12:27 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2012-07-21 12:27 - 2012-07-21 12:27 - 00198864 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2012-07-21 12:27 - 2012-07-21 12:27 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2012-07-21 12:27 - 2012-07-21 12:27 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2012-07-21 12:27 - 2010-04-29 01:47 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2012-07-21 12:27 - 2010-04-29 01:47 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2012-07-11 01:06 - 2006-11-02 04:34 - 00002983 ____A C:\Windows\win.ini
2012-07-11 01:03 - 2006-11-02 04:35 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-28 13:13 - 2009-12-21 11:51 - 00375794 ____A C:\Users\Main\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
2012-06-28 13:13 - 2009-12-21 11:51 - 00323086 ____A C:\Users\Main\AppData\Local\dd_dotnetfx35install.txt
2012-06-13 05:58 - 2012-07-11 01:01 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 05:57 - 2012-06-12 05:57 - 14771880 ____A C:\Users\Main\Documents\cam.zip
2012-06-08 09:59 - 2012-07-10 20:29 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 09:47 - 2012-07-10 20:29 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 08:47 - 2012-07-10 20:29 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 08:47 - 2012-07-10 20:29 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 08:22 - 2012-07-10 20:29 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 08:22 - 2012-07-10 20:29 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-04 07:29 - 2012-07-10 20:29 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-21 14:51 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 14:51 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 14:51 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-21 14:51 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 14:51 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 14:51 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-21 14:51 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-21 14:51 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 14:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-21 14:51 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 13:19 - 2012-06-21 14:51 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 13:19 - 2012-06-21 14:51 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 13:15 - 2012-06-21 14:51 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 13:12 - 2012-06-21 14:51 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-02 04:49 - 2012-07-11 01:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 01:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 01:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 01:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 01:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 01:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 01:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 01:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 01:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 01:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 01:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 01:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 01:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 01:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 01:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 01:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 01:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 01:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 01:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 01:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 01:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 01:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 01:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 01:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 01:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 01:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 01:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 01:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 16:22 - 2012-07-10 20:29 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:22 - 2012-07-10 20:29 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:05 - 2012-07-10 20:29 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 16:04 - 2012-07-10 20:29 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 16:03 - 2012-07-10 20:29 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-05-31 10:25 - 2009-12-21 11:54 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 6134.18 MB
Available physical RAM: 5294.03 MB
Total Pagefile: 5800.35 MB
Available Pagefile: 5257.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:1397.26 GB) (Free:968.9 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (FRMCXFRE_EN_DVD) (CDROM) (Total:3.66 GB) (Free:0 GB) UDF
3 Drive e: (UDISK) (Removable) (Total:1.89 GB) (Free:0.26 GB) FAT32
4 Drive f: (SWISSMEMORY) (Removable) (Total:0.49 GB) (Free:0.28 GB) FAT
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 1397 GB 0 B
Disk 1 Online 1944 MB 0 B
Disk 2 Online 499 MB 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1944 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E UDISK FAT32 Removable 1944 MB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 498 MB 16 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F SWISSMEMORY FAT Removable 498 MB Healthy
==================================================================================
Last Boot: 2012-08-24 02:25
======================= End Of Log ==========================
Now the search.txt log for userinit.exe
Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 2012-08-24 14:00:19
Running from F:\VI_TOOLS
================== Search: "userinit.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008-01-20 18:49] - [2008-01-20 18:49] - 0025088 ____A (Microsoft Corporation) 0E135526E9785D085BCD9AEDE6FBCBF9
C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
[2008-01-20 18:48] - [2008-01-20 18:48] - 0028160 ____A (Microsoft Corporation) A0AB2BB9A92293D9CE66E252719AB5FE
C:\Windows\SysWOW64\userinit.exe
[2008-01-20 18:49] - [2008-01-20 18:49] - 0025088 ____A (Microsoft Corporation) 0E135526E9785D085BCD9AEDE6FBCBF9
C:\Windows\System32\userinit.exe
[2008-01-20 18:48] - [2008-01-20 18:48] - 0028160 ____A (Microsoft Corporation) A0AB2BB9A92293D9CE66E252719AB5FE
C:\Windows\erdnt\cache86\userinit.exe
[2012-08-17 10:31] - [2008-01-20 18:49] - 0025088 ____N (Microsoft Corporation) 0E135526E9785D085BCD9AEDE6FBCBF9
C:\Windows\erdnt\cache64\userinit.exe
[2012-08-17 10:31] - [2008-01-20 18:48] - 0028160 ____A (Microsoft Corporation) A0AB2BB9A92293D9CE66E252719AB5FE
====== End Of Search ======