datanomics
Posts: 17 +0
Greetings. Great forum. Great work. I, like many others here, have been infected by sirefef variant. MSE warnings appear, on-screen keyboard keeps appearing, desktop background keeps changing, and system restarts after 1 minute. I had run Norton Power Eraser before finding this forum. I have downloaded and run Farbar. Results below. Machine is Windows Vista Ultimate on an HP laptop with Centrino 2.
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
Run Scan in Farbar Recovery Scan Tool:
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Scan result of Farbar Recovery Scan Tool Version: 13-08-2012
Ran by SYSTEM at 13-08-2012 18:02:56
Running from F:\
Windows Vista (TM) Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [912688 2008-09-23] (Hewlett-Packard)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [16395880 2009-10-03] (NVIDIA Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-21] (IDT, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [1148200 2008-09-26] (CyberLink Corp.)
HKLM-x32\...\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [1152296 2008-09-25] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [189736 2008-09-25] (CyberLink)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2008-09-26] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-06-16] (Hewlett-Packard)
HKLM-x32\...\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2008-04-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Acrobat Assistant 7.0] "C:\Program Files General\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [483328 2008-04-22] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" [206120 2009-04-22] (CyberLink Corp.)
HKLM-x32\...\Run: [hpqSRMon] [x]
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-03-08] (RealNetworks, Inc.)
HKLM-x32\...\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~1\SEARCH~1\DATAMN~1.EXE [1700752 2011-09-27] (Bandoo Media, inc)
HKLM-x32\...\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2012-03-27] (LG Electronics)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1107552 2012-08-13] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iBryte browseforchange Desktop] "C:\Program Files (x86)\iBryte\browseforchange\ibrytedesktop.exe" [163840 2012-04-06] (iBryte)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Girls\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Girls\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Logan\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Logan\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Logan\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Logan\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2012-02-03] (Valve Corporation)
HKU\Tim\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Tim\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.152
AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
3 Adobe LM Service; "C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" [72704 2009-03-05] (Adobe Systems)
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
2 Autodesk Content Service; "C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe" [18656 2011-02-02] ()
3 GameConsoleService; "C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe" [246520 2010-09-30] (WildTangent, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MSSQL$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [57617752 2009-03-30] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NSL; "C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe" /s "NSL" /m "C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\diMaster.dll" /prefetch:1 [262584 2010-12-02] (Symantec Corporation)
2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365904 2008-09-23] ()
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [241734 2008-06-29] ()
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
4 SQLAgent$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -I SQLEXPRESS [427880 2009-03-30] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe [240128 2009-07-21] (IDT, Inc.)
2 TVCapSvc; "C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe" [296320 2009-04-22] ()
2 TVSched; "C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe" [116104 2009-04-22] ()
2 Updater Service for StartNow Toolbar; C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [265952 2012-04-20] ()
2 vToolbarUpdater10.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [918880 2012-03-12] ()
========================== Drivers (Whitelisted) =============
3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2010-12-07] (LG Electronics Inc.)
3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2010-12-07] (LG Electronics Inc.)
3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2010-12-07] (LG Electronics Inc.)
3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [34304 2010-12-07] (LG Electronics Inc.)
3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-05] (LG Electronics Inc.)
3 AndNetGps; C:\Windows\System32\DRIVERS\lgandnetgps64.sys [28160 2011-09-05] (LG Electronics Inc.)
3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-05] (LG Electronics Inc.)
3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [103936 2011-09-16] (LG Electronics Inc.)
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
3 HPFXBULK; C:\Windows\System32\drivers\hpfx64bulk.sys [20504 2007-07-16] (Hewlett Packard)
3 HPFXFAX; C:\Windows\System32\drivers\hpfx64fax.sys [23064 2007-07-16] (Hewlett Packard)
0 SMR300; C:\Windows\System32\Drivers\SMR300.sys [96376 2012-07-05] (Symantec Corporation)
2 {55662437-DA8C-40c0-AADA-2C816A897A49}; \??\C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [27632 2008-09-26] (Cyberlink Corp.)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 18:02 - 2012-08-13 18:02 - 00000000 ____D C:\FRST
2012-08-13 13:41 - 2012-08-13 13:41 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eawvdpvr.sys
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\SMRBackup300.dat
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\Application Data\SMRBackup300.dat
============ 3 Months Modified Files ========================
2012-08-13 13:41 - 2012-08-13 13:41 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eawvdpvr.sys
2012-08-13 13:34 - 2009-03-04 10:36 - 00782692 ____A C:\Windows\System32\perfh00A.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00769452 ____A C:\Windows\System32\prfh0816.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00735832 ____A C:\Windows\System32\perfh007.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00721250 ____A C:\Windows\System32\perfh00E.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00709292 ____A C:\Windows\System32\perfh005.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00472762 ____A C:\Windows\System32\perfh011.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00191638 ____A C:\Windows\System32\perfc00E.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00177726 ____A C:\Windows\System32\perfc00A.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00172870 ____A C:\Windows\System32\prfc0816.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00169284 ____A C:\Windows\System32\perfc007.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00161344 ____A C:\Windows\System32\perfc005.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00143908 ____A C:\Windows\System32\perfc011.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00784614 ____A C:\Windows\System32\perfh00C.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00783426 ____A C:\Windows\System32\perfh013.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00778846 ____A C:\Windows\System32\perfh015.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00777976 ____A C:\Windows\System32\perfh010.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00767542 ____A C:\Windows\System32\perfh019.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00753282 ____A C:\Windows\System32\prfh0416.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00708730 ____A C:\Windows\System32\perfh01D.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00701592 ____A C:\Windows\System32\perfh01F.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00674682 ____A C:\Windows\System32\perfh008.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00575976 ____A C:\Windows\System32\perfh006.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00563314 ____A C:\Windows\System32\perfh014.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00548616 ____A C:\Windows\System32\perfh00B.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00547900 ____A C:\Windows\System32\perfh001.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00486124 ____A C:\Windows\System32\perfh012.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00461696 ____A C:\Windows\System32\perfh00D.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00455538 ____A C:\Windows\System32\prfh0404.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00445840 ____A C:\Windows\System32\prfh0804.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00175192 ____A C:\Windows\System32\perfc015.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00173604 ____A C:\Windows\System32\perfc013.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00171290 ____A C:\Windows\System32\perfc019.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00169230 ____A C:\Windows\System32\perfc00C.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00167254 ____A C:\Windows\System32\prfc0416.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00166564 ____A C:\Windows\System32\perfc010.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00163154 ____A C:\Windows\System32\perfc01D.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00160940 ____A C:\Windows\System32\perfc01F.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00143746 ____A C:\Windows\System32\prfc0404.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00143740 ____A C:\Windows\System32\prfc0804.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00143676 ____A C:\Windows\System32\perfc012.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00137506 ____A C:\Windows\System32\perfc008.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00127186 ____A C:\Windows\System32\perfc00B.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00122984 ____A C:\Windows\System32\perfc006.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00121702 ____A C:\Windows\System32\perfc014.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00121056 ____A C:\Windows\System32\perfc001.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00111252 ____A C:\Windows\System32\perfc00D.dat
2012-08-13 13:34 - 2006-11-02 04:46 - 19228470 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-13 13:26 - 2011-12-25 22:10 - 00002413 ____A C:\Windows\SysWOW64\lgAxconfig.ini
2012-08-13 13:24 - 2012-06-09 17:19 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-13 13:23 - 2009-03-10 14:38 - 00095193 ____A C:\Users\All Users\nvModes.001
2012-08-13 13:23 - 2009-03-10 14:38 - 00095193 ____A C:\Users\All Users\Application Data\nvModes.001
2012-08-13 13:22 - 2011-06-30 10:26 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-13 13:22 - 2009-03-10 14:16 - 00095193 ____A C:\Users\All Users\nvModes.dat
2012-08-13 13:22 - 2009-03-10 14:16 - 00095193 ____A C:\Users\All Users\Application Data\nvModes.dat
2012-08-13 13:21 - 2006-11-02 07:40 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 13:21 - 2006-11-02 07:21 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-13 13:21 - 2006-11-02 07:21 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-13 06:36 - 2006-11-02 04:33 - 26476544 ____A C:\Windows\System32\config\system_previous
2012-08-13 06:36 - 2006-11-02 04:33 - 159645696 ____A C:\Windows\System32\config\software_previous
2012-08-13 06:25 - 2006-11-02 04:33 - 294649856 ____A C:\Windows\System32\config\components_previous
2012-08-13 06:25 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\SMRBackup300.dat
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\Application Data\SMRBackup300.dat
2012-08-13 02:46 - 2012-07-05 05:19 - 00182062 ____A C:\Windows\ntbtlog.txt.bak
2012-08-13 02:46 - 2009-02-24 01:54 - 01951144 ____A C:\Windows\WindowsUpdate.log
2012-07-05 08:43 - 2006-11-02 04:33 - 06815744 ____A C:\Windows\System32\config\default_previous
2012-07-05 08:43 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-07-05 06:10 - 2011-06-30 10:26 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 05:53 - 2012-07-05 05:52 - 00050000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nvlhsiap.sys
2012-07-05 05:52 - 2012-07-05 05:52 - 00050000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vnducexs.sys
2012-07-05 05:37 - 2008-10-16 08:35 - 00001076 ____A C:\Windows\bthservsdp.dat
2012-07-05 05:37 - 2006-11-02 07:40 - 00032534 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-05 05:10 - 2012-07-05 08:13 - 00096376 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR300.SYS
2012-07-05 05:08 - 2012-07-05 05:08 - 02841104 ____A (Symantec Corporation) C:\Users\Logan\Downloads\NPE.exe
2012-07-03 08:44 - 2011-06-25 12:10 - 00007808 ____A C:\Users\Logan\Local Settings\d3d9caps.dat
2012-07-03 08:44 - 2011-06-25 12:10 - 00007808 ____A C:\Users\Logan\Local Settings\Application Data\d3d9caps.dat
2012-07-03 08:44 - 2011-06-25 12:10 - 00007808 ____A C:\Users\Logan\AppData\Local\d3d9caps.dat
2012-07-03 08:43 - 2012-06-09 17:19 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-03 08:43 - 2011-08-28 10:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-03 06:09 - 2006-11-02 07:39 - 01549094 ____A C:\Windows\PFRO.log
2012-07-03 06:04 - 2012-07-03 06:04 - 00000519 ____A C:\Windows\wininit.ini
2012-06-23 17:02 - 2012-06-23 17:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tmdgwfrv.sys
2012-06-23 16:47 - 2012-06-23 16:47 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\qnokossx.sys
2012-06-23 16:46 - 2012-06-23 16:46 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bckrjbrm.sys
2012-06-18 10:33 - 2012-06-18 10:35 - 00772592 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-06-18 10:33 - 2012-06-18 10:35 - 00227824 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-06-18 10:33 - 2012-06-18 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-18 10:33 - 2012-06-18 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-18 10:33 - 2010-05-06 09:59 - 00687600 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-06-18 06:21 - 2012-06-09 19:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-18 06:09 - 2011-07-11 13:10 - 19597586 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-18 05:40 - 2012-06-18 05:40 - 12621696 ____A (Microsoft Corporation) C:\Users\Logan\Downloads\mseinstall.exe
2012-06-15 16:30 - 2009-07-31 16:04 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-15 16:22 - 2012-06-15 16:22 - 00152136 ____A C:\Users\Logan\Downloads\o
2012-06-15 16:22 - 2012-06-15 16:22 - 00152072 ____A C:\Users\Logan\Downloads\search
2012-06-14 04:27 - 2012-06-14 04:27 - 00155176 ____A C:\Users\Girls\Local Settings\GDIPFONTCACHEV1.DAT
2012-06-14 04:27 - 2012-06-14 04:27 - 00155176 ____A C:\Users\Girls\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2012-06-14 04:27 - 2012-06-14 04:27 - 00155176 ____A C:\Users\Girls\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-14 04:26 - 2012-06-14 04:26 - 00000020 __ASH C:\Users\Girls\ntuser.ini
2012-06-13 23:58 - 2006-11-02 07:21 - 00534288 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 23:17 - 2006-11-02 04:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-10 17:35 - 2006-11-02 07:26 - 00138737 ____A C:\Windows\setupact.log
2012-06-10 04:44 - 2011-06-23 08:41 - 00012788 ____A C:\Windows\IE9_main.log
2012-06-10 04:42 - 2012-06-10 04:39 - 38229856 ____A (Microsoft Corporation) C:\Users\Logan\Downloads\BOIE9_ENUS_BO0084_VIS64.EXE
2012-06-09 06:05 - 2011-09-16 01:41 - 00020992 ____A C:\Users\Logan\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-09 06:05 - 2011-09-16 01:41 - 00020992 ____A C:\Users\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-09 06:05 - 2011-09-16 01:41 - 00020992 ____A C:\Users\Logan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-02 14:19 - 2012-07-03 09:04 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-07-03 09:04 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-07-03 09:04 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-07-03 09:04 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-07-03 09:01 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-07-03 09:01 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 11:19 - 2012-07-03 09:01 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:19 - 2012-07-03 09:01 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 11:15 - 2012-07-03 09:01 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 11:12 - 2012-07-03 09:01 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-05-29 19:02 - 2012-05-29 19:02 - 00290784 ____A C:\Windows\Minidump\Mini052912-01.dmp
2012-05-29 19:02 - 2011-09-08 17:44 - 622086487 ____A C:\Windows\MEMORY.DMP
2012-05-26 18:51 - 2012-03-13 22:09 - 00000888 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-26 18:51 - 2012-03-13 22:09 - 00000888 ____A C:\Users\All Users\Desktop\Mozilla Firefox.lnk
2012-05-17 18:47 - 2012-06-13 23:29 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 23:29 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 23:29 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 23:29 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 23:29 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 23:29 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 23:29 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 23:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 23:29 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 23:29 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 23:29 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 23:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 23:29 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 23:29 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 23:29 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 23:29 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 23:29 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 23:29 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 23:29 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 23:29 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 23:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 23:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 23:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 23:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 23:29 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 23:29 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 23:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 23:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
ZeroAccess:
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\00000004.@
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\1afb2d56
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\201d3dde
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\55490ac4
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe B8844F93D2C5F1DCDB179AAA9AF134B7 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 4093.02 MB
Available physical RAM: 3319.57 MB
Total Pagefile: 3768.22 MB
Available Pagefile: 3303.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:284.08 GB) (Free:106.48 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:14.01 GB) (Free:2.13 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive f: (KINGSTON) (Removable) (Total:7.45 GB) (Free:1.36 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 7644 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 284 GB 32 KB
Partition 2 Primary 14 GB 284 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 284 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7644 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 7644 MB Healthy
==================================================================================
Last Boot: 2012-07-05 08:37
======================= End Of Log ==========================
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
Run Search File(s) for "services.exe" in Farbar Recovery Scan Tool:
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Farbar Recovery Scan Tool Version: 13-08-2012
Ran by SYSTEM at 2012-08-13 18:04:57
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009-08-19 04:35] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-01-20 18:49] - [2008-01-20 18:49] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2009-08-19 04:36] - [2009-04-10 23:10] - 0384512 ____A (Microsoft Corporation) 934E0B7D77FF78C18D9F8891221B6DE3
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe
[2008-01-20 18:48] - [2008-01-20 18:48] - 0384512 ____A (Microsoft Corporation) DFAC660F0F139276CC9299812DE42719
C:\Windows\SysWOW64\services.exe
[2009-08-19 04:35] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\System32\services.exe
[2009-08-19 04:36] - [2009-04-10 23:10] - 0381952 ____A (Microsoft Corporation) B8844F93D2C5F1DCDB179AAA9AF134B7
====== End Of Search ======
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
Run Scan in Farbar Recovery Scan Tool:
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Scan result of Farbar Recovery Scan Tool Version: 13-08-2012
Ran by SYSTEM at 13-08-2012 18:02:56
Running from F:\
Windows Vista (TM) Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [912688 2008-09-23] (Hewlett-Packard)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [16395880 2009-10-03] (NVIDIA Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-21] (IDT, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [1148200 2008-09-26] (CyberLink Corp.)
HKLM-x32\...\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [1152296 2008-09-25] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [189736 2008-09-25] (CyberLink)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2008-09-26] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-06-16] (Hewlett-Packard)
HKLM-x32\...\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2008-04-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Acrobat Assistant 7.0] "C:\Program Files General\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [483328 2008-04-22] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" [206120 2009-04-22] (CyberLink Corp.)
HKLM-x32\...\Run: [hpqSRMon] [x]
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [202256 2010-03-08] (RealNetworks, Inc.)
HKLM-x32\...\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~1\SEARCH~1\DATAMN~1.EXE [1700752 2011-09-27] (Bandoo Media, inc)
HKLM-x32\...\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2012-03-27] (LG Electronics)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1107552 2012-08-13] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iBryte browseforchange Desktop] "C:\Program Files (x86)\iBryte\browseforchange\ibrytedesktop.exe" [163840 2012-04-06] (iBryte)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Girls\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Girls\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Logan\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [972080 2008-09-30] (Hewlett-Packard)
HKU\Logan\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Logan\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Logan\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2012-02-03] (Valve Corporation)
HKU\Tim\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Tim\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.152
AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
3 Adobe LM Service; "C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" [72704 2009-03-05] (Adobe Systems)
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
2 Autodesk Content Service; "C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe" [18656 2011-02-02] ()
3 GameConsoleService; "C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe" [246520 2010-09-30] (WildTangent, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MSSQL$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [57617752 2009-03-30] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NSL; "C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe" /s "NSL" /m "C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\diMaster.dll" /prefetch:1 [262584 2010-12-02] (Symantec Corporation)
2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365904 2008-09-23] ()
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [241734 2008-06-29] ()
2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
4 SQLAgent$SQLEXPRESS; "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -I SQLEXPRESS [427880 2009-03-30] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe [240128 2009-07-21] (IDT, Inc.)
2 TVCapSvc; "C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe" [296320 2009-04-22] ()
2 TVSched; "C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe" [116104 2009-04-22] ()
2 Updater Service for StartNow Toolbar; C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [265952 2012-04-20] ()
2 vToolbarUpdater10.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [918880 2012-03-12] ()
========================== Drivers (Whitelisted) =============
3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2010-12-07] (LG Electronics Inc.)
3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2010-12-07] (LG Electronics Inc.)
3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2010-12-07] (LG Electronics Inc.)
3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [34304 2010-12-07] (LG Electronics Inc.)
3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-05] (LG Electronics Inc.)
3 AndNetGps; C:\Windows\System32\DRIVERS\lgandnetgps64.sys [28160 2011-09-05] (LG Electronics Inc.)
3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-05] (LG Electronics Inc.)
3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [103936 2011-09-16] (LG Electronics Inc.)
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
3 HPFXBULK; C:\Windows\System32\drivers\hpfx64bulk.sys [20504 2007-07-16] (Hewlett Packard)
3 HPFXFAX; C:\Windows\System32\drivers\hpfx64fax.sys [23064 2007-07-16] (Hewlett Packard)
0 SMR300; C:\Windows\System32\Drivers\SMR300.sys [96376 2012-07-05] (Symantec Corporation)
2 {55662437-DA8C-40c0-AADA-2C816A897A49}; \??\C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [27632 2008-09-26] (Cyberlink Corp.)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 18:02 - 2012-08-13 18:02 - 00000000 ____D C:\FRST
2012-08-13 13:41 - 2012-08-13 13:41 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eawvdpvr.sys
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\SMRBackup300.dat
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\Application Data\SMRBackup300.dat
============ 3 Months Modified Files ========================
2012-08-13 13:41 - 2012-08-13 13:41 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eawvdpvr.sys
2012-08-13 13:34 - 2009-03-04 10:36 - 00782692 ____A C:\Windows\System32\perfh00A.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00769452 ____A C:\Windows\System32\prfh0816.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00735832 ____A C:\Windows\System32\perfh007.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00721250 ____A C:\Windows\System32\perfh00E.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00709292 ____A C:\Windows\System32\perfh005.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00472762 ____A C:\Windows\System32\perfh011.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00191638 ____A C:\Windows\System32\perfc00E.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00177726 ____A C:\Windows\System32\perfc00A.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00172870 ____A C:\Windows\System32\prfc0816.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00169284 ____A C:\Windows\System32\perfc007.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00161344 ____A C:\Windows\System32\perfc005.dat
2012-08-13 13:34 - 2009-03-04 10:36 - 00143908 ____A C:\Windows\System32\perfc011.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00784614 ____A C:\Windows\System32\perfh00C.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00783426 ____A C:\Windows\System32\perfh013.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00778846 ____A C:\Windows\System32\perfh015.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00777976 ____A C:\Windows\System32\perfh010.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00767542 ____A C:\Windows\System32\perfh019.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00753282 ____A C:\Windows\System32\prfh0416.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00708730 ____A C:\Windows\System32\perfh01D.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00701592 ____A C:\Windows\System32\perfh01F.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00674682 ____A C:\Windows\System32\perfh008.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00575976 ____A C:\Windows\System32\perfh006.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00563314 ____A C:\Windows\System32\perfh014.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00548616 ____A C:\Windows\System32\perfh00B.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00547900 ____A C:\Windows\System32\perfh001.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00486124 ____A C:\Windows\System32\perfh012.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00461696 ____A C:\Windows\System32\perfh00D.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00455538 ____A C:\Windows\System32\prfh0404.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00445840 ____A C:\Windows\System32\prfh0804.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00175192 ____A C:\Windows\System32\perfc015.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00173604 ____A C:\Windows\System32\perfc013.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00171290 ____A C:\Windows\System32\perfc019.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00169230 ____A C:\Windows\System32\perfc00C.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00167254 ____A C:\Windows\System32\prfc0416.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00166564 ____A C:\Windows\System32\perfc010.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00163154 ____A C:\Windows\System32\perfc01D.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00160940 ____A C:\Windows\System32\perfc01F.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00143746 ____A C:\Windows\System32\prfc0404.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00143740 ____A C:\Windows\System32\prfc0804.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00143676 ____A C:\Windows\System32\perfc012.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00137506 ____A C:\Windows\System32\perfc008.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00127186 ____A C:\Windows\System32\perfc00B.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00122984 ____A C:\Windows\System32\perfc006.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00121702 ____A C:\Windows\System32\perfc014.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00121056 ____A C:\Windows\System32\perfc001.dat
2012-08-13 13:34 - 2009-03-04 04:36 - 00111252 ____A C:\Windows\System32\perfc00D.dat
2012-08-13 13:34 - 2006-11-02 04:46 - 19228470 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-13 13:26 - 2011-12-25 22:10 - 00002413 ____A C:\Windows\SysWOW64\lgAxconfig.ini
2012-08-13 13:24 - 2012-06-09 17:19 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-13 13:23 - 2009-03-10 14:38 - 00095193 ____A C:\Users\All Users\nvModes.001
2012-08-13 13:23 - 2009-03-10 14:38 - 00095193 ____A C:\Users\All Users\Application Data\nvModes.001
2012-08-13 13:22 - 2011-06-30 10:26 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-13 13:22 - 2009-03-10 14:16 - 00095193 ____A C:\Users\All Users\nvModes.dat
2012-08-13 13:22 - 2009-03-10 14:16 - 00095193 ____A C:\Users\All Users\Application Data\nvModes.dat
2012-08-13 13:21 - 2006-11-02 07:40 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 13:21 - 2006-11-02 07:21 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-13 13:21 - 2006-11-02 07:21 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-13 06:36 - 2006-11-02 04:33 - 26476544 ____A C:\Windows\System32\config\system_previous
2012-08-13 06:36 - 2006-11-02 04:33 - 159645696 ____A C:\Windows\System32\config\software_previous
2012-08-13 06:25 - 2006-11-02 04:33 - 294649856 ____A C:\Windows\System32\config\components_previous
2012-08-13 06:25 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\SMRBackup300.dat
2012-08-13 02:52 - 2012-08-13 02:52 - 00000759 ____A C:\Users\All Users\Application Data\SMRBackup300.dat
2012-08-13 02:46 - 2012-07-05 05:19 - 00182062 ____A C:\Windows\ntbtlog.txt.bak
2012-08-13 02:46 - 2009-02-24 01:54 - 01951144 ____A C:\Windows\WindowsUpdate.log
2012-07-05 08:43 - 2006-11-02 04:33 - 06815744 ____A C:\Windows\System32\config\default_previous
2012-07-05 08:43 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-07-05 06:10 - 2011-06-30 10:26 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 05:53 - 2012-07-05 05:52 - 00050000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nvlhsiap.sys
2012-07-05 05:52 - 2012-07-05 05:52 - 00050000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\vnducexs.sys
2012-07-05 05:37 - 2008-10-16 08:35 - 00001076 ____A C:\Windows\bthservsdp.dat
2012-07-05 05:37 - 2006-11-02 07:40 - 00032534 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-05 05:10 - 2012-07-05 08:13 - 00096376 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR300.SYS
2012-07-05 05:08 - 2012-07-05 05:08 - 02841104 ____A (Symantec Corporation) C:\Users\Logan\Downloads\NPE.exe
2012-07-03 08:44 - 2011-06-25 12:10 - 00007808 ____A C:\Users\Logan\Local Settings\d3d9caps.dat
2012-07-03 08:44 - 2011-06-25 12:10 - 00007808 ____A C:\Users\Logan\Local Settings\Application Data\d3d9caps.dat
2012-07-03 08:44 - 2011-06-25 12:10 - 00007808 ____A C:\Users\Logan\AppData\Local\d3d9caps.dat
2012-07-03 08:43 - 2012-06-09 17:19 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-03 08:43 - 2011-08-28 10:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-03 06:09 - 2006-11-02 07:39 - 01549094 ____A C:\Windows\PFRO.log
2012-07-03 06:04 - 2012-07-03 06:04 - 00000519 ____A C:\Windows\wininit.ini
2012-06-23 17:02 - 2012-06-23 17:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tmdgwfrv.sys
2012-06-23 16:47 - 2012-06-23 16:47 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\qnokossx.sys
2012-06-23 16:46 - 2012-06-23 16:46 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bckrjbrm.sys
2012-06-18 10:33 - 2012-06-18 10:35 - 00772592 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-06-18 10:33 - 2012-06-18 10:35 - 00227824 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-06-18 10:33 - 2012-06-18 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-18 10:33 - 2012-06-18 10:34 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-18 10:33 - 2010-05-06 09:59 - 00687600 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-06-18 06:21 - 2012-06-09 19:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-18 06:09 - 2011-07-11 13:10 - 19597586 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-18 05:40 - 2012-06-18 05:40 - 12621696 ____A (Microsoft Corporation) C:\Users\Logan\Downloads\mseinstall.exe
2012-06-15 16:30 - 2009-07-31 16:04 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-15 16:22 - 2012-06-15 16:22 - 00152136 ____A C:\Users\Logan\Downloads\o
2012-06-15 16:22 - 2012-06-15 16:22 - 00152072 ____A C:\Users\Logan\Downloads\search
2012-06-14 04:27 - 2012-06-14 04:27 - 00155176 ____A C:\Users\Girls\Local Settings\GDIPFONTCACHEV1.DAT
2012-06-14 04:27 - 2012-06-14 04:27 - 00155176 ____A C:\Users\Girls\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2012-06-14 04:27 - 2012-06-14 04:27 - 00155176 ____A C:\Users\Girls\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-14 04:26 - 2012-06-14 04:26 - 00000020 __ASH C:\Users\Girls\ntuser.ini
2012-06-13 23:58 - 2006-11-02 07:21 - 00534288 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 23:17 - 2006-11-02 04:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-10 17:35 - 2006-11-02 07:26 - 00138737 ____A C:\Windows\setupact.log
2012-06-10 04:44 - 2011-06-23 08:41 - 00012788 ____A C:\Windows\IE9_main.log
2012-06-10 04:42 - 2012-06-10 04:39 - 38229856 ____A (Microsoft Corporation) C:\Users\Logan\Downloads\BOIE9_ENUS_BO0084_VIS64.EXE
2012-06-09 06:05 - 2011-09-16 01:41 - 00020992 ____A C:\Users\Logan\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-09 06:05 - 2011-09-16 01:41 - 00020992 ____A C:\Users\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-09 06:05 - 2011-09-16 01:41 - 00020992 ____A C:\Users\Logan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-02 14:19 - 2012-07-03 09:04 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-07-03 09:04 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-07-03 09:04 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-07-03 09:01 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-07-03 09:04 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-07-03 09:01 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-07-03 09:01 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 11:19 - 2012-07-03 09:01 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:19 - 2012-07-03 09:01 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 11:15 - 2012-07-03 09:01 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 11:12 - 2012-07-03 09:01 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-05-29 19:02 - 2012-05-29 19:02 - 00290784 ____A C:\Windows\Minidump\Mini052912-01.dmp
2012-05-29 19:02 - 2011-09-08 17:44 - 622086487 ____A C:\Windows\MEMORY.DMP
2012-05-26 18:51 - 2012-03-13 22:09 - 00000888 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-26 18:51 - 2012-03-13 22:09 - 00000888 ____A C:\Users\All Users\Desktop\Mozilla Firefox.lnk
2012-05-17 18:47 - 2012-06-13 23:29 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 23:29 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 23:29 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 23:29 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 23:29 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 23:29 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 23:29 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 23:29 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 23:29 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 23:29 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 23:29 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 23:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 23:29 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 23:29 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 23:29 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 23:29 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 23:29 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 23:29 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 23:29 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 23:29 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 23:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 23:29 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 23:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 23:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 23:29 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 23:29 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 23:29 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 23:29 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
ZeroAccess:
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\00000004.@
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\1afb2d56
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\201d3dde
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\55490ac4
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe B8844F93D2C5F1DCDB179AAA9AF134B7 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 4093.02 MB
Available physical RAM: 3319.57 MB
Total Pagefile: 3768.22 MB
Available Pagefile: 3303.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:284.08 GB) (Free:106.48 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:14.01 GB) (Free:2.13 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive f: (KINGSTON) (Removable) (Total:7.45 GB) (Free:1.36 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 7644 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 284 GB 32 KB
Partition 2 Primary 14 GB 284 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 284 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7644 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 7644 MB Healthy
==================================================================================
Last Boot: 2012-07-05 08:37
======================= End Of Log ==========================
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
Run Search File(s) for "services.exe" in Farbar Recovery Scan Tool:
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Farbar Recovery Scan Tool Version: 13-08-2012
Ran by SYSTEM at 2012-08-13 18:04:57
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009-08-19 04:35] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-01-20 18:49] - [2008-01-20 18:49] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2009-08-19 04:36] - [2009-04-10 23:10] - 0384512 ____A (Microsoft Corporation) 934E0B7D77FF78C18D9F8891221B6DE3
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe
[2008-01-20 18:48] - [2008-01-20 18:48] - 0384512 ____A (Microsoft Corporation) DFAC660F0F139276CC9299812DE42719
C:\Windows\SysWOW64\services.exe
[2009-08-19 04:35] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\System32\services.exe
[2009-08-19 04:36] - [2009-04-10 23:10] - 0381952 ____A (Microsoft Corporation) B8844F93D2C5F1DCDB179AAA9AF134B7
====== End Of Search ======