Faizal Aboo
Posts: 42 +0
Hi ...
So it appears I've fallen victim to what I think is SIREFEF (I think that is what its called); my MSE didn't initially pick it up; as soon as it did pick it up my PC started shutting/restarting. I've managed to access my PC and do a scan with FRST; I shall post the logs of the scan below and the search for "services.exe" - I hope this helps and I hope to be helped too. I wish to thank the helper(s) in advance for their esteemed assistance.
============ One Month Created Files and Folders ==============
2012-08-16 17:37 - 2012-08-16 17:37 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-16 17:05 - 2012-08-16 17:05 - 00136384 ____A C:\Windows\Minidump\Mini081712-01.dmp
2012-08-16 17:05 - 2012-08-16 17:05 - 00000000 ____D C:\Windows\Minidump
2012-08-16 17:04 - 2012-08-16 17:04 - 119874748 ____A C:\Windows\MEMORY.DMP
2012-08-16 16:11 - 2012-08-16 17:31 - 00000000 ____D C:\Windows\pss
2012-08-16 15:27 - 2012-08-16 15:27 - 00000000 ____D C:\Program Files\Microsoft Security Client(2)
2012-08-16 15:16 - 2012-08-16 15:18 - 10288512 ____A (Microsoft Corporation) C:\Users\Faizy\Downloads\mseinstall.exe
2012-08-15 15:27 - 2012-08-15 16:25 - 00000000 ____D C:\Users\Faizy\Desktop\Body of Proof
2012-08-14 13:59 - 2012-08-16 15:04 - 00000000 ____D C:\Users\Faizy\Desktop\YUMNA INS
2012-08-14 13:36 - 2012-08-16 14:18 - 00000000 ____D C:\Users\Faizy\Desktop\Yumna 2
2012-08-14 12:50 - 2012-08-14 12:54 - 00009455 ____A C:\Users\Faizy\Documents\Yumna.xlsx
2012-08-13 15:19 - 2012-08-13 15:19 - 00000000 ____D C:\Users\Faizy\Documents\Daniusoft Digital Music Converter
2012-08-13 15:02 - 2012-08-13 15:03 - 00000000 ____D C:\Users\Faizy\Documents\Aimersoft DRM Media Converter
2012-08-13 14:59 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(5).sys
2012-08-13 14:57 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(4).sys
2012-08-13 14:55 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(3).sys
2012-08-13 14:53 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(2).sys
2012-08-13 14:53 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(1).sys
2012-08-13 14:16 - 2012-08-13 14:16 - 00000000 ____D C:\Program Files\NirSoft
2012-08-13 13:48 - 2012-08-13 13:48 - 00001842 ____A C:\Users\Public\Desktop\InterVideo WinDVD Creator 2.lnk
2012-08-13 13:48 - 2012-08-13 13:48 - 00000000 ____D C:\Program Files\InterVideo
2012-08-13 13:48 - 2001-12-10 07:42 - 00204800 ____A C:\Windows\System32\IVIresizeW7.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00200704 ____A C:\Windows\System32\IVIresizeA6.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00192512 ____A C:\Windows\System32\IVIresizeP6.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00192512 ____A C:\Windows\System32\IVIresizeM6.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00188416 ____A C:\Windows\System32\IVIresizePX.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00020480 ____A C:\Windows\System32\IVIresize.dll
2012-08-13 13:24 - 2012-08-13 13:25 - 00000000 ____D C:\Users\Faizy\AppData\Roaming\Corel
2012-08-13 13:24 - 2012-08-13 13:25 - 00000000 ____D C:\Users\All Users\Protexis
2012-08-13 13:23 - 2012-08-13 13:23 - 00000000 ____D C:\Users\Faizy\Corel
2012-08-13 13:22 - 2012-08-13 13:22 - 00000040 ___AH C:\Windows\System32\ivireg.ivr
2012-08-13 13:22 - 2012-08-13 13:22 - 00000000 ____D C:\Users\All Users\Corel
2012-08-13 13:22 - 2012-08-13 13:22 - 00000000 ____D C:\Program Files\Common Files\Protexis
2012-08-13 13:21 - 2012-08-13 13:21 - 00001770 ____A C:\Users\Public\Desktop\Corel WinDVD Pro 11.lnk
2012-08-13 13:21 - 2012-08-13 13:21 - 00000000 ____D C:\Program Files\Corel
2012-08-13 13:21 - 2010-11-16 06:24 - 00013880 ____A (InterVideo) C:\Windows\System32\Drivers\regi.sys
2012-08-13 13:20 - 2006-02-02 22:43 - 02332368 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_29.dll
2012-08-13 12:53 - 2012-08-13 13:19 - 123908088 ____A (Acresso Software Inc.) C:\Users\Faizy\Downloads\WinDVD11_Pro_TBYB.exe
2012-08-11 18:02 - 2012-08-11 18:02 - 00002065 ____A C:\Users\Faizy\Desktop\DStv Desktop Player BETA.lnk
2012-08-09 15:18 - 2012-08-09 15:46 - 00000000 ____D C:\Users\Faizy\Desktop\For Fuji
2012-08-09 14:38 - 2012-08-13 13:13 - 00009600 ____A C:\Users\Faizy\Documents\cubics.xlsx
2012-08-09 14:29 - 2012-08-09 17:17 - 297564076 ____A C:\Users\Faizy\Desktop\Batman.The.Dark.Knight.2008.1080p.BluRay_high.mp4
2012-08-08 11:35 - 2012-08-08 11:51 - 00000000 ____D C:\Users\Faizy\Desktop\Toe Rings
2012-08-06 10:18 - 2012-08-06 10:18 - 00788141 ____A C:\Users\Faizy\Desktop\zeenat mup.zip
2012-08-05 13:37 - 2012-08-05 15:10 - 00000000 ____D C:\Users\Faizy\Desktop\Nikita
2012-08-05 07:18 - 2012-08-05 07:18 - 00001552 ____A C:\Users\Faizy\Desktop\Puzzle.pcf
2012-08-05 07:18 - 2012-08-05 07:18 - 00000000 ____D C:\Users\Faizy\Desktop\Puzzle files
2012-08-05 07:07 - 2012-08-05 07:07 - 00300234 ____A C:\Users\Faizy\Desktop\Walimah.pbf
2012-08-05 07:07 - 2012-08-05 07:07 - 00000000 ____D C:\Users\Faizy\Desktop\Walimah files
2012-08-03 14:44 - 2012-08-05 06:33 - 00000000 ____D C:\Users\Faizy\Desktop\Walimah Album
2012-08-03 13:46 - 2012-08-03 13:49 - 00000000 ____D C:\Users\Faizy\Desktop\Shank2
2012-08-02 16:21 - 2012-08-05 07:13 - 00255791 ____A C:\Users\Faizy\Desktop\W Album.pbf
2012-08-02 16:21 - 2012-08-02 16:21 - 00000000 ____D C:\Users\Faizy\Desktop\W Album files
2012-08-02 13:35 - 2012-08-02 14:01 - 00000000 ____D C:\Users\Faizy\Desktop\Wedding Album
2012-08-02 06:13 - 2012-08-02 06:15 - 00000000 ____D C:\Users\Faizy\Desktop\Emerald Rings
2012-08-01 13:22 - 2012-08-01 13:24 - 00361429 ____A C:\Users\Faizy\Desktop\All in Black.zip
2012-08-01 11:33 - 2012-08-01 12:38 - 00000000 ____D C:\Users\Faizy\Desktop\yumna
2012-08-01 10:21 - 2012-08-01 10:29 - 00000000 ____D C:\Users\Faizy\Desktop\New Folder
2012-07-30 14:32 - 2012-07-31 14:50 - 40973248 ____A ( ) C:\Users\Faizy\Downloads\fujifilm_digital_printing.exe
2012-07-30 14:06 - 2012-07-30 14:44 - 00000000 ____D C:\Users\Faizy\AppData\Local\PhotoGenie
2012-07-30 13:56 - 2012-07-30 14:21 - 48081222 ____A C:\Users\Faizy\Downloads\Anger_Management_-_S01E01_-_Charlie_Goes_Back_to_Therapy.mp4
2012-07-27 15:11 - 2012-07-31 15:52 - 00000000 ____D C:\Users\Faizy\Desktop\Blue Bloods
2012-07-25 12:44 - 2012-07-25 12:44 - 00000000 ____D C:\Users\All Users\xml_param
2012-07-25 12:42 - 2012-07-25 12:44 - 00000000 ____D C:\Users\Faizy\Desktop\iTunes Converted
2012-07-25 12:40 - 2012-08-16 15:09 - 00000000 ____D C:\Program Files\Aimersoft
2012-07-25 12:40 - 2012-07-25 12:42 - 00000000 ____D C:\Users\Faizy\Documents\Aimersoft Video Converter Ultimate
2012-07-25 12:40 - 2012-07-25 12:40 - 00000000 ____D C:\Users\Faizy\AppData\Roaming\Aimersoft Video Converter Ultimate
2012-07-25 12:40 - 2012-07-25 12:40 - 00000000 ____D C:\Users\Faizy\AppData\Local\Aimersoft
2012-07-25 12:40 - 2012-07-25 12:40 - 00000000 ____D C:\Program Files\Common Files\Aimersoft
2012-07-25 12:40 - 2011-08-31 04:39 - 00892928 ____A (Free Software Foundation) C:\Windows\System32\iconv.dll
2012-07-25 12:40 - 2011-08-31 04:39 - 00675840 ____A () C:\Windows\System32\ac3filter.ax
2012-07-25 12:40 - 2011-08-31 04:39 - 00496640 ____A C:\Windows\System32\xvid.ax
2012-07-24 15:29 - 2012-07-24 15:31 - 00000000 ___SD C:\Users\Faizy\Documents\My DocsToGo
2012-07-24 15:29 - 2012-07-24 15:29 - 00000547 ____A C:\Users\Public\Desktop\My DocsToGo.lnk
2012-07-24 15:28 - 2012-07-24 15:28 - 03200280 ____A C:\Users\Faizy\Downloads\documentstogoiphn4.0001.010.exe
2012-07-24 15:19 - 2012-07-24 15:19 - 00010475 ____A C:\Users\Faizy\Documents\Diamond Prices.xlsx
============ 3 Months Modified Files ========================
2012-08-17 13:12 - 2006-11-02 05:01 - 00030734 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-17 13:12 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-17 13:12 - 2006-11-02 04:47 - 00004128 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-17 13:12 - 2006-11-02 04:47 - 00004128 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-17 12:59 - 2011-05-31 00:05 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-17 12:56 - 2011-03-28 09:55 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-17 02:57 - 2006-11-02 02:22 - 38010880 ____A C:\Windows\System32\config\software_previous
2012-08-17 02:57 - 2006-11-02 02:22 - 23330816 ____A C:\Windows\System32\config\system_previous
2012-08-17 02:49 - 2006-11-02 02:22 - 41943040 ____A C:\Windows\System32\config\components_previous
2012-08-17 02:49 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-08-16 17:41 - 2011-03-28 09:55 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-16 17:40 - 2006-11-02 02:33 - 00698162 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-16 17:38 - 2006-11-02 04:52 - 01478017 ____A C:\Windows\WindowsUpdate.log
2012-08-16 17:37 - 2011-03-24 13:42 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-16 17:15 - 2011-03-24 12:40 - 00001356 ____A C:\Users\Faizy\AppData\Local\d3d9caps.dat
2012-08-16 17:05 - 2012-08-16 17:05 - 00136384 ____A C:\Windows\Minidump\Mini081712-01.dmp
2012-08-16 17:04 - 2012-08-16 17:04 - 119874748 ____A C:\Windows\MEMORY.DMP
2012-08-16 16:23 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-08-16 16:23 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\default_previous
2012-08-16 15:18 - 2012-08-16 15:16 - 10288512 ____A (Microsoft Corporation) C:\Users\Faizy\Downloads\mseinstall.exe
2012-08-16 14:10 - 2012-05-03 16:38 - 00009631 ____A C:\Users\Faizy\Documents\W.xlsx
2012-08-16 13:10 - 2011-05-08 13:40 - 00001078 ____A C:\DebugTraceAP.log
2012-08-16 12:46 - 2006-11-02 05:00 - 00018860 ____A C:\Windows\PFRO.log
2012-08-15 16:25 - 2011-03-28 09:22 - 00176640 ____A C:\Users\Faizy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-14 12:54 - 2012-08-14 12:50 - 00009455 ____A C:\Users\Faizy\Documents\Yumna.xlsx
2012-08-13 13:48 - 2012-08-13 13:48 - 00001842 ____A C:\Users\Public\Desktop\InterVideo WinDVD Creator 2.lnk
2012-08-13 13:22 - 2012-08-13 13:22 - 00000040 ___AH C:\Windows\System32\ivireg.ivr
2012-08-13 13:21 - 2012-08-13 13:21 - 00001770 ____A C:\Users\Public\Desktop\Corel WinDVD Pro 11.lnk
2012-08-13 13:19 - 2012-08-13 12:53 - 123908088 ____A (Acresso Software Inc.) C:\Users\Faizy\Downloads\WinDVD11_Pro_TBYB.exe
2012-08-13 13:13 - 2012-08-09 14:38 - 00009600 ____A C:\Users\Faizy\Documents\cubics.xlsx
2012-08-12 16:00 - 2011-06-07 14:48 - 00637954 ____A C:\Users\Faizy\AppData\Roaming\mdbu.bin
2012-08-11 18:02 - 2012-08-11 18:02 - 00002065 ____A C:\Users\Faizy\Desktop\DStv Desktop Player BETA.lnk
2012-08-09 17:17 - 2012-08-09 14:29 - 297564076 ____A C:\Users\Faizy\Desktop\Batman.The.Dark.Knight.2008.1080p.BluRay_high.mp4
2012-08-06 10:18 - 2012-08-06 10:18 - 00788141 ____A C:\Users\Faizy\Desktop\zeenat mup.zip
2012-08-05 07:18 - 2012-08-05 07:18 - 00001552 ____A C:\Users\Faizy\Desktop\Puzzle.pcf
2012-08-05 07:13 - 2012-08-02 16:21 - 00255791 ____A C:\Users\Faizy\Desktop\W Album.pbf
2012-08-05 07:07 - 2012-08-05 07:07 - 00300234 ____A C:\Users\Faizy\Desktop\Walimah.pbf
2012-08-02 15:34 - 2006-11-02 04:52 - 00054484 ____A C:\Windows\setupact.log
2012-08-01 13:24 - 2012-08-01 13:22 - 00361429 ____A C:\Users\Faizy\Desktop\All in Black.zip
2012-08-01 12:39 - 2012-07-10 13:42 - 01228238 ____A C:\Users\Faizy\Desktop\Ladies Collection.zip
2012-07-31 14:50 - 2012-07-30 14:32 - 40973248 ____A ( ) C:\Users\Faizy\Downloads\fujifilm_digital_printing.exe
2012-07-31 14:50 - 2011-05-31 15:45 - 00001871 ____A C:\Users\Public\Desktop\Fuji Film digital printing.lnk
2012-07-30 14:21 - 2012-07-30 13:56 - 48081222 ____A C:\Users\Faizy\Downloads\Anger_Management_-_S01E01_-_Charlie_Goes_Back_to_Therapy.mp4
2012-07-24 15:29 - 2012-07-24 15:29 - 00000547 ____A C:\Users\Public\Desktop\My DocsToGo.lnk
2012-07-24 15:28 - 2012-07-24 15:28 - 03200280 ____A C:\Users\Faizy\Downloads\documentstogoiphn4.0001.010.exe
2012-07-24 15:19 - 2012-07-24 15:19 - 00010475 ____A C:\Users\Faizy\Documents\Diamond Prices.xlsx
2012-07-17 07:30 - 2012-07-17 07:30 - 00352768 ____A C:\Users\Faizy\Desktop\Hons Linear Programming.ppt
2012-07-12 17:02 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
2012-07-12 12:25 - 2012-07-12 12:25 - 00198894 ____A C:\Users\Faizy\Desktop\Wedding Bands LC.zip
2012-07-11 17:22 - 2006-11-02 04:47 - 00371808 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 17:01 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-10 14:18 - 2012-07-10 14:18 - 00464626 ____N C:\Users\Faizy\Desktop\Titanium.MDI
2012-07-10 13:42 - 2012-07-10 13:42 - 00379047 ____A C:\Users\Faizy\Desktop\Mens Collection.zip
2012-06-30 09:22 - 2012-06-30 09:22 - 00304182 ____A C:\2012-6-30_19-22-23-591.bmp
2012-06-25 14:36 - 2012-06-25 14:36 - 00018944 ____A C:\Users\Faizy\Documents\EV TEST BC.xls
2012-06-25 14:35 - 2012-06-25 14:35 - 00009286 ____A C:\Users\Faizy\Documents\EV TEST BC.xlsx
2012-06-25 14:31 - 2012-01-24 10:49 - 00000919 ____A C:\Users\Faizy\Desktop\Dropbox.lnk
2012-06-25 05:28 - 2012-06-25 05:28 - 00001664 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-13 05:40 - 2012-07-11 17:03 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 09:47 - 2012-07-11 15:45 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 08:47 - 2012-07-11 15:26 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-11 15:26 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 07:26 - 2012-07-11 14:44 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-19 02:41 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 02:41 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 02:41 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 02:41 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 02:41 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 02:41 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 02:41 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 05:19 - 2012-06-19 02:41 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 05:12 - 2012-06-19 02:41 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-12 17:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-12 17:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-12 17:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-12 17:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-12 17:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 17:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-12 17:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-12 17:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 17:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 17:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-12 17:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-12 17:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 17:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 17:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 16:04 - 2012-07-11 14:44 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-11 14:44 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-30 09:07 - 2012-05-30 09:07 - 00169100 ___AH C:\Windows\System32\mlfcache.dat
2012-05-30 08:29 - 2012-05-30 07:55 - 74982768 ____A (Apple Inc.) C:\Users\Faizy\Downloads\iTunesSetup.exe
2012-05-28 13:05 - 2012-05-28 13:05 - 00011513 ____A C:\Users\Faizy\Documents\Adila.xlsx
2012-05-26 17:17 - 2012-05-26 17:17 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-05-26 17:17 - 2012-05-26 17:17 - 00580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-26 17:17 - 2012-05-26 17:17 - 00353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\advpack.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-05-26 17:17 - 2012-05-26 17:17 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-05-26 17:17 - 2012-05-26 17:04 - 00003837 ____A C:\Windows\IE9_main.log
2012-05-26 17:17 - 2006-11-01 22:32 - 00008798 ____A C:\Windows\System32\icrav03.rat
2012-05-26 17:17 - 2006-11-01 22:32 - 00001988 ____A C:\Windows\System32\ticrf.rat
2012-05-26 17:13 - 2012-05-26 17:13 - 02873344 ____A (Microsoft Corporation) C:\Windows\System32\mf.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 01554432 ____A (Microsoft Corporation) C:\Windows\System32\xpsservices.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 01075712 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 01029120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00979456 ____A (Microsoft Corporation) C:\Windows\System32\MFH264Dec.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00876032 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00847360 ____A (Microsoft Corporation) C:\Windows\System32\OpcServices.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00797184 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00667648 ____A (Microsoft Corporation) C:\Windows\System32\printfilterpipelinesvc.exe
2012-05-26 17:13 - 2012-05-26 17:13 - 00638336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2012-05-26 17:13 - 2012-05-26 17:13 - 00586240 ____A (Microsoft Corporation) C:\Windows\System32\stobject.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00486400 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00478720 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00357376 ____A (Microsoft Corporation) C:\Windows\System32\MFHEAACdec.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00302592 ____A (Microsoft Corporation) C:\Windows\System32\mfmp4src.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00288768 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00261632 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00258048 ____A (Microsoft Corporation) C:\Windows\System32\winspool.drv
2012-05-26 17:13 - 2012-05-26 17:13 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\mfplat.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00189952 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\XpsRasterService.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00098816 ____A (Microsoft Corporation) C:\Windows\System32\mfps.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00026112 ____A (Microsoft Corporation) C:\Windows\System32\printfilterpipelineprxy.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00974848 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00519680 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00369664 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00321024 ____A (Microsoft Corporation) C:\Windows\System32\PhotoMetadataHandler.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00252928 ____A (Microsoft Corporation) C:\Windows\System32\dxdiag.exe
2012-05-26 17:12 - 2012-05-26 17:12 - 00195584 ____A (Microsoft Corporation) C:\Windows\System32\dxdiagn.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00189440 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll
2012-05-26 10:45 - 2012-05-26 10:45 - 06467392 ____A (D6 Technology ) C:\Users\Faizy\Downloads\jcsa_installer.exe
2012-05-26 10:45 - 2012-05-26 10:45 - 00001971 ____A C:\Users\Public\Desktop\Jewellery Council of South Africa.lnk
2012-05-25 12:03 - 2012-05-25 12:03 - 00008928 ____A C:\Users\Faizy\Documents\Amy.xlsx
2012-05-25 10:57 - 2012-05-25 10:47 - 00073216 ____A C:\Users\Faizy\Desktop\10_EKN03X7_2012_6 (1)_10.xls
2012-05-23 04:05 - 2012-05-23 04:05 - 00000022 ____A C:\Users\Faizy\Desktop\attachments.zip
ZeroAccess:
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\@
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\L
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\n
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\U
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\L\00000004.@
ZeroAccess:
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\@
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\L
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 3892.53 MB
Available physical RAM: 3358.63 MB
Total Pagefile: 3650.46 MB
Available Pagefile: 3414.14 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.72 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:1863.01 GB) (Free:1514.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (LRMCFRE_EN_DVD) (CDROM) (Total:2.49 GB) (Free:0 GB) UDF
3 Drive e: () (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 1863 GB 1081 KB
Disk 1 Online 1928 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 1863 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1928 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E FAT Removable 1928 MB Healthy
==================================================================================
Last Boot: 2012-08-16 17:38
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 2012-08-17 23:20:43
Running from E:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2011-05-31 00:05] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2011-04-04 15:15] - [2008-01-18 23:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 00:35] - [2006-11-02 01:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\Windows\System32\services.exe
[2011-05-31 00:05] - [2012-08-17 12:59] - 0279552 ____A (Microsoft Corporation) 8737764F4FD36D6808EE80578409C843
=== End Of Search ===
So it appears I've fallen victim to what I think is SIREFEF (I think that is what its called); my MSE didn't initially pick it up; as soon as it did pick it up my PC started shutting/restarting. I've managed to access my PC and do a scan with FRST; I shall post the logs of the scan below and the search for "services.exe" - I hope this helps and I hope to be helped too. I wish to thank the helper(s) in advance for their esteemed assistance.
============ One Month Created Files and Folders ==============
2012-08-16 17:37 - 2012-08-16 17:37 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-16 17:05 - 2012-08-16 17:05 - 00136384 ____A C:\Windows\Minidump\Mini081712-01.dmp
2012-08-16 17:05 - 2012-08-16 17:05 - 00000000 ____D C:\Windows\Minidump
2012-08-16 17:04 - 2012-08-16 17:04 - 119874748 ____A C:\Windows\MEMORY.DMP
2012-08-16 16:11 - 2012-08-16 17:31 - 00000000 ____D C:\Windows\pss
2012-08-16 15:27 - 2012-08-16 15:27 - 00000000 ____D C:\Program Files\Microsoft Security Client(2)
2012-08-16 15:16 - 2012-08-16 15:18 - 10288512 ____A (Microsoft Corporation) C:\Users\Faizy\Downloads\mseinstall.exe
2012-08-15 15:27 - 2012-08-15 16:25 - 00000000 ____D C:\Users\Faizy\Desktop\Body of Proof
2012-08-14 13:59 - 2012-08-16 15:04 - 00000000 ____D C:\Users\Faizy\Desktop\YUMNA INS
2012-08-14 13:36 - 2012-08-16 14:18 - 00000000 ____D C:\Users\Faizy\Desktop\Yumna 2
2012-08-14 12:50 - 2012-08-14 12:54 - 00009455 ____A C:\Users\Faizy\Documents\Yumna.xlsx
2012-08-13 15:19 - 2012-08-13 15:19 - 00000000 ____D C:\Users\Faizy\Documents\Daniusoft Digital Music Converter
2012-08-13 15:02 - 2012-08-13 15:03 - 00000000 ____D C:\Users\Faizy\Documents\Aimersoft DRM Media Converter
2012-08-13 14:59 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(5).sys
2012-08-13 14:57 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(4).sys
2012-08-13 14:55 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(3).sys
2012-08-13 14:53 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(2).sys
2012-08-13 14:53 - 2011-12-09 05:35 - 00025704 ____A (Wondershare) C:\Windows\System32\Drivers\WsAudio_DeviceS(1).sys
2012-08-13 14:16 - 2012-08-13 14:16 - 00000000 ____D C:\Program Files\NirSoft
2012-08-13 13:48 - 2012-08-13 13:48 - 00001842 ____A C:\Users\Public\Desktop\InterVideo WinDVD Creator 2.lnk
2012-08-13 13:48 - 2012-08-13 13:48 - 00000000 ____D C:\Program Files\InterVideo
2012-08-13 13:48 - 2001-12-10 07:42 - 00204800 ____A C:\Windows\System32\IVIresizeW7.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00200704 ____A C:\Windows\System32\IVIresizeA6.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00192512 ____A C:\Windows\System32\IVIresizeP6.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00192512 ____A C:\Windows\System32\IVIresizeM6.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00188416 ____A C:\Windows\System32\IVIresizePX.dll
2012-08-13 13:48 - 2001-12-10 07:42 - 00020480 ____A C:\Windows\System32\IVIresize.dll
2012-08-13 13:24 - 2012-08-13 13:25 - 00000000 ____D C:\Users\Faizy\AppData\Roaming\Corel
2012-08-13 13:24 - 2012-08-13 13:25 - 00000000 ____D C:\Users\All Users\Protexis
2012-08-13 13:23 - 2012-08-13 13:23 - 00000000 ____D C:\Users\Faizy\Corel
2012-08-13 13:22 - 2012-08-13 13:22 - 00000040 ___AH C:\Windows\System32\ivireg.ivr
2012-08-13 13:22 - 2012-08-13 13:22 - 00000000 ____D C:\Users\All Users\Corel
2012-08-13 13:22 - 2012-08-13 13:22 - 00000000 ____D C:\Program Files\Common Files\Protexis
2012-08-13 13:21 - 2012-08-13 13:21 - 00001770 ____A C:\Users\Public\Desktop\Corel WinDVD Pro 11.lnk
2012-08-13 13:21 - 2012-08-13 13:21 - 00000000 ____D C:\Program Files\Corel
2012-08-13 13:21 - 2010-11-16 06:24 - 00013880 ____A (InterVideo) C:\Windows\System32\Drivers\regi.sys
2012-08-13 13:20 - 2006-02-02 22:43 - 02332368 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_29.dll
2012-08-13 12:53 - 2012-08-13 13:19 - 123908088 ____A (Acresso Software Inc.) C:\Users\Faizy\Downloads\WinDVD11_Pro_TBYB.exe
2012-08-11 18:02 - 2012-08-11 18:02 - 00002065 ____A C:\Users\Faizy\Desktop\DStv Desktop Player BETA.lnk
2012-08-09 15:18 - 2012-08-09 15:46 - 00000000 ____D C:\Users\Faizy\Desktop\For Fuji
2012-08-09 14:38 - 2012-08-13 13:13 - 00009600 ____A C:\Users\Faizy\Documents\cubics.xlsx
2012-08-09 14:29 - 2012-08-09 17:17 - 297564076 ____A C:\Users\Faizy\Desktop\Batman.The.Dark.Knight.2008.1080p.BluRay_high.mp4
2012-08-08 11:35 - 2012-08-08 11:51 - 00000000 ____D C:\Users\Faizy\Desktop\Toe Rings
2012-08-06 10:18 - 2012-08-06 10:18 - 00788141 ____A C:\Users\Faizy\Desktop\zeenat mup.zip
2012-08-05 13:37 - 2012-08-05 15:10 - 00000000 ____D C:\Users\Faizy\Desktop\Nikita
2012-08-05 07:18 - 2012-08-05 07:18 - 00001552 ____A C:\Users\Faizy\Desktop\Puzzle.pcf
2012-08-05 07:18 - 2012-08-05 07:18 - 00000000 ____D C:\Users\Faizy\Desktop\Puzzle files
2012-08-05 07:07 - 2012-08-05 07:07 - 00300234 ____A C:\Users\Faizy\Desktop\Walimah.pbf
2012-08-05 07:07 - 2012-08-05 07:07 - 00000000 ____D C:\Users\Faizy\Desktop\Walimah files
2012-08-03 14:44 - 2012-08-05 06:33 - 00000000 ____D C:\Users\Faizy\Desktop\Walimah Album
2012-08-03 13:46 - 2012-08-03 13:49 - 00000000 ____D C:\Users\Faizy\Desktop\Shank2
2012-08-02 16:21 - 2012-08-05 07:13 - 00255791 ____A C:\Users\Faizy\Desktop\W Album.pbf
2012-08-02 16:21 - 2012-08-02 16:21 - 00000000 ____D C:\Users\Faizy\Desktop\W Album files
2012-08-02 13:35 - 2012-08-02 14:01 - 00000000 ____D C:\Users\Faizy\Desktop\Wedding Album
2012-08-02 06:13 - 2012-08-02 06:15 - 00000000 ____D C:\Users\Faizy\Desktop\Emerald Rings
2012-08-01 13:22 - 2012-08-01 13:24 - 00361429 ____A C:\Users\Faizy\Desktop\All in Black.zip
2012-08-01 11:33 - 2012-08-01 12:38 - 00000000 ____D C:\Users\Faizy\Desktop\yumna
2012-08-01 10:21 - 2012-08-01 10:29 - 00000000 ____D C:\Users\Faizy\Desktop\New Folder
2012-07-30 14:32 - 2012-07-31 14:50 - 40973248 ____A ( ) C:\Users\Faizy\Downloads\fujifilm_digital_printing.exe
2012-07-30 14:06 - 2012-07-30 14:44 - 00000000 ____D C:\Users\Faizy\AppData\Local\PhotoGenie
2012-07-30 13:56 - 2012-07-30 14:21 - 48081222 ____A C:\Users\Faizy\Downloads\Anger_Management_-_S01E01_-_Charlie_Goes_Back_to_Therapy.mp4
2012-07-27 15:11 - 2012-07-31 15:52 - 00000000 ____D C:\Users\Faizy\Desktop\Blue Bloods
2012-07-25 12:44 - 2012-07-25 12:44 - 00000000 ____D C:\Users\All Users\xml_param
2012-07-25 12:42 - 2012-07-25 12:44 - 00000000 ____D C:\Users\Faizy\Desktop\iTunes Converted
2012-07-25 12:40 - 2012-08-16 15:09 - 00000000 ____D C:\Program Files\Aimersoft
2012-07-25 12:40 - 2012-07-25 12:42 - 00000000 ____D C:\Users\Faizy\Documents\Aimersoft Video Converter Ultimate
2012-07-25 12:40 - 2012-07-25 12:40 - 00000000 ____D C:\Users\Faizy\AppData\Roaming\Aimersoft Video Converter Ultimate
2012-07-25 12:40 - 2012-07-25 12:40 - 00000000 ____D C:\Users\Faizy\AppData\Local\Aimersoft
2012-07-25 12:40 - 2012-07-25 12:40 - 00000000 ____D C:\Program Files\Common Files\Aimersoft
2012-07-25 12:40 - 2011-08-31 04:39 - 00892928 ____A (Free Software Foundation) C:\Windows\System32\iconv.dll
2012-07-25 12:40 - 2011-08-31 04:39 - 00675840 ____A () C:\Windows\System32\ac3filter.ax
2012-07-25 12:40 - 2011-08-31 04:39 - 00496640 ____A C:\Windows\System32\xvid.ax
2012-07-24 15:29 - 2012-07-24 15:31 - 00000000 ___SD C:\Users\Faizy\Documents\My DocsToGo
2012-07-24 15:29 - 2012-07-24 15:29 - 00000547 ____A C:\Users\Public\Desktop\My DocsToGo.lnk
2012-07-24 15:28 - 2012-07-24 15:28 - 03200280 ____A C:\Users\Faizy\Downloads\documentstogoiphn4.0001.010.exe
2012-07-24 15:19 - 2012-07-24 15:19 - 00010475 ____A C:\Users\Faizy\Documents\Diamond Prices.xlsx
============ 3 Months Modified Files ========================
2012-08-17 13:12 - 2006-11-02 05:01 - 00030734 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-17 13:12 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-17 13:12 - 2006-11-02 04:47 - 00004128 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-17 13:12 - 2006-11-02 04:47 - 00004128 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-17 12:59 - 2011-05-31 00:05 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-17 12:56 - 2011-03-28 09:55 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-17 02:57 - 2006-11-02 02:22 - 38010880 ____A C:\Windows\System32\config\software_previous
2012-08-17 02:57 - 2006-11-02 02:22 - 23330816 ____A C:\Windows\System32\config\system_previous
2012-08-17 02:49 - 2006-11-02 02:22 - 41943040 ____A C:\Windows\System32\config\components_previous
2012-08-17 02:49 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-08-16 17:41 - 2011-03-28 09:55 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-16 17:40 - 2006-11-02 02:33 - 00698162 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-16 17:38 - 2006-11-02 04:52 - 01478017 ____A C:\Windows\WindowsUpdate.log
2012-08-16 17:37 - 2011-03-24 13:42 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-16 17:15 - 2011-03-24 12:40 - 00001356 ____A C:\Users\Faizy\AppData\Local\d3d9caps.dat
2012-08-16 17:05 - 2012-08-16 17:05 - 00136384 ____A C:\Windows\Minidump\Mini081712-01.dmp
2012-08-16 17:04 - 2012-08-16 17:04 - 119874748 ____A C:\Windows\MEMORY.DMP
2012-08-16 16:23 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-08-16 16:23 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\default_previous
2012-08-16 15:18 - 2012-08-16 15:16 - 10288512 ____A (Microsoft Corporation) C:\Users\Faizy\Downloads\mseinstall.exe
2012-08-16 14:10 - 2012-05-03 16:38 - 00009631 ____A C:\Users\Faizy\Documents\W.xlsx
2012-08-16 13:10 - 2011-05-08 13:40 - 00001078 ____A C:\DebugTraceAP.log
2012-08-16 12:46 - 2006-11-02 05:00 - 00018860 ____A C:\Windows\PFRO.log
2012-08-15 16:25 - 2011-03-28 09:22 - 00176640 ____A C:\Users\Faizy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-14 12:54 - 2012-08-14 12:50 - 00009455 ____A C:\Users\Faizy\Documents\Yumna.xlsx
2012-08-13 13:48 - 2012-08-13 13:48 - 00001842 ____A C:\Users\Public\Desktop\InterVideo WinDVD Creator 2.lnk
2012-08-13 13:22 - 2012-08-13 13:22 - 00000040 ___AH C:\Windows\System32\ivireg.ivr
2012-08-13 13:21 - 2012-08-13 13:21 - 00001770 ____A C:\Users\Public\Desktop\Corel WinDVD Pro 11.lnk
2012-08-13 13:19 - 2012-08-13 12:53 - 123908088 ____A (Acresso Software Inc.) C:\Users\Faizy\Downloads\WinDVD11_Pro_TBYB.exe
2012-08-13 13:13 - 2012-08-09 14:38 - 00009600 ____A C:\Users\Faizy\Documents\cubics.xlsx
2012-08-12 16:00 - 2011-06-07 14:48 - 00637954 ____A C:\Users\Faizy\AppData\Roaming\mdbu.bin
2012-08-11 18:02 - 2012-08-11 18:02 - 00002065 ____A C:\Users\Faizy\Desktop\DStv Desktop Player BETA.lnk
2012-08-09 17:17 - 2012-08-09 14:29 - 297564076 ____A C:\Users\Faizy\Desktop\Batman.The.Dark.Knight.2008.1080p.BluRay_high.mp4
2012-08-06 10:18 - 2012-08-06 10:18 - 00788141 ____A C:\Users\Faizy\Desktop\zeenat mup.zip
2012-08-05 07:18 - 2012-08-05 07:18 - 00001552 ____A C:\Users\Faizy\Desktop\Puzzle.pcf
2012-08-05 07:13 - 2012-08-02 16:21 - 00255791 ____A C:\Users\Faizy\Desktop\W Album.pbf
2012-08-05 07:07 - 2012-08-05 07:07 - 00300234 ____A C:\Users\Faizy\Desktop\Walimah.pbf
2012-08-02 15:34 - 2006-11-02 04:52 - 00054484 ____A C:\Windows\setupact.log
2012-08-01 13:24 - 2012-08-01 13:22 - 00361429 ____A C:\Users\Faizy\Desktop\All in Black.zip
2012-08-01 12:39 - 2012-07-10 13:42 - 01228238 ____A C:\Users\Faizy\Desktop\Ladies Collection.zip
2012-07-31 14:50 - 2012-07-30 14:32 - 40973248 ____A ( ) C:\Users\Faizy\Downloads\fujifilm_digital_printing.exe
2012-07-31 14:50 - 2011-05-31 15:45 - 00001871 ____A C:\Users\Public\Desktop\Fuji Film digital printing.lnk
2012-07-30 14:21 - 2012-07-30 13:56 - 48081222 ____A C:\Users\Faizy\Downloads\Anger_Management_-_S01E01_-_Charlie_Goes_Back_to_Therapy.mp4
2012-07-24 15:29 - 2012-07-24 15:29 - 00000547 ____A C:\Users\Public\Desktop\My DocsToGo.lnk
2012-07-24 15:28 - 2012-07-24 15:28 - 03200280 ____A C:\Users\Faizy\Downloads\documentstogoiphn4.0001.010.exe
2012-07-24 15:19 - 2012-07-24 15:19 - 00010475 ____A C:\Users\Faizy\Documents\Diamond Prices.xlsx
2012-07-17 07:30 - 2012-07-17 07:30 - 00352768 ____A C:\Users\Faizy\Desktop\Hons Linear Programming.ppt
2012-07-12 17:02 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
2012-07-12 12:25 - 2012-07-12 12:25 - 00198894 ____A C:\Users\Faizy\Desktop\Wedding Bands LC.zip
2012-07-11 17:22 - 2006-11-02 04:47 - 00371808 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 17:01 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-10 14:18 - 2012-07-10 14:18 - 00464626 ____N C:\Users\Faizy\Desktop\Titanium.MDI
2012-07-10 13:42 - 2012-07-10 13:42 - 00379047 ____A C:\Users\Faizy\Desktop\Mens Collection.zip
2012-06-30 09:22 - 2012-06-30 09:22 - 00304182 ____A C:\2012-6-30_19-22-23-591.bmp
2012-06-25 14:36 - 2012-06-25 14:36 - 00018944 ____A C:\Users\Faizy\Documents\EV TEST BC.xls
2012-06-25 14:35 - 2012-06-25 14:35 - 00009286 ____A C:\Users\Faizy\Documents\EV TEST BC.xlsx
2012-06-25 14:31 - 2012-01-24 10:49 - 00000919 ____A C:\Users\Faizy\Desktop\Dropbox.lnk
2012-06-25 05:28 - 2012-06-25 05:28 - 00001664 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-13 05:40 - 2012-07-11 17:03 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 09:47 - 2012-07-11 15:45 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 08:47 - 2012-07-11 15:26 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-11 15:26 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 07:26 - 2012-07-11 14:44 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-19 02:41 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 02:41 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 02:41 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 02:41 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 02:41 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 02:41 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 02:41 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 05:19 - 2012-06-19 02:41 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 05:12 - 2012-06-19 02:41 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-12 17:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-12 17:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-12 17:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-12 17:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-12 17:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 17:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-12 17:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-12 17:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 17:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 17:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-12 17:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-12 17:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 17:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 17:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 16:04 - 2012-07-11 14:44 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-11 14:44 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-30 09:07 - 2012-05-30 09:07 - 00169100 ___AH C:\Windows\System32\mlfcache.dat
2012-05-30 08:29 - 2012-05-30 07:55 - 74982768 ____A (Apple Inc.) C:\Users\Faizy\Downloads\iTunesSetup.exe
2012-05-28 13:05 - 2012-05-28 13:05 - 00011513 ____A C:\Users\Faizy\Documents\Adila.xlsx
2012-05-26 17:17 - 2012-05-26 17:17 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-05-26 17:17 - 2012-05-26 17:17 - 00580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-26 17:17 - 2012-05-26 17:17 - 00353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\advpack.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-05-26 17:17 - 2012-05-26 17:17 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-26 17:17 - 2012-05-26 17:17 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-05-26 17:17 - 2012-05-26 17:17 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-05-26 17:17 - 2012-05-26 17:04 - 00003837 ____A C:\Windows\IE9_main.log
2012-05-26 17:17 - 2006-11-01 22:32 - 00008798 ____A C:\Windows\System32\icrav03.rat
2012-05-26 17:17 - 2006-11-01 22:32 - 00001988 ____A C:\Windows\System32\ticrf.rat
2012-05-26 17:13 - 2012-05-26 17:13 - 02873344 ____A (Microsoft Corporation) C:\Windows\System32\mf.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 01554432 ____A (Microsoft Corporation) C:\Windows\System32\xpsservices.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 01075712 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 01029120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00979456 ____A (Microsoft Corporation) C:\Windows\System32\MFH264Dec.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00876032 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00847360 ____A (Microsoft Corporation) C:\Windows\System32\OpcServices.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00797184 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00667648 ____A (Microsoft Corporation) C:\Windows\System32\printfilterpipelinesvc.exe
2012-05-26 17:13 - 2012-05-26 17:13 - 00638336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2012-05-26 17:13 - 2012-05-26 17:13 - 00586240 ____A (Microsoft Corporation) C:\Windows\System32\stobject.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00486400 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00478720 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00357376 ____A (Microsoft Corporation) C:\Windows\System32\MFHEAACdec.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00302592 ____A (Microsoft Corporation) C:\Windows\System32\mfmp4src.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00288768 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00261632 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00258048 ____A (Microsoft Corporation) C:\Windows\System32\winspool.drv
2012-05-26 17:13 - 2012-05-26 17:13 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\mfplat.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00189952 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\XpsRasterService.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00098816 ____A (Microsoft Corporation) C:\Windows\System32\mfps.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2012-05-26 17:13 - 2012-05-26 17:13 - 00026112 ____A (Microsoft Corporation) C:\Windows\System32\printfilterpipelineprxy.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00974848 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00519680 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00369664 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00321024 ____A (Microsoft Corporation) C:\Windows\System32\PhotoMetadataHandler.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00252928 ____A (Microsoft Corporation) C:\Windows\System32\dxdiag.exe
2012-05-26 17:12 - 2012-05-26 17:12 - 00195584 ____A (Microsoft Corporation) C:\Windows\System32\dxdiagn.dll
2012-05-26 17:12 - 2012-05-26 17:12 - 00189440 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll
2012-05-26 10:45 - 2012-05-26 10:45 - 06467392 ____A (D6 Technology ) C:\Users\Faizy\Downloads\jcsa_installer.exe
2012-05-26 10:45 - 2012-05-26 10:45 - 00001971 ____A C:\Users\Public\Desktop\Jewellery Council of South Africa.lnk
2012-05-25 12:03 - 2012-05-25 12:03 - 00008928 ____A C:\Users\Faizy\Documents\Amy.xlsx
2012-05-25 10:57 - 2012-05-25 10:47 - 00073216 ____A C:\Users\Faizy\Desktop\10_EKN03X7_2012_6 (1)_10.xls
2012-05-23 04:05 - 2012-05-23 04:05 - 00000022 ____A C:\Users\Faizy\Desktop\attachments.zip
ZeroAccess:
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\@
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\L
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\n
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\U
C:\Windows\Installer\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\L\00000004.@
ZeroAccess:
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\@
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\L
C:\Users\Faizy\AppData\Local\{2802c15d-9fd9-e80d-d7c3-c1469499038c}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 3892.53 MB
Available physical RAM: 3358.63 MB
Total Pagefile: 3650.46 MB
Available Pagefile: 3414.14 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.72 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:1863.01 GB) (Free:1514.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (LRMCFRE_EN_DVD) (CDROM) (Total:2.49 GB) (Free:0 GB) UDF
3 Drive e: () (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 1863 GB 1081 KB
Disk 1 Online 1928 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 1863 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1928 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E FAT Removable 1928 MB Healthy
==================================================================================
Last Boot: 2012-08-16 17:38
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 2012-08-17 23:20:43
Running from E:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2011-05-31 00:05] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2011-04-04 15:15] - [2008-01-18 23:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 00:35] - [2006-11-02 01:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\Windows\System32\services.exe
[2011-05-31 00:05] - [2012-08-17 12:59] - 0279552 ____A (Microsoft Corporation) 8737764F4FD36D6808EE80578409C843
=== End Of Search ===