Pete Bartram
Posts: 13 +0
At least, I'm assuming that's what it is; the computer I'm trying (& failing so far, despite running various rescue prgarms via Sardu) to fix is doing the auto-restart thing. Following advice to others (which I know is not always a good idea), I've run Farbar, and these are the log files it's generated.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 04-08-2012 17:09:49
Running from J:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [7703072 2009-08-04] (Realtek Semiconductor)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [63048 2010-09-17] (LogMeIn, Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\LogMeInRemoteUser\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-05] (Google Inc.)
HKU\LogMeInRemoteUser\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [3905920 2012-03-07] (SUPERAntiSpyware.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
================================ Services (Whitelisted) ==================
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE.EXE" [116608 2011-08-11] (SUPERAntiSpyware.com)
2 BFBackupUtilityService; C:\Program Files\BUFFALO\Backup_Utility\BUService.exe -Service_Execute [320888 2010-08-19] (BUFFALO INC.)
2 BFBackupUtilityVSSService; C:\Program Files\BUFFALO\Backup_Utility\BUVSSService.exe -Service_Execute [247160 2010-04-27] (BUFFALO INC.)
2 bufssvr; C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe [95608 2010-03-15] (BUFFALO INC.)
4 EASEUS Agent; C:\Program Files\EASEUS\Todo Backup 2.0\bin\Agent.exe [55688 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION)
2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
4 Hamachi2Svc; "C:\Program Files\LogMeIn Hamachi\hamachi-2.exe" -s [1373576 2012-02-28] (LogMeIn Inc.)
2 LMIGuardianSvc; "C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe" [374184 2012-07-12] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files\LogMeIn\x86\RaMaint.exe" [136616 2012-07-12] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files\LogMeIn\x86\LogMeIn.exe" [390528 2010-11-08] (LogMeIn, Inc.)
4 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
2 MSSQL$INFLOWSQL; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINFLOWSQL [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
4 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
========================== Drivers (Whitelisted) =============
3 athur; C:\Windows\System32\DRIVERS\athur.sys [1570304 2011-04-20] (Atheros Communications, Inc.)
0 bftpdskc; C:\Windows\System32\drivers\bftpdskc.sys [41472 2010-10-14] (BUFFALO INC.)
3 bftpusbx; C:\Windows\System32\drivers\bftpusbx.sys [11776 2010-09-21] (BUFFALO INC.)
0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [31112 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
1 EUDSKACS; \??\C:\Windows\system32\drivers\eudskacs.sys [15240 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
0 EUFS; C:\Windows\System32\drivers\eufs.sys [21896 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
2 LMIInfo; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys [12856 2010-09-17] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [10144 2010-09-17] (LogMeIn, Inc.)
2 LMIRfsDriver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [47640 2010-09-17] (LogMeIn, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
2 ppsio2; C:\Windows\System32\Drivers\ppsio2.sys [23200 1999-06-29] ()
3 RTL8192su; C:\Windows\System32\DRIVERS\RTL8192su.sys [603240 2010-11-24] (Realtek Semiconductor Corporation )
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
4 LMIRfsClientNP; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-03 23:56 - 2012-08-03 23:56 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-02 04:46 - 2012-08-03 10:40 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-07-31 00:51 - 2012-07-31 00:51 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-30 10:42 - 2012-07-30 10:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{9AF2849D-5CF9-413F-913A-EA0BD7980515}
2012-07-30 10:42 - 2012-07-30 10:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{2C86F956-D034-4D44-91BB-4D6605148C05}
2012-07-29 05:16 - 2012-07-29 05:16 - 00166408 ____A C:\Windows\Minidump\072912-14929-01.dmp
2012-07-29 02:15 - 2012-07-29 02:16 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{3A6FC11A-EBE8-4235-A3B9-47873FAC29E4}
2012-07-29 02:15 - 2012-07-29 02:15 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F3692599-DBC7-497A-BA48-DB3DD6D3FAD8}
2012-07-28 14:14 - 2012-07-28 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B5CE533E-756C-4460-B542-EE6949D03955}
2012-07-28 14:14 - 2012-07-28 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{59AA0593-B157-4500-9448-CA5D9BA245A6}
2012-07-28 00:29 - 2012-07-28 00:29 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{C783B4F9-C055-414F-A29E-FBA898BE2C1F}
2012-07-28 00:29 - 2012-07-28 00:29 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{465DB4D1-645C-439F-93D2-F0CB336587BA}
2012-07-27 04:44 - 2012-07-27 04:44 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E8B56172-F831-453E-A7DA-AE7EA148C3F3}
2012-07-27 04:44 - 2012-07-27 04:44 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{1D08DCFB-0E56-4D57-AEAA-881DF58F6F18}
2012-07-27 02:23 - 2012-07-27 02:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B9F20DCD-9435-4DCE-9388-EBF84E9CF4EB}
2012-07-27 02:23 - 2012-07-27 02:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{1AB135E2-0886-48BA-B1D6-2AD1121C6CDA}
2012-07-26 14:12 - 2012-07-26 14:12 - 00033920 ____A C:\Users\Gwyn\Desktop\Riley RMC 59SS 4990 1.htm
2012-07-26 13:51 - 2012-07-26 13:52 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CC579666-FAB1-48ED-8C34-FD8F70CF5ABE}
2012-07-26 13:51 - 2012-07-26 13:51 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{1FBE7D1C-FE7D-48F5-8073-7492163F126D}
2012-07-26 04:50 - 2012-07-26 04:50 - 00166408 ____A C:\Windows\Minidump\072612-13681-01.dmp
2012-07-26 01:42 - 2012-07-26 01:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{6231AB51-AA04-4741-919B-140905B5682E}
2012-07-26 01:42 - 2012-07-26 01:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{6080759B-6B16-4F3C-850A-EEC27C32EC74}
2012-07-25 13:08 - 2012-07-25 13:09 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{6129E0F5-015B-4EA7-BAAA-4684EFFC2031}
2012-07-25 13:08 - 2012-07-25 13:08 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{0FC64805-1B01-402B-B3D7-06E1F90810D6}
2012-07-25 01:08 - 2012-07-25 01:08 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F4EC7F9C-E1B5-4E39-9E8A-52F676C50A5E}
2012-07-25 01:07 - 2012-07-25 01:08 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{76E170F3-8D88-4D2A-B163-2F4D5F8CAE07}
2012-07-24 13:00 - 2012-07-24 13:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E9A2F80C-577B-4D6B-B6B0-75EF2B5B5A66}
2012-07-24 13:00 - 2012-07-24 13:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{826CAE1E-AF39-4DC4-B156-CD64B211C2B5}
2012-07-24 11:02 - 2012-07-24 11:02 - 00166408 ____A C:\Windows\Minidump\072412-13540-01.dmp
2012-07-24 04:11 - 2012-07-24 04:11 - 00166408 ____A C:\Windows\Minidump\072412-15241-01.dmp
2012-07-24 00:59 - 2012-07-24 00:59 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CABE8A9D-3A4B-4591-BC32-F6E2C5498DD4}
2012-07-24 00:59 - 2012-07-24 00:59 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B56637D0-692E-4A38-BDCA-F7A568E65029}
2012-07-23 09:38 - 2012-07-23 09:38 - 00166408 ____A C:\Windows\Minidump\072312-14211-01.dmp
2012-07-23 05:23 - 2012-07-23 05:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CA98AAC7-0DF0-4B12-8918-B1E413702B1E}
2012-07-23 05:22 - 2012-07-23 05:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{44428345-DEE0-470A-BB97-333B0459CF78}
2012-07-22 12:08 - 2012-07-22 12:08 - 00166408 ____A C:\Windows\Minidump\072212-14476-01.dmp
2012-07-22 09:52 - 2012-07-22 09:52 - 00000000 ____D C:\Users\Gwyn\Downloads\backups
2012-07-22 09:49 - 2012-07-22 09:49 - 00388608 ____A (Trend Micro Inc.) C:\Users\Gwyn\Downloads\HijackThis.exe
2012-07-22 09:49 - 2012-07-22 09:49 - 00007768 ____A C:\Users\Gwyn\Downloads\hijackthis.log
2012-07-22 09:10 - 2012-07-22 09:10 - 00002959 ____A C:\Users\Gwyn\Desktop\HiJackThis.lnk
2012-07-22 09:10 - 2012-07-22 09:10 - 00000000 ____D C:\Program Files\Trend Micro
2012-07-22 09:09 - 2012-07-22 09:09 - 01402880 ____A C:\Users\Gwyn\Downloads\HiJackThis.msi
2012-07-22 08:55 - 2012-07-22 08:55 - 00000000 ____D C:\Users\Gwyn\AppData\Roaming\Malwarebytes
2012-07-22 08:46 - 2012-07-22 08:46 - 01012656 ____A C:\Users\Gwyn\Desktop\rkill.exe
2012-07-22 03:47 - 2012-07-22 03:47 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{DE04460F-F384-4E6B-BB71-D67B03E848BB}
2012-07-22 03:47 - 2012-07-22 03:47 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{2473BEF3-C5D2-414C-A802-6FE3AACC456C}
2012-07-21 10:35 - 2012-07-21 10:35 - 00166408 ____A C:\Windows\Minidump\072112-14274-01.dmp
2012-07-21 04:56 - 2012-07-21 04:57 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{5C4C2820-A844-43A4-A58A-8CE87DA10954}
2012-07-21 04:56 - 2012-07-21 04:56 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{81F1BB1E-4391-4BB3-9D17-C8E7BE65856D}
2012-07-21 04:52 - 2012-07-21 04:52 - 00166408 ____A C:\Windows\Minidump\072112-15210-01.dmp
2012-07-20 14:14 - 2012-07-20 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{D2FA5B7B-D818-4461-8E83-29FE451C89FF}
2012-07-20 14:13 - 2012-07-20 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{95131E5B-091A-4AD8-8F69-398D3C1D63FF}
2012-07-20 05:33 - 2012-07-20 05:33 - 00000218 ____A C:\Users\Gwyn\.recently-used.xbel
2012-07-20 02:06 - 2012-07-20 02:07 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E27E783E-65A8-479E-9331-10DF558C5173}
2012-07-20 02:06 - 2012-07-20 02:06 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E0197778-1E7C-4B68-A2E6-5341DD7C0EEB}
2012-07-19 14:06 - 2012-07-19 14:06 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{7ABC5EEB-13E0-4B5C-B2EB-271625304E9D}
2012-07-19 14:06 - 2012-07-19 14:06 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{2B25BEC4-C8C7-4F98-9989-95D1BA4815EC}
2012-07-19 02:05 - 2012-07-19 02:05 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{9F466BBB-8997-4384-A43F-1074321665AD}
2012-07-19 02:05 - 2012-07-19 02:05 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{05317589-B5AE-40FF-9380-2068D64C7767}
2012-07-18 04:37 - 2012-07-18 04:37 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{5F727C78-D578-45A6-B886-6826972B5E64}
2012-07-18 04:37 - 2012-07-18 04:37 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{290138E1-5C68-41D8-B578-A8FD55B652B8}
2012-07-18 02:33 - 2012-07-18 02:33 - 21041152 ____A C:\Users\Gwyn\Documents\Gwyn.evtx
2012-07-18 02:33 - 2012-07-18 02:33 - 00000000 ____D C:\Users\Gwyn\Documents\LocaleMetaData
2012-07-17 14:43 - 2012-07-17 14:43 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{FB33A973-1718-400D-A157-0D45CE448205}
2012-07-17 14:42 - 2012-07-17 14:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{5E4236B1-8A96-4897-BCD7-F145EE715909}
2012-07-17 01:33 - 2012-07-17 01:42 - 01068032 ____A C:\Users\Gwyn\Downloads\Vehicle Database Record for Forum July 2012.xls
2012-07-17 01:33 - 2012-07-17 01:33 - 01077248 ____A C:\Users\Gwyn\Downloads\Backup of Vehicle Database Record for Forum July 2012.xlk
2012-07-17 01:03 - 2012-07-17 01:03 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F739956B-F2E0-4A1C-A528-4D665D17A38E}
2012-07-17 01:02 - 2012-07-17 01:03 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{ABC7756C-0FAB-48DE-AF97-41890D8CA9CF}
2012-07-16 15:10 - 2012-07-16 15:10 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{8F2259B2-A66C-45E2-B91B-DE516A9A35F1}
2012-07-16 14:58 - 2012-07-16 14:58 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{4CF99DD4-C3F4-4D16-9E7C-A02389A4E76C}
2012-07-16 06:38 - 2012-07-16 06:38 - 00166408 ____A C:\Windows\Minidump\071612-15990-01.dmp
2012-07-16 01:54 - 2012-07-16 01:54 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{80BE07CC-402E-4CA2-A62B-365E6E3C8EAF}
2012-07-16 01:54 - 2012-07-16 01:54 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{7D52B1AF-701B-4632-BCA3-B6186736A21F}
2012-07-15 13:14 - 2012-07-15 13:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{AE785B1A-0391-47AD-9EF1-E57F5AFCAD58}
2012-07-15 13:14 - 2012-07-15 13:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{47D61808-77F8-4E8A-A842-A0CDC83E90BA}
2012-07-14 23:33 - 2012-07-14 23:33 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{02A162D1-7821-4480-AE18-2435B80A1C36}
2012-07-14 23:32 - 2012-07-14 23:33 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E86B0ED7-BCEB-45C3-8A88-4FBD2B5D674D}
2012-07-14 11:22 - 2012-07-14 11:22 - 00166408 ____A C:\Windows\Minidump\071412-13494-01.dmp
2012-07-14 05:00 - 2012-07-14 05:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{C838E630-1043-49CA-AEDE-FF078A0A3F4D}
2012-07-14 05:00 - 2012-07-14 05:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{30CC3237-7153-449D-9C14-1C35363EF3BF}
2012-07-13 14:35 - 2012-07-13 14:35 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B678F90D-D6C8-418A-ABBB-07EB2253D79B}
2012-07-13 14:34 - 2012-07-13 14:35 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{A2A6C564-E29B-434B-AFB3-68C81BB625CF}
2012-07-13 04:05 - 2012-07-13 04:05 - 00166408 ____A C:\Windows\Minidump\071312-19531-01.dmp
2012-07-13 02:31 - 2012-07-13 02:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{412BB466-5B6C-48C9-8BA7-840CE05A2A61}
2012-07-13 02:31 - 2012-07-13 02:31 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{8DB67416-91A1-47D3-99E2-428A781FE4CF}
2012-07-12 13:02 - 2012-07-12 13:02 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{55DEDE60-7AB4-4861-9E90-69E358B95450}
2012-07-12 13:01 - 2012-07-12 13:02 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{700B0FB5-5216-403C-B65A-937EFC98B25D}
2012-07-11 23:32 - 2012-07-11 23:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{D8FE7A5F-3B7E-40DB-A773-35F40428024C}
2012-07-11 23:32 - 2012-07-11 23:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CAAB5001-9744-48D7-9895-37972AD7A038}
2012-07-11 15:00 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 11:38 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 11:38 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 11:38 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 11:38 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 11:38 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 11:38 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 11:38 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 11:38 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 11:38 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 11:38 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 10:19 - 2012-07-11 10:20 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F4D6462C-E307-4070-8595-D3BBCFC4B0B1}
2012-07-11 10:19 - 2012-07-11 10:19 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{82B94320-BDC9-4D17-8F11-BE53413162A4}
2012-07-05 00:58 - 2012-07-05 01:01 - 00694206 ____A C:\Users\Gwyn\Documents\RM Vehicle Database location.bmp
2012-07-05 00:32 - 2012-07-05 00:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{D38B37FB-0BC1-4739-8119-D13E61A7FA3D}
2012-07-05 00:32 - 2012-07-05 00:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{7E82A8EC-92EC-4B50-9CD3-0FA7A9F19C25}
============ 3 Months Modified Files ========================
2012-08-04 07:56 - 2012-03-28 04:51 - 01825438 ____A C:\Windows\WindowsUpdate.log
2012-08-04 07:56 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-04 07:56 - 2009-07-13 20:39 - 03981260 ____A C:\Windows\setupact.log
2012-08-04 07:45 - 2010-03-03 16:00 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-03 23:56 - 2012-08-03 23:56 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-03 00:26 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-02 03:45 - 2012-03-28 05:19 - 00795260 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-02 03:40 - 2009-07-13 20:33 - 00419768 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-31 06:01 - 2009-11-20 09:18 - 00132356 ____A C:\Windows\PFRO.log
2012-07-31 04:56 - 2010-03-03 16:00 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-31 03:49 - 2012-04-08 07:35 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-31 03:16 - 2009-07-13 20:53 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-31 00:53 - 2012-03-24 11:29 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-31 00:42 - 2012-04-08 09:01 - 00000497 ____A C:\rkill.log
2012-07-31 00:32 - 2009-07-13 20:34 - 00022928 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-31 00:32 - 2009-07-13 20:34 - 00022928 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 05:16 - 2012-07-29 05:16 - 00166408 ____A C:\Windows\Minidump\072912-14929-01.dmp
2012-07-29 05:16 - 2012-04-06 05:12 - 314480265 ____A C:\Windows\MEMORY.DMP
2012-07-28 07:58 - 2011-02-02 09:04 - 10099712 __ASH C:\Users\Gwyn\Documents\Thumbs.db
2012-07-27 09:05 - 2011-03-17 14:39 - 00536704 ____A C:\Users\Gwyn\Documents\Vehicle Records Mar 2011 - Via REG NUMBER.xlsx
2012-07-27 00:48 - 2012-04-08 07:34 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-27 00:48 - 2012-03-05 15:56 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-26 14:12 - 2012-07-26 14:12 - 00033920 ____A C:\Users\Gwyn\Desktop\Riley RMC 59SS 4990 1.htm
2012-07-26 04:50 - 2012-07-26 04:50 - 00166408 ____A C:\Windows\Minidump\072612-13681-01.dmp
2012-07-24 11:02 - 2012-07-24 11:02 - 00166408 ____A C:\Windows\Minidump\072412-13540-01.dmp
2012-07-24 04:11 - 2012-07-24 04:11 - 00166408 ____A C:\Windows\Minidump\072412-15241-01.dmp
2012-07-23 09:38 - 2012-07-23 09:38 - 00166408 ____A C:\Windows\Minidump\072312-14211-01.dmp
2012-07-22 12:08 - 2012-07-22 12:08 - 00166408 ____A C:\Windows\Minidump\072212-14476-01.dmp
2012-07-22 09:49 - 2012-07-22 09:49 - 00388608 ____A (Trend Micro Inc.) C:\Users\Gwyn\Downloads\HijackThis.exe
2012-07-22 09:49 - 2012-07-22 09:49 - 00007768 ____A C:\Users\Gwyn\Downloads\hijackthis.log
2012-07-22 09:10 - 2012-07-22 09:10 - 00002959 ____A C:\Users\Gwyn\Desktop\HiJackThis.lnk
2012-07-22 09:09 - 2012-07-22 09:09 - 01402880 ____A C:\Users\Gwyn\Downloads\HiJackThis.msi
2012-07-22 08:46 - 2012-07-22 08:46 - 01012656 ____A C:\Users\Gwyn\Desktop\rkill.exe
2012-07-21 10:35 - 2012-07-21 10:35 - 00166408 ____A C:\Windows\Minidump\072112-14274-01.dmp
2012-07-21 04:52 - 2012-07-21 04:52 - 00166408 ____A C:\Windows\Minidump\072112-15210-01.dmp
2012-07-20 05:33 - 2012-07-20 05:33 - 00000218 ____A C:\Users\Gwyn\.recently-used.xbel
2012-07-18 02:33 - 2012-07-18 02:33 - 21041152 ____A C:\Users\Gwyn\Documents\Gwyn.evtx
2012-07-17 02:55 - 2011-03-17 14:39 - 00536685 ____A C:\Users\Gwyn\Documents\Backup of Vehicle Records Mar 2011 - Via REG NUMBER.xlk
2012-07-17 01:42 - 2012-07-17 01:33 - 01068032 ____A C:\Users\Gwyn\Downloads\Vehicle Database Record for Forum July 2012.xls
2012-07-17 01:33 - 2012-07-17 01:33 - 01077248 ____A C:\Users\Gwyn\Downloads\Backup of Vehicle Database Record for Forum July 2012.xlk
2012-07-16 07:30 - 2011-10-31 00:33 - 00014915 ____A C:\Users\Gwyn\Documents\Chris Wright.xlsx
2012-07-16 06:38 - 2012-07-16 06:38 - 00166408 ____A C:\Windows\Minidump\071612-15990-01.dmp
2012-07-14 11:22 - 2012-07-14 11:22 - 00166408 ____A C:\Windows\Minidump\071412-13494-01.dmp
2012-07-13 04:05 - 2012-07-13 04:05 - 00166408 ____A C:\Windows\Minidump\071312-19531-01.dmp
2012-07-13 00:12 - 2011-02-09 06:14 - 00011096 ____A C:\Users\Gwyn\Documents\RM Con Rod Shell Conversions.xlsx
2012-07-12 10:17 - 2010-02-21 12:17 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-07-12 10:17 - 2010-02-21 12:17 - 00083392 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-07-12 10:17 - 2010-02-21 12:17 - 00030624 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-07-11 15:02 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-11 15:00 - 2012-03-28 06:22 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-05 01:01 - 2012-07-05 00:58 - 00694206 ____A C:\Users\Gwyn\Documents\RM Vehicle Database location.bmp
2012-07-03 04:46 - 2012-04-08 08:57 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 09:18 - 2012-07-02 09:18 - 00013399 ____A C:\Users\Gwyn\Desktop\hs_err_pid1444.log
2012-07-02 04:28 - 2012-07-02 04:28 - 00166408 ____A C:\Windows\Minidump\070212-16520-01.dmp
2012-06-30 12:38 - 2010-02-21 12:17 - 00001024 ____A C:\.rnd
2012-06-30 12:36 - 2012-06-30 12:36 - 00166408 ____A C:\Windows\Minidump\063012-20420-01.dmp
2012-06-30 02:55 - 2012-06-30 02:55 - 00166408 ____A C:\Windows\Minidump\063012-16957-01.dmp
2012-06-29 07:36 - 2012-06-29 07:36 - 00166408 ____A C:\Windows\Minidump\062912-17784-01.dmp
2012-06-27 04:13 - 2012-06-27 04:13 - 00166408 ____A C:\Windows\Minidump\062712-15709-01.dmp
2012-06-26 10:52 - 2012-06-26 10:52 - 00166408 ____A C:\Windows\Minidump\062612-12246-01.dmp
2012-06-26 06:47 - 2011-10-20 15:20 - 00014810 ____A C:\Users\Gwyn\Documents\Roger Turner.xlsx
2012-06-25 09:50 - 2012-06-25 09:50 - 00166408 ____A C:\Windows\Minidump\062512-12168-01.dmp
2012-06-25 04:05 - 2012-06-25 04:05 - 00166408 ____A C:\Windows\Minidump\062512-11856-01.dmp
2012-06-24 11:08 - 2012-06-24 11:08 - 00166408 ____A C:\Windows\Minidump\062412-12246-01.dmp
2012-06-22 10:53 - 2012-06-22 10:53 - 00166408 ____A C:\Windows\Minidump\062212-17316-01.dmp
2012-06-18 14:46 - 2012-06-18 14:46 - 00166408 ____A C:\Windows\Minidump\061812-12870-01.dmp
2012-06-14 05:10 - 2012-06-14 05:10 - 00166408 ____A C:\Windows\Minidump\061412-12760-01.dmp
2012-06-13 07:01 - 2012-06-13 07:01 - 00166408 ____A C:\Windows\Minidump\061312-11793-01.dmp
2012-06-13 04:07 - 2012-06-13 04:07 - 00166408 ____A C:\Windows\Minidump\061312-12448-01.dmp
2012-06-12 12:45 - 2012-06-12 12:45 - 00010209 ____A C:\Users\Gwyn\Documents\Gwyn - Blood Press Check.xlsx
2012-06-12 10:54 - 2012-06-12 10:54 - 00166408 ____A C:\Windows\Minidump\061212-18657-01.dmp
2012-06-11 18:40 - 2012-07-11 15:00 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 07:43 - 2012-06-10 07:43 - 00166408 ____A C:\Windows\Minidump\061012-13010-01.dmp
2012-06-09 08:44 - 2012-06-09 08:44 - 00166408 ____A C:\Windows\Minidump\060912-11824-01.dmp
2012-06-09 05:01 - 2012-06-09 05:01 - 00160232 ____A C:\Windows\Minidump\060912-13743-01.dmp
2012-06-08 20:41 - 2012-07-11 11:38 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-06 11:14 - 2012-06-06 11:14 - 00166408 ____A C:\Windows\Minidump\060612-14461-01.dmp
2012-06-06 06:28 - 2012-06-06 06:28 - 00166408 ____A C:\Windows\Minidump\060612-12058-01.dmp
2012-06-06 02:15 - 2012-06-06 02:15 - 00166408 ____A C:\Windows\Minidump\060612-16707-01.dmp
2012-06-05 21:05 - 2012-07-11 11:38 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-11 11:38 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-11 11:38 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 03:43 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 03:43 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 03:43 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 13:57 - 2012-06-02 13:57 - 00166408 ____A C:\Windows\Minidump\060212-14398-01.dmp
2012-06-02 06:19 - 2012-06-19 03:43 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-19 03:43 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 05:54 - 2012-06-02 05:54 - 00166408 ____A C:\Windows\Minidump\060212-15397-01.dmp
2012-06-01 20:45 - 2012-07-11 11:38 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-11 11:38 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-11 11:38 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-11 11:38 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-11 11:38 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 09:19 - 2012-06-01 09:19 - 00166408 ____A C:\Windows\Minidump\060112-13291-01.dmp
2012-05-31 08:29 - 2012-05-31 08:29 - 00166408 ____A C:\Windows\Minidump\053112-18720-01.dmp
2012-05-22 10:07 - 2012-05-22 10:07 - 00166408 ____A C:\Windows\Minidump\052212-16380-01.dmp
2012-05-21 10:28 - 2010-02-21 12:17 - 00083360 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll.000.bak
2012-05-21 09:50 - 2012-05-21 09:50 - 00166408 ____A C:\Windows\Minidump\052112-17893-01.dmp
2012-05-21 05:41 - 2012-05-21 05:41 - 00166408 ____A C:\Windows\Minidump\052112-13712-01.dmp
2012-05-17 06:58 - 2012-05-17 06:57 - 00166408 ____A C:\Windows\Minidump\051712-11497-01.dmp
2012-05-16 15:10 - 2012-05-16 15:10 - 00166408 ____A C:\Windows\Minidump\051712-11590-01.dmp
2012-05-16 10:46 - 2012-05-16 10:46 - 00166408 ____A C:\Windows\Minidump\051612-14882-01.dmp
2012-05-14 19:03 - 2012-06-13 10:48 - 00981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 19:00 - 2012-06-13 10:48 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 13:29 - 2012-05-14 13:29 - 00166408 ____A C:\Windows\Minidump\051412-14991-01.dmp
ZeroAccess:
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\@
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\U
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\00000004.@
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\1afb2d56
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\201d3dde
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\55490ac4
ZeroAccess:
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\@
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-03 00:26] - 0259072 ____A (Microsoft Corporation) CE3495D096245069D7B63E348C91A74B
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3063.11 MB
Available physical RAM: 2579.68 MB
Total Pagefile: 3061.39 MB
Available Pagefile: 2596 MB
Total Virtual: 2047.88 MB
Available Virtual: 1962.3 MB
======================= Partitions =========================
1 Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:838.37 GB) NTFS
2 Drive e: (Recover) (Fixed) (Total:20 GB) (Free:10.54 GB) NTFS
7 Drive j: (INTENSO) (Removable) (Total:29.65 GB) (Free:19.02 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 Online 29 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 910 GB 101 MB
Partition 3 Primary 20 GB 910 GB
Partition 4 OEM 1025 MB 930 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Boot NTFS Partition 910 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recover NTFS Partition 20 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 12
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 NTFS Partition 1025 MB Healthy Hidden
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 29 GB 19 MB
==================================================================================
Disk: 4
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J INTENSO FAT32 Removable 29 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 01:34
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-04 17:25:15
Running from J:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-03 00:26] - 0259072 ____A (Microsoft Corporation) CE3495D096245069D7B63E348C91A74B
=== End Of Search ===
Thank you for taking the time to help (assuming you do!)
Pete
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 04-08-2012 17:09:49
Running from J:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [7703072 2009-08-04] (Realtek Semiconductor)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [63048 2010-09-17] (LogMeIn, Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\LogMeInRemoteUser\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-05] (Google Inc.)
HKU\LogMeInRemoteUser\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [3905920 2012-03-07] (SUPERAntiSpyware.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
================================ Services (Whitelisted) ==================
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE.EXE" [116608 2011-08-11] (SUPERAntiSpyware.com)
2 BFBackupUtilityService; C:\Program Files\BUFFALO\Backup_Utility\BUService.exe -Service_Execute [320888 2010-08-19] (BUFFALO INC.)
2 BFBackupUtilityVSSService; C:\Program Files\BUFFALO\Backup_Utility\BUVSSService.exe -Service_Execute [247160 2010-04-27] (BUFFALO INC.)
2 bufssvr; C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe [95608 2010-03-15] (BUFFALO INC.)
4 EASEUS Agent; C:\Program Files\EASEUS\Todo Backup 2.0\bin\Agent.exe [55688 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION)
2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
4 Hamachi2Svc; "C:\Program Files\LogMeIn Hamachi\hamachi-2.exe" -s [1373576 2012-02-28] (LogMeIn Inc.)
2 LMIGuardianSvc; "C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe" [374184 2012-07-12] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files\LogMeIn\x86\RaMaint.exe" [136616 2012-07-12] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files\LogMeIn\x86\LogMeIn.exe" [390528 2010-11-08] (LogMeIn, Inc.)
4 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
2 MSSQL$INFLOWSQL; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINFLOWSQL [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
4 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
========================== Drivers (Whitelisted) =============
3 athur; C:\Windows\System32\DRIVERS\athur.sys [1570304 2011-04-20] (Atheros Communications, Inc.)
0 bftpdskc; C:\Windows\System32\drivers\bftpdskc.sys [41472 2010-10-14] (BUFFALO INC.)
3 bftpusbx; C:\Windows\System32\drivers\bftpusbx.sys [11776 2010-09-21] (BUFFALO INC.)
0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [31112 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
1 EUDSKACS; \??\C:\Windows\system32\drivers\eudskacs.sys [15240 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
0 EUFS; C:\Windows\System32\drivers\eufs.sys [21896 2010-12-26] (CHENGDU YIWO Tech Development Co., Ltd)
3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
2 LMIInfo; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys [12856 2010-09-17] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [10144 2010-09-17] (LogMeIn, Inc.)
2 LMIRfsDriver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [47640 2010-09-17] (LogMeIn, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
2 ppsio2; C:\Windows\System32\Drivers\ppsio2.sys [23200 1999-06-29] ()
3 RTL8192su; C:\Windows\System32\DRIVERS\RTL8192su.sys [603240 2010-11-24] (Realtek Semiconductor Corporation )
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
4 LMIRfsClientNP; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-03 23:56 - 2012-08-03 23:56 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-02 04:46 - 2012-08-03 10:40 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-07-31 00:51 - 2012-07-31 00:51 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-30 10:42 - 2012-07-30 10:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{9AF2849D-5CF9-413F-913A-EA0BD7980515}
2012-07-30 10:42 - 2012-07-30 10:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{2C86F956-D034-4D44-91BB-4D6605148C05}
2012-07-29 05:16 - 2012-07-29 05:16 - 00166408 ____A C:\Windows\Minidump\072912-14929-01.dmp
2012-07-29 02:15 - 2012-07-29 02:16 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{3A6FC11A-EBE8-4235-A3B9-47873FAC29E4}
2012-07-29 02:15 - 2012-07-29 02:15 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F3692599-DBC7-497A-BA48-DB3DD6D3FAD8}
2012-07-28 14:14 - 2012-07-28 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B5CE533E-756C-4460-B542-EE6949D03955}
2012-07-28 14:14 - 2012-07-28 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{59AA0593-B157-4500-9448-CA5D9BA245A6}
2012-07-28 00:29 - 2012-07-28 00:29 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{C783B4F9-C055-414F-A29E-FBA898BE2C1F}
2012-07-28 00:29 - 2012-07-28 00:29 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{465DB4D1-645C-439F-93D2-F0CB336587BA}
2012-07-27 04:44 - 2012-07-27 04:44 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E8B56172-F831-453E-A7DA-AE7EA148C3F3}
2012-07-27 04:44 - 2012-07-27 04:44 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{1D08DCFB-0E56-4D57-AEAA-881DF58F6F18}
2012-07-27 02:23 - 2012-07-27 02:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B9F20DCD-9435-4DCE-9388-EBF84E9CF4EB}
2012-07-27 02:23 - 2012-07-27 02:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{1AB135E2-0886-48BA-B1D6-2AD1121C6CDA}
2012-07-26 14:12 - 2012-07-26 14:12 - 00033920 ____A C:\Users\Gwyn\Desktop\Riley RMC 59SS 4990 1.htm
2012-07-26 13:51 - 2012-07-26 13:52 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CC579666-FAB1-48ED-8C34-FD8F70CF5ABE}
2012-07-26 13:51 - 2012-07-26 13:51 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{1FBE7D1C-FE7D-48F5-8073-7492163F126D}
2012-07-26 04:50 - 2012-07-26 04:50 - 00166408 ____A C:\Windows\Minidump\072612-13681-01.dmp
2012-07-26 01:42 - 2012-07-26 01:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{6231AB51-AA04-4741-919B-140905B5682E}
2012-07-26 01:42 - 2012-07-26 01:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{6080759B-6B16-4F3C-850A-EEC27C32EC74}
2012-07-25 13:08 - 2012-07-25 13:09 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{6129E0F5-015B-4EA7-BAAA-4684EFFC2031}
2012-07-25 13:08 - 2012-07-25 13:08 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{0FC64805-1B01-402B-B3D7-06E1F90810D6}
2012-07-25 01:08 - 2012-07-25 01:08 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F4EC7F9C-E1B5-4E39-9E8A-52F676C50A5E}
2012-07-25 01:07 - 2012-07-25 01:08 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{76E170F3-8D88-4D2A-B163-2F4D5F8CAE07}
2012-07-24 13:00 - 2012-07-24 13:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E9A2F80C-577B-4D6B-B6B0-75EF2B5B5A66}
2012-07-24 13:00 - 2012-07-24 13:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{826CAE1E-AF39-4DC4-B156-CD64B211C2B5}
2012-07-24 11:02 - 2012-07-24 11:02 - 00166408 ____A C:\Windows\Minidump\072412-13540-01.dmp
2012-07-24 04:11 - 2012-07-24 04:11 - 00166408 ____A C:\Windows\Minidump\072412-15241-01.dmp
2012-07-24 00:59 - 2012-07-24 00:59 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CABE8A9D-3A4B-4591-BC32-F6E2C5498DD4}
2012-07-24 00:59 - 2012-07-24 00:59 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B56637D0-692E-4A38-BDCA-F7A568E65029}
2012-07-23 09:38 - 2012-07-23 09:38 - 00166408 ____A C:\Windows\Minidump\072312-14211-01.dmp
2012-07-23 05:23 - 2012-07-23 05:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CA98AAC7-0DF0-4B12-8918-B1E413702B1E}
2012-07-23 05:22 - 2012-07-23 05:23 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{44428345-DEE0-470A-BB97-333B0459CF78}
2012-07-22 12:08 - 2012-07-22 12:08 - 00166408 ____A C:\Windows\Minidump\072212-14476-01.dmp
2012-07-22 09:52 - 2012-07-22 09:52 - 00000000 ____D C:\Users\Gwyn\Downloads\backups
2012-07-22 09:49 - 2012-07-22 09:49 - 00388608 ____A (Trend Micro Inc.) C:\Users\Gwyn\Downloads\HijackThis.exe
2012-07-22 09:49 - 2012-07-22 09:49 - 00007768 ____A C:\Users\Gwyn\Downloads\hijackthis.log
2012-07-22 09:10 - 2012-07-22 09:10 - 00002959 ____A C:\Users\Gwyn\Desktop\HiJackThis.lnk
2012-07-22 09:10 - 2012-07-22 09:10 - 00000000 ____D C:\Program Files\Trend Micro
2012-07-22 09:09 - 2012-07-22 09:09 - 01402880 ____A C:\Users\Gwyn\Downloads\HiJackThis.msi
2012-07-22 08:55 - 2012-07-22 08:55 - 00000000 ____D C:\Users\Gwyn\AppData\Roaming\Malwarebytes
2012-07-22 08:46 - 2012-07-22 08:46 - 01012656 ____A C:\Users\Gwyn\Desktop\rkill.exe
2012-07-22 03:47 - 2012-07-22 03:47 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{DE04460F-F384-4E6B-BB71-D67B03E848BB}
2012-07-22 03:47 - 2012-07-22 03:47 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{2473BEF3-C5D2-414C-A802-6FE3AACC456C}
2012-07-21 10:35 - 2012-07-21 10:35 - 00166408 ____A C:\Windows\Minidump\072112-14274-01.dmp
2012-07-21 04:56 - 2012-07-21 04:57 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{5C4C2820-A844-43A4-A58A-8CE87DA10954}
2012-07-21 04:56 - 2012-07-21 04:56 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{81F1BB1E-4391-4BB3-9D17-C8E7BE65856D}
2012-07-21 04:52 - 2012-07-21 04:52 - 00166408 ____A C:\Windows\Minidump\072112-15210-01.dmp
2012-07-20 14:14 - 2012-07-20 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{D2FA5B7B-D818-4461-8E83-29FE451C89FF}
2012-07-20 14:13 - 2012-07-20 14:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{95131E5B-091A-4AD8-8F69-398D3C1D63FF}
2012-07-20 05:33 - 2012-07-20 05:33 - 00000218 ____A C:\Users\Gwyn\.recently-used.xbel
2012-07-20 02:06 - 2012-07-20 02:07 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E27E783E-65A8-479E-9331-10DF558C5173}
2012-07-20 02:06 - 2012-07-20 02:06 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E0197778-1E7C-4B68-A2E6-5341DD7C0EEB}
2012-07-19 14:06 - 2012-07-19 14:06 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{7ABC5EEB-13E0-4B5C-B2EB-271625304E9D}
2012-07-19 14:06 - 2012-07-19 14:06 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{2B25BEC4-C8C7-4F98-9989-95D1BA4815EC}
2012-07-19 02:05 - 2012-07-19 02:05 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{9F466BBB-8997-4384-A43F-1074321665AD}
2012-07-19 02:05 - 2012-07-19 02:05 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{05317589-B5AE-40FF-9380-2068D64C7767}
2012-07-18 04:37 - 2012-07-18 04:37 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{5F727C78-D578-45A6-B886-6826972B5E64}
2012-07-18 04:37 - 2012-07-18 04:37 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{290138E1-5C68-41D8-B578-A8FD55B652B8}
2012-07-18 02:33 - 2012-07-18 02:33 - 21041152 ____A C:\Users\Gwyn\Documents\Gwyn.evtx
2012-07-18 02:33 - 2012-07-18 02:33 - 00000000 ____D C:\Users\Gwyn\Documents\LocaleMetaData
2012-07-17 14:43 - 2012-07-17 14:43 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{FB33A973-1718-400D-A157-0D45CE448205}
2012-07-17 14:42 - 2012-07-17 14:42 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{5E4236B1-8A96-4897-BCD7-F145EE715909}
2012-07-17 01:33 - 2012-07-17 01:42 - 01068032 ____A C:\Users\Gwyn\Downloads\Vehicle Database Record for Forum July 2012.xls
2012-07-17 01:33 - 2012-07-17 01:33 - 01077248 ____A C:\Users\Gwyn\Downloads\Backup of Vehicle Database Record for Forum July 2012.xlk
2012-07-17 01:03 - 2012-07-17 01:03 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F739956B-F2E0-4A1C-A528-4D665D17A38E}
2012-07-17 01:02 - 2012-07-17 01:03 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{ABC7756C-0FAB-48DE-AF97-41890D8CA9CF}
2012-07-16 15:10 - 2012-07-16 15:10 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{8F2259B2-A66C-45E2-B91B-DE516A9A35F1}
2012-07-16 14:58 - 2012-07-16 14:58 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{4CF99DD4-C3F4-4D16-9E7C-A02389A4E76C}
2012-07-16 06:38 - 2012-07-16 06:38 - 00166408 ____A C:\Windows\Minidump\071612-15990-01.dmp
2012-07-16 01:54 - 2012-07-16 01:54 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{80BE07CC-402E-4CA2-A62B-365E6E3C8EAF}
2012-07-16 01:54 - 2012-07-16 01:54 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{7D52B1AF-701B-4632-BCA3-B6186736A21F}
2012-07-15 13:14 - 2012-07-15 13:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{AE785B1A-0391-47AD-9EF1-E57F5AFCAD58}
2012-07-15 13:14 - 2012-07-15 13:14 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{47D61808-77F8-4E8A-A842-A0CDC83E90BA}
2012-07-14 23:33 - 2012-07-14 23:33 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{02A162D1-7821-4480-AE18-2435B80A1C36}
2012-07-14 23:32 - 2012-07-14 23:33 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{E86B0ED7-BCEB-45C3-8A88-4FBD2B5D674D}
2012-07-14 11:22 - 2012-07-14 11:22 - 00166408 ____A C:\Windows\Minidump\071412-13494-01.dmp
2012-07-14 05:00 - 2012-07-14 05:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{C838E630-1043-49CA-AEDE-FF078A0A3F4D}
2012-07-14 05:00 - 2012-07-14 05:00 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{30CC3237-7153-449D-9C14-1C35363EF3BF}
2012-07-13 14:35 - 2012-07-13 14:35 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{B678F90D-D6C8-418A-ABBB-07EB2253D79B}
2012-07-13 14:34 - 2012-07-13 14:35 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{A2A6C564-E29B-434B-AFB3-68C81BB625CF}
2012-07-13 04:05 - 2012-07-13 04:05 - 00166408 ____A C:\Windows\Minidump\071312-19531-01.dmp
2012-07-13 02:31 - 2012-07-13 02:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{412BB466-5B6C-48C9-8BA7-840CE05A2A61}
2012-07-13 02:31 - 2012-07-13 02:31 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{8DB67416-91A1-47D3-99E2-428A781FE4CF}
2012-07-12 13:02 - 2012-07-12 13:02 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{55DEDE60-7AB4-4861-9E90-69E358B95450}
2012-07-12 13:01 - 2012-07-12 13:02 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{700B0FB5-5216-403C-B65A-937EFC98B25D}
2012-07-11 23:32 - 2012-07-11 23:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{D8FE7A5F-3B7E-40DB-A773-35F40428024C}
2012-07-11 23:32 - 2012-07-11 23:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{CAAB5001-9744-48D7-9895-37972AD7A038}
2012-07-11 15:00 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 11:38 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 11:38 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 11:38 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 11:38 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 11:38 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 11:38 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 11:38 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 11:38 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 11:38 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 11:38 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 10:19 - 2012-07-11 10:20 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{F4D6462C-E307-4070-8595-D3BBCFC4B0B1}
2012-07-11 10:19 - 2012-07-11 10:19 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{82B94320-BDC9-4D17-8F11-BE53413162A4}
2012-07-05 00:58 - 2012-07-05 01:01 - 00694206 ____A C:\Users\Gwyn\Documents\RM Vehicle Database location.bmp
2012-07-05 00:32 - 2012-07-05 00:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{D38B37FB-0BC1-4739-8119-D13E61A7FA3D}
2012-07-05 00:32 - 2012-07-05 00:32 - 00000000 ____D C:\Users\Gwyn\AppData\Local\{7E82A8EC-92EC-4B50-9CD3-0FA7A9F19C25}
============ 3 Months Modified Files ========================
2012-08-04 07:56 - 2012-03-28 04:51 - 01825438 ____A C:\Windows\WindowsUpdate.log
2012-08-04 07:56 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-04 07:56 - 2009-07-13 20:39 - 03981260 ____A C:\Windows\setupact.log
2012-08-04 07:45 - 2010-03-03 16:00 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-03 23:56 - 2012-08-03 23:56 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-03 00:26 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-02 03:45 - 2012-03-28 05:19 - 00795260 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-02 03:40 - 2009-07-13 20:33 - 00419768 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-31 06:01 - 2009-11-20 09:18 - 00132356 ____A C:\Windows\PFRO.log
2012-07-31 04:56 - 2010-03-03 16:00 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-31 03:49 - 2012-04-08 07:35 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-31 03:16 - 2009-07-13 20:53 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-31 00:53 - 2012-03-24 11:29 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-31 00:42 - 2012-04-08 09:01 - 00000497 ____A C:\rkill.log
2012-07-31 00:32 - 2009-07-13 20:34 - 00022928 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-31 00:32 - 2009-07-13 20:34 - 00022928 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 05:16 - 2012-07-29 05:16 - 00166408 ____A C:\Windows\Minidump\072912-14929-01.dmp
2012-07-29 05:16 - 2012-04-06 05:12 - 314480265 ____A C:\Windows\MEMORY.DMP
2012-07-28 07:58 - 2011-02-02 09:04 - 10099712 __ASH C:\Users\Gwyn\Documents\Thumbs.db
2012-07-27 09:05 - 2011-03-17 14:39 - 00536704 ____A C:\Users\Gwyn\Documents\Vehicle Records Mar 2011 - Via REG NUMBER.xlsx
2012-07-27 00:48 - 2012-04-08 07:34 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-27 00:48 - 2012-03-05 15:56 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-26 14:12 - 2012-07-26 14:12 - 00033920 ____A C:\Users\Gwyn\Desktop\Riley RMC 59SS 4990 1.htm
2012-07-26 04:50 - 2012-07-26 04:50 - 00166408 ____A C:\Windows\Minidump\072612-13681-01.dmp
2012-07-24 11:02 - 2012-07-24 11:02 - 00166408 ____A C:\Windows\Minidump\072412-13540-01.dmp
2012-07-24 04:11 - 2012-07-24 04:11 - 00166408 ____A C:\Windows\Minidump\072412-15241-01.dmp
2012-07-23 09:38 - 2012-07-23 09:38 - 00166408 ____A C:\Windows\Minidump\072312-14211-01.dmp
2012-07-22 12:08 - 2012-07-22 12:08 - 00166408 ____A C:\Windows\Minidump\072212-14476-01.dmp
2012-07-22 09:49 - 2012-07-22 09:49 - 00388608 ____A (Trend Micro Inc.) C:\Users\Gwyn\Downloads\HijackThis.exe
2012-07-22 09:49 - 2012-07-22 09:49 - 00007768 ____A C:\Users\Gwyn\Downloads\hijackthis.log
2012-07-22 09:10 - 2012-07-22 09:10 - 00002959 ____A C:\Users\Gwyn\Desktop\HiJackThis.lnk
2012-07-22 09:09 - 2012-07-22 09:09 - 01402880 ____A C:\Users\Gwyn\Downloads\HiJackThis.msi
2012-07-22 08:46 - 2012-07-22 08:46 - 01012656 ____A C:\Users\Gwyn\Desktop\rkill.exe
2012-07-21 10:35 - 2012-07-21 10:35 - 00166408 ____A C:\Windows\Minidump\072112-14274-01.dmp
2012-07-21 04:52 - 2012-07-21 04:52 - 00166408 ____A C:\Windows\Minidump\072112-15210-01.dmp
2012-07-20 05:33 - 2012-07-20 05:33 - 00000218 ____A C:\Users\Gwyn\.recently-used.xbel
2012-07-18 02:33 - 2012-07-18 02:33 - 21041152 ____A C:\Users\Gwyn\Documents\Gwyn.evtx
2012-07-17 02:55 - 2011-03-17 14:39 - 00536685 ____A C:\Users\Gwyn\Documents\Backup of Vehicle Records Mar 2011 - Via REG NUMBER.xlk
2012-07-17 01:42 - 2012-07-17 01:33 - 01068032 ____A C:\Users\Gwyn\Downloads\Vehicle Database Record for Forum July 2012.xls
2012-07-17 01:33 - 2012-07-17 01:33 - 01077248 ____A C:\Users\Gwyn\Downloads\Backup of Vehicle Database Record for Forum July 2012.xlk
2012-07-16 07:30 - 2011-10-31 00:33 - 00014915 ____A C:\Users\Gwyn\Documents\Chris Wright.xlsx
2012-07-16 06:38 - 2012-07-16 06:38 - 00166408 ____A C:\Windows\Minidump\071612-15990-01.dmp
2012-07-14 11:22 - 2012-07-14 11:22 - 00166408 ____A C:\Windows\Minidump\071412-13494-01.dmp
2012-07-13 04:05 - 2012-07-13 04:05 - 00166408 ____A C:\Windows\Minidump\071312-19531-01.dmp
2012-07-13 00:12 - 2011-02-09 06:14 - 00011096 ____A C:\Users\Gwyn\Documents\RM Con Rod Shell Conversions.xlsx
2012-07-12 10:17 - 2010-02-21 12:17 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-07-12 10:17 - 2010-02-21 12:17 - 00083392 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-07-12 10:17 - 2010-02-21 12:17 - 00030624 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-07-11 15:02 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-11 15:00 - 2012-03-28 06:22 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-05 01:01 - 2012-07-05 00:58 - 00694206 ____A C:\Users\Gwyn\Documents\RM Vehicle Database location.bmp
2012-07-03 04:46 - 2012-04-08 08:57 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 09:18 - 2012-07-02 09:18 - 00013399 ____A C:\Users\Gwyn\Desktop\hs_err_pid1444.log
2012-07-02 04:28 - 2012-07-02 04:28 - 00166408 ____A C:\Windows\Minidump\070212-16520-01.dmp
2012-06-30 12:38 - 2010-02-21 12:17 - 00001024 ____A C:\.rnd
2012-06-30 12:36 - 2012-06-30 12:36 - 00166408 ____A C:\Windows\Minidump\063012-20420-01.dmp
2012-06-30 02:55 - 2012-06-30 02:55 - 00166408 ____A C:\Windows\Minidump\063012-16957-01.dmp
2012-06-29 07:36 - 2012-06-29 07:36 - 00166408 ____A C:\Windows\Minidump\062912-17784-01.dmp
2012-06-27 04:13 - 2012-06-27 04:13 - 00166408 ____A C:\Windows\Minidump\062712-15709-01.dmp
2012-06-26 10:52 - 2012-06-26 10:52 - 00166408 ____A C:\Windows\Minidump\062612-12246-01.dmp
2012-06-26 06:47 - 2011-10-20 15:20 - 00014810 ____A C:\Users\Gwyn\Documents\Roger Turner.xlsx
2012-06-25 09:50 - 2012-06-25 09:50 - 00166408 ____A C:\Windows\Minidump\062512-12168-01.dmp
2012-06-25 04:05 - 2012-06-25 04:05 - 00166408 ____A C:\Windows\Minidump\062512-11856-01.dmp
2012-06-24 11:08 - 2012-06-24 11:08 - 00166408 ____A C:\Windows\Minidump\062412-12246-01.dmp
2012-06-22 10:53 - 2012-06-22 10:53 - 00166408 ____A C:\Windows\Minidump\062212-17316-01.dmp
2012-06-18 14:46 - 2012-06-18 14:46 - 00166408 ____A C:\Windows\Minidump\061812-12870-01.dmp
2012-06-14 05:10 - 2012-06-14 05:10 - 00166408 ____A C:\Windows\Minidump\061412-12760-01.dmp
2012-06-13 07:01 - 2012-06-13 07:01 - 00166408 ____A C:\Windows\Minidump\061312-11793-01.dmp
2012-06-13 04:07 - 2012-06-13 04:07 - 00166408 ____A C:\Windows\Minidump\061312-12448-01.dmp
2012-06-12 12:45 - 2012-06-12 12:45 - 00010209 ____A C:\Users\Gwyn\Documents\Gwyn - Blood Press Check.xlsx
2012-06-12 10:54 - 2012-06-12 10:54 - 00166408 ____A C:\Windows\Minidump\061212-18657-01.dmp
2012-06-11 18:40 - 2012-07-11 15:00 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 07:43 - 2012-06-10 07:43 - 00166408 ____A C:\Windows\Minidump\061012-13010-01.dmp
2012-06-09 08:44 - 2012-06-09 08:44 - 00166408 ____A C:\Windows\Minidump\060912-11824-01.dmp
2012-06-09 05:01 - 2012-06-09 05:01 - 00160232 ____A C:\Windows\Minidump\060912-13743-01.dmp
2012-06-08 20:41 - 2012-07-11 11:38 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-06 11:14 - 2012-06-06 11:14 - 00166408 ____A C:\Windows\Minidump\060612-14461-01.dmp
2012-06-06 06:28 - 2012-06-06 06:28 - 00166408 ____A C:\Windows\Minidump\060612-12058-01.dmp
2012-06-06 02:15 - 2012-06-06 02:15 - 00166408 ____A C:\Windows\Minidump\060612-16707-01.dmp
2012-06-05 21:05 - 2012-07-11 11:38 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-11 11:38 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-11 11:38 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 03:43 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 03:43 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 03:43 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 03:43 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 13:57 - 2012-06-02 13:57 - 00166408 ____A C:\Windows\Minidump\060212-14398-01.dmp
2012-06-02 06:19 - 2012-06-19 03:43 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-19 03:43 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 05:54 - 2012-06-02 05:54 - 00166408 ____A C:\Windows\Minidump\060212-15397-01.dmp
2012-06-01 20:45 - 2012-07-11 11:38 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-11 11:38 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-11 11:38 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-11 11:38 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-11 11:38 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 09:19 - 2012-06-01 09:19 - 00166408 ____A C:\Windows\Minidump\060112-13291-01.dmp
2012-05-31 08:29 - 2012-05-31 08:29 - 00166408 ____A C:\Windows\Minidump\053112-18720-01.dmp
2012-05-22 10:07 - 2012-05-22 10:07 - 00166408 ____A C:\Windows\Minidump\052212-16380-01.dmp
2012-05-21 10:28 - 2010-02-21 12:17 - 00083360 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll.000.bak
2012-05-21 09:50 - 2012-05-21 09:50 - 00166408 ____A C:\Windows\Minidump\052112-17893-01.dmp
2012-05-21 05:41 - 2012-05-21 05:41 - 00166408 ____A C:\Windows\Minidump\052112-13712-01.dmp
2012-05-17 06:58 - 2012-05-17 06:57 - 00166408 ____A C:\Windows\Minidump\051712-11497-01.dmp
2012-05-16 15:10 - 2012-05-16 15:10 - 00166408 ____A C:\Windows\Minidump\051712-11590-01.dmp
2012-05-16 10:46 - 2012-05-16 10:46 - 00166408 ____A C:\Windows\Minidump\051612-14882-01.dmp
2012-05-14 19:03 - 2012-06-13 10:48 - 00981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 19:00 - 2012-06-13 10:48 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 13:29 - 2012-05-14 13:29 - 00166408 ____A C:\Windows\Minidump\051412-14991-01.dmp
ZeroAccess:
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\@
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\U
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\00000004.@
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\1afb2d56
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\201d3dde
C:\Windows\Installer\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L\55490ac4
ZeroAccess:
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\@
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\L
C:\Users\Gwyn\AppData\Local\{bbbd2744-9466-efd7-0a2a-bbddc51a15a3}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-03 00:26] - 0259072 ____A (Microsoft Corporation) CE3495D096245069D7B63E348C91A74B
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3063.11 MB
Available physical RAM: 2579.68 MB
Total Pagefile: 3061.39 MB
Available Pagefile: 2596 MB
Total Virtual: 2047.88 MB
Available Virtual: 1962.3 MB
======================= Partitions =========================
1 Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:838.37 GB) NTFS
2 Drive e: (Recover) (Fixed) (Total:20 GB) (Free:10.54 GB) NTFS
7 Drive j: (INTENSO) (Removable) (Total:29.65 GB) (Free:19.02 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 Online 29 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 910 GB 101 MB
Partition 3 Primary 20 GB 910 GB
Partition 4 OEM 1025 MB 930 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Boot NTFS Partition 910 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recover NTFS Partition 20 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 12
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 NTFS Partition 1025 MB Healthy Hidden
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 29 GB 19 MB
==================================================================================
Disk: 4
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J INTENSO FAT32 Removable 29 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 01:34
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-04 17:25:15
Running from J:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-03 00:26] - 0259072 ____A (Microsoft Corporation) CE3495D096245069D7B63E348C91A74B
=== End Of Search ===
Thank you for taking the time to help (assuming you do!)
Pete