I'm running Windows 7 32 bit and have the svchost.exe issue where several instances are running and increase in RAM usage infinitely. While running mbam.exe has been run twice and handled 6 items twice (same items) Trendmicro begins to work and then the Critical issue / one minute warning occurs and then the pc shuts down.
I've followed another active thread through downloading and running "First.exe" and here is the log.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-08-2012 02
Ran by SYSTEM at 09-08-2012 14:48:01
Running from E:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" [1107552 2012-07-09] ()
HKLM\...\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [89456 2011-03-07] (Elaborate Bytes AG)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_22\bin\jusched.exe" [75648 2009-10-08] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickBooksDB20] C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe -n QB_TREASURY_20 -qs -gd ALL -gk all -gp 4096 -gu all -ch 256M -c 128M -x tcpip(BroadcastListener=NO;port=55338) -ti 0 -ec simple -qi -qw -tl 120 -oe C:\PROGRA~2\Intuit\QUICKB~2\DBSTAR~1.LOG -y [3271 2012-08-09] ()
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM\...\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [1439496 2010-10-19] (Intuit Inc. All rights reserved.)
HKLM\...\Run: [HF_G_Jul] "C:\Program Files\AVG Secure Search\HF_G_Jul.exe" /DoAction [36960 2012-07-18] ()
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" [2587008 2012-04-05] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKU\Derrick Hedstrom\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2009-07-13] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
AppInit_DLLs: C:\Users\Derrick Hedstrom\AppData\Local\o4wsy.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.6.lnk
ShortcutTarget: ImageMixer 3 SE Camera Monitor Ver.6.lnk -> C:\Program Files\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe (PIXELA CORPORATION)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\SideACT!.lnk
ShortcutTarget: SideACT!.lnk -> C:\Program Files\ACT\SideACT.exe ()
Startup: C:\Users\Derrick Hedstrom\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
4 AVGIDSAgent; "C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe" [5160568 2012-07-04] (AVG Technologies CZ, s.r.o.)
4 avgwd; "C:\Program Files\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 MSSQL$ACT7; "C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe" -sACT7 [42884448 2010-05-05] (Microsoft Corporation)
4 MSSQLServerADHelper100; "C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE" [44896 2010-05-05] (Microsoft Corporation)
2 QBCFMonitorService; "C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe" [45056 2011-11-11] (Intuit)
3 QBFCService; "C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe" [61440 2009-07-23] (Intuit Inc.)
4 QuickBooksDB20; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [678912 2009-08-17] (Intuit, Inc.)
4 SQLAgent$ACT7; "C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\SQLAGENT.EXE" -I ACT7 [367456 2010-05-05] (Microsoft Corporation)
2 vToolbarUpdater11.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [935008 2012-07-09] ()
========================== Drivers (Whitelisted) =============
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [139856 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfilterx.sys [24144 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [24896 2012-04-19] (AVG Technologies CZ, s.r.o. )
3 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [17232 2011-12-23] (AVG Technologies CZ, s.r.o. )
1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [235216 2012-02-22] (AVG Technologies CZ, s.r.o.)
1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [41040 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [31952 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [301248 2012-03-19] (AVG Technologies CZ, s.r.o.)
1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
4 RsFx0150; C:\Windows\System32\DRIVERS\RsFx0150.sys [240608 2010-04-03] (Microsoft Corporation)
2 adfs; [x]
3 catchme; \??\C:\Users\DERRIC~1\AppData\Local\Temp\catchme.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 14:47 - 2012-08-09 14:48 - 00000000 ____D C:\FRST
2012-08-09 10:03 - 2012-08-09 10:12 - 00000000 ____D C:\Windows\pss
2012-08-09 07:50 - 2012-06-04 23:37 - 00256904 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-08-09 07:49 - 2012-08-09 07:49 - 02002944 ____A (Trend Micro Inc.) C:\Users\Derrick Hedstrom\Downloads\HousecallLauncher.exe
2012-08-08 12:04 - 2012-08-08 12:04 - 00139616 ____A C:\Windows\Minidump\080812-50125-01.dmp
2012-08-08 11:17 - 2012-08-08 11:17 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-08 11:14 - 2012-08-08 11:14 - 00000000 ____D C:\Program Files\Axantum
2012-08-08 11:13 - 2012-08-08 11:13 - 00000000 ____D C:\Users\Derrick Hedstrom\AppData\Roaming\OpenCandy
2012-08-08 11:13 - 2012-08-08 11:13 - 00000000 ____D C:\Users\All Users\Real
2012-08-08 11:12 - 2012-08-08 11:12 - 03396552 ____A (Axantum Software AB) C:\Users\Derrick Hedstrom\Desktop\AxCrypt-1.7.2931.0-Setup.exe
2012-08-08 08:10 - 2012-08-08 08:10 - 00000000 ____D C:\Users\Derrick Hedstrom\Desktop\vostro 1000
2012-08-07 10:52 - 2012-08-07 10:52 - 00274353 ____A C:\Users\Derrick Hedstrom\Desktop\2011SCR.txt
2012-08-07 10:52 - 2012-08-07 10:52 - 00128639 ____A C:\Users\Derrick Hedstrom\Desktop\SCR2012.txt
2012-08-07 10:42 - 2012-08-07 10:42 - 00055803 ____A C:\Users\Derrick Hedstrom\Desktop\2012 DR.txt
2012-08-07 10:41 - 2012-08-07 10:41 - 00090474 ____A C:\Users\Derrick Hedstrom\Desktop\2011 DR.txt
2012-08-07 06:22 - 2012-08-07 06:22 - 13404730 ____A C:\Users\Derrick Hedstrom\Documents\Hedstrom 0020189080.zip
2012-08-02 09:12 - 2012-08-06 12:30 - 00000000 ____D C:\Users\Derrick Hedstrom\Desktop\SOF FUll DVD
2012-07-26 13:55 - 2012-07-26 14:02 - 00025600 ____A C:\Users\Derrick Hedstrom\Desktop\THis is to route.xls
2012-07-26 12:30 - 2012-08-02 09:54 - 00063680 ____A C:\Users\Derrick Hedstrom\Desktop\Doctor project.xlsx
2012-07-26 09:29 - 2012-07-26 09:29 - 00177959 ____A C:\Users\Derrick Hedstrom\Documents\Doctor project
2012-07-16 11:02 - 2012-07-16 11:02 - 00027520 ____A C:\Users\Derrick Hedstrom\AppData\Local\dt.dat
============ 3 Months Modified Files ========================
2012-08-09 10:22 - 2011-12-07 12:02 - 00000312 ____A C:\Windows\Tasks\AutoKMS.job
2012-08-09 10:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 10:22 - 2009-07-13 20:39 - 00037389 ____A C:\Windows\setupact.log
2012-08-09 10:20 - 2009-07-13 20:53 - 00032572 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-09 09:45 - 2012-07-09 05:02 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 09:34 - 2011-04-18 11:11 - 00817474 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 09:28 - 2011-04-19 02:53 - 00066006 ____A C:\Windows\PFRO.log
2012-08-09 07:49 - 2012-08-09 07:49 - 02002944 ____A (Trend Micro Inc.) C:\Users\Derrick Hedstrom\Downloads\HousecallLauncher.exe
2012-08-08 12:49 - 2012-06-29 05:12 - 00001149 ____A C:\Users\Derrick Hedstrom\Desktop\NueMD.lnk
2012-08-08 12:04 - 2012-08-08 12:04 - 00139616 ____A C:\Windows\Minidump\080812-50125-01.dmp
2012-08-08 12:03 - 2011-06-09 08:34 - 94921048 ____A C:\Windows\MEMORY.DMP
2012-08-08 11:12 - 2012-08-08 11:12 - 03396552 ____A (Axantum Software AB) C:\Users\Derrick Hedstrom\Desktop\AxCrypt-1.7.2931.0-Setup.exe
2012-08-08 10:56 - 2011-10-03 07:25 - 88104960 ___RA C:\Users\Public\AppData\HealthMotionPhysicalTherapy,Inc.QBW
2012-08-08 10:56 - 2011-10-03 07:25 - 00589824 ___RA C:\Users\Public\AppData\HealthMotionPhysicalTherapy,Inc.QBW.TLG
2012-08-08 10:56 - 2011-10-03 07:25 - 00000398 ____A C:\Users\Public\AppData\HealthMotionPhysicalTherapy,Inc.QBW.ND
2012-08-08 10:29 - 2012-05-16 10:06 - 00851968 ___RA C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.QBW.TLG
2012-08-08 10:29 - 2012-05-16 10:06 - 00000393 ____A C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.QBW.ND
2012-08-08 10:29 - 2011-07-27 05:42 - 10752000 ___RA C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.QBW
2012-08-07 10:52 - 2012-08-07 10:52 - 00274353 ____A C:\Users\Derrick Hedstrom\Desktop\2011SCR.txt
2012-08-07 10:52 - 2012-08-07 10:52 - 00128639 ____A C:\Users\Derrick Hedstrom\Desktop\SCR2012.txt
2012-08-07 10:42 - 2012-08-07 10:42 - 00055803 ____A C:\Users\Derrick Hedstrom\Desktop\2012 DR.txt
2012-08-07 10:41 - 2012-08-07 10:41 - 00090474 ____A C:\Users\Derrick Hedstrom\Desktop\2011 DR.txt
2012-08-07 06:22 - 2012-08-07 06:22 - 13404730 ____A C:\Users\Derrick Hedstrom\Documents\Hedstrom 0020189080.zip
2012-08-06 12:32 - 2011-11-21 13:03 - 00001185 ____A C:\Users\Derrick Hedstrom\AppData\Roaming\vso_ts_preview.xml
2012-08-02 16:45 - 2012-04-09 05:16 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 16:45 - 2011-05-17 02:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 09:54 - 2012-07-26 12:30 - 00063680 ____A C:\Users\Derrick Hedstrom\Desktop\Doctor project.xlsx
2012-07-26 14:02 - 2012-07-26 13:55 - 00025600 ____A C:\Users\Derrick Hedstrom\Desktop\THis is to route.xls
2012-07-26 09:29 - 2012-07-26 09:29 - 00177959 ____A C:\Users\Derrick Hedstrom\Documents\Doctor project
2012-07-25 09:28 - 2012-06-08 06:17 - 00015802 ____A C:\Users\Derrick Hedstrom\Desktop\Screen Bonuses 2012.xlsx
2012-07-17 04:53 - 2012-07-06 09:01 - 02162176 ____A C:\Users\Derrick Hedstrom\Documents\DVD Covers.pub
2012-07-16 11:02 - 2012-07-16 11:02 - 00027520 ____A C:\Users\Derrick Hedstrom\AppData\Local\dt.dat
2012-07-13 10:14 - 2011-04-18 11:09 - 01342680 ____A C:\Windows\WindowsUpdate.log
2012-07-05 13:03 - 2012-07-05 13:03 - 00026295 ____A C:\Users\Derrick Hedstrom\Documents\Scale of Function.XtoDVD
2012-07-03 09:46 - 2011-06-10 15:18 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-25 04:28 - 2012-06-25 04:28 - 00005681 ____A C:\Users\Derrick Hedstrom\Documents\Drefs
2012-06-19 09:47 - 2012-06-19 09:47 - 00483738 ____A C:\Users\Derrick Hedstrom\Downloads\legalaccounts.zip
2012-06-11 11:03 - 2012-06-11 08:19 - 00011417 ____A C:\Users\Derrick Hedstrom\Downloads\Eaton Health Fair.xlsx
2012-06-04 23:37 - 2012-08-09 07:50 - 00256904 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-05-29 11:53 - 2012-05-29 06:01 - 00011127 ____A C:\Users\Derrick Hedstrom\Documents\Hope Network Attendees.xlsx
2012-05-25 08:18 - 2012-05-25 07:32 - 00010898 ____A C:\Users\Derrick Hedstrom\Documents\Copy of Hope Network Vendor Attending (Autosaved).xlsx
2012-05-23 06:44 - 2012-05-23 06:44 - 00139616 ____A C:\Windows\Minidump\052312-36562-01.dmp
2012-05-22 08:49 - 2012-05-22 08:49 - 00000165 ___AH C:\Users\Derrick Hedstrom\Documents\~$Copy of Hope Network Vendor Attending.xlsx
2012-05-17 10:56 - 2012-05-17 10:56 - 00010519 ____A C:\Users\Derrick Hedstrom\Documents\Copy of Hope Network Vendor Attending.xlsx
2012-05-16 10:27 - 2012-05-12 08:24 - 00010901 ____A C:\Users\Derrick Hedstrom\Documents\Hope NETwork.xlsx
2012-05-16 10:06 - 2012-05-16 10:06 - 00000496 ___RA C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.lgb
2012-05-15 11:26 - 2012-05-15 11:26 - 00010627 ____A C:\Users\Derrick Hedstrom\Desktop\today
2012-05-14 10:53 - 2012-05-14 10:53 - 00001821 ____A C:\Users\Derrick Hedstrom\Documents\week3
2012-05-12 09:01 - 2012-05-12 08:59 - 00113664 ____A C:\Users\Derrick Hedstrom\Documents\Shelly Commend.pub
ZeroAccess:
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\L
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\L\00000004.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\L\201d3dde
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\00000004.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\00000008.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\000000cb.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\80000000.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\80000032.@
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 24%
Total physical RAM: 1535.05 MB
Available physical RAM: 1152.16 MB
Total Pagefile: 1535.05 MB
Available Pagefile: 1166.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:465.75 GB) (Free:346.08 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive d: (CD_ROM) (CDROM) (Total:3.48 GB) (Free:0 GB) CDFS
4 Drive e: (Lexar) (Removable) (Total:0.47 GB) (Free:0.37 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 9 MB
Disk 1 Online 483 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 483 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 04
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E Lexar FAT Removable 483 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-07 04:38
======================= End Of Log ==========================
I've followed another active thread through downloading and running "First.exe" and here is the log.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-08-2012 02
Ran by SYSTEM at 09-08-2012 14:48:01
Running from E:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" [1107552 2012-07-09] ()
HKLM\...\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [89456 2011-03-07] (Elaborate Bytes AG)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_22\bin\jusched.exe" [75648 2009-10-08] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickBooksDB20] C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe -n QB_TREASURY_20 -qs -gd ALL -gk all -gp 4096 -gu all -ch 256M -c 128M -x tcpip(BroadcastListener=NO;port=55338) -ti 0 -ec simple -qi -qw -tl 120 -oe C:\PROGRA~2\Intuit\QUICKB~2\DBSTAR~1.LOG -y [3271 2012-08-09] ()
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM\...\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [1439496 2010-10-19] (Intuit Inc. All rights reserved.)
HKLM\...\Run: [HF_G_Jul] "C:\Program Files\AVG Secure Search\HF_G_Jul.exe" /DoAction [36960 2012-07-18] ()
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" [2587008 2012-04-05] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKU\Derrick Hedstrom\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2009-07-13] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
AppInit_DLLs: C:\Users\Derrick Hedstrom\AppData\Local\o4wsy.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.6.lnk
ShortcutTarget: ImageMixer 3 SE Camera Monitor Ver.6.lnk -> C:\Program Files\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe (PIXELA CORPORATION)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\SideACT!.lnk
ShortcutTarget: SideACT!.lnk -> C:\Program Files\ACT\SideACT.exe ()
Startup: C:\Users\Derrick Hedstrom\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
4 AVGIDSAgent; "C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe" [5160568 2012-07-04] (AVG Technologies CZ, s.r.o.)
4 avgwd; "C:\Program Files\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 MSSQL$ACT7; "C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe" -sACT7 [42884448 2010-05-05] (Microsoft Corporation)
4 MSSQLServerADHelper100; "C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE" [44896 2010-05-05] (Microsoft Corporation)
2 QBCFMonitorService; "C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe" [45056 2011-11-11] (Intuit)
3 QBFCService; "C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe" [61440 2009-07-23] (Intuit Inc.)
4 QuickBooksDB20; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [678912 2009-08-17] (Intuit, Inc.)
4 SQLAgent$ACT7; "C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\SQLAGENT.EXE" -I ACT7 [367456 2010-05-05] (Microsoft Corporation)
2 vToolbarUpdater11.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [935008 2012-07-09] ()
========================== Drivers (Whitelisted) =============
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [139856 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfilterx.sys [24144 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [24896 2012-04-19] (AVG Technologies CZ, s.r.o. )
3 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [17232 2011-12-23] (AVG Technologies CZ, s.r.o. )
1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [235216 2012-02-22] (AVG Technologies CZ, s.r.o.)
1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [41040 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [31952 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [301248 2012-03-19] (AVG Technologies CZ, s.r.o.)
1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
4 RsFx0150; C:\Windows\System32\DRIVERS\RsFx0150.sys [240608 2010-04-03] (Microsoft Corporation)
2 adfs; [x]
3 catchme; \??\C:\Users\DERRIC~1\AppData\Local\Temp\catchme.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 14:47 - 2012-08-09 14:48 - 00000000 ____D C:\FRST
2012-08-09 10:03 - 2012-08-09 10:12 - 00000000 ____D C:\Windows\pss
2012-08-09 07:50 - 2012-06-04 23:37 - 00256904 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-08-09 07:49 - 2012-08-09 07:49 - 02002944 ____A (Trend Micro Inc.) C:\Users\Derrick Hedstrom\Downloads\HousecallLauncher.exe
2012-08-08 12:04 - 2012-08-08 12:04 - 00139616 ____A C:\Windows\Minidump\080812-50125-01.dmp
2012-08-08 11:17 - 2012-08-08 11:17 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-08 11:14 - 2012-08-08 11:14 - 00000000 ____D C:\Program Files\Axantum
2012-08-08 11:13 - 2012-08-08 11:13 - 00000000 ____D C:\Users\Derrick Hedstrom\AppData\Roaming\OpenCandy
2012-08-08 11:13 - 2012-08-08 11:13 - 00000000 ____D C:\Users\All Users\Real
2012-08-08 11:12 - 2012-08-08 11:12 - 03396552 ____A (Axantum Software AB) C:\Users\Derrick Hedstrom\Desktop\AxCrypt-1.7.2931.0-Setup.exe
2012-08-08 08:10 - 2012-08-08 08:10 - 00000000 ____D C:\Users\Derrick Hedstrom\Desktop\vostro 1000
2012-08-07 10:52 - 2012-08-07 10:52 - 00274353 ____A C:\Users\Derrick Hedstrom\Desktop\2011SCR.txt
2012-08-07 10:52 - 2012-08-07 10:52 - 00128639 ____A C:\Users\Derrick Hedstrom\Desktop\SCR2012.txt
2012-08-07 10:42 - 2012-08-07 10:42 - 00055803 ____A C:\Users\Derrick Hedstrom\Desktop\2012 DR.txt
2012-08-07 10:41 - 2012-08-07 10:41 - 00090474 ____A C:\Users\Derrick Hedstrom\Desktop\2011 DR.txt
2012-08-07 06:22 - 2012-08-07 06:22 - 13404730 ____A C:\Users\Derrick Hedstrom\Documents\Hedstrom 0020189080.zip
2012-08-02 09:12 - 2012-08-06 12:30 - 00000000 ____D C:\Users\Derrick Hedstrom\Desktop\SOF FUll DVD
2012-07-26 13:55 - 2012-07-26 14:02 - 00025600 ____A C:\Users\Derrick Hedstrom\Desktop\THis is to route.xls
2012-07-26 12:30 - 2012-08-02 09:54 - 00063680 ____A C:\Users\Derrick Hedstrom\Desktop\Doctor project.xlsx
2012-07-26 09:29 - 2012-07-26 09:29 - 00177959 ____A C:\Users\Derrick Hedstrom\Documents\Doctor project
2012-07-16 11:02 - 2012-07-16 11:02 - 00027520 ____A C:\Users\Derrick Hedstrom\AppData\Local\dt.dat
============ 3 Months Modified Files ========================
2012-08-09 10:22 - 2011-12-07 12:02 - 00000312 ____A C:\Windows\Tasks\AutoKMS.job
2012-08-09 10:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 10:22 - 2009-07-13 20:39 - 00037389 ____A C:\Windows\setupact.log
2012-08-09 10:20 - 2009-07-13 20:53 - 00032572 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-09 09:45 - 2012-07-09 05:02 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 09:34 - 2011-04-18 11:11 - 00817474 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 09:28 - 2011-04-19 02:53 - 00066006 ____A C:\Windows\PFRO.log
2012-08-09 07:49 - 2012-08-09 07:49 - 02002944 ____A (Trend Micro Inc.) C:\Users\Derrick Hedstrom\Downloads\HousecallLauncher.exe
2012-08-08 12:49 - 2012-06-29 05:12 - 00001149 ____A C:\Users\Derrick Hedstrom\Desktop\NueMD.lnk
2012-08-08 12:04 - 2012-08-08 12:04 - 00139616 ____A C:\Windows\Minidump\080812-50125-01.dmp
2012-08-08 12:03 - 2011-06-09 08:34 - 94921048 ____A C:\Windows\MEMORY.DMP
2012-08-08 11:12 - 2012-08-08 11:12 - 03396552 ____A (Axantum Software AB) C:\Users\Derrick Hedstrom\Desktop\AxCrypt-1.7.2931.0-Setup.exe
2012-08-08 10:56 - 2011-10-03 07:25 - 88104960 ___RA C:\Users\Public\AppData\HealthMotionPhysicalTherapy,Inc.QBW
2012-08-08 10:56 - 2011-10-03 07:25 - 00589824 ___RA C:\Users\Public\AppData\HealthMotionPhysicalTherapy,Inc.QBW.TLG
2012-08-08 10:56 - 2011-10-03 07:25 - 00000398 ____A C:\Users\Public\AppData\HealthMotionPhysicalTherapy,Inc.QBW.ND
2012-08-08 10:29 - 2012-05-16 10:06 - 00851968 ___RA C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.QBW.TLG
2012-08-08 10:29 - 2012-05-16 10:06 - 00000393 ____A C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.QBW.ND
2012-08-08 10:29 - 2011-07-27 05:42 - 10752000 ___RA C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.QBW
2012-08-07 10:52 - 2012-08-07 10:52 - 00274353 ____A C:\Users\Derrick Hedstrom\Desktop\2011SCR.txt
2012-08-07 10:52 - 2012-08-07 10:52 - 00128639 ____A C:\Users\Derrick Hedstrom\Desktop\SCR2012.txt
2012-08-07 10:42 - 2012-08-07 10:42 - 00055803 ____A C:\Users\Derrick Hedstrom\Desktop\2012 DR.txt
2012-08-07 10:41 - 2012-08-07 10:41 - 00090474 ____A C:\Users\Derrick Hedstrom\Desktop\2011 DR.txt
2012-08-07 06:22 - 2012-08-07 06:22 - 13404730 ____A C:\Users\Derrick Hedstrom\Documents\Hedstrom 0020189080.zip
2012-08-06 12:32 - 2011-11-21 13:03 - 00001185 ____A C:\Users\Derrick Hedstrom\AppData\Roaming\vso_ts_preview.xml
2012-08-02 16:45 - 2012-04-09 05:16 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 16:45 - 2011-05-17 02:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 09:54 - 2012-07-26 12:30 - 00063680 ____A C:\Users\Derrick Hedstrom\Desktop\Doctor project.xlsx
2012-07-26 14:02 - 2012-07-26 13:55 - 00025600 ____A C:\Users\Derrick Hedstrom\Desktop\THis is to route.xls
2012-07-26 09:29 - 2012-07-26 09:29 - 00177959 ____A C:\Users\Derrick Hedstrom\Documents\Doctor project
2012-07-25 09:28 - 2012-06-08 06:17 - 00015802 ____A C:\Users\Derrick Hedstrom\Desktop\Screen Bonuses 2012.xlsx
2012-07-17 04:53 - 2012-07-06 09:01 - 02162176 ____A C:\Users\Derrick Hedstrom\Documents\DVD Covers.pub
2012-07-16 11:02 - 2012-07-16 11:02 - 00027520 ____A C:\Users\Derrick Hedstrom\AppData\Local\dt.dat
2012-07-13 10:14 - 2011-04-18 11:09 - 01342680 ____A C:\Windows\WindowsUpdate.log
2012-07-05 13:03 - 2012-07-05 13:03 - 00026295 ____A C:\Users\Derrick Hedstrom\Documents\Scale of Function.XtoDVD
2012-07-03 09:46 - 2011-06-10 15:18 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-25 04:28 - 2012-06-25 04:28 - 00005681 ____A C:\Users\Derrick Hedstrom\Documents\Drefs
2012-06-19 09:47 - 2012-06-19 09:47 - 00483738 ____A C:\Users\Derrick Hedstrom\Downloads\legalaccounts.zip
2012-06-11 11:03 - 2012-06-11 08:19 - 00011417 ____A C:\Users\Derrick Hedstrom\Downloads\Eaton Health Fair.xlsx
2012-06-04 23:37 - 2012-08-09 07:50 - 00256904 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-05-29 11:53 - 2012-05-29 06:01 - 00011127 ____A C:\Users\Derrick Hedstrom\Documents\Hope Network Attendees.xlsx
2012-05-25 08:18 - 2012-05-25 07:32 - 00010898 ____A C:\Users\Derrick Hedstrom\Documents\Copy of Hope Network Vendor Attending (Autosaved).xlsx
2012-05-23 06:44 - 2012-05-23 06:44 - 00139616 ____A C:\Windows\Minidump\052312-36562-01.dmp
2012-05-22 08:49 - 2012-05-22 08:49 - 00000165 ___AH C:\Users\Derrick Hedstrom\Documents\~$Copy of Hope Network Vendor Attending.xlsx
2012-05-17 10:56 - 2012-05-17 10:56 - 00010519 ____A C:\Users\Derrick Hedstrom\Documents\Copy of Hope Network Vendor Attending.xlsx
2012-05-16 10:27 - 2012-05-12 08:24 - 00010901 ____A C:\Users\Derrick Hedstrom\Documents\Hope NETwork.xlsx
2012-05-16 10:06 - 2012-05-16 10:06 - 00000496 ___RA C:\Users\Derrick Hedstrom\Desktop\Derrick Hedstrom.lgb
2012-05-15 11:26 - 2012-05-15 11:26 - 00010627 ____A C:\Users\Derrick Hedstrom\Desktop\today
2012-05-14 10:53 - 2012-05-14 10:53 - 00001821 ____A C:\Users\Derrick Hedstrom\Documents\week3
2012-05-12 09:01 - 2012-05-12 08:59 - 00113664 ____A C:\Users\Derrick Hedstrom\Documents\Shelly Commend.pub
ZeroAccess:
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\L
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\L\00000004.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\L\201d3dde
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\00000004.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\00000008.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\000000cb.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\80000000.@
C:\Windows\Installer\{7df236bd-f013-4ca8-e2f6-c08973fa1e10}\U\80000032.@
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 24%
Total physical RAM: 1535.05 MB
Available physical RAM: 1152.16 MB
Total Pagefile: 1535.05 MB
Available Pagefile: 1166.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:465.75 GB) (Free:346.08 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive d: (CD_ROM) (CDROM) (Total:3.48 GB) (Free:0 GB) CDFS
4 Drive e: (Lexar) (Removable) (Total:0.47 GB) (Free:0.37 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 9 MB
Disk 1 Online 483 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 483 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 04
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E Lexar FAT Removable 483 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-07 04:38
======================= End Of Log ==========================