Geremy Walker
Posts: 18 +0
So after looking through the threads here, it seems I've got the same issue as many others with a sirefef/fake flash install virus. It came up asking me to install flash, to which I said NO multiple times, and I thought it was odd that it kept forcing itself..
Anyway, I've read through a few threads on the topic, and I have performed the first few steps/reports already. Posting of the contents follows.
Scan result of Farbar Recovery Scan Tool Version: 03-07-2012 01
Ran by Geremy at 03-07-2012 22:09:32
Running from F:\
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-03 22:05 - 2012-07-03 22:05 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zxcahoyv.sys
2012-07-03 22:04 - 2012-07-03 22:09 - 00000000 ____D C:\FRST
2012-07-03 21:42 - 2012-07-03 21:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.055BF01D61730CA8
2012-07-03 21:39 - 2012-07-03 21:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA897737214FB219
2012-07-03 21:39 - 2012-07-03 21:39 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndzhiclp.sys
2012-07-03 21:36 - 2012-07-03 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7650BBB7848E48AB
2012-07-03 21:34 - 2012-07-03 21:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC49998995B969C2
2012-07-03 21:28 - 2012-07-03 21:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.79FE9C5165055EC3
2012-07-03 21:25 - 2012-07-03 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66BBA8088936891B
2012-07-03 21:21 - 2012-07-03 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F2CD0B82DBC534F
2012-07-03 21:10 - 2012-07-03 21:10 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-03 21:10 - 2012-07-03 21:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-03 21:07 - 2012-07-03 21:08 - 12621696 ____A (Microsoft Corporation) C:\Users\Geremy\Downloads\mseinstall.exe
2012-07-03 20:54 - 2012-07-03 20:54 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2012-07-03 20:52 - 2012-07-03 20:52 - 00007597 ____A C:\Users\Geremy\AppData\Local\Resmon.ResmonCfg
2012-07-03 19:39 - 2012-07-03 19:39 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-03 02:01 - 2012-07-03 02:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{92192416-5FE4-4C6A-BFEB-14956D31EA06}
2012-07-03 02:00 - 2012-07-03 02:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{B958EE0C-8769-47CC-8A7A-977FCD0592D8}
2012-07-02 14:00 - 2012-07-02 14:00 - 00000000 ____D C:\Users\Geremy\AppData\Local\{B9840E06-A25A-4276-A36D-50B8E6D90108}
2012-07-02 13:59 - 2012-07-02 14:00 - 00000000 ____D C:\Users\Geremy\AppData\Local\{1B7FB947-6B40-440A-99F2-48BC06BA4953}
2012-06-30 00:50 - 2012-06-30 00:50 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5E34E0E6-92BB-42EF-9641-52D7000979BC}
2012-06-30 00:49 - 2012-06-30 00:50 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5E082280-2A43-4F81-8DF0-E20A4975BA1A}
2012-06-28 18:16 - 2012-06-28 18:16 - 00033939 ____A C:\Users\Geremy\.recently-used.xbel
2012-06-28 17:03 - 2012-06-28 17:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{65F1A6B0-A98E-44AC-B794-04A531830FB6}
2012-06-28 17:03 - 2012-06-28 17:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{0AAA81A1-A307-44A2-AC5C-C3E1B98318D5}
2012-06-27 15:55 - 2012-07-02 13:54 - 00000000 ____D C:\Users\Geremy\Desktop\INVOICE
2012-06-27 15:39 - 2012-06-27 15:39 - 00000000 ____D C:\Users\Geremy\AppData\Local\{BA52C587-F055-4F70-9240-8162AE36672F}
2012-06-27 15:38 - 2012-06-27 15:39 - 00000000 ____D C:\Users\Geremy\AppData\Local\{DCF3C70D-06B9-4311-B25E-C9578688371D}
2012-06-26 15:32 - 2012-06-26 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9953C31F-9209-4CBD-BC80-BEFFCE08F805}
2012-06-26 15:31 - 2012-06-26 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{35AAADBD-DF4D-4D81-828E-AEE29DAAD7F3}
2012-06-26 03:31 - 2012-06-26 03:31 - 00000000 ____D C:\Users\Geremy\AppData\Local\{F7DB33B9-AD2C-491E-A483-0925C6A82AEB}
2012-06-26 03:30 - 2012-06-26 03:31 - 00000000 ____D C:\Users\Geremy\AppData\Local\{BB392046-C479-4E70-B31F-8DD55C267523}
2012-06-25 15:30 - 2012-06-25 15:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{52BDA77A-1712-4E2E-B9AC-A2B945A12531}
2012-06-25 15:30 - 2012-06-25 15:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{4076F621-C0CA-404B-8C67-DF04C02B7819}
2012-06-24 16:59 - 2012-06-24 16:59 - 00000000 ____D C:\Users\Geremy\AppData\Local\{7E94472B-8468-4499-837F-2038AD9708D7}
2012-06-24 16:58 - 2012-06-24 16:59 - 00000000 ____D C:\Users\Geremy\AppData\Local\{FFAB4195-C70E-4034-B2D9-3EAEE6F4D94A}
2012-06-24 04:57 - 2012-06-24 04:58 - 00000000 ____D C:\Users\Geremy\AppData\Local\{33D07FA2-81E9-4928-8B64-BC902825E1AA}
2012-06-24 04:57 - 2012-06-24 04:57 - 00000000 ____D C:\Users\Geremy\AppData\Local\{6112897A-4EA7-4D01-88BC-61BF2366E03E}
2012-06-23 19:05 - 2012-06-23 19:05 - 00008929 ____A C:\Users\Geremy\Desktop\CBS_EP02_SCRIPT_V02.rtf
2012-06-23 16:56 - 2012-06-23 16:57 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D27590C7-1033-4602-BE66-1BE9CA35BBB7}
2012-06-23 16:56 - 2012-06-23 16:56 - 00000000 ____D C:\Users\Geremy\AppData\Local\{0DF7F726-D872-4215-9FE0-36AC304B3B9D}
2012-06-23 03:33 - 2012-06-23 03:33 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D729755C-1642-4E14-AB72-A5012474F1EA}
2012-06-23 03:33 - 2012-06-23 03:33 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D48BF521-094C-4C96-8C73-00A29816C6EE}
2012-06-22 19:25 - 2012-06-23 05:17 - 01827840 ____A C:\Users\Geremy\Desktop\Sal.fla
2012-06-22 16:48 - 2012-06-22 16:48 - 00078304 ____A C:\Users\Geremy\Downloads\PQA.psd
2012-06-22 15:32 - 2012-06-22 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{330AE8A4-AADC-4F36-A90E-87D780C8012C}
2012-06-22 15:32 - 2012-06-22 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{149B6F4E-47CB-430D-8CB8-C642DBE282C8}
2012-06-21 23:08 - 2012-06-21 23:08 - 00000096 ____A C:\Users\Geremy\.gtk-bookmarks
2012-06-21 16:51 - 2012-06-21 16:51 - 00000000 ____D C:\Users\Geremy\AppData\Local\{361D62CD-B1AE-4558-80B1-17765F205A67}
2012-06-21 16:50 - 2012-06-21 16:51 - 00000000 ____D C:\Users\Geremy\AppData\Local\{ADF83F54-E58A-4974-AFB5-59990AE0DF74}
2012-06-21 14:18 - 2012-06-02 19:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 14:18 - 2012-06-02 19:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 14:18 - 2012-06-02 19:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 14:18 - 2012-06-02 19:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 14:18 - 2012-06-02 19:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 14:18 - 2012-06-02 19:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 14:18 - 2012-06-02 19:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 14:18 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 14:18 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 02:32 - 2012-06-21 02:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9C90918B-E3C7-4AEC-B5AD-05339D157616}
2012-06-21 02:32 - 2012-06-21 02:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{7F938E0F-8F43-48EE-BBA8-0DE6F5238C8D}
2012-06-20 13:25 - 2012-06-20 13:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{A20DE781-FA0A-4D09-AA1B-9E91043F0A48}
2012-06-20 13:24 - 2012-06-20 13:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{414D82B2-8FAA-4366-968A-C79AA13AD4DB}
2012-06-20 13:21 - 2012-06-20 13:21 - 00000000 ____D C:\Windows\en
2012-06-20 13:19 - 2012-06-20 13:19 - 00000000 ____D C:\Users\Geremy\AppData\Local\{638CB385-4E3C-4DDF-A04C-B06110B95ACC}
2012-06-20 13:18 - 2012-06-20 13:19 - 00000000 ____D C:\Users\Geremy\AppData\Local\{EC93710E-5F45-4A88-B825-2F361EBC36A4}
2012-06-19 15:50 - 2012-06-19 15:51 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9E69DE35-C9D7-4674-AD70-2273844957B5}
2012-06-19 15:50 - 2012-06-19 15:50 - 00000000 ____D C:\Users\Geremy\AppData\Local\{25DD17FC-824D-49C9-8465-3C1253552915}
2012-06-18 15:28 - 2012-06-18 15:28 - 00000000 ____D C:\Users\Geremy\AppData\Local\{3B3ED46F-EBCF-4D84-AC05-7B59375ED611}
2012-06-17 22:24 - 2012-06-17 22:24 - 00000000 ____D C:\Users\Geremy\AppData\Local\{4E32EF7C-80F1-466E-A0EB-F8B3DE014EAF}
2012-06-16 18:57 - 2012-06-16 18:58 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D6B81E3B-A225-47ED-AE2B-77569FCA1180}
2012-06-14 20:12 - 2012-06-14 20:13 - 00000000 ____D C:\Users\Geremy\AppData\Local\{03DED491-F596-45B7-83E3-008E603BA87C}
2012-06-14 20:12 - 2012-06-14 20:12 - 00000000 ____D C:\Users\Geremy\AppData\Local\{257C78DF-5A1A-4EE3-B390-4693C989DCCE}
2012-06-14 02:24 - 2012-06-14 02:24 - 00000000 ____D C:\Users\Geremy\AppData\Local\{257EAE8E-4ADB-4608-8722-9D63A4EC32F9}
2012-06-14 02:23 - 2012-06-14 02:24 - 00000000 ____D C:\Users\Geremy\AppData\Local\{F4032FCE-8B5D-4A85-AA1D-810D06B467A0}
2012-06-13 13:05 - 2012-06-13 13:06 - 00000000 ____D C:\Users\Geremy\AppData\Local\{660C9A8E-F4A6-4A79-BAA4-CC21A4E3926D}
2012-06-13 13:05 - 2012-06-13 13:05 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9658A3DB-5832-49B3-9731-F0DB896BD980}
2012-06-13 02:43 - 2012-06-13 02:43 - 00002204 ____A C:\Users\Public\Desktop\NVIDIA FX Composer 2.5.lnk
2012-06-13 02:40 - 2012-06-13 02:40 - 00000000 ____D C:\Users\Geremy\Documents\FX Composer 2
2012-06-13 02:40 - 2012-06-13 02:40 - 00000000 ____D C:\Users\Geremy\AppData\Local\NVIDIA Corporation
2012-06-13 02:39 - 2012-06-13 02:39 - 00000000 ____D C:\Python24
2012-06-13 02:38 - 2012-06-13 02:42 - 00151552 ____A C:\Windows\SysWOW64\nvRegDev.dll
2012-06-13 00:38 - 2012-05-15 01:01 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 00:38 - 2012-05-15 00:59 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 00:38 - 2012-05-15 00:03 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 00:38 - 2012-04-20 02:00 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 00:38 - 2012-04-20 01:57 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 00:38 - 2012-04-20 01:57 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-06-13 00:38 - 2012-04-20 01:57 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 00:38 - 2012-04-20 01:56 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 00:38 - 2012-04-20 01:56 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 00:38 - 2012-04-20 01:56 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 00:37 - 2012-05-15 00:00 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 00:37 - 2012-04-20 02:42 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 00:37 - 2012-04-20 02:00 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 00:37 - 2012-04-20 00:45 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 00:37 - 2012-04-20 00:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 00:36 - 2012-05-14 22:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 00:36 - 2012-05-04 08:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 00:36 - 2012-05-04 07:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 00:36 - 2012-05-04 07:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 00:36 - 2012-04-26 02:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 00:36 - 2012-04-26 02:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 00:36 - 2012-04-26 02:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 00:35 - 2012-04-28 00:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 23:36 - 2012-06-12 23:36 - 00284408 ____A C:\Windows\Minidump\061212-24648-01.dmp
2012-06-12 20:01 - 2012-06-12 20:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{96E0E45F-9012-4A99-9262-1AADC2D48367}
2012-06-12 20:01 - 2012-06-12 20:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{64571201-6773-4E1B-91B7-535FFF475157}
2012-06-12 18:50 - 2012-06-12 19:08 - 187408302 ____A (InstallShield Software Corporation) C:\Users\Geremy\Downloads\FX_Composer2_Shader_Debugger_Bundle_2.53.0524.1905.exe
2012-06-11 21:15 - 2012-06-11 21:15 - 00000000 ____D C:\Users\Geremy\AppData\Local\{F4777474-C6C4-48A7-A1BB-5BBD542BEEEC}
2012-06-11 21:15 - 2012-06-11 21:15 - 00000000 ____D C:\Users\Geremy\AppData\Local\{325BE52B-08F5-4B20-9BAD-57911A251349}
2012-06-10 12:03 - 2012-06-10 12:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{E92691E0-D411-4F25-AA90-4CC147F951C3}
2012-06-10 12:02 - 2012-06-10 12:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5C36DA0F-C4A1-4444-843E-FC48BB6E5859}
2012-06-09 19:07 - 2012-06-09 19:07 - 00000000 ____D C:\Users\Geremy\AppData\Local\{DC23FC4B-80A2-4387-B6F3-810114A6B012}
2012-06-09 19:07 - 2012-06-09 19:07 - 00000000 ____D C:\Users\Geremy\AppData\Local\{CBBFB753-B711-469C-8AFF-D72157CE963B}
2012-06-08 23:13 - 2012-06-08 23:13 - 00000000 ____D C:\Users\Geremy\AppData\Local\{96F70C3E-B94B-46B5-9D6E-91D7D000836B}
2012-06-08 23:13 - 2012-06-08 23:13 - 00000000 ____D C:\Users\Geremy\AppData\Local\{4BAA9FBE-EE21-4033-A1FB-EF0F99B1AE46}
2012-06-07 20:03 - 2012-06-07 20:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D85E649C-6738-4DCB-885B-8182DC02C4C5}
2012-06-07 20:03 - 2012-06-07 20:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{34B38445-F731-4CE9-B788-067F94033EE6}
2012-06-05 19:22 - 2012-06-05 19:23 - 00000000 ____D C:\Users\Geremy\AppData\Local\{8E651E0C-5A15-4073-98DD-FB8157C76917}
2012-06-05 19:22 - 2012-06-05 19:22 - 00000000 ____D C:\Users\Geremy\AppData\Local\{57FD4A32-A41F-4A9A-82FF-A0ADF632DF24}
2012-06-04 18:25 - 2012-06-04 18:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{ADD7099E-4BA3-490C-B07E-6E73BDE4A4F4}
2012-06-04 18:25 - 2012-06-04 18:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5260D42D-095F-433F-ACAC-8534992E36F5}
2012-06-03 12:30 - 2012-06-03 12:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5B06A04C-26AC-4232-9E3A-D7D9D9981588}
2012-06-03 12:30 - 2012-06-03 12:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{434978B2-9973-42C5-84FB-4A6229C845E2}
============ 3 Months Modified Files ========================
2012-07-03 22:09 - 2009-07-14 02:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-03 22:09 - 2009-07-14 01:51 - 00238315 ____A C:\Windows\setupact.log
2012-07-03 22:05 - 2012-07-03 22:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BAE6D825FC2B802B
2012-07-03 22:05 - 2012-07-03 22:05 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zxcahoyv.sys
2012-07-03 21:42 - 2012-07-03 21:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.055BF01D61730CA8
2012-07-03 21:39 - 2012-07-03 21:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA897737214FB219
2012-07-03 21:39 - 2012-07-03 21:39 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndzhiclp.sys
2012-07-03 21:36 - 2012-07-03 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7650BBB7848E48AB
2012-07-03 21:34 - 2012-07-03 21:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC49998995B969C2
2012-07-03 21:31 - 2009-07-13 20:19 - 00328704 ____A C:\Windows\System32\services.exe
2012-07-03 21:28 - 2012-07-03 21:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.79FE9C5165055EC3
2012-07-03 21:25 - 2012-07-03 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66BBA8088936891B
2012-07-03 21:22 - 2009-07-14 02:13 - 00782528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-03 21:21 - 2012-07-03 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F2CD0B82DBC534F
2012-07-03 21:12 - 2009-07-14 01:45 - 00014832 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-03 21:12 - 2009-07-14 01:45 - 00014832 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-03 21:11 - 2011-02-01 02:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-03 21:11 - 2010-10-15 23:37 - 01511428 ____A C:\Windows\WindowsUpdate.log
2012-07-03 21:10 - 2011-02-01 02:16 - 00789382 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-03 21:08 - 2012-07-03 21:07 - 12621696 ____A (Microsoft Corporation) C:\Users\Geremy\Downloads\mseinstall.exe
2012-07-03 20:52 - 2012-07-03 20:52 - 00007597 ____A C:\Users\Geremy\AppData\Local\Resmon.ResmonCfg
2012-07-03 19:37 - 2012-04-02 22:36 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-03 19:37 - 2011-05-14 15:24 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-03 18:09 - 2010-10-17 15:24 - 00000052 ____A C:\Users\Geremy\AppData\default.pls
2012-06-28 18:16 - 2012-06-28 18:16 - 00033939 ____A C:\Users\Geremy\.recently-used.xbel
2012-06-23 19:05 - 2012-06-23 19:05 - 00008929 ____A C:\Users\Geremy\Desktop\CBS_EP02_SCRIPT_V02.rtf
2012-06-23 05:17 - 2012-06-22 19:25 - 01827840 ____A C:\Users\Geremy\Desktop\Sal.fla
2012-06-22 16:48 - 2012-06-22 16:48 - 00078304 ____A C:\Users\Geremy\Downloads\PQA.psd
2012-06-21 23:08 - 2012-06-21 23:08 - 00000096 ____A C:\Users\Geremy\.gtk-bookmarks
2012-06-20 23:56 - 2012-03-06 00:50 - 00004096 ____A C:\Users\Geremy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-20 13:19 - 2010-10-12 14:41 - 00453638 ____A C:\Windows\DirectX.log
2012-06-16 02:51 - 2012-02-06 01:52 - 00000900 ____A C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2012-06-13 13:02 - 2009-07-14 01:45 - 04888992 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 03:05 - 2010-08-04 18:37 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 02:43 - 2012-06-13 02:43 - 00002204 ____A C:\Users\Public\Desktop\NVIDIA FX Composer 2.5.lnk
2012-06-13 02:42 - 2012-06-13 02:38 - 00151552 ____A C:\Windows\SysWOW64\nvRegDev.dll
2012-06-13 02:17 - 2010-10-15 19:45 - 00079376 ____A C:\Users\Geremy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-12 23:36 - 2012-06-12 23:36 - 00284408 ____A C:\Windows\Minidump\061212-24648-01.dmp
2012-06-12 23:36 - 2010-12-13 00:29 - 432553323 ____A C:\Windows\MEMORY.DMP
2012-06-12 20:00 - 2010-10-16 17:56 - 00001114 ___AH C:\IPH.PH
2012-06-12 19:08 - 2012-06-12 18:50 - 187408302 ____A (InstallShield Software Corporation) C:\Users\Geremy\Downloads\FX_Composer2_Shader_Debugger_Bundle_2.53.0524.1905.exe
2012-06-02 19:19 - 2012-06-21 14:18 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 19:19 - 2012-06-21 14:18 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 19:19 - 2012-06-21 14:18 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 19:19 - 2012-06-21 14:18 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 19:19 - 2012-06-21 14:18 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 19:15 - 2012-06-21 14:18 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 19:15 - 2012-06-21 14:18 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-21 14:18 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:15 - 2012-06-21 14:18 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-15 01:01 - 2012-06-13 00:38 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-15 00:59 - 2012-06-13 00:38 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-15 00:03 - 2012-06-13 00:38 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-15 00:00 - 2012-06-13 00:37 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-14 22:32 - 2012-06-13 00:36 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-05 03:38 - 2012-04-02 22:38 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 08:06 - 2012-06-13 00:36 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 07:03 - 2012-06-13 00:36 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 07:03 - 2012-06-13 00:36 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 17:57 - 2012-05-01 17:57 - 00001662 ____A C:\Users\Public\Desktop\TERA-Launcher.lnk
2012-04-28 00:55 - 2012-06-13 00:35 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 19:42 - 2012-04-26 19:37 - 36149065 ____A C:\Users\Geremy\Downloads\pz_0_1_5d.1.zip
2012-04-26 02:41 - 2012-06-13 00:36 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 02:41 - 2012-06-13 00:36 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 02:34 - 2012-06-13 00:36 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-22 00:15 - 2011-06-27 20:19 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-22 00:15 - 2011-06-27 20:19 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-22 00:15 - 2011-06-27 20:19 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-22 00:15 - 2011-01-12 16:41 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-04-20 02:42 - 2012-06-13 00:37 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-04-20 02:00 - 2012-06-13 00:38 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-04-20 02:00 - 2012-06-13 00:37 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-04-20 01:57 - 2012-06-13 00:38 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-04-20 01:57 - 2012-06-13 00:38 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-04-20 01:57 - 2012-06-13 00:38 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-04-20 01:56 - 2012-06-13 00:38 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-04-20 01:56 - 2012-06-13 00:38 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-04-20 01:56 - 2012-06-13 00:38 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-04-20 00:45 - 2012-06-13 00:37 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-04-20 00:16 - 2012-06-13 00:37 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-04-11 23:14 - 2012-04-11 23:14 - 00001973 ____A C:\Users\Geremy\Desktop\Legend of Grimrock.lnk
2012-04-11 22:41 - 2012-04-11 21:52 - 483918688 ____A C:\Users\Geremy\Downloads\grimrock-rc6-1.1.3-installer.zip
2012-04-10 02:32 - 2011-05-20 20:25 - 00000734 ____A C:\Users\Geremy\Documents\(TerrariaEinhander).xpadderprofile
ZeroAccess:
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\@
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\L
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\n
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\U
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\U\00000001.@
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\U\800000cb.@
ZeroAccess:
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}\@
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}\L
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}\U
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 20:19] - [2012-07-03 21:31] - 0328704 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 8190.18 MB
Available physical RAM: 6782.64 MB
Total Pagefile: 16378.54 MB
Available Pagefile: 14923.87 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
======================= Partitions =========================
1 Drive c: (SystemDisk) (Fixed) (Total:1863.01 GB) (Free:1658.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive f: (GB_BATTERY) (Removable) (Total:7.45 GB) (Free:0.18 GB) FAT32
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==========================================================
Last Boot: 2012-06-28 00:58
======================= End Of Log ==========================
I also performed the search for "Services.exe". Results follow.
Farbar Recovery Scan Tool Version: 03-07-2012 01
Ran by Geremy at 2012-07-03 22:20:33
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 20:19] - [2009-07-13 22:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 20:19] - [2012-07-03 21:31] - 0328704 ____A () D41D8CD98F00B204E9800998ECF8427E
====== End Of Search ======
Thanks in advance. I work at home from my PC so this is potentially devastating to me. I will stand by until instructed.
Anyway, I've read through a few threads on the topic, and I have performed the first few steps/reports already. Posting of the contents follows.
Scan result of Farbar Recovery Scan Tool Version: 03-07-2012 01
Ran by Geremy at 03-07-2012 22:09:32
Running from F:\
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-03 22:05 - 2012-07-03 22:05 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zxcahoyv.sys
2012-07-03 22:04 - 2012-07-03 22:09 - 00000000 ____D C:\FRST
2012-07-03 21:42 - 2012-07-03 21:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.055BF01D61730CA8
2012-07-03 21:39 - 2012-07-03 21:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA897737214FB219
2012-07-03 21:39 - 2012-07-03 21:39 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndzhiclp.sys
2012-07-03 21:36 - 2012-07-03 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7650BBB7848E48AB
2012-07-03 21:34 - 2012-07-03 21:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC49998995B969C2
2012-07-03 21:28 - 2012-07-03 21:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.79FE9C5165055EC3
2012-07-03 21:25 - 2012-07-03 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66BBA8088936891B
2012-07-03 21:21 - 2012-07-03 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F2CD0B82DBC534F
2012-07-03 21:10 - 2012-07-03 21:10 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-03 21:10 - 2012-07-03 21:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-03 21:07 - 2012-07-03 21:08 - 12621696 ____A (Microsoft Corporation) C:\Users\Geremy\Downloads\mseinstall.exe
2012-07-03 20:54 - 2012-07-03 20:54 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2012-07-03 20:52 - 2012-07-03 20:52 - 00007597 ____A C:\Users\Geremy\AppData\Local\Resmon.ResmonCfg
2012-07-03 19:39 - 2012-07-03 19:39 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-03 02:01 - 2012-07-03 02:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{92192416-5FE4-4C6A-BFEB-14956D31EA06}
2012-07-03 02:00 - 2012-07-03 02:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{B958EE0C-8769-47CC-8A7A-977FCD0592D8}
2012-07-02 14:00 - 2012-07-02 14:00 - 00000000 ____D C:\Users\Geremy\AppData\Local\{B9840E06-A25A-4276-A36D-50B8E6D90108}
2012-07-02 13:59 - 2012-07-02 14:00 - 00000000 ____D C:\Users\Geremy\AppData\Local\{1B7FB947-6B40-440A-99F2-48BC06BA4953}
2012-06-30 00:50 - 2012-06-30 00:50 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5E34E0E6-92BB-42EF-9641-52D7000979BC}
2012-06-30 00:49 - 2012-06-30 00:50 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5E082280-2A43-4F81-8DF0-E20A4975BA1A}
2012-06-28 18:16 - 2012-06-28 18:16 - 00033939 ____A C:\Users\Geremy\.recently-used.xbel
2012-06-28 17:03 - 2012-06-28 17:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{65F1A6B0-A98E-44AC-B794-04A531830FB6}
2012-06-28 17:03 - 2012-06-28 17:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{0AAA81A1-A307-44A2-AC5C-C3E1B98318D5}
2012-06-27 15:55 - 2012-07-02 13:54 - 00000000 ____D C:\Users\Geremy\Desktop\INVOICE
2012-06-27 15:39 - 2012-06-27 15:39 - 00000000 ____D C:\Users\Geremy\AppData\Local\{BA52C587-F055-4F70-9240-8162AE36672F}
2012-06-27 15:38 - 2012-06-27 15:39 - 00000000 ____D C:\Users\Geremy\AppData\Local\{DCF3C70D-06B9-4311-B25E-C9578688371D}
2012-06-26 15:32 - 2012-06-26 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9953C31F-9209-4CBD-BC80-BEFFCE08F805}
2012-06-26 15:31 - 2012-06-26 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{35AAADBD-DF4D-4D81-828E-AEE29DAAD7F3}
2012-06-26 03:31 - 2012-06-26 03:31 - 00000000 ____D C:\Users\Geremy\AppData\Local\{F7DB33B9-AD2C-491E-A483-0925C6A82AEB}
2012-06-26 03:30 - 2012-06-26 03:31 - 00000000 ____D C:\Users\Geremy\AppData\Local\{BB392046-C479-4E70-B31F-8DD55C267523}
2012-06-25 15:30 - 2012-06-25 15:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{52BDA77A-1712-4E2E-B9AC-A2B945A12531}
2012-06-25 15:30 - 2012-06-25 15:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{4076F621-C0CA-404B-8C67-DF04C02B7819}
2012-06-24 16:59 - 2012-06-24 16:59 - 00000000 ____D C:\Users\Geremy\AppData\Local\{7E94472B-8468-4499-837F-2038AD9708D7}
2012-06-24 16:58 - 2012-06-24 16:59 - 00000000 ____D C:\Users\Geremy\AppData\Local\{FFAB4195-C70E-4034-B2D9-3EAEE6F4D94A}
2012-06-24 04:57 - 2012-06-24 04:58 - 00000000 ____D C:\Users\Geremy\AppData\Local\{33D07FA2-81E9-4928-8B64-BC902825E1AA}
2012-06-24 04:57 - 2012-06-24 04:57 - 00000000 ____D C:\Users\Geremy\AppData\Local\{6112897A-4EA7-4D01-88BC-61BF2366E03E}
2012-06-23 19:05 - 2012-06-23 19:05 - 00008929 ____A C:\Users\Geremy\Desktop\CBS_EP02_SCRIPT_V02.rtf
2012-06-23 16:56 - 2012-06-23 16:57 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D27590C7-1033-4602-BE66-1BE9CA35BBB7}
2012-06-23 16:56 - 2012-06-23 16:56 - 00000000 ____D C:\Users\Geremy\AppData\Local\{0DF7F726-D872-4215-9FE0-36AC304B3B9D}
2012-06-23 03:33 - 2012-06-23 03:33 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D729755C-1642-4E14-AB72-A5012474F1EA}
2012-06-23 03:33 - 2012-06-23 03:33 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D48BF521-094C-4C96-8C73-00A29816C6EE}
2012-06-22 19:25 - 2012-06-23 05:17 - 01827840 ____A C:\Users\Geremy\Desktop\Sal.fla
2012-06-22 16:48 - 2012-06-22 16:48 - 00078304 ____A C:\Users\Geremy\Downloads\PQA.psd
2012-06-22 15:32 - 2012-06-22 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{330AE8A4-AADC-4F36-A90E-87D780C8012C}
2012-06-22 15:32 - 2012-06-22 15:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{149B6F4E-47CB-430D-8CB8-C642DBE282C8}
2012-06-21 23:08 - 2012-06-21 23:08 - 00000096 ____A C:\Users\Geremy\.gtk-bookmarks
2012-06-21 16:51 - 2012-06-21 16:51 - 00000000 ____D C:\Users\Geremy\AppData\Local\{361D62CD-B1AE-4558-80B1-17765F205A67}
2012-06-21 16:50 - 2012-06-21 16:51 - 00000000 ____D C:\Users\Geremy\AppData\Local\{ADF83F54-E58A-4974-AFB5-59990AE0DF74}
2012-06-21 14:18 - 2012-06-02 19:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 14:18 - 2012-06-02 19:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 14:18 - 2012-06-02 19:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 14:18 - 2012-06-02 19:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 14:18 - 2012-06-02 19:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 14:18 - 2012-06-02 19:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 14:18 - 2012-06-02 19:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 14:18 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 14:18 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 02:32 - 2012-06-21 02:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9C90918B-E3C7-4AEC-B5AD-05339D157616}
2012-06-21 02:32 - 2012-06-21 02:32 - 00000000 ____D C:\Users\Geremy\AppData\Local\{7F938E0F-8F43-48EE-BBA8-0DE6F5238C8D}
2012-06-20 13:25 - 2012-06-20 13:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{A20DE781-FA0A-4D09-AA1B-9E91043F0A48}
2012-06-20 13:24 - 2012-06-20 13:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{414D82B2-8FAA-4366-968A-C79AA13AD4DB}
2012-06-20 13:21 - 2012-06-20 13:21 - 00000000 ____D C:\Windows\en
2012-06-20 13:19 - 2012-06-20 13:19 - 00000000 ____D C:\Users\Geremy\AppData\Local\{638CB385-4E3C-4DDF-A04C-B06110B95ACC}
2012-06-20 13:18 - 2012-06-20 13:19 - 00000000 ____D C:\Users\Geremy\AppData\Local\{EC93710E-5F45-4A88-B825-2F361EBC36A4}
2012-06-19 15:50 - 2012-06-19 15:51 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9E69DE35-C9D7-4674-AD70-2273844957B5}
2012-06-19 15:50 - 2012-06-19 15:50 - 00000000 ____D C:\Users\Geremy\AppData\Local\{25DD17FC-824D-49C9-8465-3C1253552915}
2012-06-18 15:28 - 2012-06-18 15:28 - 00000000 ____D C:\Users\Geremy\AppData\Local\{3B3ED46F-EBCF-4D84-AC05-7B59375ED611}
2012-06-17 22:24 - 2012-06-17 22:24 - 00000000 ____D C:\Users\Geremy\AppData\Local\{4E32EF7C-80F1-466E-A0EB-F8B3DE014EAF}
2012-06-16 18:57 - 2012-06-16 18:58 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D6B81E3B-A225-47ED-AE2B-77569FCA1180}
2012-06-14 20:12 - 2012-06-14 20:13 - 00000000 ____D C:\Users\Geremy\AppData\Local\{03DED491-F596-45B7-83E3-008E603BA87C}
2012-06-14 20:12 - 2012-06-14 20:12 - 00000000 ____D C:\Users\Geremy\AppData\Local\{257C78DF-5A1A-4EE3-B390-4693C989DCCE}
2012-06-14 02:24 - 2012-06-14 02:24 - 00000000 ____D C:\Users\Geremy\AppData\Local\{257EAE8E-4ADB-4608-8722-9D63A4EC32F9}
2012-06-14 02:23 - 2012-06-14 02:24 - 00000000 ____D C:\Users\Geremy\AppData\Local\{F4032FCE-8B5D-4A85-AA1D-810D06B467A0}
2012-06-13 13:05 - 2012-06-13 13:06 - 00000000 ____D C:\Users\Geremy\AppData\Local\{660C9A8E-F4A6-4A79-BAA4-CC21A4E3926D}
2012-06-13 13:05 - 2012-06-13 13:05 - 00000000 ____D C:\Users\Geremy\AppData\Local\{9658A3DB-5832-49B3-9731-F0DB896BD980}
2012-06-13 02:43 - 2012-06-13 02:43 - 00002204 ____A C:\Users\Public\Desktop\NVIDIA FX Composer 2.5.lnk
2012-06-13 02:40 - 2012-06-13 02:40 - 00000000 ____D C:\Users\Geremy\Documents\FX Composer 2
2012-06-13 02:40 - 2012-06-13 02:40 - 00000000 ____D C:\Users\Geremy\AppData\Local\NVIDIA Corporation
2012-06-13 02:39 - 2012-06-13 02:39 - 00000000 ____D C:\Python24
2012-06-13 02:38 - 2012-06-13 02:42 - 00151552 ____A C:\Windows\SysWOW64\nvRegDev.dll
2012-06-13 00:38 - 2012-05-15 01:01 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 00:38 - 2012-05-15 00:59 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 00:38 - 2012-05-15 00:03 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 00:38 - 2012-04-20 02:42 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 00:38 - 2012-04-20 02:00 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 00:38 - 2012-04-20 01:57 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 00:38 - 2012-04-20 01:57 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-06-13 00:38 - 2012-04-20 01:57 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 00:38 - 2012-04-20 01:56 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 00:38 - 2012-04-20 01:56 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 00:38 - 2012-04-20 01:56 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 00:37 - 2012-05-15 00:00 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 00:37 - 2012-04-20 02:42 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 00:37 - 2012-04-20 02:00 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 00:37 - 2012-04-20 00:45 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 00:37 - 2012-04-20 00:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 00:36 - 2012-05-14 22:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 00:36 - 2012-05-04 08:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 00:36 - 2012-05-04 07:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 00:36 - 2012-05-04 07:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 00:36 - 2012-04-26 02:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 00:36 - 2012-04-26 02:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 00:36 - 2012-04-26 02:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 00:35 - 2012-04-28 00:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 23:36 - 2012-06-12 23:36 - 00284408 ____A C:\Windows\Minidump\061212-24648-01.dmp
2012-06-12 20:01 - 2012-06-12 20:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{96E0E45F-9012-4A99-9262-1AADC2D48367}
2012-06-12 20:01 - 2012-06-12 20:01 - 00000000 ____D C:\Users\Geremy\AppData\Local\{64571201-6773-4E1B-91B7-535FFF475157}
2012-06-12 18:50 - 2012-06-12 19:08 - 187408302 ____A (InstallShield Software Corporation) C:\Users\Geremy\Downloads\FX_Composer2_Shader_Debugger_Bundle_2.53.0524.1905.exe
2012-06-11 21:15 - 2012-06-11 21:15 - 00000000 ____D C:\Users\Geremy\AppData\Local\{F4777474-C6C4-48A7-A1BB-5BBD542BEEEC}
2012-06-11 21:15 - 2012-06-11 21:15 - 00000000 ____D C:\Users\Geremy\AppData\Local\{325BE52B-08F5-4B20-9BAD-57911A251349}
2012-06-10 12:03 - 2012-06-10 12:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{E92691E0-D411-4F25-AA90-4CC147F951C3}
2012-06-10 12:02 - 2012-06-10 12:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5C36DA0F-C4A1-4444-843E-FC48BB6E5859}
2012-06-09 19:07 - 2012-06-09 19:07 - 00000000 ____D C:\Users\Geremy\AppData\Local\{DC23FC4B-80A2-4387-B6F3-810114A6B012}
2012-06-09 19:07 - 2012-06-09 19:07 - 00000000 ____D C:\Users\Geremy\AppData\Local\{CBBFB753-B711-469C-8AFF-D72157CE963B}
2012-06-08 23:13 - 2012-06-08 23:13 - 00000000 ____D C:\Users\Geremy\AppData\Local\{96F70C3E-B94B-46B5-9D6E-91D7D000836B}
2012-06-08 23:13 - 2012-06-08 23:13 - 00000000 ____D C:\Users\Geremy\AppData\Local\{4BAA9FBE-EE21-4033-A1FB-EF0F99B1AE46}
2012-06-07 20:03 - 2012-06-07 20:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{D85E649C-6738-4DCB-885B-8182DC02C4C5}
2012-06-07 20:03 - 2012-06-07 20:03 - 00000000 ____D C:\Users\Geremy\AppData\Local\{34B38445-F731-4CE9-B788-067F94033EE6}
2012-06-05 19:22 - 2012-06-05 19:23 - 00000000 ____D C:\Users\Geremy\AppData\Local\{8E651E0C-5A15-4073-98DD-FB8157C76917}
2012-06-05 19:22 - 2012-06-05 19:22 - 00000000 ____D C:\Users\Geremy\AppData\Local\{57FD4A32-A41F-4A9A-82FF-A0ADF632DF24}
2012-06-04 18:25 - 2012-06-04 18:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{ADD7099E-4BA3-490C-B07E-6E73BDE4A4F4}
2012-06-04 18:25 - 2012-06-04 18:25 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5260D42D-095F-433F-ACAC-8534992E36F5}
2012-06-03 12:30 - 2012-06-03 12:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{5B06A04C-26AC-4232-9E3A-D7D9D9981588}
2012-06-03 12:30 - 2012-06-03 12:30 - 00000000 ____D C:\Users\Geremy\AppData\Local\{434978B2-9973-42C5-84FB-4A6229C845E2}
============ 3 Months Modified Files ========================
2012-07-03 22:09 - 2009-07-14 02:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-03 22:09 - 2009-07-14 01:51 - 00238315 ____A C:\Windows\setupact.log
2012-07-03 22:05 - 2012-07-03 22:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BAE6D825FC2B802B
2012-07-03 22:05 - 2012-07-03 22:05 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zxcahoyv.sys
2012-07-03 21:42 - 2012-07-03 21:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.055BF01D61730CA8
2012-07-03 21:39 - 2012-07-03 21:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA897737214FB219
2012-07-03 21:39 - 2012-07-03 21:39 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndzhiclp.sys
2012-07-03 21:36 - 2012-07-03 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7650BBB7848E48AB
2012-07-03 21:34 - 2012-07-03 21:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC49998995B969C2
2012-07-03 21:31 - 2009-07-13 20:19 - 00328704 ____A C:\Windows\System32\services.exe
2012-07-03 21:28 - 2012-07-03 21:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.79FE9C5165055EC3
2012-07-03 21:25 - 2012-07-03 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66BBA8088936891B
2012-07-03 21:22 - 2009-07-14 02:13 - 00782528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-03 21:21 - 2012-07-03 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F2CD0B82DBC534F
2012-07-03 21:12 - 2009-07-14 01:45 - 00014832 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-03 21:12 - 2009-07-14 01:45 - 00014832 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-03 21:11 - 2011-02-01 02:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-03 21:11 - 2010-10-15 23:37 - 01511428 ____A C:\Windows\WindowsUpdate.log
2012-07-03 21:10 - 2011-02-01 02:16 - 00789382 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-03 21:08 - 2012-07-03 21:07 - 12621696 ____A (Microsoft Corporation) C:\Users\Geremy\Downloads\mseinstall.exe
2012-07-03 20:52 - 2012-07-03 20:52 - 00007597 ____A C:\Users\Geremy\AppData\Local\Resmon.ResmonCfg
2012-07-03 19:37 - 2012-04-02 22:36 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-03 19:37 - 2011-05-14 15:24 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-03 18:09 - 2010-10-17 15:24 - 00000052 ____A C:\Users\Geremy\AppData\default.pls
2012-06-28 18:16 - 2012-06-28 18:16 - 00033939 ____A C:\Users\Geremy\.recently-used.xbel
2012-06-23 19:05 - 2012-06-23 19:05 - 00008929 ____A C:\Users\Geremy\Desktop\CBS_EP02_SCRIPT_V02.rtf
2012-06-23 05:17 - 2012-06-22 19:25 - 01827840 ____A C:\Users\Geremy\Desktop\Sal.fla
2012-06-22 16:48 - 2012-06-22 16:48 - 00078304 ____A C:\Users\Geremy\Downloads\PQA.psd
2012-06-21 23:08 - 2012-06-21 23:08 - 00000096 ____A C:\Users\Geremy\.gtk-bookmarks
2012-06-20 23:56 - 2012-03-06 00:50 - 00004096 ____A C:\Users\Geremy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-20 13:19 - 2010-10-12 14:41 - 00453638 ____A C:\Windows\DirectX.log
2012-06-16 02:51 - 2012-02-06 01:52 - 00000900 ____A C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2012-06-13 13:02 - 2009-07-14 01:45 - 04888992 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 03:05 - 2010-08-04 18:37 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 02:43 - 2012-06-13 02:43 - 00002204 ____A C:\Users\Public\Desktop\NVIDIA FX Composer 2.5.lnk
2012-06-13 02:42 - 2012-06-13 02:38 - 00151552 ____A C:\Windows\SysWOW64\nvRegDev.dll
2012-06-13 02:17 - 2010-10-15 19:45 - 00079376 ____A C:\Users\Geremy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-12 23:36 - 2012-06-12 23:36 - 00284408 ____A C:\Windows\Minidump\061212-24648-01.dmp
2012-06-12 23:36 - 2010-12-13 00:29 - 432553323 ____A C:\Windows\MEMORY.DMP
2012-06-12 20:00 - 2010-10-16 17:56 - 00001114 ___AH C:\IPH.PH
2012-06-12 19:08 - 2012-06-12 18:50 - 187408302 ____A (InstallShield Software Corporation) C:\Users\Geremy\Downloads\FX_Composer2_Shader_Debugger_Bundle_2.53.0524.1905.exe
2012-06-02 19:19 - 2012-06-21 14:18 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 19:19 - 2012-06-21 14:18 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 19:19 - 2012-06-21 14:18 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 19:19 - 2012-06-21 14:18 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 19:19 - 2012-06-21 14:18 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 19:15 - 2012-06-21 14:18 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 19:15 - 2012-06-21 14:18 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-21 14:18 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:15 - 2012-06-21 14:18 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-15 01:01 - 2012-06-13 00:38 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-15 00:59 - 2012-06-13 00:38 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-15 00:03 - 2012-06-13 00:38 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-15 00:00 - 2012-06-13 00:37 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-14 22:32 - 2012-06-13 00:36 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-05 03:38 - 2012-04-02 22:38 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 08:06 - 2012-06-13 00:36 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 07:03 - 2012-06-13 00:36 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 07:03 - 2012-06-13 00:36 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 17:57 - 2012-05-01 17:57 - 00001662 ____A C:\Users\Public\Desktop\TERA-Launcher.lnk
2012-04-28 00:55 - 2012-06-13 00:35 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 19:42 - 2012-04-26 19:37 - 36149065 ____A C:\Users\Geremy\Downloads\pz_0_1_5d.1.zip
2012-04-26 02:41 - 2012-06-13 00:36 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 02:41 - 2012-06-13 00:36 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 02:34 - 2012-06-13 00:36 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-22 00:15 - 2011-06-27 20:19 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-22 00:15 - 2011-06-27 20:19 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-22 00:15 - 2011-06-27 20:19 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-22 00:15 - 2011-01-12 16:41 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-04-20 02:42 - 2012-06-13 00:38 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-04-20 02:42 - 2012-06-13 00:37 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-04-20 02:00 - 2012-06-13 00:38 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-04-20 02:00 - 2012-06-13 00:37 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-04-20 01:57 - 2012-06-13 00:38 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-04-20 01:57 - 2012-06-13 00:38 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-04-20 01:57 - 2012-06-13 00:38 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-04-20 01:56 - 2012-06-13 00:38 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-04-20 01:56 - 2012-06-13 00:38 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-04-20 01:56 - 2012-06-13 00:38 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-04-20 00:45 - 2012-06-13 00:37 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-04-20 00:16 - 2012-06-13 00:37 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-04-11 23:14 - 2012-04-11 23:14 - 00001973 ____A C:\Users\Geremy\Desktop\Legend of Grimrock.lnk
2012-04-11 22:41 - 2012-04-11 21:52 - 483918688 ____A C:\Users\Geremy\Downloads\grimrock-rc6-1.1.3-installer.zip
2012-04-10 02:32 - 2011-05-20 20:25 - 00000734 ____A C:\Users\Geremy\Documents\(TerrariaEinhander).xpadderprofile
ZeroAccess:
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\@
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\L
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\n
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\U
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\U\00000001.@
C:\Windows\Installer\{4308a726-4453-1462-f29a-c04da33cd417}\U\800000cb.@
ZeroAccess:
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}\@
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}\L
C:\Users\Geremy\AppData\Local\{4308a726-4453-1462-f29a-c04da33cd417}\U
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 20:19] - [2012-07-03 21:31] - 0328704 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 8190.18 MB
Available physical RAM: 6782.64 MB
Total Pagefile: 16378.54 MB
Available Pagefile: 14923.87 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
======================= Partitions =========================
1 Drive c: (SystemDisk) (Fixed) (Total:1863.01 GB) (Free:1658.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive f: (GB_BATTERY) (Removable) (Total:7.45 GB) (Free:0.18 GB) FAT32
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==========================================================
Last Boot: 2012-06-28 00:58
======================= End Of Log ==========================
I also performed the search for "Services.exe". Results follow.
Farbar Recovery Scan Tool Version: 03-07-2012 01
Ran by Geremy at 2012-07-03 22:20:33
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 20:19] - [2009-07-13 22:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 20:19] - [2012-07-03 21:31] - 0328704 ____A () D41D8CD98F00B204E9800998ECF8427E
====== End Of Search ======
Thanks in advance. I work at home from my PC so this is potentially devastating to me. I will stand by until instructed.