Andy Sweetman
Posts: 21 +0
Hi
I have a Windows 7 64 bit system and have today got the trojan sirefef.y which disabled MSE and started Windows shutting down after finding critical error. I have installed Antimalware software per the pinned thread on this forum however the pc does not allow (even in safe mode) time for the process to scan before the computer reboots after 60 seconds.
I have downloaded the FRST file and attach the text output below - please help Broni!
Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 13-06-2012 15:21:20
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RunDLLEntry_THXCfg] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [RunDLLEntry_EptMon] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64 [21504 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8158240 2009-10-06] (Realtek Semiconductor)
HKLM\...\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon [644696 2007-05-14] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [1840720 2007-04-03] (CANON INC.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2009-07-17] (Alcor Micro Corp.)
HKLM-x32\...\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m [1807680 2010-02-09] ()
HKLM-x32\...\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r [963584 2009-12-01] (Creative Technology Ltd)
HKLM-x32\...\Run: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-04-13] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [75048 2010-04-27] (cyberlink)
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [111640 2009-09-30] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\MediaShow4" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1" [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-12-15] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0" [218408 2009-02-17] (CyberLink Corp.)
HKLM-x32\...\Run: [LGODDFU] "C:\Program Files (x86)\lg_fwupdate\fwupdate.exe" blrun [557056 2011-08-17] (BitLeader)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [222504 2010-06-02] (CyberLink Corp.)
HKLM-x32\...\Run: [OpwareSE4] "C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe" [79400 2007-02-04] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [185640 2009-09-26] (Seagate LLC)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [887976 2011-08-23] (Ask)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1987976 2012-02-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641664 2012-04-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-21] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [AmdAgent] C:\Windows\Temp\temp88.exe [792576 2012-06-13] ()
HKU\Andy\...\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [247728 2011-04-22] (TomTom)
HKU\Andy\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Andy\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Andy\...\Policies\system: [LogonHoursAction] 2
HKU\Andy\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Ben\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Ben\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17344176 2012-06-05] (Skype Technologies S.A.)
HKU\Ben\...\Policies\system: [LogonHoursAction] 2
HKU\Ben\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Hannah\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Hannah\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\Hannah\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17344176 2012-06-05] (Skype Technologies S.A.)
HKU\Hannah\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2012-05-28] (Valve Corporation)
HKU\Hannah\...\Policies\system: [LogonHoursAction] 2
HKU\Hannah\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Lucy\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Lucy\...\Policies\system: [LogonHoursAction] 2
HKU\Lucy\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Sam\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Sam\...\Policies\system: [LogonHoursAction] 2
HKU\Sam\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Sam.Desktop\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Sam.Desktop\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\Sam.Desktop\...\Policies\system: [LogonHoursAction] 2
HKU\Sam.Desktop\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-04] (Dell)
HKLM-x32\...\runonceex: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-26] (Sonic Solutions)
Startup: C:\Users\Andy\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Ben\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Hannah\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Lucy\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sam\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sam.Desktop\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-06-15] (Microsoft Corporation)
2 FreeAgentGoNext Service; "C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe" [189736 2009-09-26] (Seagate Technology LLC)
2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [2343816 2012-02-28] (LogMeIn Inc.)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [244904 2009-07-02] ()
3 RoxMediaDB10; "C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe" [1124848 2009-06-26] (Sonic Solutions)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-05-30] (Skype Technologies S.A.)
2 TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [92592 2011-04-22] (TomTom)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2009-09-30] (Intel Corporation)
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
2 SessionLauncher; C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
========================== Drivers (Whitelisted) =============
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
1 RxFilter; C:\Windows\SysWow64\Drivers\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 13:40 - 2012-06-13 13:40 - 00000162 ___AH C:\Users\Andy\My Documents\~$ternet IDs.doc
2012-06-13 13:40 - 2012-06-13 13:40 - 00000162 ___AH C:\Users\Andy\Documents\~$ternet IDs.doc
2012-06-13 13:01 - 2012-06-13 13:01 - 00003352 ____N C:\bootsqm.dat
2012-06-13 11:35 - 2012-06-13 11:35 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 11:35 - 2012-06-13 11:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Sam.Desktop\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Lucy\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Hannah\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Ben\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Andy\Desktop\Live Security Platinum.lnk
2012-06-11 18:24 - 2012-06-11 18:24 - 00000000 ____D C:\Users\Ben\Desktop\Minecraft
2012-06-10 21:27 - 2012-06-10 21:27 - 00419840 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00413696 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00133632 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00110592 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00000221 ____A C:\Users\Ben\Desktop\Clones Demo.url
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\My Documents\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\Documents\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\Application Data\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\AppData\Roaming\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Program Files (x86)\OpenAL
2012-06-10 18:52 - 2012-06-10 18:52 - 00015910 ____A C:\Users\Ben\Desktop\hs_err_pid26928.log
2012-06-10 18:37 - 2012-06-10 18:38 - 00002018 ____A C:\Users\Ben\My Documents\mcedit.ini
2012-06-10 18:37 - 2012-06-10 18:38 - 00002018 ____A C:\Users\Ben\Documents\mcedit.ini
2012-06-10 18:37 - 2012-06-10 18:37 - 00060473 ____A C:\Users\Ben\Downloads\mcedit-uninstall.exe
2012-06-10 18:37 - 2012-06-10 18:37 - 00001693 ____A C:\Users\Ben\Desktop\MCEdit.lnk
2012-06-10 18:37 - 2012-06-10 18:37 - 00001671 ____A C:\Users\Ben\Downloads\MCEdit.lnk
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\My Documents\MCEdit-schematics
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Downloads\MCEditData
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Downloads\doc
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Documents\MCEdit-schematics
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Application Data\pymclevel
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\AppData\Roaming\pymclevel
2012-06-10 18:35 - 2012-06-10 18:36 - 10629010 ____A C:\Users\Ben\Downloads\MCEdit-stable33-win32-setup.exe
2012-06-10 18:34 - 2012-06-10 18:34 - 01779847 ____A C:\Users\Ben\Downloads\mcedit-mcedit-0.1.1-1-g41ea379.zip
2012-06-10 18:08 - 2012-06-10 18:08 - 01589718 ____A C:\Users\Ben\Downloads\Minecraft_Server.exe
2012-06-10 18:07 - 2012-06-10 21:26 - 00000000 ____D C:\Users\Ben\Desktop\Ben's Minecraft Server
2012-06-09 22:22 - 2012-06-09 22:28 - 00000000 ____D C:\Users\Hannah\Application Data\Mozilla
2012-06-09 22:22 - 2012-06-09 22:28 - 00000000 ____D C:\Users\Hannah\AppData\Roaming\Mozilla
2012-06-09 22:21 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\My Documents\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\Documents\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:21 - 00000000 ____D C:\Users\Hannah\Local Settings\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:21 - 00000000 ____D C:\Users\Hannah\Local Settings\Application Data\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:21 - 00000000 ____D C:\Users\Hannah\AppData\Local\The Lord of the Rings Online
2012-06-09 22:17 - 2009-09-04 18:29 - 01974616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2012-06-09 22:17 - 2009-09-04 18:29 - 00235344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2012-06-09 22:06 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\Local Settings\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\Local Settings\Application Data\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\AppData\Local\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:18 - 00000000 ____D C:\Users\Hannah\Local Settings\Turbine
2012-06-09 22:06 - 2012-06-09 22:18 - 00000000 ____D C:\Users\Hannah\Local Settings\Application Data\Turbine
2012-06-09 22:06 - 2012-06-09 22:18 - 00000000 ____D C:\Users\Hannah\AppData\Local\Turbine
2012-06-09 22:06 - 2012-06-09 22:06 - 00000094 ____A C:\Users\Hannah\Local Settings\fusioncache.dat
2012-06-09 22:06 - 2012-06-09 22:06 - 00000094 ____A C:\Users\Hannah\Local Settings\Application Data\fusioncache.dat
2012-06-09 22:06 - 2012-06-09 22:06 - 00000094 ____A C:\Users\Hannah\AppData\Local\fusioncache.dat
2012-06-09 22:06 - 2012-06-09 22:06 - 00000000 ____D C:\Users\Andy\Local Settings\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:06 - 00000000 ____D C:\Users\Andy\Local Settings\Application Data\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:06 - 00000000 ____D C:\Users\Andy\AppData\Local\ApplicationHistory
2012-06-09 22:05 - 2012-06-09 22:05 - 00000000 ____D C:\Windows\SysWOW64\URTTEMP
2012-06-09 22:05 - 2007-03-12 17:42 - 03495784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2012-06-09 22:00 - 2012-06-09 22:01 - 09067083 ____A C:\Users\Hannah\Downloads\Soartex Fanver.zip
2012-06-09 21:58 - 2012-06-09 21:58 - 01440341 ____A C:\Users\Hannah\Downloads\soartex1.2.5.zip
2012-06-09 20:09 - 2012-06-09 20:09 - 00000000 ____D C:\Users\Ben\Application Data\Trine2
2012-06-09 20:09 - 2012-06-09 20:09 - 00000000 ____D C:\Users\Ben\AppData\Roaming\Trine2
2012-06-09 19:50 - 2012-06-09 19:50 - 00000210 ____A C:\Users\Ben\Desktop\The Lord of the Rings Online.url
2012-06-06 22:48 - 2012-06-06 22:48 - 00000197 ____A C:\Users\Hannah\Desktop\Portal First Slice.url
2012-06-06 21:57 - 2012-06-06 21:57 - 00000000 ____D C:\Users\Hannah\Application Data\Trine2
2012-06-06 21:57 - 2012-06-06 21:57 - 00000000 ____D C:\Users\Hannah\AppData\Roaming\Trine2
2012-06-06 21:56 - 2008-05-30 15:11 - 04991496 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_38.dll
2012-06-06 21:56 - 2008-05-30 15:11 - 03850760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2012-06-06 21:56 - 2007-04-04 19:54 - 00107368 ____A (Microsoft Corporation) C:\Windows\System32\xinput1_3.dll
2012-06-06 21:51 - 2012-06-06 21:51 - 00000194 ____A C:\Users\Hannah\Desktop\Trine 2 Demo.url
2012-06-06 17:37 - 2012-06-06 17:37 - 00000000 ____D C:\Users\Lucy\Local Settings\Application Data\Adobe
2012-06-06 17:37 - 2012-06-06 17:37 - 00000000 ____D C:\Users\Lucy\Local Settings\Adobe
2012-06-06 17:37 - 2012-06-06 17:37 - 00000000 ____D C:\Users\Lucy\AppData\Local\Adobe
2012-06-06 17:12 - 2012-06-06 17:12 - 01007734 ____A C:\Users\Ben\Downloads\LightCraft by Skalander97.zip
2012-06-06 15:00 - 2012-06-06 15:01 - 05356584 ____A (Code Laboratories, Inc.) C:\Users\Andy\Downloads\CL-Eye-Driver-5.0.1.0528 (1).exe
2012-06-06 14:37 - 2012-06-06 15:01 - 00001236 ____A C:\Users\Public\Desktop\CL-Eye Test.lnk
2012-06-06 14:37 - 2012-06-06 14:37 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01009.Wdf
2012-06-06 14:37 - 2012-06-06 14:37 - 00000000 ____D C:\Program Files (x86)\Code Laboratories
2012-06-06 09:37 - 2012-06-06 09:37 - 00015948 ____A C:\Users\Hannah\Downloads\hs_err_pid99584.log
2012-06-03 08:41 - 2012-06-03 08:42 - 08386590 ____A C:\Users\Ben\Downloads\Soartex Fanver.zip
2012-06-02 21:26 - 2012-06-02 21:26 - 00084993 ____A C:\Users\Ben\Downloads\Dynamic Lights 1.2.4.zip
2012-05-30 22:46 - 2012-05-30 22:46 - 00001807 ____A C:\Users\Hannah\Downloads\sketch (1).png
2012-05-30 22:43 - 2012-05-30 22:43 - 00002022 ____A C:\Users\Hannah\Downloads\sketch.png
2012-05-30 18:27 - 2012-05-30 18:27 - 00013146 ____A C:\Users\Ben\Downloads\hs_err_pid24560.log
2012-05-30 18:19 - 2012-05-30 18:20 - 05938896 ____A C:\Users\Ben\Downloads\MAtmos__1_2_4_r12__WithWeaponInteractions.zip
2012-05-29 20:44 - 2012-05-29 20:45 - 00002122 ____A C:\Users\Ben\Downloads\sketch.png
2012-05-29 18:12 - 2012-05-29 18:12 - 00000221 ____A C:\Users\Ben\Desktop\AI War Fleet Command - Demo.url
2012-05-29 17:17 - 2012-05-29 17:17 - 00000000 ____D C:\Windows\SysWOW64\xlive
2012-05-29 17:17 - 2012-05-29 17:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-05-29 17:17 - 2009-09-04 18:29 - 01892184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2012-05-29 17:17 - 2009-09-04 18:29 - 00453456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2012-05-29 17:17 - 2007-04-04 19:53 - 00081768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 05631312 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 04379984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 02605920 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 02036576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 00519000 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 00452440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2012-05-29 17:15 - 2005-03-18 18:19 - 02337488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2012-05-29 17:07 - 2012-05-29 17:07 - 00000222 ____A C:\Users\Ben\Desktop\Age of Empires Online.url
2012-05-29 07:36 - 2012-05-29 07:36 - 00067464 ____A C:\Windows\System32\CLEyeDevices.dll
2012-05-28 22:24 - 2012-06-12 21:59 - 00000000 ____D C:\Program Files (x86)\Steam
2012-05-28 22:24 - 2012-05-28 22:24 - 01606656 ____A C:\Users\Hannah\Downloads\SteamInstall.msi
2012-05-28 22:24 - 2012-05-28 22:24 - 00000919 ____A C:\Users\Public\Desktop\Steam.lnk
2012-05-28 22:16 - 2012-05-28 22:16 - 01653839 ____A C:\Users\Hannah\Downloads\Shaders-Windows.zip
2012-05-26 18:59 - 2012-05-26 18:59 - 00105478 ____A C:\Users\Ben\Downloads\[1.2.5] Cheat Pack 1.5 #2 Singleplayer.zip
2012-05-26 18:54 - 2012-05-26 18:54 - 00109228 ____A C:\Users\Ben\Downloads\Minecraft 1.2.5 Singleplayer Cheat Pack.zip
2012-05-26 18:37 - 2012-05-26 18:37 - 00276586 ____A C:\Users\Ben\Downloads\zombe's_modpack-v6.2_MC.1.2.5.zip
2012-05-26 14:24 - 2012-05-26 14:24 - 00051131 ____A C:\Users\Ben\Downloads\TooManyItems2012_04_13_1.2.5.zip
2012-05-26 14:14 - 2012-05-26 14:15 - 43813068 ____A C:\Users\Ben\Downloads\Spatial Distortion.zip
2012-05-26 12:20 - 2012-05-26 12:22 - 69677540 ____A C:\Users\Ben\Downloads\The Minecraft Files217.zip
2012-05-26 10:35 - 2012-05-26 10:35 - 00649502 ____A C:\Users\Ben\Downloads\Yay-Toast-Pack-125upgrade.zip
2012-05-20 16:25 - 2012-05-20 16:24 - 00054926 ____A C:\Users\Ben\Downloads\Backpack_1.2.5_FML_r3 - Copy.rar
2012-05-20 16:24 - 2012-05-20 16:24 - 00054926 ____A C:\Users\Ben\Downloads\Backpack_1.2.5_FML_r3.rar
2012-05-20 09:37 - 2012-05-20 09:38 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-05-20 09:37 - 2012-05-20 09:37 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-19 22:54 - 2012-05-19 22:54 - 00240023 ____A C:\Users\Hannah\Downloads\[1.2.5]ReiMinimap_v3.0_06.zip
2012-05-19 22:01 - 2012-05-19 22:01 - 18220021 ____A C:\Users\Hannah\Downloads\Sphax PureBDCraft 128x.zip
2012-05-19 19:59 - 2012-05-19 20:00 - 19735526 ____A C:\Users\Ben\Downloads\MineLoL Texturepack Realistic 128x128.zip
2012-05-19 19:59 - 2012-05-19 20:00 - 11085411 ____A C:\Users\Ben\Downloads\Another Castle!.zip
2012-05-19 19:58 - 2012-05-19 20:00 - 33085073 ____A C:\Users\Ben\Downloads\WoW Pack 1.2.5.zip
2012-05-19 19:57 - 2012-05-19 19:57 - 02151082 ____A C:\Users\Ben\Downloads\Super-Mario.zip
2012-05-19 14:27 - 2012-05-19 14:27 - 01539265 ____A C:\Users\Ben\Downloads\mcpatcher-2.3.6.exe
2012-05-19 14:22 - 2012-05-19 14:22 - 00240023 ____A C:\Users\Ben\Downloads\[1.2.5]ReiMinimap_v3.0_06 (1).zip
2012-05-19 14:21 - 2012-05-19 14:21 - 00240023 ____A C:\Users\Ben\Downloads\[1.2.5]ReiMinimap_v3.0_06.zip
2012-05-18 19:51 - 2012-05-18 19:52 - 08688607 ____A C:\Users\Ben\Downloads\The Survival Games 2.zip
2012-05-16 21:26 - 2012-05-16 21:50 - 00000000 ____D C:\Users\Sam.Desktop\Application Data\Skype
2012-05-16 21:26 - 2012-05-16 21:50 - 00000000 ____D C:\Users\Sam.Desktop\AppData\Roaming\Skype
I have a Windows 7 64 bit system and have today got the trojan sirefef.y which disabled MSE and started Windows shutting down after finding critical error. I have installed Antimalware software per the pinned thread on this forum however the pc does not allow (even in safe mode) time for the process to scan before the computer reboots after 60 seconds.
I have downloaded the FRST file and attach the text output below - please help Broni!
Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 13-06-2012 15:21:20
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RunDLLEntry_THXCfg] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [RunDLLEntry_EptMon] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64 [21504 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8158240 2009-10-06] (Realtek Semiconductor)
HKLM\...\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon [644696 2007-05-14] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [1840720 2007-04-03] (CANON INC.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2009-07-17] (Alcor Micro Corp.)
HKLM-x32\...\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m [1807680 2010-02-09] ()
HKLM-x32\...\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r [963584 2009-12-01] (Creative Technology Ltd)
HKLM-x32\...\Run: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-04-13] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [75048 2010-04-27] (cyberlink)
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [111640 2009-09-30] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\MediaShow4" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1" [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-12-15] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0" [218408 2009-02-17] (CyberLink Corp.)
HKLM-x32\...\Run: [LGODDFU] "C:\Program Files (x86)\lg_fwupdate\fwupdate.exe" blrun [557056 2011-08-17] (BitLeader)
HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [222504 2010-06-02] (CyberLink Corp.)
HKLM-x32\...\Run: [OpwareSE4] "C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe" [79400 2007-02-04] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [185640 2009-09-26] (Seagate LLC)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [887976 2011-08-23] (Ask)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1987976 2012-02-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641664 2012-04-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-21] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [AmdAgent] C:\Windows\Temp\temp88.exe [792576 2012-06-13] ()
HKU\Andy\...\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [247728 2011-04-22] (TomTom)
HKU\Andy\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Andy\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Andy\...\Policies\system: [LogonHoursAction] 2
HKU\Andy\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Ben\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Ben\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17344176 2012-06-05] (Skype Technologies S.A.)
HKU\Ben\...\Policies\system: [LogonHoursAction] 2
HKU\Ben\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Hannah\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Hannah\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\Hannah\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17344176 2012-06-05] (Skype Technologies S.A.)
HKU\Hannah\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2012-05-28] (Valve Corporation)
HKU\Hannah\...\Policies\system: [LogonHoursAction] 2
HKU\Hannah\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Lucy\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Lucy\...\Policies\system: [LogonHoursAction] 2
HKU\Lucy\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Sam\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Sam\...\Policies\system: [LogonHoursAction] 2
HKU\Sam\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Sam.Desktop\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-18] (Google Inc.)
HKU\Sam.Desktop\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\Sam.Desktop\...\Policies\system: [LogonHoursAction] 2
HKU\Sam.Desktop\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-04] (Dell)
HKLM-x32\...\runonceex: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-26] (Sonic Solutions)
Startup: C:\Users\Andy\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Ben\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Hannah\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Lucy\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sam\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Sam.Desktop\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-06-15] (Microsoft Corporation)
2 FreeAgentGoNext Service; "C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe" [189736 2009-09-26] (Seagate Technology LLC)
2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [2343816 2012-02-28] (LogMeIn Inc.)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [244904 2009-07-02] ()
3 RoxMediaDB10; "C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe" [1124848 2009-06-26] (Sonic Solutions)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-05-30] (Skype Technologies S.A.)
2 TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [92592 2011-04-22] (TomTom)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2009-09-30] (Intel Corporation)
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
2 SessionLauncher; C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
========================== Drivers (Whitelisted) =============
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
1 RxFilter; C:\Windows\SysWow64\Drivers\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 13:40 - 2012-06-13 13:40 - 00000162 ___AH C:\Users\Andy\My Documents\~$ternet IDs.doc
2012-06-13 13:40 - 2012-06-13 13:40 - 00000162 ___AH C:\Users\Andy\Documents\~$ternet IDs.doc
2012-06-13 13:01 - 2012-06-13 13:01 - 00003352 ____N C:\bootsqm.dat
2012-06-13 11:35 - 2012-06-13 11:35 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 11:35 - 2012-06-13 11:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Sam.Desktop\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Lucy\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Hannah\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Ben\Desktop\Live Security Platinum.lnk
2012-06-13 11:24 - 2012-06-13 11:24 - 00001096 ____A C:\Users\Andy\Desktop\Live Security Platinum.lnk
2012-06-11 18:24 - 2012-06-11 18:24 - 00000000 ____D C:\Users\Ben\Desktop\Minecraft
2012-06-10 21:27 - 2012-06-10 21:27 - 00419840 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00413696 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00133632 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00110592 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-06-10 21:27 - 2012-06-10 21:27 - 00000221 ____A C:\Users\Ben\Desktop\Clones Demo.url
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\My Documents\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\Documents\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\Application Data\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Users\Ben\AppData\Roaming\ClonesDemo
2012-06-10 21:27 - 2012-06-10 21:27 - 00000000 ____D C:\Program Files (x86)\OpenAL
2012-06-10 18:52 - 2012-06-10 18:52 - 00015910 ____A C:\Users\Ben\Desktop\hs_err_pid26928.log
2012-06-10 18:37 - 2012-06-10 18:38 - 00002018 ____A C:\Users\Ben\My Documents\mcedit.ini
2012-06-10 18:37 - 2012-06-10 18:38 - 00002018 ____A C:\Users\Ben\Documents\mcedit.ini
2012-06-10 18:37 - 2012-06-10 18:37 - 00060473 ____A C:\Users\Ben\Downloads\mcedit-uninstall.exe
2012-06-10 18:37 - 2012-06-10 18:37 - 00001693 ____A C:\Users\Ben\Desktop\MCEdit.lnk
2012-06-10 18:37 - 2012-06-10 18:37 - 00001671 ____A C:\Users\Ben\Downloads\MCEdit.lnk
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\My Documents\MCEdit-schematics
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Downloads\MCEditData
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Downloads\doc
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Documents\MCEdit-schematics
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\Application Data\pymclevel
2012-06-10 18:37 - 2012-06-10 18:37 - 00000000 ____D C:\Users\Ben\AppData\Roaming\pymclevel
2012-06-10 18:35 - 2012-06-10 18:36 - 10629010 ____A C:\Users\Ben\Downloads\MCEdit-stable33-win32-setup.exe
2012-06-10 18:34 - 2012-06-10 18:34 - 01779847 ____A C:\Users\Ben\Downloads\mcedit-mcedit-0.1.1-1-g41ea379.zip
2012-06-10 18:08 - 2012-06-10 18:08 - 01589718 ____A C:\Users\Ben\Downloads\Minecraft_Server.exe
2012-06-10 18:07 - 2012-06-10 21:26 - 00000000 ____D C:\Users\Ben\Desktop\Ben's Minecraft Server
2012-06-09 22:22 - 2012-06-09 22:28 - 00000000 ____D C:\Users\Hannah\Application Data\Mozilla
2012-06-09 22:22 - 2012-06-09 22:28 - 00000000 ____D C:\Users\Hannah\AppData\Roaming\Mozilla
2012-06-09 22:21 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\My Documents\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\Documents\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:21 - 00000000 ____D C:\Users\Hannah\Local Settings\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:21 - 00000000 ____D C:\Users\Hannah\Local Settings\Application Data\The Lord of the Rings Online
2012-06-09 22:21 - 2012-06-09 22:21 - 00000000 ____D C:\Users\Hannah\AppData\Local\The Lord of the Rings Online
2012-06-09 22:17 - 2009-09-04 18:29 - 01974616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2012-06-09 22:17 - 2009-09-04 18:29 - 00235344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2012-06-09 22:06 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\Local Settings\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\Local Settings\Application Data\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:29 - 00000000 ____D C:\Users\Hannah\AppData\Local\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:18 - 00000000 ____D C:\Users\Hannah\Local Settings\Turbine
2012-06-09 22:06 - 2012-06-09 22:18 - 00000000 ____D C:\Users\Hannah\Local Settings\Application Data\Turbine
2012-06-09 22:06 - 2012-06-09 22:18 - 00000000 ____D C:\Users\Hannah\AppData\Local\Turbine
2012-06-09 22:06 - 2012-06-09 22:06 - 00000094 ____A C:\Users\Hannah\Local Settings\fusioncache.dat
2012-06-09 22:06 - 2012-06-09 22:06 - 00000094 ____A C:\Users\Hannah\Local Settings\Application Data\fusioncache.dat
2012-06-09 22:06 - 2012-06-09 22:06 - 00000094 ____A C:\Users\Hannah\AppData\Local\fusioncache.dat
2012-06-09 22:06 - 2012-06-09 22:06 - 00000000 ____D C:\Users\Andy\Local Settings\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:06 - 00000000 ____D C:\Users\Andy\Local Settings\Application Data\ApplicationHistory
2012-06-09 22:06 - 2012-06-09 22:06 - 00000000 ____D C:\Users\Andy\AppData\Local\ApplicationHistory
2012-06-09 22:05 - 2012-06-09 22:05 - 00000000 ____D C:\Windows\SysWOW64\URTTEMP
2012-06-09 22:05 - 2007-03-12 17:42 - 03495784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2012-06-09 22:00 - 2012-06-09 22:01 - 09067083 ____A C:\Users\Hannah\Downloads\Soartex Fanver.zip
2012-06-09 21:58 - 2012-06-09 21:58 - 01440341 ____A C:\Users\Hannah\Downloads\soartex1.2.5.zip
2012-06-09 20:09 - 2012-06-09 20:09 - 00000000 ____D C:\Users\Ben\Application Data\Trine2
2012-06-09 20:09 - 2012-06-09 20:09 - 00000000 ____D C:\Users\Ben\AppData\Roaming\Trine2
2012-06-09 19:50 - 2012-06-09 19:50 - 00000210 ____A C:\Users\Ben\Desktop\The Lord of the Rings Online.url
2012-06-06 22:48 - 2012-06-06 22:48 - 00000197 ____A C:\Users\Hannah\Desktop\Portal First Slice.url
2012-06-06 21:57 - 2012-06-06 21:57 - 00000000 ____D C:\Users\Hannah\Application Data\Trine2
2012-06-06 21:57 - 2012-06-06 21:57 - 00000000 ____D C:\Users\Hannah\AppData\Roaming\Trine2
2012-06-06 21:56 - 2008-05-30 15:11 - 04991496 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_38.dll
2012-06-06 21:56 - 2008-05-30 15:11 - 03850760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2012-06-06 21:56 - 2007-04-04 19:54 - 00107368 ____A (Microsoft Corporation) C:\Windows\System32\xinput1_3.dll
2012-06-06 21:51 - 2012-06-06 21:51 - 00000194 ____A C:\Users\Hannah\Desktop\Trine 2 Demo.url
2012-06-06 17:37 - 2012-06-06 17:37 - 00000000 ____D C:\Users\Lucy\Local Settings\Application Data\Adobe
2012-06-06 17:37 - 2012-06-06 17:37 - 00000000 ____D C:\Users\Lucy\Local Settings\Adobe
2012-06-06 17:37 - 2012-06-06 17:37 - 00000000 ____D C:\Users\Lucy\AppData\Local\Adobe
2012-06-06 17:12 - 2012-06-06 17:12 - 01007734 ____A C:\Users\Ben\Downloads\LightCraft by Skalander97.zip
2012-06-06 15:00 - 2012-06-06 15:01 - 05356584 ____A (Code Laboratories, Inc.) C:\Users\Andy\Downloads\CL-Eye-Driver-5.0.1.0528 (1).exe
2012-06-06 14:37 - 2012-06-06 15:01 - 00001236 ____A C:\Users\Public\Desktop\CL-Eye Test.lnk
2012-06-06 14:37 - 2012-06-06 14:37 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01009.Wdf
2012-06-06 14:37 - 2012-06-06 14:37 - 00000000 ____D C:\Program Files (x86)\Code Laboratories
2012-06-06 09:37 - 2012-06-06 09:37 - 00015948 ____A C:\Users\Hannah\Downloads\hs_err_pid99584.log
2012-06-03 08:41 - 2012-06-03 08:42 - 08386590 ____A C:\Users\Ben\Downloads\Soartex Fanver.zip
2012-06-02 21:26 - 2012-06-02 21:26 - 00084993 ____A C:\Users\Ben\Downloads\Dynamic Lights 1.2.4.zip
2012-05-30 22:46 - 2012-05-30 22:46 - 00001807 ____A C:\Users\Hannah\Downloads\sketch (1).png
2012-05-30 22:43 - 2012-05-30 22:43 - 00002022 ____A C:\Users\Hannah\Downloads\sketch.png
2012-05-30 18:27 - 2012-05-30 18:27 - 00013146 ____A C:\Users\Ben\Downloads\hs_err_pid24560.log
2012-05-30 18:19 - 2012-05-30 18:20 - 05938896 ____A C:\Users\Ben\Downloads\MAtmos__1_2_4_r12__WithWeaponInteractions.zip
2012-05-29 20:44 - 2012-05-29 20:45 - 00002122 ____A C:\Users\Ben\Downloads\sketch.png
2012-05-29 18:12 - 2012-05-29 18:12 - 00000221 ____A C:\Users\Ben\Desktop\AI War Fleet Command - Demo.url
2012-05-29 17:17 - 2012-05-29 17:17 - 00000000 ____D C:\Windows\SysWOW64\xlive
2012-05-29 17:17 - 2012-05-29 17:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-05-29 17:17 - 2009-09-04 18:29 - 01892184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2012-05-29 17:17 - 2009-09-04 18:29 - 00453456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2012-05-29 17:17 - 2007-04-04 19:53 - 00081768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 05631312 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 04379984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 02605920 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 02036576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 00519000 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_40.dll
2012-05-29 17:15 - 2008-10-15 07:22 - 00452440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2012-05-29 17:15 - 2005-03-18 18:19 - 02337488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2012-05-29 17:07 - 2012-05-29 17:07 - 00000222 ____A C:\Users\Ben\Desktop\Age of Empires Online.url
2012-05-29 07:36 - 2012-05-29 07:36 - 00067464 ____A C:\Windows\System32\CLEyeDevices.dll
2012-05-28 22:24 - 2012-06-12 21:59 - 00000000 ____D C:\Program Files (x86)\Steam
2012-05-28 22:24 - 2012-05-28 22:24 - 01606656 ____A C:\Users\Hannah\Downloads\SteamInstall.msi
2012-05-28 22:24 - 2012-05-28 22:24 - 00000919 ____A C:\Users\Public\Desktop\Steam.lnk
2012-05-28 22:16 - 2012-05-28 22:16 - 01653839 ____A C:\Users\Hannah\Downloads\Shaders-Windows.zip
2012-05-26 18:59 - 2012-05-26 18:59 - 00105478 ____A C:\Users\Ben\Downloads\[1.2.5] Cheat Pack 1.5 #2 Singleplayer.zip
2012-05-26 18:54 - 2012-05-26 18:54 - 00109228 ____A C:\Users\Ben\Downloads\Minecraft 1.2.5 Singleplayer Cheat Pack.zip
2012-05-26 18:37 - 2012-05-26 18:37 - 00276586 ____A C:\Users\Ben\Downloads\zombe's_modpack-v6.2_MC.1.2.5.zip
2012-05-26 14:24 - 2012-05-26 14:24 - 00051131 ____A C:\Users\Ben\Downloads\TooManyItems2012_04_13_1.2.5.zip
2012-05-26 14:14 - 2012-05-26 14:15 - 43813068 ____A C:\Users\Ben\Downloads\Spatial Distortion.zip
2012-05-26 12:20 - 2012-05-26 12:22 - 69677540 ____A C:\Users\Ben\Downloads\The Minecraft Files217.zip
2012-05-26 10:35 - 2012-05-26 10:35 - 00649502 ____A C:\Users\Ben\Downloads\Yay-Toast-Pack-125upgrade.zip
2012-05-20 16:25 - 2012-05-20 16:24 - 00054926 ____A C:\Users\Ben\Downloads\Backpack_1.2.5_FML_r3 - Copy.rar
2012-05-20 16:24 - 2012-05-20 16:24 - 00054926 ____A C:\Users\Ben\Downloads\Backpack_1.2.5_FML_r3.rar
2012-05-20 09:37 - 2012-05-20 09:38 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-05-20 09:37 - 2012-05-20 09:37 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-19 22:54 - 2012-05-19 22:54 - 00240023 ____A C:\Users\Hannah\Downloads\[1.2.5]ReiMinimap_v3.0_06.zip
2012-05-19 22:01 - 2012-05-19 22:01 - 18220021 ____A C:\Users\Hannah\Downloads\Sphax PureBDCraft 128x.zip
2012-05-19 19:59 - 2012-05-19 20:00 - 19735526 ____A C:\Users\Ben\Downloads\MineLoL Texturepack Realistic 128x128.zip
2012-05-19 19:59 - 2012-05-19 20:00 - 11085411 ____A C:\Users\Ben\Downloads\Another Castle!.zip
2012-05-19 19:58 - 2012-05-19 20:00 - 33085073 ____A C:\Users\Ben\Downloads\WoW Pack 1.2.5.zip
2012-05-19 19:57 - 2012-05-19 19:57 - 02151082 ____A C:\Users\Ben\Downloads\Super-Mario.zip
2012-05-19 14:27 - 2012-05-19 14:27 - 01539265 ____A C:\Users\Ben\Downloads\mcpatcher-2.3.6.exe
2012-05-19 14:22 - 2012-05-19 14:22 - 00240023 ____A C:\Users\Ben\Downloads\[1.2.5]ReiMinimap_v3.0_06 (1).zip
2012-05-19 14:21 - 2012-05-19 14:21 - 00240023 ____A C:\Users\Ben\Downloads\[1.2.5]ReiMinimap_v3.0_06.zip
2012-05-18 19:51 - 2012-05-18 19:52 - 08688607 ____A C:\Users\Ben\Downloads\The Survival Games 2.zip
2012-05-16 21:26 - 2012-05-16 21:50 - 00000000 ____D C:\Users\Sam.Desktop\Application Data\Skype
2012-05-16 21:26 - 2012-05-16 21:50 - 00000000 ____D C:\Users\Sam.Desktop\AppData\Roaming\Skype