Hi all, somehow Live Platinum fake antivirus program started running on my system. I was just browsing around the internet, didn't even click/download on anything. I followed instructions to remove it but I think it made it worse and now I have sirefef with my computer restarting every 60 seconds, firewall not being able to turn on, and mse not being able to start. Please help!
Scan result of Farbar Recovery Scan Tool Version: 14-06-2012
Ran by SYSTEM at 15-06-2012 00:17:30
Running from G:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe" [495616 2011-03-08] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [856064 2011-03-08] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2011-11-13] (VMware, Inc.)
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2215768 2011-12-06] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Dragon\...\Run: [Spotify] "C:\Users\Dragon\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart [9478320 2012-05-11] (Spotify Ltd)
HKU\Dragon\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2012-02-23] (Apple Inc.)
HKU\Dragon\...\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2012-02-24] (Apple Inc.)
HKU\Dragon\...\Run: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe [4923784 2010-09-21] ()
HKU\Dragon\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Dragon\...\Run: [SteelSeries Engine] C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [231424 2012-04-05] ()
HKU\Dragon\...\Run: [Spotify Web Helper] "C:\Users\Dragon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [932528 2012-05-11] ()
HKU\Guest\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Guest\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKU\Guest\...\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIH4A.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4540 Series" /EF "HKCU" [239488 2011-07-18] (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\CrashPlan Tray.lnk
ShortcutTarget: CrashPlan Tray.lnk -> C:\Program Files\CrashPlan\CrashPlanTray.exe (Code 42 Software, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\RealTemp.exe - Shortcut.lnk
ShortcutTarget: RealTemp.exe - Shortcut.lnk -> C:\Downloads\RealTemp_370\RealTemp.exe (No File)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\SABnzbd.lnk
ShortcutTarget: SABnzbd.lnk -> C:\Program Files (x86)\SABnzbd\SABnzbd.exe ()
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\Trillian.lnk
ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\volume.ahk ()
==================== Services (Whitelisted) ======
2 atnthost; "C:\ProgramData\webex\MyWebEx\319\atnthost.exe" [16776 2011-12-14] (WebEx Communications, Inc.)
2 BotkindSyncService; C:\Program Files\Allway Sync\Bin\SyncService.exe service [261632 2012-02-07] ()
2 CrashPlanService; "C:\Program Files\CrashPlan\CrashPlanService.exe" [222720 2011-03-16] (CrashPlan)
2 EpsonCustomerParticipation; "C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe" [555392 2011-06-09] (SEIKO EPSON CORPORATION)
4 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe" [135584 2011-12-09] (Futuremark Corporation)
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-21] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-21] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [113120 2012-06-06] (Mozilla Foundation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 QBCFMonitorService; "C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe" [45056 2012-03-14] (Intuit)
3 QBFCService; "C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe" [61440 2011-08-19] (Intuit Inc.)
2 QBVSS; "C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe" [1248256 2011-08-19] (Intuit Inc.)
2 VMUSBArbService; "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" [846448 2011-08-29] (VMware, Inc.)
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-10] ()
3 wampapache; "C:\wamp\bin\apache\apache2.2.21\bin\httpd.exe" -k runservice [21504 2011-09-26] (Apache Software Foundation)
3 wampmysqld; C:\wamp\bin\mysql\mysql5.5.20\bin\mysqld.exe wampmysqld [9690112 2012-01-25] ()
2 Apache2.2; "C:\xampp\apache\bin\httpd.exe" -k runservice [x]
2 mysql; C:\xampp\mysql\bin\mysqld.exe --defaults-file=C:\xampp\mysql\bin\my.ini mysql [x]
========================== Drivers (Whitelisted) =============
3 busenum; C:\Windows\System32\DRIVERS\SteelBus64.sys [106496 2012-01-20] (SteelSeries Corporation)
2 cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2011-09-21] (CPUID)
3 hitmanpro35; \??\C:\Windows\system32\drivers\hitmanpro36.sys [30496 2012-06-14] ()
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2011-09-16] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2011-09-16] (LogMeIn, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [34944 2012-01-20] (SteelSeries Corporation)
4 LMIRfsClientNP; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-15 00:17 - 2012-06-15 00:17 - 00000000 ____D C:\FRST
2012-06-14 23:03 - 2012-06-14 23:03 - 00136012 ____A C:\TDSSKiller.2.7.39.0_15.06.2012_00.03.56_log.txt
2012-06-14 23:03 - 2012-06-14 23:03 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\83023745.sys
2012-06-14 23:03 - 2012-06-14 07:12 - 02127448 ____A (Kaspersky Lab ZAO) C:\Users\Dragon\Desktop\TDSSKiller.exe
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 22:11 - 2012-06-14 22:11 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-14 22:10 - 2012-06-14 22:10 - 00000808 ____A C:\Windows\System32\.crusader
2012-06-14 22:06 - 2012-06-14 22:10 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-14 21:55 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-14 21:52 - 2012-06-14 21:52 - 00000361 ____A C:\rkill.log
2012-06-14 21:44 - 2012-06-14 22:48 - 01232802 ____A C:\Windows\ntbtlog.txt
2012-06-14 21:42 - 2012-06-14 21:42 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-14 21:38 - 2012-06-14 21:38 - 00000000 ____D C:\Users\All Users\99058D9B000415CB00038E50B4EB2331
2012-06-14 20:25 - 2012-06-14 20:25 - 00000000 __RHD C:\ESD
2012-06-14 17:47 - 2012-06-14 17:47 - 00000000 ____D C:\Users\Dragon\AppData\Local\Macromedia
2012-06-14 10:07 - 2012-06-14 20:53 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-14 08:59 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 08:59 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 08:59 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 08:59 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 08:59 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 08:59 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 08:59 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 08:59 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 08:59 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 08:59 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 08:59 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 08:59 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 08:59 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 08:59 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 08:59 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 08:59 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 08:59 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 08:59 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 08:59 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 08:59 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 08:59 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 08:59 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 08:59 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 08:59 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 08:59 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 08:59 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 08:59 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 08:59 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 15:58 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 15:58 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 15:58 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 15:58 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 15:58 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 15:58 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 15:58 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 15:58 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 15:58 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 15:58 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 15:58 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 15:58 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 15:58 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 15:58 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 15:58 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 15:58 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 15:58 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-08 14:55 - 2012-06-08 14:55 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Notepad++
2012-06-08 14:20 - 2012-06-08 14:20 - 00143766 ____A C:\Users\Guest\Downloads\Service Agreement - NY.pdf
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-03 17:57 - 2012-06-03 17:57 - 00000000 ____D C:\Windows\Microsoft Antimalware
2012-06-03 17:13 - 2012-06-03 17:13 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-06-03 17:12 - 2012-06-03 17:13 - 00137352 ____A C:\TDSSKiller.2.7.36.0_03.06.2012_18.12.55_log.txt
2012-05-29 11:36 - 2012-05-29 11:38 - 00001348 ____A C:\Windows\System32\Drivers\etc\hosts.umbrella
2012-05-29 11:36 - 2012-05-29 11:37 - 00000144 ____A C:\Users\Dragon\umbrella0.log
2012-05-29 11:36 - 2012-05-29 11:37 - 00000000 ____D C:\Users\Dragon\.shsh
2012-05-28 15:32 - 2012-05-28 15:32 - 00000000 ____D C:\Users\Dragon\AppData\Local\libimobiledevice
2012-05-20 20:55 - 2012-06-14 10:53 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-20 20:55 - 2012-05-20 20:55 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-20 10:14 - 2012-06-06 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Mozilla
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Local\Mozilla
2012-05-19 14:28 - 2012-06-06 22:09 - 00000000 ____D C:\Program Files (x86)\Diablo III
============ 3 Months Modified Files and Folders =============
2012-06-15 00:17 - 2012-06-15 00:17 - 00000000 ____D C:\FRST
2012-06-14 23:12 - 2012-04-10 10:58 - 00000000 ____D C:\Users\All Users\VMware
2012-06-14 23:12 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-14 23:12 - 2009-07-13 20:51 - 00040624 ____A C:\Windows\setupact.log
2012-06-14 23:04 - 2012-06-14 23:03 - 00136012 ____A C:\TDSSKiller.2.7.39.0_15.06.2012_00.03.56_log.txt
2012-06-14 23:04 - 2012-02-18 22:44 - 01696751 ____A C:\Windows\WindowsUpdate.log
2012-06-14 23:03 - 2012-06-14 23:03 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\83023745.sys
2012-06-14 23:03 - 2012-02-25 17:46 - 00000000 ___HD C:\jexepackres
2012-06-14 23:03 - 2012-02-20 23:20 - 00015342 ____A C:\test.log
2012-06-14 23:03 - 2012-02-19 18:02 - 00000000 ____D C:\Users\Dragon\AppData\Local\sabnzbd
2012-06-14 23:03 - 2012-02-19 01:56 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Dropbox
2012-06-14 23:03 - 2012-02-19 01:56 - 00000000 ____D C:\Users\Dragon\AppData\Local\Spotify
2012-06-14 23:01 - 2012-02-25 17:50 - 00000000 ____D C:\Users\All Users\LogMeIn
2012-06-14 22:48 - 2012-06-14 21:44 - 01232802 ____A C:\Windows\ntbtlog.txt
2012-06-14 22:18 - 2009-07-13 20:45 - 00020528 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-14 22:18 - 2009-07-13 20:45 - 00020528 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-14 22:17 - 2009-07-13 21:13 - 00807822 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 22:16 - 2012-02-19 01:57 - 00821480 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-14 22:16 - 2012-02-19 01:57 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-14 22:16 - 2012-02-19 01:56 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Spotify
2012-06-14 22:11 - 2012-06-14 22:11 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-14 22:11 - 2012-02-19 01:56 - 00000000 ____D C:\Program Files (x86)\Trillian
2012-06-14 22:10 - 2012-06-14 22:10 - 00000808 ____A C:\Windows\System32\.crusader
2012-06-14 22:10 - 2012-06-14 22:06 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-14 22:10 - 2012-02-19 18:01 - 00000000 ____D C:\Program Files (x86)\SABnzbd
2012-06-14 22:10 - 2012-02-19 01:55 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2229342774-3388454487-1059482264-1000UA.job
2012-06-14 22:10 - 2012-02-19 00:47 - 00000000 __SHD C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}
2012-06-14 22:06 - 2010-11-20 19:47 - 00012374 ____A C:\Windows\PFRO.log
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-14 21:52 - 2012-06-14 21:52 - 00000361 ____A C:\rkill.log
2012-06-14 21:46 - 2009-07-13 20:45 - 04997552 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 21:42 - 2012-06-14 21:42 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-14 21:38 - 2012-06-14 21:38 - 00000000 ____D C:\Users\All Users\99058D9B000415CB00038E50B4EB2331
2012-06-14 21:09 - 2012-02-19 15:39 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\vlc
2012-06-14 21:05 - 2012-04-20 07:25 - 00005632 ____A C:\Users\Dragon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-14 20:56 - 2012-02-19 19:01 - 00000000 ____D C:\Users\Dragon\AppData\Local\4673A125-DF05-4C80-B515-4F7AD151636E.aplzod
2012-06-14 20:53 - 2012-06-14 10:07 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-14 20:25 - 2012-06-14 20:25 - 00000000 __RHD C:\ESD
2012-06-14 17:47 - 2012-06-14 17:47 - 00000000 ____D C:\Users\Dragon\AppData\Local\Macromedia
2012-06-14 10:53 - 2012-05-20 20:55 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-14 10:53 - 2012-03-12 20:10 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-14 10:06 - 2012-02-19 01:55 - 00000000 ____D C:\Program Files (x86)\uTorrent
2012-06-14 10:03 - 2012-02-19 10:22 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Skype
2012-06-14 09:03 - 2012-02-19 11:22 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-14 09:02 - 2012-02-19 00:47 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-14 07:12 - 2012-06-14 23:03 - 02127448 ____A (Kaspersky Lab ZAO) C:\Users\Dragon\Desktop\TDSSKiller.exe
2012-06-14 05:01 - 2012-03-16 23:47 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{495C90479FCE17D0BAAA76C781C684B9}.job
2012-06-14 05:00 - 2012-05-02 09:17 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{43EF9D144C5BCAA06DB442334766A4A1}.job
2012-06-14 04:00 - 2012-03-16 23:47 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{45E5C387E307B1C3881AD4D30DB2B796}.job
2012-06-14 03:00 - 2012-03-16 23:46 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{47D430BC3C7BF20BA4CF6D65DE5E76A6}.job
2012-06-14 02:00 - 2012-03-16 23:46 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{4F0C1497E9A5A062AD06B978802E02AB}.job
2012-06-14 01:10 - 2012-02-19 01:55 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2229342774-3388454487-1059482264-1000Core.job
2012-06-10 02:40 - 2012-02-19 00:40 - 00000458 ____A C:\Windows\Tasks\Intel_C_CVCV15340AN7120BGN.job
2012-06-09 14:20 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-06-08 14:55 - 2012-06-08 14:55 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Notepad++
2012-06-08 14:20 - 2012-06-08 14:20 - 00143766 ____A C:\Users\Guest\Downloads\Service Agreement - NY.pdf
2012-06-08 14:19 - 2012-03-03 11:01 - 00114776 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-07 07:48 - 2009-07-13 19:20 - 00000000 ___HD C:\Windows\System32\GroupPolicy
2012-06-07 07:28 - 2012-02-19 01:55 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\uTorrent
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-06 22:54 - 2012-05-20 10:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-06 22:09 - 2012-05-19 14:28 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-06-03 17:57 - 2012-06-03 17:57 - 00000000 ____D C:\Windows\Microsoft Antimalware
2012-06-03 17:13 - 2012-06-03 17:13 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-06-03 17:13 - 2012-06-03 17:12 - 00137352 ____A C:\TDSSKiller.2.7.36.0_03.06.2012_18.12.55_log.txt
2012-06-03 00:00 - 2012-02-25 16:27 - 00000000 ____D C:\Users\Dragon\AppData\Local\ElevatedDiagnostics
2012-06-02 19:02 - 2012-04-06 23:55 - 00000000 ____D C:\Users\All Users\Sonos,_Inc
2012-06-02 18:39 - 2012-02-19 12:27 - 00000000 ____D C:\Users\Dragon\AppData\Local\Futuremark_Corporation
2012-06-01 16:31 - 2012-02-18 22:42 - 00000000 ____D C:\users\Dragon
2012-06-01 07:00 - 2012-03-03 09:49 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\HandBrake
2012-05-31 20:53 - 2012-02-19 00:34 - 00114776 ____A C:\Users\Dragon\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-31 20:33 - 2012-04-10 11:01 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\VMware
2012-05-29 18:07 - 2012-04-10 11:01 - 00000000 ____D C:\Users\Dragon\AppData\Local\VMware
2012-05-29 11:38 - 2012-05-29 11:36 - 00001348 ____A C:\Windows\System32\Drivers\etc\hosts.umbrella
2012-05-29 11:38 - 2009-07-13 18:34 - 00001348 ____A C:\Windows\System32\Drivers\etc\hosts
2012-05-29 11:37 - 2012-05-29 11:36 - 00000144 ____A C:\Users\Dragon\umbrella0.log
2012-05-29 11:37 - 2012-05-29 11:36 - 00000000 ____D C:\Users\Dragon\.shsh
2012-05-28 15:32 - 2012-05-28 15:32 - 00000000 ____D C:\Users\Dragon\AppData\Local\libimobiledevice
2012-05-24 21:18 - 2012-03-12 08:46 - 00007609 ____A C:\Users\Dragon\AppData\Local\Resmon.ResmonCfg
2012-05-21 17:52 - 2012-02-25 17:50 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-05-21 17:52 - 2012-02-25 17:50 - 00080768 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-05-21 17:52 - 2012-02-25 17:50 - 00034688 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-05-21 17:52 - 2012-02-25 17:50 - 00000000 ____D C:\Program Files (x86)\LogMeIn
2012-05-20 20:55 - 2012-05-20 20:55 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-20 10:19 - 2012-02-18 22:42 - 00000000 ____D C:\Users\Dragon\AppData\LocalLow
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Mozilla
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Local\Mozilla
2012-05-17 22:54 - 2012-05-01 08:22 - 00000000 ____D C:\Users\All Users\webex
2012-05-17 18:47 - 2012-06-14 08:59 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 08:59 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 08:59 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 08:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 08:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 08:59 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 08:59 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 08:59 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 08:59 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 08:59 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 08:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 08:59 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 08:59 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 08:59 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 08:59 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 08:59 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 08:59 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 08:59 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 08:59 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 08:59 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 08:59 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 08:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 08:59 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 08:59 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 08:59 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 08:59 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 08:59 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 08:59 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-16 12:07 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports
2012-05-14 17:32 - 2012-06-13 15:58 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 10:28 - 2012-02-28 14:03 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\FileZilla
2012-05-11 10:24 - 2012-05-11 10:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-11 10:24 - 2012-05-11 10:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 10:24 - 2010-11-20 23:17 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-08 22:35 - 2012-05-08 21:42 - 00000600 ____A C:\Users\Dragon\AppData\Roaming\PUTTY.RND
2012-05-08 22:35 - 2012-05-07 18:26 - 00000600 ____A C:\Users\Dragon\AppData\Local\PUTTY.RND
2012-05-08 18:19 - 2012-05-08 09:37 - 00000000 ____D C:\Users\Dragon\ZipForm
2012-05-08 09:37 - 2012-05-08 09:37 - 00000088 ____A C:\Users\Dragon\.java.policy
2012-05-06 21:03 - 2012-05-06 21:03 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\MindTerm
2012-05-04 03:06 - 2012-06-13 15:58 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 15:58 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 15:58 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 10:24 - 2012-03-12 14:37 - 00191824 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-05-03 10:23 - 2012-05-03 10:23 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-05-03 10:20 - 2012-02-19 19:01 - 00000000 ____D C:\Users\Dragon\AppData\Local\Adobe
2012-05-03 10:20 - 2012-02-19 02:01 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Adobe
2012-05-02 08:56 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-05-01 16:46 - 2012-05-01 16:46 - 04472832 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2012-04-30 21:40 - 2012-06-13 15:58 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 11:01 - 2012-03-23 17:24 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Epson
2012-04-27 19:55 - 2012-06-13 15:58 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 21:35 - 2012-04-26 19:38 - 00244174 ____A C:\Users\Guest\Documents\Tax Outline 2012.2.0.docx
2012-04-26 19:47 - 2012-04-26 18:45 - 00284312 ____A C:\Users\Guest\Desktop\TAXATION OF BUSINESS ENTERPRISES outline 3.docx
2012-04-25 21:41 - 2012-06-13 15:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 15:58 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 15:58 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Users\Dragon\AppData\Local\Brice_Lambson
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Users\All Users\Package Cache
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Program Files\Image Resizer for Windows
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Program Files (x86)\Image Resizer for Windows
2012-04-24 09:53 - 2012-04-23 19:44 - 00000000 ____D C:\Program Files (x86)\Diablo III Beta
2012-04-23 21:37 - 2012-06-13 15:58 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 15:58 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 15:58 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 15:58 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 15:58 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 15:58 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 19:41 - 2012-04-23 19:41 - 00000000 ____D C:\Users\All Users\Battle.net
2012-04-17 21:42 - 2012-03-03 11:01 - 00000000 ____D C:\Users\Guest\Documents\StarCraft II
2012-04-17 13:38 - 2012-04-17 13:38 - 00000442 ___AH C:\Windows\Tasks\Fortus Capital, LLC 1334698711.job
2012-04-17 10:38 - 2012-02-20 23:20 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\SteelSeries
2012-04-17 10:37 - 2012-02-20 23:20 - 00000000 ____D C:\Users\All Users\SteelSeries
2012-04-17 10:36 - 2012-02-20 23:20 - 00000000 ____D C:\Program Files\SteelSeries
2012-04-16 14:57 - 2012-04-16 14:57 - 00000000 ____D C:\Users\Guest\AppData\Local\Apple Computer
2012-04-16 14:57 - 2012-03-03 11:01 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Apple Computer
2012-04-15 13:03 - 2012-04-14 14:05 - 00000090 ____A C:\Windows\QBChanUtil_Trigger.ini
2012-04-15 12:29 - 2012-04-15 12:29 - 00288152 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-04-15 12:29 - 2012-04-15 12:29 - 00281774 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-04-15 12:08 - 2012-04-15 12:08 - 00000000 ____D C:\Users\Guest\AppData\Local\Intuit
2012-04-15 12:08 - 2012-03-27 11:57 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Adobe
2012-04-14 15:55 - 2012-04-14 14:06 - 00000000 ____D C:\Users\Dragon\AppData\Local\Intuit
2012-04-14 15:54 - 2012-04-14 14:05 - 00000000 ____D C:\Users\All Users\Intuit
2012-04-14 14:10 - 2012-04-14 14:10 - 00000000 ____D C:\Program Files\Common Files\Intuit
2012-04-14 14:09 - 2012-04-14 14:05 - 00000000 ____D C:\Users\All Users\SQL Anywhere 11
2012-04-14 14:08 - 2012-04-14 14:05 - 00000000 ____D C:\Program Files (x86)\Intuit
2012-04-14 14:05 - 2012-04-14 14:05 - 00000000 ____D C:\Users\Public\Documents\Intuit
2012-04-14 14:05 - 2012-04-14 14:05 - 00000000 ____D C:\Users\All Users\Nuance
2012-04-14 14:04 - 2012-04-14 14:04 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2012-04-14 14:03 - 2012-04-14 14:03 - 00000000 ____D C:\Windows\Intuit
2012-04-11 09:08 - 2012-04-04 09:17 - 00000000 ____D C:\Sites
2012-04-11 08:54 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-04-10 13:19 - 2012-04-10 13:19 - 00000000 ____D C:\Program Files\Common Files\VMware
2012-04-10 13:19 - 2012-04-10 10:58 - 00000000 ____D C:\Program Files (x86)\VMware
2012-04-10 11:54 - 2012-04-08 19:09 - 00000000 ____D C:\Program Files (x86)\hpmonitor
2012-04-10 10:58 - 2012-04-10 10:58 - 00000000 ____D C:\Users\Public\Documents\Shared Virtual Machines
2012-04-10 10:58 - 2012-02-25 17:50 - 00001024 ____A C:\.rnd
2012-04-08 19:09 - 2012-04-08 19:09 - 00000000 ____D C:\Program Files\MediaInfo
2012-04-08 14:02 - 2012-04-03 09:47 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\1UPIndustries
2012-04-08 14:02 - 2012-04-03 09:47 - 00000000 ____D C:\Users\All Users\1UPIndustries
2012-04-07 07:42 - 2012-04-07 07:42 - 00000000 ____D C:\Users\Dragon\AppData\Local\Sonos,_Inc
2012-04-07 04:31 - 2012-06-13 15:58 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 15:58 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-06 23:55 - 2012-04-06 23:55 - 00000000 ____D C:\Users\Dragon\AppData\Local\Downloaded Installations
2012-04-06 23:55 - 2012-04-06 23:55 - 00000000 ____D C:\Program Files (x86)\Sonos
2012-04-06 09:49 - 2012-04-06 09:49 - 00000000 ____D C:\Program Files\iTunes
2012-04-06 09:49 - 2012-04-06 09:49 - 00000000 ____D C:\Program Files\iPod
2012-04-06 09:49 - 2012-04-06 09:49 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-04-05 09:33 - 2012-04-05 09:28 - 00000000 ____D C:\Users\Dragon\.jedit
2012-04-04 17:10 - 2012-04-04 17:10 - 00000065 ____A C:\Users\Dragon\.gitconfig
2012-04-04 17:04 - 2012-04-04 09:18 - 00000000 ____D C:\Users\Dragon\.ssh
2012-04-04 14:56 - 2012-06-14 21:55 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-04 09:21 - 2012-04-04 09:21 - 00000000 ____D C:\Users\Dragon\.gem
2012-04-04 09:17 - 2012-04-04 09:17 - 00000000 ____D C:\RailsInstaller
2012-04-03 09:47 - 2012-04-03 09:47 - 00000000 ____D C:\Program Files\1UPIndustries
2012-04-01 18:54 - 2012-04-01 18:54 - 00000000 ____D C:\Users\All Users\Freemake
2012-04-01 18:54 - 2012-04-01 18:54 - 00000000 ____D C:\Program Files (x86)\Freemake
2012-03-30 03:35 - 2012-05-08 19:33 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-27 23:37 - 2012-03-27 23:37 - 00000000 ____D C:\Users\All Users\ATI
2012-03-27 23:24 - 2012-03-27 23:23 - 00000000 ____D C:\Program Files\ATI Technologies
2012-03-27 23:23 - 2012-03-27 23:23 - 00000000 ____D C:\Program Files\ATI
2012-03-27 12:40 - 2012-03-27 12:40 - 00000000 ____D C:\Users\Guest\AppData\Local\Adobe
2012-03-27 11:57 - 2012-03-03 11:01 - 00000000 ____D C:\Users\Guest\AppData\LocalLow
2012-03-27 11:56 - 2012-03-27 11:56 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Epson
2012-03-26 20:11 - 2012-02-25 16:45 - 00000000 ____D C:\Program Files\CrashPlan
2012-03-25 22:58 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-03-25 18:31 - 2012-02-21 10:35 - 00000000 ____D C:\Program Files (x86)\Brother
2012-03-25 18:30 - 2012-03-25 18:30 - 00000000 ____A C:\Windows\EEventManager.INI
2012-03-25 18:25 - 2012-03-23 17:23 - 00000000 ____D C:\Users\All Users\EPSON
2012-03-24 19:32 - 2012-02-21 10:42 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-03-23 17:34 - 2012-03-23 17:22 - 00000106 ____A C:\Windows\EP4540.ini
2012-03-23 17:32 - 2012-03-23 17:32 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Leadertech
2012-03-23 17:32 - 2012-03-23 17:23 - 00000000 ____D C:\Program Files (x86)\Epson Software
2012-03-23 17:31 - 2012-03-23 17:31 - 00000000 ____D C:\Program Files\Common Files\EPSON
2012-03-23 17:24 - 2012-03-23 17:24 - 00000000 ____D C:\Program Files\EpsonNet
2012-03-23 17:24 - 2012-03-23 17:24 - 00000000 ____D C:\Program Files\EPSON
2012-03-23 17:24 - 2012-02-19 00:33 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-03-23 17:23 - 2012-03-23 17:23 - 00000000 ____D C:\Program Files (x86)\Epson America Inc
2012-03-23 17:23 - 2012-03-23 17:23 - 00000000 ____D C:\Program Files (x86)\epson
2012-03-23 09:04 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-03-22 20:14 - 2012-02-19 01:55 - 00000000 ____D C:\Users\Dragon\AppData\Local\Google
2012-03-21 23:38 - 2012-03-21 23:38 - 00000000 ____D C:\Users\All Users\Synology
2012-03-20 19:44 - 2012-03-20 19:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 19:44 - 2012-03-20 19:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
ZeroAccess:
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\@
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\L
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\n
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\U
ZeroAccess:
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\@
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\L
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16360.86 MB
Available physical RAM: 15213.17 MB
Total Pagefile: 16359.06 MB
Available Pagefile: 15219.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.69 GB) (Free:9.04 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (WDO_Media64) (Removable) (Total:3.92 GB) (Free:3.63 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (Emperor) (Fixed) (Total:2794.52 GB) (Free:1246.9 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 2794 GB 0 B *
Disk 1 Online 111 GB 0 B
Disk 2 Online 4014 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 2794 GB 1024 KB
======================================================================================================
Disk: 0
Partition 1
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y Emperor NTFS Partition 2794 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 111 GB 101 MB
======================================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 111 GB Healthy
======================================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 4013 MB 32 KB
======================================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G WDO_Media64 NTFS Removable 4013 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-07 23:37
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 14-06-2012
Ran by SYSTEM at 2012-06-15 00:18:26
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
Scan result of Farbar Recovery Scan Tool Version: 14-06-2012
Ran by SYSTEM at 15-06-2012 00:17:30
Running from G:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe" [495616 2011-03-08] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [856064 2011-03-08] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2011-11-13] (VMware, Inc.)
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2215768 2011-12-06] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Dragon\...\Run: [Spotify] "C:\Users\Dragon\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart [9478320 2012-05-11] (Spotify Ltd)
HKU\Dragon\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2012-02-23] (Apple Inc.)
HKU\Dragon\...\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2012-02-24] (Apple Inc.)
HKU\Dragon\...\Run: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe [4923784 2010-09-21] ()
HKU\Dragon\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Dragon\...\Run: [SteelSeries Engine] C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [231424 2012-04-05] ()
HKU\Dragon\...\Run: [Spotify Web Helper] "C:\Users\Dragon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [932528 2012-05-11] ()
HKU\Guest\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Guest\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKU\Guest\...\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIH4A.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4540 Series" /EF "HKCU" [239488 2011-07-18] (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\CrashPlan Tray.lnk
ShortcutTarget: CrashPlan Tray.lnk -> C:\Program Files\CrashPlan\CrashPlanTray.exe (Code 42 Software, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\RealTemp.exe - Shortcut.lnk
ShortcutTarget: RealTemp.exe - Shortcut.lnk -> C:\Downloads\RealTemp_370\RealTemp.exe (No File)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\SABnzbd.lnk
ShortcutTarget: SABnzbd.lnk -> C:\Program Files (x86)\SABnzbd\SABnzbd.exe ()
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\Trillian.lnk
ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
Startup: C:\Users\Dragon\Start Menu\Programs\Startup\volume.ahk ()
==================== Services (Whitelisted) ======
2 atnthost; "C:\ProgramData\webex\MyWebEx\319\atnthost.exe" [16776 2011-12-14] (WebEx Communications, Inc.)
2 BotkindSyncService; C:\Program Files\Allway Sync\Bin\SyncService.exe service [261632 2012-02-07] ()
2 CrashPlanService; "C:\Program Files\CrashPlan\CrashPlanService.exe" [222720 2011-03-16] (CrashPlan)
2 EpsonCustomerParticipation; "C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe" [555392 2011-06-09] (SEIKO EPSON CORPORATION)
4 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe" [135584 2011-12-09] (Futuremark Corporation)
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-21] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-21] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [113120 2012-06-06] (Mozilla Foundation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 QBCFMonitorService; "C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe" [45056 2012-03-14] (Intuit)
3 QBFCService; "C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe" [61440 2011-08-19] (Intuit Inc.)
2 QBVSS; "C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe" [1248256 2011-08-19] (Intuit Inc.)
2 VMUSBArbService; "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" [846448 2011-08-29] (VMware, Inc.)
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-10] ()
3 wampapache; "C:\wamp\bin\apache\apache2.2.21\bin\httpd.exe" -k runservice [21504 2011-09-26] (Apache Software Foundation)
3 wampmysqld; C:\wamp\bin\mysql\mysql5.5.20\bin\mysqld.exe wampmysqld [9690112 2012-01-25] ()
2 Apache2.2; "C:\xampp\apache\bin\httpd.exe" -k runservice [x]
2 mysql; C:\xampp\mysql\bin\mysqld.exe --defaults-file=C:\xampp\mysql\bin\my.ini mysql [x]
========================== Drivers (Whitelisted) =============
3 busenum; C:\Windows\System32\DRIVERS\SteelBus64.sys [106496 2012-01-20] (SteelSeries Corporation)
2 cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2011-09-21] (CPUID)
3 hitmanpro35; \??\C:\Windows\system32\drivers\hitmanpro36.sys [30496 2012-06-14] ()
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2011-09-16] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2011-09-16] (LogMeIn, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [34944 2012-01-20] (SteelSeries Corporation)
4 LMIRfsClientNP; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-15 00:17 - 2012-06-15 00:17 - 00000000 ____D C:\FRST
2012-06-14 23:03 - 2012-06-14 23:03 - 00136012 ____A C:\TDSSKiller.2.7.39.0_15.06.2012_00.03.56_log.txt
2012-06-14 23:03 - 2012-06-14 23:03 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\83023745.sys
2012-06-14 23:03 - 2012-06-14 07:12 - 02127448 ____A (Kaspersky Lab ZAO) C:\Users\Dragon\Desktop\TDSSKiller.exe
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 22:11 - 2012-06-14 22:11 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-14 22:10 - 2012-06-14 22:10 - 00000808 ____A C:\Windows\System32\.crusader
2012-06-14 22:06 - 2012-06-14 22:10 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-14 21:55 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-14 21:52 - 2012-06-14 21:52 - 00000361 ____A C:\rkill.log
2012-06-14 21:44 - 2012-06-14 22:48 - 01232802 ____A C:\Windows\ntbtlog.txt
2012-06-14 21:42 - 2012-06-14 21:42 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-14 21:38 - 2012-06-14 21:38 - 00000000 ____D C:\Users\All Users\99058D9B000415CB00038E50B4EB2331
2012-06-14 20:25 - 2012-06-14 20:25 - 00000000 __RHD C:\ESD
2012-06-14 17:47 - 2012-06-14 17:47 - 00000000 ____D C:\Users\Dragon\AppData\Local\Macromedia
2012-06-14 10:07 - 2012-06-14 20:53 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-14 08:59 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 08:59 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 08:59 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 08:59 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 08:59 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 08:59 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 08:59 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 08:59 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 08:59 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 08:59 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 08:59 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 08:59 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 08:59 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 08:59 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 08:59 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 08:59 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 08:59 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 08:59 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 08:59 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 08:59 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 08:59 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 08:59 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 08:59 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 08:59 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 08:59 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 08:59 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 08:59 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 08:59 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 15:58 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 15:58 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 15:58 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 15:58 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 15:58 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 15:58 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 15:58 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 15:58 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 15:58 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 15:58 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 15:58 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 15:58 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 15:58 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 15:58 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 15:58 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 15:58 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 15:58 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-08 14:55 - 2012-06-08 14:55 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Notepad++
2012-06-08 14:20 - 2012-06-08 14:20 - 00143766 ____A C:\Users\Guest\Downloads\Service Agreement - NY.pdf
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-03 17:57 - 2012-06-03 17:57 - 00000000 ____D C:\Windows\Microsoft Antimalware
2012-06-03 17:13 - 2012-06-03 17:13 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-06-03 17:12 - 2012-06-03 17:13 - 00137352 ____A C:\TDSSKiller.2.7.36.0_03.06.2012_18.12.55_log.txt
2012-05-29 11:36 - 2012-05-29 11:38 - 00001348 ____A C:\Windows\System32\Drivers\etc\hosts.umbrella
2012-05-29 11:36 - 2012-05-29 11:37 - 00000144 ____A C:\Users\Dragon\umbrella0.log
2012-05-29 11:36 - 2012-05-29 11:37 - 00000000 ____D C:\Users\Dragon\.shsh
2012-05-28 15:32 - 2012-05-28 15:32 - 00000000 ____D C:\Users\Dragon\AppData\Local\libimobiledevice
2012-05-20 20:55 - 2012-06-14 10:53 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-20 20:55 - 2012-05-20 20:55 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-20 10:14 - 2012-06-06 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Mozilla
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Local\Mozilla
2012-05-19 14:28 - 2012-06-06 22:09 - 00000000 ____D C:\Program Files (x86)\Diablo III
============ 3 Months Modified Files and Folders =============
2012-06-15 00:17 - 2012-06-15 00:17 - 00000000 ____D C:\FRST
2012-06-14 23:12 - 2012-04-10 10:58 - 00000000 ____D C:\Users\All Users\VMware
2012-06-14 23:12 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-14 23:12 - 2009-07-13 20:51 - 00040624 ____A C:\Windows\setupact.log
2012-06-14 23:04 - 2012-06-14 23:03 - 00136012 ____A C:\TDSSKiller.2.7.39.0_15.06.2012_00.03.56_log.txt
2012-06-14 23:04 - 2012-02-18 22:44 - 01696751 ____A C:\Windows\WindowsUpdate.log
2012-06-14 23:03 - 2012-06-14 23:03 - 00116016 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\83023745.sys
2012-06-14 23:03 - 2012-02-25 17:46 - 00000000 ___HD C:\jexepackres
2012-06-14 23:03 - 2012-02-20 23:20 - 00015342 ____A C:\test.log
2012-06-14 23:03 - 2012-02-19 18:02 - 00000000 ____D C:\Users\Dragon\AppData\Local\sabnzbd
2012-06-14 23:03 - 2012-02-19 01:56 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Dropbox
2012-06-14 23:03 - 2012-02-19 01:56 - 00000000 ____D C:\Users\Dragon\AppData\Local\Spotify
2012-06-14 23:01 - 2012-02-25 17:50 - 00000000 ____D C:\Users\All Users\LogMeIn
2012-06-14 22:48 - 2012-06-14 21:44 - 01232802 ____A C:\Windows\ntbtlog.txt
2012-06-14 22:18 - 2009-07-13 20:45 - 00020528 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-14 22:18 - 2009-07-13 20:45 - 00020528 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-14 22:17 - 2009-07-13 21:13 - 00807822 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-14 22:16 - 2012-06-14 22:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-14 22:16 - 2012-02-19 01:57 - 00821480 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-14 22:16 - 2012-02-19 01:57 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-14 22:16 - 2012-02-19 01:56 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Spotify
2012-06-14 22:11 - 2012-06-14 22:11 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-06-14 22:11 - 2012-02-19 01:56 - 00000000 ____D C:\Program Files (x86)\Trillian
2012-06-14 22:10 - 2012-06-14 22:10 - 00000808 ____A C:\Windows\System32\.crusader
2012-06-14 22:10 - 2012-06-14 22:06 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-14 22:10 - 2012-02-19 18:01 - 00000000 ____D C:\Program Files (x86)\SABnzbd
2012-06-14 22:10 - 2012-02-19 01:55 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2229342774-3388454487-1059482264-1000UA.job
2012-06-14 22:10 - 2012-02-19 00:47 - 00000000 __SHD C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}
2012-06-14 22:06 - 2010-11-20 19:47 - 00012374 ____A C:\Windows\PFRO.log
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-14 21:55 - 2012-06-14 21:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-14 21:52 - 2012-06-14 21:52 - 00000361 ____A C:\rkill.log
2012-06-14 21:46 - 2009-07-13 20:45 - 04997552 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 21:42 - 2012-06-14 21:42 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-14 21:38 - 2012-06-14 21:38 - 00000000 ____D C:\Users\All Users\99058D9B000415CB00038E50B4EB2331
2012-06-14 21:09 - 2012-02-19 15:39 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\vlc
2012-06-14 21:05 - 2012-04-20 07:25 - 00005632 ____A C:\Users\Dragon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-14 20:56 - 2012-02-19 19:01 - 00000000 ____D C:\Users\Dragon\AppData\Local\4673A125-DF05-4C80-B515-4F7AD151636E.aplzod
2012-06-14 20:53 - 2012-06-14 10:07 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-14 20:25 - 2012-06-14 20:25 - 00000000 __RHD C:\ESD
2012-06-14 17:47 - 2012-06-14 17:47 - 00000000 ____D C:\Users\Dragon\AppData\Local\Macromedia
2012-06-14 10:53 - 2012-05-20 20:55 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-14 10:53 - 2012-03-12 20:10 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-14 10:06 - 2012-02-19 01:55 - 00000000 ____D C:\Program Files (x86)\uTorrent
2012-06-14 10:03 - 2012-02-19 10:22 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Skype
2012-06-14 09:03 - 2012-02-19 11:22 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-14 09:02 - 2012-02-19 00:47 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-14 07:12 - 2012-06-14 23:03 - 02127448 ____A (Kaspersky Lab ZAO) C:\Users\Dragon\Desktop\TDSSKiller.exe
2012-06-14 05:01 - 2012-03-16 23:47 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{495C90479FCE17D0BAAA76C781C684B9}.job
2012-06-14 05:00 - 2012-05-02 09:17 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{43EF9D144C5BCAA06DB442334766A4A1}.job
2012-06-14 04:00 - 2012-03-16 23:47 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{45E5C387E307B1C3881AD4D30DB2B796}.job
2012-06-14 03:00 - 2012-03-16 23:46 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{47D430BC3C7BF20BA4CF6D65DE5E76A6}.job
2012-06-14 02:00 - 2012-03-16 23:46 - 00000374 ____A C:\Windows\Tasks\Allway Sync_{4F0C1497E9A5A062AD06B978802E02AB}.job
2012-06-14 01:10 - 2012-02-19 01:55 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2229342774-3388454487-1059482264-1000Core.job
2012-06-10 02:40 - 2012-02-19 00:40 - 00000458 ____A C:\Windows\Tasks\Intel_C_CVCV15340AN7120BGN.job
2012-06-09 14:20 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-06-08 14:55 - 2012-06-08 14:55 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Notepad++
2012-06-08 14:20 - 2012-06-08 14:20 - 00143766 ____A C:\Users\Guest\Downloads\Service Agreement - NY.pdf
2012-06-08 14:19 - 2012-03-03 11:01 - 00114776 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-07 07:48 - 2009-07-13 19:20 - 00000000 ___HD C:\Windows\System32\GroupPolicy
2012-06-07 07:28 - 2012-02-19 01:55 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\uTorrent
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-06 22:54 - 2012-06-06 22:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-06 22:54 - 2012-05-20 10:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-06 22:09 - 2012-05-19 14:28 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-06-03 17:57 - 2012-06-03 17:57 - 00000000 ____D C:\Windows\Microsoft Antimalware
2012-06-03 17:13 - 2012-06-03 17:13 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-06-03 17:13 - 2012-06-03 17:12 - 00137352 ____A C:\TDSSKiller.2.7.36.0_03.06.2012_18.12.55_log.txt
2012-06-03 00:00 - 2012-02-25 16:27 - 00000000 ____D C:\Users\Dragon\AppData\Local\ElevatedDiagnostics
2012-06-02 19:02 - 2012-04-06 23:55 - 00000000 ____D C:\Users\All Users\Sonos,_Inc
2012-06-02 18:39 - 2012-02-19 12:27 - 00000000 ____D C:\Users\Dragon\AppData\Local\Futuremark_Corporation
2012-06-01 16:31 - 2012-02-18 22:42 - 00000000 ____D C:\users\Dragon
2012-06-01 07:00 - 2012-03-03 09:49 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\HandBrake
2012-05-31 20:53 - 2012-02-19 00:34 - 00114776 ____A C:\Users\Dragon\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-31 20:33 - 2012-04-10 11:01 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\VMware
2012-05-29 18:07 - 2012-04-10 11:01 - 00000000 ____D C:\Users\Dragon\AppData\Local\VMware
2012-05-29 11:38 - 2012-05-29 11:36 - 00001348 ____A C:\Windows\System32\Drivers\etc\hosts.umbrella
2012-05-29 11:38 - 2009-07-13 18:34 - 00001348 ____A C:\Windows\System32\Drivers\etc\hosts
2012-05-29 11:37 - 2012-05-29 11:36 - 00000144 ____A C:\Users\Dragon\umbrella0.log
2012-05-29 11:37 - 2012-05-29 11:36 - 00000000 ____D C:\Users\Dragon\.shsh
2012-05-28 15:32 - 2012-05-28 15:32 - 00000000 ____D C:\Users\Dragon\AppData\Local\libimobiledevice
2012-05-24 21:18 - 2012-03-12 08:46 - 00007609 ____A C:\Users\Dragon\AppData\Local\Resmon.ResmonCfg
2012-05-21 17:52 - 2012-02-25 17:50 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-05-21 17:52 - 2012-02-25 17:50 - 00080768 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-05-21 17:52 - 2012-02-25 17:50 - 00034688 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-05-21 17:52 - 2012-02-25 17:50 - 00000000 ____D C:\Program Files (x86)\LogMeIn
2012-05-20 20:55 - 2012-05-20 20:55 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-20 10:19 - 2012-02-18 22:42 - 00000000 ____D C:\Users\Dragon\AppData\LocalLow
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Mozilla
2012-05-20 10:14 - 2012-05-20 10:14 - 00000000 ____D C:\Users\Dragon\AppData\Local\Mozilla
2012-05-17 22:54 - 2012-05-01 08:22 - 00000000 ____D C:\Users\All Users\webex
2012-05-17 18:47 - 2012-06-14 08:59 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 08:59 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 08:59 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 08:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 08:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 08:59 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 08:59 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 08:59 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 08:59 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 08:59 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 08:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 08:59 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 08:59 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 08:59 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 08:59 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 08:59 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 08:59 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 08:59 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 08:59 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 08:59 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 08:59 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 08:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 08:59 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 08:59 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 08:59 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 08:59 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 08:59 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 08:59 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-16 12:07 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports
2012-05-14 17:32 - 2012-06-13 15:58 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 10:28 - 2012-02-28 14:03 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\FileZilla
2012-05-11 10:24 - 2012-05-11 10:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-11 10:24 - 2012-05-11 10:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 10:24 - 2010-11-20 23:17 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-08 22:35 - 2012-05-08 21:42 - 00000600 ____A C:\Users\Dragon\AppData\Roaming\PUTTY.RND
2012-05-08 22:35 - 2012-05-07 18:26 - 00000600 ____A C:\Users\Dragon\AppData\Local\PUTTY.RND
2012-05-08 18:19 - 2012-05-08 09:37 - 00000000 ____D C:\Users\Dragon\ZipForm
2012-05-08 09:37 - 2012-05-08 09:37 - 00000088 ____A C:\Users\Dragon\.java.policy
2012-05-06 21:03 - 2012-05-06 21:03 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\MindTerm
2012-05-04 03:06 - 2012-06-13 15:58 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 15:58 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 15:58 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 10:24 - 2012-03-12 14:37 - 00191824 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-05-03 10:23 - 2012-05-03 10:23 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-05-03 10:20 - 2012-02-19 19:01 - 00000000 ____D C:\Users\Dragon\AppData\Local\Adobe
2012-05-03 10:20 - 2012-02-19 02:01 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Adobe
2012-05-02 08:56 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-05-01 16:46 - 2012-05-01 16:46 - 04472832 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2012-04-30 21:40 - 2012-06-13 15:58 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 11:01 - 2012-03-23 17:24 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Epson
2012-04-27 19:55 - 2012-06-13 15:58 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 21:35 - 2012-04-26 19:38 - 00244174 ____A C:\Users\Guest\Documents\Tax Outline 2012.2.0.docx
2012-04-26 19:47 - 2012-04-26 18:45 - 00284312 ____A C:\Users\Guest\Desktop\TAXATION OF BUSINESS ENTERPRISES outline 3.docx
2012-04-25 21:41 - 2012-06-13 15:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 15:58 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 15:58 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Users\Dragon\AppData\Local\Brice_Lambson
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Users\All Users\Package Cache
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Program Files\Image Resizer for Windows
2012-04-25 12:20 - 2012-04-25 12:20 - 00000000 ____D C:\Program Files (x86)\Image Resizer for Windows
2012-04-24 09:53 - 2012-04-23 19:44 - 00000000 ____D C:\Program Files (x86)\Diablo III Beta
2012-04-23 21:37 - 2012-06-13 15:58 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 15:58 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 15:58 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 15:58 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 15:58 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 15:58 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 19:41 - 2012-04-23 19:41 - 00000000 ____D C:\Users\All Users\Battle.net
2012-04-17 21:42 - 2012-03-03 11:01 - 00000000 ____D C:\Users\Guest\Documents\StarCraft II
2012-04-17 13:38 - 2012-04-17 13:38 - 00000442 ___AH C:\Windows\Tasks\Fortus Capital, LLC 1334698711.job
2012-04-17 10:38 - 2012-02-20 23:20 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\SteelSeries
2012-04-17 10:37 - 2012-02-20 23:20 - 00000000 ____D C:\Users\All Users\SteelSeries
2012-04-17 10:36 - 2012-02-20 23:20 - 00000000 ____D C:\Program Files\SteelSeries
2012-04-16 14:57 - 2012-04-16 14:57 - 00000000 ____D C:\Users\Guest\AppData\Local\Apple Computer
2012-04-16 14:57 - 2012-03-03 11:01 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Apple Computer
2012-04-15 13:03 - 2012-04-14 14:05 - 00000090 ____A C:\Windows\QBChanUtil_Trigger.ini
2012-04-15 12:29 - 2012-04-15 12:29 - 00288152 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-04-15 12:29 - 2012-04-15 12:29 - 00281774 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-04-15 12:08 - 2012-04-15 12:08 - 00000000 ____D C:\Users\Guest\AppData\Local\Intuit
2012-04-15 12:08 - 2012-03-27 11:57 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Adobe
2012-04-14 15:55 - 2012-04-14 14:06 - 00000000 ____D C:\Users\Dragon\AppData\Local\Intuit
2012-04-14 15:54 - 2012-04-14 14:05 - 00000000 ____D C:\Users\All Users\Intuit
2012-04-14 14:10 - 2012-04-14 14:10 - 00000000 ____D C:\Program Files\Common Files\Intuit
2012-04-14 14:09 - 2012-04-14 14:05 - 00000000 ____D C:\Users\All Users\SQL Anywhere 11
2012-04-14 14:08 - 2012-04-14 14:05 - 00000000 ____D C:\Program Files (x86)\Intuit
2012-04-14 14:05 - 2012-04-14 14:05 - 00000000 ____D C:\Users\Public\Documents\Intuit
2012-04-14 14:05 - 2012-04-14 14:05 - 00000000 ____D C:\Users\All Users\Nuance
2012-04-14 14:04 - 2012-04-14 14:04 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2012-04-14 14:03 - 2012-04-14 14:03 - 00000000 ____D C:\Windows\Intuit
2012-04-11 09:08 - 2012-04-04 09:17 - 00000000 ____D C:\Sites
2012-04-11 08:54 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-04-10 13:19 - 2012-04-10 13:19 - 00000000 ____D C:\Program Files\Common Files\VMware
2012-04-10 13:19 - 2012-04-10 10:58 - 00000000 ____D C:\Program Files (x86)\VMware
2012-04-10 11:54 - 2012-04-08 19:09 - 00000000 ____D C:\Program Files (x86)\hpmonitor
2012-04-10 10:58 - 2012-04-10 10:58 - 00000000 ____D C:\Users\Public\Documents\Shared Virtual Machines
2012-04-10 10:58 - 2012-02-25 17:50 - 00001024 ____A C:\.rnd
2012-04-08 19:09 - 2012-04-08 19:09 - 00000000 ____D C:\Program Files\MediaInfo
2012-04-08 14:02 - 2012-04-03 09:47 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\1UPIndustries
2012-04-08 14:02 - 2012-04-03 09:47 - 00000000 ____D C:\Users\All Users\1UPIndustries
2012-04-07 07:42 - 2012-04-07 07:42 - 00000000 ____D C:\Users\Dragon\AppData\Local\Sonos,_Inc
2012-04-07 04:31 - 2012-06-13 15:58 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 15:58 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-06 23:55 - 2012-04-06 23:55 - 00000000 ____D C:\Users\Dragon\AppData\Local\Downloaded Installations
2012-04-06 23:55 - 2012-04-06 23:55 - 00000000 ____D C:\Program Files (x86)\Sonos
2012-04-06 09:49 - 2012-04-06 09:49 - 00000000 ____D C:\Program Files\iTunes
2012-04-06 09:49 - 2012-04-06 09:49 - 00000000 ____D C:\Program Files\iPod
2012-04-06 09:49 - 2012-04-06 09:49 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-04-05 09:33 - 2012-04-05 09:28 - 00000000 ____D C:\Users\Dragon\.jedit
2012-04-04 17:10 - 2012-04-04 17:10 - 00000065 ____A C:\Users\Dragon\.gitconfig
2012-04-04 17:04 - 2012-04-04 09:18 - 00000000 ____D C:\Users\Dragon\.ssh
2012-04-04 14:56 - 2012-06-14 21:55 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-04 09:21 - 2012-04-04 09:21 - 00000000 ____D C:\Users\Dragon\.gem
2012-04-04 09:17 - 2012-04-04 09:17 - 00000000 ____D C:\RailsInstaller
2012-04-03 09:47 - 2012-04-03 09:47 - 00000000 ____D C:\Program Files\1UPIndustries
2012-04-01 18:54 - 2012-04-01 18:54 - 00000000 ____D C:\Users\All Users\Freemake
2012-04-01 18:54 - 2012-04-01 18:54 - 00000000 ____D C:\Program Files (x86)\Freemake
2012-03-30 03:35 - 2012-05-08 19:33 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-27 23:37 - 2012-03-27 23:37 - 00000000 ____D C:\Users\All Users\ATI
2012-03-27 23:24 - 2012-03-27 23:23 - 00000000 ____D C:\Program Files\ATI Technologies
2012-03-27 23:23 - 2012-03-27 23:23 - 00000000 ____D C:\Program Files\ATI
2012-03-27 12:40 - 2012-03-27 12:40 - 00000000 ____D C:\Users\Guest\AppData\Local\Adobe
2012-03-27 11:57 - 2012-03-03 11:01 - 00000000 ____D C:\Users\Guest\AppData\LocalLow
2012-03-27 11:56 - 2012-03-27 11:56 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Epson
2012-03-26 20:11 - 2012-02-25 16:45 - 00000000 ____D C:\Program Files\CrashPlan
2012-03-25 22:58 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-03-25 18:31 - 2012-02-21 10:35 - 00000000 ____D C:\Program Files (x86)\Brother
2012-03-25 18:30 - 2012-03-25 18:30 - 00000000 ____A C:\Windows\EEventManager.INI
2012-03-25 18:25 - 2012-03-23 17:23 - 00000000 ____D C:\Users\All Users\EPSON
2012-03-24 19:32 - 2012-02-21 10:42 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-03-23 17:34 - 2012-03-23 17:22 - 00000106 ____A C:\Windows\EP4540.ini
2012-03-23 17:32 - 2012-03-23 17:32 - 00000000 ____D C:\Users\Dragon\AppData\Roaming\Leadertech
2012-03-23 17:32 - 2012-03-23 17:23 - 00000000 ____D C:\Program Files (x86)\Epson Software
2012-03-23 17:31 - 2012-03-23 17:31 - 00000000 ____D C:\Program Files\Common Files\EPSON
2012-03-23 17:24 - 2012-03-23 17:24 - 00000000 ____D C:\Program Files\EpsonNet
2012-03-23 17:24 - 2012-03-23 17:24 - 00000000 ____D C:\Program Files\EPSON
2012-03-23 17:24 - 2012-02-19 00:33 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-03-23 17:23 - 2012-03-23 17:23 - 00000000 ____D C:\Program Files (x86)\Epson America Inc
2012-03-23 17:23 - 2012-03-23 17:23 - 00000000 ____D C:\Program Files (x86)\epson
2012-03-23 09:04 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-03-22 20:14 - 2012-02-19 01:55 - 00000000 ____D C:\Users\Dragon\AppData\Local\Google
2012-03-21 23:38 - 2012-03-21 23:38 - 00000000 ____D C:\Users\All Users\Synology
2012-03-20 19:44 - 2012-03-20 19:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 19:44 - 2012-03-20 19:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
ZeroAccess:
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\@
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\L
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\n
C:\Windows\Installer\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\U
ZeroAccess:
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\@
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\L
C:\Users\Dragon\AppData\Local\{b58b6628-02d0-6b52-8c97-2b4e1b53b3a4}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16360.86 MB
Available physical RAM: 15213.17 MB
Total Pagefile: 16359.06 MB
Available Pagefile: 15219.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.69 GB) (Free:9.04 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (WDO_Media64) (Removable) (Total:3.92 GB) (Free:3.63 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (Emperor) (Fixed) (Total:2794.52 GB) (Free:1246.9 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 2794 GB 0 B *
Disk 1 Online 111 GB 0 B
Disk 2 Online 4014 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 2794 GB 1024 KB
======================================================================================================
Disk: 0
Partition 1
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y Emperor NTFS Partition 2794 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 111 GB 101 MB
======================================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 111 GB Healthy
======================================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 4013 MB 32 KB
======================================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G WDO_Media64 NTFS Removable 4013 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-07 23:37
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 14-06-2012
Ran by SYSTEM at 2012-06-15 00:18:26
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======