Stui Wilson
Posts: 15 +0
Hi There,
Seems as though I have the same problem as everyone else. Would love some help. Please find below my logs. Thanks
FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 26-07-2012 15:49:23
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SoundMan] SOUNDMAN.EXE [x]
HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-20] (Microsoft Corporation)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-05] (Apple Inc.)
HKLM\...\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" [1298320 2011-04-12] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1808784 2011-04-12] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe [112600 2010-11-14] (PC Tools)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-23] (Apple Inc.)
HKLM\...\Run: [Wondershare Helper Compact.exe] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1406976 2011-12-20] (Wondershare)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [RMAlert] "C:\Program Files\Registry Mechanic\Alert.exe" /PRODUCT=RM /R [1016792 2010-09-15] (PC Tool)
HKLM\...\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [973488 2012-07-02] (Malwarebytes Corporation)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-02] (Malwarebytes Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-25] (Microsoft Corporation)
HKU\Stuart Wilson\...\Run: [Google Update] "C:\Users\Stuart Wilson\AppData\Local\Google\Update\GoogleUpdate.exe" /c [133104 2009-10-07] (Google Inc.)
HKU\Stuart Wilson\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-22] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100 Smart Wizard.lnk
ShortcutTarget: NETGEAR WNA3100 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WNA3100\WNA3100.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\NETGEAR WNDA4100 Genie.lnk
ShortcutTarget: NETGEAR WNDA4100 Genie.lnk -> C:\Program Files\NETGEAR\WNDA4100\WNDA4100.EXE (NETGEAR)
================================ Services (Whitelisted) ==================
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-02] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-25] (Microsoft Corporation)
2 MSSQL$PROPHETSQL; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sPROPHETSQL [29293408 2010-12-09] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-25] (Microsoft Corporation)
2 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [632792 2011-01-27] (PC Tools)
2 RalinkRegistryWriter; "C:\Program Files\NETGEAR\WNDA4100\Service\RaRegistry.exe" [377088 2011-11-20] (Ralink Technology, Corp.)
2 SeagateDashboardService; C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [14088 2010-07-06] (Memeo)
2 WSWNA3100; C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe [285152 2010-08-25] ()
2 msftesql$PROPHETSQL; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f
ROPHETSQL [x]
========================== Drivers (Whitelisted) =============
3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC.SYS [4172832 2009-06-18] (Realtek Semiconductor Corp.)
3 BCMH43XX; C:\Windows\System32\DRIVERS\bcmwlhigh6.sys [699896 2009-11-05] (Broadcom Corporation)
3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [20992 2008-01-18] (Microsoft Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-02] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18432 2011-05-09] (Apple Inc.)
3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [1277504 2012-01-12] (Ralink Technology Corp.)
3 NPF; C:\Windows\System32\DRIVERS\npf.sys [50704 2010-02-02] (CACE Technologies, Inc.)
3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [21792 2011-04-12] (Microsoft Corporation)
0 SCMNdisP; C:\Windows\System32\DRIVERS\scmndisp.sys [21728 2007-01-19] (Windows (R) Codename Longhorn DDK provider)
4 RelevantKnowledge; [x]
3 RTL8192su; C:\Windows\System32\DRIVERS\RTL8192su.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-26 15:49 - 2012-07-26 15:49 - 00000000 ____D C:\FRST
2012-07-26 02:47 - 2012-07-26 06:54 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-07-25 21:01 - 2012-07-25 21:01 - 00000000 ____D C:\Users\Stuart Wilson\Downloads\NETGEAR
2012-07-23 14:41 - 2012-07-23 14:41 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-23 14:39 - 2012-07-23 14:39 - 10288512 ____A (Microsoft Corporation) C:\Users\Stuart Wilson\Downloads\mseinstall.exe
2012-07-22 22:50 - 2012-07-22 22:50 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Stuart Wilson\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-22 22:50 - 2012-07-22 22:50 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-22 21:35 - 2012-07-22 21:35 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-22 14:14 - 2012-07-22 20:33 - 00000000 ____D C:\Poker
2012-07-20 03:53 - 2012-07-13 12:44 - 366967146 ____A C:\Users\Stuart Wilson\Documents\Sons.of.Anarchy.S03E02.Oiled.HDTV.XviD-FQM.avi
2012-07-18 15:52 - 2012-07-18 15:52 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-12 21:24 - 2012-07-22 15:39 - 00000000 ____D C:\Users\Stuart Wilson\AppData\Roaming\BitLord
2012-07-12 21:24 - 2012-07-12 21:24 - 00000000 ____D C:\Users\Stuart Wilson\AppData\Roaming\Python-Eggs
2012-07-12 21:23 - 2012-07-12 21:23 - 00001969 ____A C:\Users\Stuart Wilson\Desktop\BitLord.lnk
2012-07-12 21:23 - 2012-07-12 21:23 - 00000000 ____D C:\Users\Stuart Wilson\Documents\BitLord
2012-07-12 21:22 - 2012-07-12 21:23 - 00000000 ____D C:\Program Files\BitLord 2
2012-07-12 21:19 - 2012-07-12 21:21 - 26143715 ____A C:\Users\Stuart Wilson\Downloads\BitLord 2.1.1 Installer.exe
2012-07-12 21:11 - 2012-07-12 21:11 - 00002025 ____A C:\Windows\System32\RaCoInst.log
2012-07-12 21:11 - 2012-07-12 21:11 - 00000000 ____D C:\Users\All Users\Ralink
2012-07-12 21:10 - 2012-07-12 21:10 - 00002025 ____A C:\Users\Public\Desktop\NETGEAR WNDA4100 Genie.lnk
2012-07-12 21:10 - 2012-07-12 21:10 - 00000000 ____D C:\Users\All Users\NETGEAR
2012-07-12 21:10 - 2012-07-12 21:10 - 00000000 ____D C:\Program Files\Cisco
2012-07-12 21:10 - 2011-11-28 02:21 - 00008192 ____A C:\Windows\System32\Drivers\rt2870.bin
2012-07-12 21:10 - 2011-05-03 19:56 - 01608768 ____A (Ralink Technology, Corp.) C:\Windows\System32\RaCertMgr.dll
2012-07-12 21:10 - 2011-05-03 19:54 - 00802880 ____A (Ralink Technology, Corp.) C:\Windows\System32\RaIHV.dll
2012-07-12 21:10 - 2010-06-30 23:45 - 00119648 ____A (Ralink Technology, Corp.) C:\Windows\System32\RaExtUI.dll
2012-07-11 22:27 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 22:27 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 22:27 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 22:27 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 22:27 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 22:27 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 22:27 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 22:27 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 22:27 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 22:27 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 22:27 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 22:27 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 22:27 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 22:27 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 22:24 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 21:04 - 2012-07-11 21:44 - 00000000 ____D C:\Users\Stuart Wilson\Desktop\Outlook Files
2012-07-11 15:40 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 15:40 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 15:40 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 15:40 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 15:40 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 15:40 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 15:40 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 15:40 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 15:40 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 15:39 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 20:37 - 2012-07-10 20:44 - 00000000 ____D C:\Users\Stuart Wilson\Desktop\New folder (2)
2012-07-02 20:14 - 2012-07-02 21:08 - 00000000 ____D C:\Users\Stuart Wilson\Desktop\New folder
============ 3 Months Modified Files ========================
2012-07-26 06:54 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-25 21:11 - 2010-09-04 21:38 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 21:11 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 21:10 - 2009-07-13 20:39 - 00106109 ____A C:\Windows\setupact.log
2012-07-23 16:14 - 2009-10-07 20:32 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-988588282-1707717258-2563674901-1001UA.job
2012-07-23 15:54 - 2010-09-04 21:38 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-23 14:49 - 2009-10-07 19:27 - 00039328 ____A C:\Windows\PFRO.log
2012-07-23 14:42 - 2009-10-07 16:52 - 01377174 ____A C:\Windows\WindowsUpdate.log
2012-07-23 14:41 - 2011-02-07 12:37 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-23 14:41 - 2009-10-07 17:01 - 00861310 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-23 14:39 - 2012-07-23 14:39 - 10288512 ____A (Microsoft Corporation) C:\Users\Stuart Wilson\Downloads\mseinstall.exe
2012-07-23 14:37 - 2009-07-13 20:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-23 14:37 - 2009-07-13 20:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-23 14:14 - 2009-10-07 20:32 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-988588282-1707717258-2563674901-1001Core.job
2012-07-22 22:50 - 2012-07-22 22:50 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Stuart Wilson\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-22 22:50 - 2012-07-22 22:50 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-18 16:58 - 2010-03-22 23:50 - 00002152 ____A C:\Users\All Users\hpzinstall.log
2012-07-18 15:52 - 2012-07-18 15:52 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-14 14:01 - 2009-07-13 20:53 - 00032586 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-14 12:35 - 2011-06-29 20:49 - 00000270 ____A C:\Windows\Tasks\RMSchedule.job
2012-07-13 12:44 - 2012-07-20 03:53 - 366967146 ____A C:\Users\Stuart Wilson\Documents\Sons.of.Anarchy.S03E02.Oiled.HDTV.XviD-FQM.avi
2012-07-12 21:23 - 2012-07-12 21:23 - 00001969 ____A C:\Users\Stuart Wilson\Desktop\BitLord.lnk
2012-07-12 21:21 - 2012-07-12 21:19 - 26143715 ____A C:\Users\Stuart Wilson\Downloads\BitLord 2.1.1 Installer.exe
2012-07-12 21:11 - 2012-07-12 21:11 - 00002025 ____A C:\Windows\System32\RaCoInst.log
2012-07-12 21:10 - 2012-07-12 21:10 - 00002025 ____A C:\Users\Public\Desktop\NETGEAR WNDA4100 Genie.lnk
2012-07-12 12:54 - 2009-07-13 20:33 - 00411248 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 22:24 - 2009-10-13 12:12 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-08 17:22 - 2010-05-20 02:51 - 00000204 ____A C:\Windows\MYOBP.INI
2012-07-08 17:22 - 2010-05-20 02:51 - 00000043 ____A C:\Windows\MYOB.INI
2012-07-02 19:46 - 2010-08-06 01:35 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 21:30 - 2012-05-09 16:20 - 00973824 ____A C:\Users\Stuart Wilson\Desktop\Elegance Oven Cleaning - Reminder List.xls
2012-06-25 17:27 - 2012-06-25 16:21 - 00000022 ____A C:\Users\Stuart Wilson\Downloads\Macquarie University Doctor of Physiotherapy - Anatomy resources.zip
2012-06-11 18:40 - 2012-07-11 22:24 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-11 15:39 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 21:05 - 2012-07-11 15:40 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-11 15:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-11 15:40 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 16:03 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 16:03 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 16:03 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 01:07 - 2012-07-11 22:27 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 22:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 22:27 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 22:27 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 22:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 22:27 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 22:27 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 22:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 22:27 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 22:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 22:27 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 22:27 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 22:27 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 22:27 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 21:19 - 2012-06-21 16:03 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 21:12 - 2012-06-21 16:03 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:45 - 2012-07-11 15:40 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-11 15:40 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-11 15:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-11 15:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-11 15:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-30 17:30 - 2012-05-30 17:30 - 02288188 ____A C:\Users\Stuart Wilson\Downloads\URGENT_-_Evaluation.zip
2012-05-23 22:50 - 2012-05-23 22:50 - 00416240 ____A C:\Users\Stuart Wilson\Downloads\Attachments_2012_05_24.zip
2012-05-23 16:59 - 2012-05-23 16:58 - 03016438 ____A C:\Users\Stuart Wilson\Downloads\2008
2012-05-17 15:23 - 2011-06-30 01:27 - 00003072 ____A C:\Windows\System32\Cache.db
2012-05-10 19:14 - 2012-05-10 19:09 - 20032520 ____A (PokerStars) C:\Users\Stuart Wilson\Downloads\PokerStarsInstall.exe
2012-05-10 17:07 - 2012-05-10 17:03 - 00855552 ____A C:\Users\Stuart Wilson\Desktop\Elegance Oven Cleaning - Reminder List 1.xls
2012-05-08 16:12 - 2012-04-30 17:35 - 00894464 ____A C:\Users\Stuart Wilson\Desktop\Oven Cleaning Reminder List.xls
2012-05-06 18:16 - 2012-05-02 16:33 - 00014896 ____A C:\Users\Stuart Wilson\Desktop\Payslip Form.xlsx
2012-05-03 13:43 - 2012-05-03 13:43 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-05-03 13:43 - 2012-05-03 13:43 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-05-03 13:43 - 2012-05-03 13:43 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-05-03 13:43 - 2012-05-03 13:43 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-05-03 13:43 - 2012-05-03 13:43 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-05-03 13:41 - 2012-05-03 13:40 - 00909088 ____A (Sun Microsystems, Inc.) C:\Users\Stuart Wilson\Downloads\jxpiinstall.exe
2012-05-02 21:16 - 2012-02-16 11:43 - 00012979 ____A C:\Users\Stuart Wilson\AppData\Roaming\Microsoft Excel 97-2003.CAL
2012-05-02 17:12 - 2012-05-02 17:12 - 00083824 ____A C:\Users\Stuart Wilson\Desktop\Contact List.xlsx
2012-05-01 14:31 - 2011-11-06 12:26 - 00000671 ____A C:\Users\Stuart Wilson\Desktop\Internet.lnk
2012-05-01 04:12 - 2012-05-01 04:12 - 00060039 ____A C:\Users\Stuart Wilson\Documents\Servicem8 Contacts.csv
2012-04-30 23:10 - 2012-01-29 14:08 - 00012374 ____A C:\Users\Stuart Wilson\Documents\Fix Jobs.xlsx
2012-04-30 20:44 - 2012-06-13 20:52 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-28 17:26 - 2011-07-25 23:49 - 00000853 ____A C:\Users\Stuart Wilson\Desktop\New Job Sheet.lnk
ZeroAccess:
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\@
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\L
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\U
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\U\00000001.@
ZeroAccess:
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\@
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\L
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-07-26 06:54] - 0259072 ____A (Microsoft Corporation) 21835BD18857B8BADD3858DE3B74F76C
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3071.55 MB
Available physical RAM: 2582 MB
Total Pagefile: 3069.83 MB
Available Pagefile: 2591.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:372.51 GB) (Free:118.06 GB) NTFS
4 Drive f: () (Removable) (Total:7.5 GB) (Free:3.88 GB) FAT32
5 Drive g: (Expansion Drive) (Fixed) (Total:1863 GB) (Free:1819.8 GB) exFAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 372 GB 0 B
Disk 1 Online 7695 MB 0 B
Disk 2 Online 1863 GB 1024 KB
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 372 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 372 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7695 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 7695 MB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G Expansion D exFAT Partition 1863 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-19 14:52
======================= End Of Log ==========================
SEARCH.TXT
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-26 15:57:34
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-07-26 06:54] - 0259072 ____A (Microsoft Corporation) 21835BD18857B8BADD3858DE3B74F76C
=== End Of Search ===
Seems as though I have the same problem as everyone else. Would love some help. Please find below my logs. Thanks
FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 26-07-2012 15:49:23
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SoundMan] SOUNDMAN.EXE [x]
HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-20] (Microsoft Corporation)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-05] (Apple Inc.)
HKLM\...\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" [1298320 2011-04-12] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1808784 2011-04-12] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe [112600 2010-11-14] (PC Tools)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-23] (Apple Inc.)
HKLM\...\Run: [Wondershare Helper Compact.exe] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1406976 2011-12-20] (Wondershare)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [RMAlert] "C:\Program Files\Registry Mechanic\Alert.exe" /PRODUCT=RM /R [1016792 2010-09-15] (PC Tool)
HKLM\...\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [973488 2012-07-02] (Malwarebytes Corporation)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-02] (Malwarebytes Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-25] (Microsoft Corporation)
HKU\Stuart Wilson\...\Run: [Google Update] "C:\Users\Stuart Wilson\AppData\Local\Google\Update\GoogleUpdate.exe" /c [133104 2009-10-07] (Google Inc.)
HKU\Stuart Wilson\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-22] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100 Smart Wizard.lnk
ShortcutTarget: NETGEAR WNA3100 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WNA3100\WNA3100.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\NETGEAR WNDA4100 Genie.lnk
ShortcutTarget: NETGEAR WNDA4100 Genie.lnk -> C:\Program Files\NETGEAR\WNDA4100\WNDA4100.EXE (NETGEAR)
================================ Services (Whitelisted) ==================
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-02] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-25] (Microsoft Corporation)
2 MSSQL$PROPHETSQL; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sPROPHETSQL [29293408 2010-12-09] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-25] (Microsoft Corporation)
2 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [632792 2011-01-27] (PC Tools)
2 RalinkRegistryWriter; "C:\Program Files\NETGEAR\WNDA4100\Service\RaRegistry.exe" [377088 2011-11-20] (Ralink Technology, Corp.)
2 SeagateDashboardService; C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [14088 2010-07-06] (Memeo)
2 WSWNA3100; C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe [285152 2010-08-25] ()
2 msftesql$PROPHETSQL; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f
========================== Drivers (Whitelisted) =============
3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC.SYS [4172832 2009-06-18] (Realtek Semiconductor Corp.)
3 BCMH43XX; C:\Windows\System32\DRIVERS\bcmwlhigh6.sys [699896 2009-11-05] (Broadcom Corporation)
3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [20992 2008-01-18] (Microsoft Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-02] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18432 2011-05-09] (Apple Inc.)
3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [1277504 2012-01-12] (Ralink Technology Corp.)
3 NPF; C:\Windows\System32\DRIVERS\npf.sys [50704 2010-02-02] (CACE Technologies, Inc.)
3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [21792 2011-04-12] (Microsoft Corporation)
0 SCMNdisP; C:\Windows\System32\DRIVERS\scmndisp.sys [21728 2007-01-19] (Windows (R) Codename Longhorn DDK provider)
4 RelevantKnowledge; [x]
3 RTL8192su; C:\Windows\System32\DRIVERS\RTL8192su.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-26 15:49 - 2012-07-26 15:49 - 00000000 ____D C:\FRST
2012-07-26 02:47 - 2012-07-26 06:54 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-07-25 21:01 - 2012-07-25 21:01 - 00000000 ____D C:\Users\Stuart Wilson\Downloads\NETGEAR
2012-07-23 14:41 - 2012-07-23 14:41 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-23 14:39 - 2012-07-23 14:39 - 10288512 ____A (Microsoft Corporation) C:\Users\Stuart Wilson\Downloads\mseinstall.exe
2012-07-22 22:50 - 2012-07-22 22:50 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Stuart Wilson\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-22 22:50 - 2012-07-22 22:50 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-22 21:35 - 2012-07-22 21:35 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-22 14:14 - 2012-07-22 20:33 - 00000000 ____D C:\Poker
2012-07-20 03:53 - 2012-07-13 12:44 - 366967146 ____A C:\Users\Stuart Wilson\Documents\Sons.of.Anarchy.S03E02.Oiled.HDTV.XviD-FQM.avi
2012-07-18 15:52 - 2012-07-18 15:52 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-12 21:24 - 2012-07-22 15:39 - 00000000 ____D C:\Users\Stuart Wilson\AppData\Roaming\BitLord
2012-07-12 21:24 - 2012-07-12 21:24 - 00000000 ____D C:\Users\Stuart Wilson\AppData\Roaming\Python-Eggs
2012-07-12 21:23 - 2012-07-12 21:23 - 00001969 ____A C:\Users\Stuart Wilson\Desktop\BitLord.lnk
2012-07-12 21:23 - 2012-07-12 21:23 - 00000000 ____D C:\Users\Stuart Wilson\Documents\BitLord
2012-07-12 21:22 - 2012-07-12 21:23 - 00000000 ____D C:\Program Files\BitLord 2
2012-07-12 21:19 - 2012-07-12 21:21 - 26143715 ____A C:\Users\Stuart Wilson\Downloads\BitLord 2.1.1 Installer.exe
2012-07-12 21:11 - 2012-07-12 21:11 - 00002025 ____A C:\Windows\System32\RaCoInst.log
2012-07-12 21:11 - 2012-07-12 21:11 - 00000000 ____D C:\Users\All Users\Ralink
2012-07-12 21:10 - 2012-07-12 21:10 - 00002025 ____A C:\Users\Public\Desktop\NETGEAR WNDA4100 Genie.lnk
2012-07-12 21:10 - 2012-07-12 21:10 - 00000000 ____D C:\Users\All Users\NETGEAR
2012-07-12 21:10 - 2012-07-12 21:10 - 00000000 ____D C:\Program Files\Cisco
2012-07-12 21:10 - 2011-11-28 02:21 - 00008192 ____A C:\Windows\System32\Drivers\rt2870.bin
2012-07-12 21:10 - 2011-05-03 19:56 - 01608768 ____A (Ralink Technology, Corp.) C:\Windows\System32\RaCertMgr.dll
2012-07-12 21:10 - 2011-05-03 19:54 - 00802880 ____A (Ralink Technology, Corp.) C:\Windows\System32\RaIHV.dll
2012-07-12 21:10 - 2010-06-30 23:45 - 00119648 ____A (Ralink Technology, Corp.) C:\Windows\System32\RaExtUI.dll
2012-07-11 22:27 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 22:27 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 22:27 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 22:27 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 22:27 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 22:27 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 22:27 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 22:27 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 22:27 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 22:27 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 22:27 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 22:27 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 22:27 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 22:27 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 22:24 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 21:04 - 2012-07-11 21:44 - 00000000 ____D C:\Users\Stuart Wilson\Desktop\Outlook Files
2012-07-11 15:40 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 15:40 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 15:40 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 15:40 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 15:40 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 15:40 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 15:40 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 15:40 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 15:40 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 15:39 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 20:37 - 2012-07-10 20:44 - 00000000 ____D C:\Users\Stuart Wilson\Desktop\New folder (2)
2012-07-02 20:14 - 2012-07-02 21:08 - 00000000 ____D C:\Users\Stuart Wilson\Desktop\New folder
============ 3 Months Modified Files ========================
2012-07-26 06:54 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-25 21:11 - 2010-09-04 21:38 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 21:11 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 21:10 - 2009-07-13 20:39 - 00106109 ____A C:\Windows\setupact.log
2012-07-23 16:14 - 2009-10-07 20:32 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-988588282-1707717258-2563674901-1001UA.job
2012-07-23 15:54 - 2010-09-04 21:38 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-23 14:49 - 2009-10-07 19:27 - 00039328 ____A C:\Windows\PFRO.log
2012-07-23 14:42 - 2009-10-07 16:52 - 01377174 ____A C:\Windows\WindowsUpdate.log
2012-07-23 14:41 - 2011-02-07 12:37 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-23 14:41 - 2009-10-07 17:01 - 00861310 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-23 14:39 - 2012-07-23 14:39 - 10288512 ____A (Microsoft Corporation) C:\Users\Stuart Wilson\Downloads\mseinstall.exe
2012-07-23 14:37 - 2009-07-13 20:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-23 14:37 - 2009-07-13 20:34 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-23 14:14 - 2009-10-07 20:32 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-988588282-1707717258-2563674901-1001Core.job
2012-07-22 22:50 - 2012-07-22 22:50 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Stuart Wilson\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-22 22:50 - 2012-07-22 22:50 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-18 16:58 - 2010-03-22 23:50 - 00002152 ____A C:\Users\All Users\hpzinstall.log
2012-07-18 15:52 - 2012-07-18 15:52 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-14 14:01 - 2009-07-13 20:53 - 00032586 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-14 12:35 - 2011-06-29 20:49 - 00000270 ____A C:\Windows\Tasks\RMSchedule.job
2012-07-13 12:44 - 2012-07-20 03:53 - 366967146 ____A C:\Users\Stuart Wilson\Documents\Sons.of.Anarchy.S03E02.Oiled.HDTV.XviD-FQM.avi
2012-07-12 21:23 - 2012-07-12 21:23 - 00001969 ____A C:\Users\Stuart Wilson\Desktop\BitLord.lnk
2012-07-12 21:21 - 2012-07-12 21:19 - 26143715 ____A C:\Users\Stuart Wilson\Downloads\BitLord 2.1.1 Installer.exe
2012-07-12 21:11 - 2012-07-12 21:11 - 00002025 ____A C:\Windows\System32\RaCoInst.log
2012-07-12 21:10 - 2012-07-12 21:10 - 00002025 ____A C:\Users\Public\Desktop\NETGEAR WNDA4100 Genie.lnk
2012-07-12 12:54 - 2009-07-13 20:33 - 00411248 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 22:24 - 2009-10-13 12:12 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-08 17:22 - 2010-05-20 02:51 - 00000204 ____A C:\Windows\MYOBP.INI
2012-07-08 17:22 - 2010-05-20 02:51 - 00000043 ____A C:\Windows\MYOB.INI
2012-07-02 19:46 - 2010-08-06 01:35 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 21:30 - 2012-05-09 16:20 - 00973824 ____A C:\Users\Stuart Wilson\Desktop\Elegance Oven Cleaning - Reminder List.xls
2012-06-25 17:27 - 2012-06-25 16:21 - 00000022 ____A C:\Users\Stuart Wilson\Downloads\Macquarie University Doctor of Physiotherapy - Anatomy resources.zip
2012-06-11 18:40 - 2012-07-11 22:24 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-11 15:39 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 21:05 - 2012-07-11 15:40 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-11 15:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-11 15:40 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 16:03 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 16:03 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 16:03 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 16:03 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 01:07 - 2012-07-11 22:27 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 22:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 22:27 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 22:27 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 22:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 22:27 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 22:27 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 22:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 22:27 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 22:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 22:27 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 22:27 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 22:27 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 22:27 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 21:19 - 2012-06-21 16:03 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 21:12 - 2012-06-21 16:03 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:45 - 2012-07-11 15:40 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-11 15:40 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-11 15:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-11 15:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-11 15:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-30 17:30 - 2012-05-30 17:30 - 02288188 ____A C:\Users\Stuart Wilson\Downloads\URGENT_-_Evaluation.zip
2012-05-23 22:50 - 2012-05-23 22:50 - 00416240 ____A C:\Users\Stuart Wilson\Downloads\Attachments_2012_05_24.zip
2012-05-23 16:59 - 2012-05-23 16:58 - 03016438 ____A C:\Users\Stuart Wilson\Downloads\2008
2012-05-17 15:23 - 2011-06-30 01:27 - 00003072 ____A C:\Windows\System32\Cache.db
2012-05-10 19:14 - 2012-05-10 19:09 - 20032520 ____A (PokerStars) C:\Users\Stuart Wilson\Downloads\PokerStarsInstall.exe
2012-05-10 17:07 - 2012-05-10 17:03 - 00855552 ____A C:\Users\Stuart Wilson\Desktop\Elegance Oven Cleaning - Reminder List 1.xls
2012-05-08 16:12 - 2012-04-30 17:35 - 00894464 ____A C:\Users\Stuart Wilson\Desktop\Oven Cleaning Reminder List.xls
2012-05-06 18:16 - 2012-05-02 16:33 - 00014896 ____A C:\Users\Stuart Wilson\Desktop\Payslip Form.xlsx
2012-05-03 13:43 - 2012-05-03 13:43 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-05-03 13:43 - 2012-05-03 13:43 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-05-03 13:43 - 2012-05-03 13:43 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-05-03 13:43 - 2012-05-03 13:43 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-05-03 13:43 - 2012-05-03 13:43 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-05-03 13:41 - 2012-05-03 13:40 - 00909088 ____A (Sun Microsystems, Inc.) C:\Users\Stuart Wilson\Downloads\jxpiinstall.exe
2012-05-02 21:16 - 2012-02-16 11:43 - 00012979 ____A C:\Users\Stuart Wilson\AppData\Roaming\Microsoft Excel 97-2003.CAL
2012-05-02 17:12 - 2012-05-02 17:12 - 00083824 ____A C:\Users\Stuart Wilson\Desktop\Contact List.xlsx
2012-05-01 14:31 - 2011-11-06 12:26 - 00000671 ____A C:\Users\Stuart Wilson\Desktop\Internet.lnk
2012-05-01 04:12 - 2012-05-01 04:12 - 00060039 ____A C:\Users\Stuart Wilson\Documents\Servicem8 Contacts.csv
2012-04-30 23:10 - 2012-01-29 14:08 - 00012374 ____A C:\Users\Stuart Wilson\Documents\Fix Jobs.xlsx
2012-04-30 20:44 - 2012-06-13 20:52 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-28 17:26 - 2011-07-25 23:49 - 00000853 ____A C:\Users\Stuart Wilson\Desktop\New Job Sheet.lnk
ZeroAccess:
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\@
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\L
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\U
C:\Windows\Installer\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\U\00000001.@
ZeroAccess:
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\@
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\L
C:\Users\Stuart Wilson\AppData\Local\{ae85b9a3-73a2-168c-aa32-564690b36f1d}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-07-26 06:54] - 0259072 ____A (Microsoft Corporation) 21835BD18857B8BADD3858DE3B74F76C
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3071.55 MB
Available physical RAM: 2582 MB
Total Pagefile: 3069.83 MB
Available Pagefile: 2591.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:372.51 GB) (Free:118.06 GB) NTFS
4 Drive f: () (Removable) (Total:7.5 GB) (Free:3.88 GB) FAT32
5 Drive g: (Expansion Drive) (Fixed) (Total:1863 GB) (Free:1819.8 GB) exFAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 372 GB 0 B
Disk 1 Online 7695 MB 0 B
Disk 2 Online 1863 GB 1024 KB
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 372 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 372 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7695 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 7695 MB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G Expansion D exFAT Partition 1863 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-19 14:52
======================= End Of Log ==========================
SEARCH.TXT
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-26 15:57:34
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-07-26 06:54] - 0259072 ____A (Microsoft Corporation) 21835BD18857B8BADD3858DE3B74F76C
=== End Of Search ===