Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-09-2012
Ran by SYSTEM at 22-09-2012 17:05:27
Running from G:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [] [x]
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] ()
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [480608 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [460088 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [742712 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1697064 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [TWebCamera] "C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [2454840 2010-02-24] (TOSHIBA CORPORATION.)
HKLM\...\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [163840 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [22840 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [30040 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [467816 2010-03-19] (TOSHIBA Corporation)
HKLM\...\Run: [VodafoneNZ_McciTrayApp] "C:\Program Files\VodafoneNZ\McciTrayApp.exe" [1574912 2010-12-06] (Alcatel-Lucent)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-02] (Malwarebytes Corporation)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [runfile] C:\Program Files\DisplayLink\DLsetup\NoConsoleExe.exe [7168 2011-03-17] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-25] (Microsoft Corporation)
HKU\Rajneel\...\Run: [AdobeBridge] [x]
HKU\Rajneel\...\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe [3077528 2011-08-16] ()
HKU\Rajneel\...\Run: [Akamai NetSession Interface] "C:\Users\Rajneel\AppData\Local\Akamai\netsession_win.exe" [4440896 2012-08-09] (Akamai Technologies, Inc.)
HKU\Rajneel\...\Run: [MPC] "C:\ProgramData\0e4a2c\MP0e4_8040.exe" /s [x]
HKU\Rajneel\...\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [75624 2012-01-05] (Alcohol Soft Development Team)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Startup: C:\Users\Rajneel\Start Menu\Programs\Startup\networx - Shortcut.lnk
ShortcutTarget: networx - Shortcut.lnk -> (No File)
==================== Services (Whitelisted) ===================
2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
2 cfWiMAXService; "C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe" [185712 2010-01-28] (TOSHIBA CORPORATION)
2 ConfigFree Service; "C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe" [46448 2009-03-10] (TOSHIBA CORPORATION)
2 DisplayLinkService; "C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe" [5240168 2011-04-10] (DisplayLink Corp.)
3 GameConsoleService; "C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe" [238328 2009-12-03] (WildTangent, Inc.)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-02] (Malwarebytes Corporation)
2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-10-06] (TOSHIBA Corporation)
2 TosCoSrv; "C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe" [468320 2009-11-05] (TOSHIBA Corporation)
3 TOSHIBA HDD SSD Alert Service; "C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe" [111960 2010-02-05] (TOSHIBA Corporation)
2 Akamai; c:\program files\common files\akamai/netsession_win_5891ae0.dll [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 MSSQL$MSSMLBIZ; "c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [x]
2 MSSQL$SQLEXPRESS; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
==================== Drivers (Whitelisted) ====================
3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5340160 2010-03-15] (ATI Technologies Inc.)
3 DisplayLinkUsbPort; C:\Windows\System32\DRIVERS\DisplayLinkUsbPort_5.6.31854.0.sys [21888 2012-05-27] (
http://libusb-win32.sourceforge.net)
3 dlkmd; C:\Windows\system32\drivers\dlkmd.sys [182896 2011-04-10] (DisplayLink Corp.)
0 dlkmdldr; C:\Windows\System32\drivers\dlkmdldr.sys [14448 2011-04-10] (DisplayLink Corp.)
3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtport.sys [12160 2009-09-28] (LG Electronics Inc.)
3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbus.sys [10496 2009-09-28] (LG Electronics Inc.)
3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmodem.sys [12928 2009-09-28] (LG Electronics Inc.)
3 MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [22344 2012-07-02] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
1 SASDIFSV; \??\C:\Users\Rajneel\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [12872 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Users\Rajneel\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS [67656 2010-05-10] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2012-06-15] (Duplex Secure Ltd.)
3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2010-04-12] (LG Electronics Inc.)
3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24960 2010-04-12] (LG Electronics Inc.)
3 EagleXNt; \??\C:\windows\system32\drivers\EagleXNt.sys [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-09-22 17:05 - 2012-09-22 17:05 - 00000000 ____D C:\FRST
2012-09-21 05:17 - 2012-09-21 05:17 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eweqqvgx.sys
2012-09-21 05:14 - 2012-09-21 05:14 - 00001281 ____A C:\Users\Rajneel\Desktop\shutdown.lnk
2012-09-21 04:31 - 2012-09-21 04:31 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-21 04:29 - 2012-09-21 04:29 - 10288512 ____A (Microsoft Corporation) C:\Users\Rajneel\Downloads\mseinstall(1).exe
2012-09-21 03:03 - 2012-09-21 03:03 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{811CC38D-B279-46BB-A097-8F2928761674}
2012-09-20 05:09 - 2012-09-20 05:10 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{80F3B1A6-33DA-4B79-B7DA-F938BFEE56D1}
2012-09-19 04:12 - 2012-09-19 04:12 - 00143728 ____A C:\Windows\Minidump\092012-19281-01.dmp
2012-09-19 01:04 - 2012-09-19 01:05 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{D32C4D40-BAEC-4D0E-BD7F-723A4838F4A8}
2012-09-17 23:55 - 2012-09-17 23:55 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{D8A9B0D7-AB08-440B-85D6-CA16D92E4255}
2012-09-17 02:03 - 2012-09-17 02:03 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{F7B54E83-416B-4325-86A8-9FE65F0FF130}
2012-09-16 02:30 - 2012-09-16 02:30 - 00143728 ____A C:\Windows\Minidump\091612-20311-01.dmp
2012-09-16 01:19 - 2012-09-19 04:12 - 209068520 ____A C:\Windows\MEMORY.DMP
2012-09-16 01:19 - 2012-09-19 04:12 - 00000000 ____D C:\Windows\Minidump
2012-09-16 01:19 - 2012-09-16 01:19 - 00143728 ____A C:\Windows\Minidump\091612-20794-01.dmp
2012-09-15 19:34 - 2012-09-15 19:34 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{613A3723-7D1A-43F9-9B74-605728CAB71E}
2012-09-15 05:21 - 2012-09-15 05:22 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{E5B2A0AD-8B00-4A77-9BBD-476BFD11964B}
2012-09-14 17:21 - 2012-09-14 17:21 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{ADED95C6-D291-487A-A213-57D31193787E}
2012-09-14 00:26 - 2012-09-14 00:26 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{22288931-EA7F-4CCE-9C91-83D671139EF3}
2012-09-13 03:00 - 2012-09-13 03:00 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{36E389B2-4C3C-4AD2-86C3-0E61CE7192F3}
2012-09-12 03:47 - 2012-09-12 03:47 - 00000000 ____D C:\Users\Rajneel\Desktop\PokeMMO-Client
2012-09-12 03:37 - 2012-09-12 03:40 - 06712943 ____A C:\Users\Rajneel\Downloads\PokeMMO-Client.zip
2012-09-12 00:56 - 2012-09-12 00:56 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{EB412FB6-B665-4205-BC91-84564E263E30}
2012-09-11 02:18 - 2012-09-11 02:18 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{56D1ED00-339D-43DA-A771-D3D103E7AB83}
2012-09-10 05:04 - 2012-09-10 05:04 - 00000000 ____D C:\Users\Rajneel\Desktop\BASTILLE_-_OTHER_PEOPLE'S_HEARTACHE
2012-09-10 04:46 - 2012-09-10 04:52 - 62947359 ____A C:\Users\Rajneel\Downloads\BASTILLE_-_OTHER_PEOPLE'S_HEARTACHE.zip
2012-09-10 00:01 - 2012-09-10 00:01 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{B1A6D14A-B821-4C61-B25C-1C63CEE50FC9}
2012-09-08 23:56 - 2012-09-08 23:56 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{650F541B-B4BD-4B52-9989-6C58DD4618DC}
2012-09-08 18:00 - 2012-09-08 18:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2012-09-07 17:51 - 2012-09-07 17:51 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{DA0F7B07-2300-4AB6-82E4-BF97DDE74826}
2012-09-06 18:19 - 2012-09-06 18:19 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{18002C75-D938-4019-A5E8-29CA4989A758}
2012-09-06 02:45 - 2012-09-06 02:45 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{EE990674-75A9-427A-89CB-70F0C38E0D1E}
2012-09-05 04:43 - 2012-09-05 04:44 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{AF1C9306-FA28-4C35-B60C-F53C97521BF3}
2012-09-05 04:35 - 2012-09-05 04:35 - 39539243 ____A C:\Users\Rajneel\Documents\c2.psd
2012-09-05 04:34 - 2012-09-05 04:34 - 55372746 ____A C:\Users\Rajneel\Documents\n2.psd
2012-09-05 04:34 - 2012-09-05 04:34 - 46745082 ____A C:\Users\Rajneel\Documents\d2.psd
2012-09-05 04:34 - 2012-09-05 04:34 - 22647172 ____A C:\Users\Rajneel\Documents\t1.psd
2012-09-05 04:33 - 2012-09-05 04:33 - 11724216 ____A C:\Users\Rajneel\Documents\0000063.psd
2012-09-04 01:30 - 2012-09-04 01:30 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{9E4702F5-D523-4E3E-9C23-F8A48BA79242}
2012-09-03 21:21 - 2012-09-03 21:21 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-09-02 19:03 - 2012-09-02 19:03 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{248A5454-1953-456C-89D4-B08D5C8219C6}
2012-09-01 18:28 - 2012-09-01 18:29 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{899338A7-11F1-4318-8750-026AD3FE92C0}
2012-08-31 23:31 - 2012-08-31 23:31 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{0810DC22-CF2C-42EC-B3C0-9D6222CF23DB}
2012-08-31 01:35 - 2012-08-31 01:35 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{590A17A5-22F3-4EC3-A57D-871B73F1F001}
2012-08-30 01:05 - 2012-08-30 01:06 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{A2282862-D2A0-4578-9D31-CDC70C82E0C6}
2012-08-28 17:18 - 2012-08-28 17:18 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{6F88A3A7-CAB6-47BA-9E04-2D415AB2E1D4}
2012-08-27 17:18 - 2012-08-27 17:19 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{B6338DB8-3310-448E-96E6-632C1BE91ADA}
2012-08-27 00:21 - 2012-08-27 03:11 - 00000000 ____D C:\Users\Rajneel\Desktop\teen wolf
2012-08-26 17:07 - 2012-08-26 17:07 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{C3C18081-E58C-4D70-B328-E09A390F6FBB}
2012-08-25 22:52 - 2012-08-25 22:55 - 00000000 ____D C:\Program Files\SPSS
2012-08-25 18:56 - 2012-08-25 18:56 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{73546CB6-5255-4E71-ACA3-78448DD8A0C0}
2012-08-24 18:15 - 2012-08-24 18:16 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{F5EC7237-250F-4CA0-893D-76D495E30497}
2012-08-24 00:04 - 2012-08-24 00:04 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{A39312B8-6D1A-4310-89B8-C49E68F20910}
2012-08-23 00:27 - 2012-08-23 00:28 - 00000000 ____D C:\Users\Rajneel\AppData\Local\{241D6DCF-84C9-4D15-8824-C253A5A26C2E}
==================== 3 Months Modified Files ==================
2012-09-21 05:17 - 2012-09-21 05:17 - 00043600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\eweqqvgx.sys
2012-09-21 05:16 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-21 05:15 - 2011-01-20 01:09 - 00046838 ____A C:\Windows\setupact.log
2012-09-21 05:14 - 2012-09-21 05:14 - 00001281 ____A C:\Users\Rajneel\Desktop\shutdown.lnk
2012-09-21 04:32 - 2011-01-20 01:11 - 01714614 ____A C:\Windows\WindowsUpdate.log
2012-09-21 04:31 - 2011-01-13 02:41 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-21 04:31 - 2010-03-22 22:55 - 00854120 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-21 04:29 - 2012-09-21 04:29 - 10288512 ____A (Microsoft Corporation) C:\Users\Rajneel\Downloads\mseinstall(1).exe
2012-09-21 04:27 - 2012-01-25 19:36 - 00001082 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-09-21 00:13 - 2009-07-13 20:34 - 00016304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-21 00:13 - 2009-07-13 20:34 - 00016304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-19 04:13 - 2009-07-13 20:53 - 00032652 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-19 04:12 - 2012-09-19 04:12 - 00143728 ____A C:\Windows\Minidump\092012-19281-01.dmp
2012-09-19 04:12 - 2012-09-16 01:19 - 209068520 ____A C:\Windows\MEMORY.DMP
2012-09-16 02:30 - 2012-09-16 02:30 - 00143728 ____A C:\Windows\Minidump\091612-20311-01.dmp
2012-09-16 01:19 - 2012-09-16 01:19 - 00143728 ____A C:\Windows\Minidump\091612-20794-01.dmp
2012-09-13 05:41 - 2012-04-07 23:39 - 00000870 ____A C:\Users\Rajneel\Desktop\New Text Document.txt
2012-09-12 03:40 - 2012-09-12 03:37 - 06712943 ____A C:\Users\Rajneel\Downloads\PokeMMO-Client.zip
2012-09-10 04:52 - 2012-09-10 04:46 - 62947359 ____A C:\Users\Rajneel\Downloads\BASTILLE_-_OTHER_PEOPLE'S_HEARTACHE.zip
2012-09-05 04:35 - 2012-09-05 04:35 - 39539243 ____A C:\Users\Rajneel\Documents\c2.psd
2012-09-05 04:34 - 2012-09-05 04:34 - 55372746 ____A C:\Users\Rajneel\Documents\n2.psd
2012-09-05 04:34 - 2012-09-05 04:34 - 46745082 ____A C:\Users\Rajneel\Documents\d2.psd
2012-09-05 04:34 - 2012-09-05 04:34 - 22647172 ____A C:\Users\Rajneel\Documents\t1.psd
2012-09-05 04:33 - 2012-09-05 04:33 - 11724216 ____A C:\Users\Rajneel\Documents\0000063.psd
2012-08-30 03:23 - 2012-03-16 03:35 - 00000728 ____A C:\Users\Rajneel\.drjava
2012-08-26 16:12 - 2009-07-13 20:33 - 03783808 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-25 23:46 - 2010-08-25 17:17 - 00115120 ____A C:\Users\Rajneel\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-19 01:54 - 2012-07-28 20:40 - 00000425 ____A C:\Users\Rajneel\Desktop\current classes.txt
2012-08-18 23:06 - 2012-08-18 23:06 - 43797043 ____A C:\Users\Rajneel\Desktop\Call_of_Duty_for_N00BS___How_to_Improve_Your_Game.flv
2012-08-15 03:20 - 2012-08-15 03:19 - 68595484 ____A C:\Users\Rajneel\Desktop\videoplayback_video_mp4_Object.mp4
2012-08-13 04:11 - 2012-07-19 22:25 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-13 04:11 - 2011-11-30 18:30 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-08 23:39 - 2011-01-04 22:24 - 00007602 ____A C:\Users\Rajneel\AppData\Local\resmon.resmoncfg
2012-08-05 02:39 - 2012-08-05 02:39 - 00000758 ____A C:\Users\Rajneel\Downloads\Game1vs2.csv
2012-08-05 00:16 - 2012-08-05 00:16 - 00000470 ____A C:\Users\Rajneel\Downloads\Coaster%20Data.csv
2012-08-02 02:06 - 2012-06-20 23:21 - 00000732 ____A C:\Users\Rajneel\Desktop\songz.txt
2012-08-01 04:19 - 2012-08-01 04:19 - 04903183 ____A C:\Users\Rajneel\Downloads\The Devil Wears Prada_Group 3.pptx
2012-08-01 02:52 - 2012-08-01 02:50 - 05953400 ____A (ManiacTools.com ) C:\Users\Rajneel\Downloads\m4a-to-mp3-converter.exe
2012-07-31 03:54 - 2012-07-31 03:44 - 114689849 ____A C:\Users\Rajneel\Downloads\Kendrick+Lamar+-+Overly+Dedicated.zip
2012-07-26 02:10 - 2012-07-26 02:10 - 39856063 ____A C:\Users\Rajneel\Desktop\MW3__ULTIMATE_Custom_Class_Tutorial.flv
2012-07-25 22:57 - 2012-07-25 22:57 - 33015963 ____A C:\Users\Rajneel\Desktop\MW3_Type_95_MOAB__41_1.flv
2012-07-25 22:53 - 2012-07-25 22:53 - 46726112 ____A C:\Users\Rajneel\Desktop\FIRST_2_M.O.A.B_s_in_1_Game.flv
2012-07-24 23:54 - 2012-07-24 23:54 - 32583775 ____A C:\Users\Rajneel\Desktop\Ab_Soul_Day_In_A_Life.flv
2012-07-21 21:27 - 2012-07-21 21:24 - 24469187 ____A C:\Users\Rajneel\Desktop\FIFA 12 _ Race to Division One _ PACE PACE PACE!!! 33.flv
2012-07-21 21:24 - 2012-07-21 21:24 - 09933531 ____A C:\Users\Rajneel\Desktop\FIFA 12 Top 5 Goals of the Week #42.flv
2012-07-02 17:46 - 2011-01-13 02:35 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-30 02:47 - 2012-06-30 02:47 - 39868373 ____A C:\Users\Rajneel\Desktop\Great_Modern_Warfare_Multiplayer_Guides_and_Tips_For_Beginners.flv
ZeroAccess:
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\@
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\L
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\n
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\U
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\L\00000004.@
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\L\201d3dde
C:\Windows\Installer\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\U\80000032.@
ZeroAccess:
C:\Users\Rajneel\AppData\Local\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}
C:\Users\Rajneel\AppData\Local\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\@
C:\Users\Rajneel\AppData\Local\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\L
C:\Users\Rajneel\AppData\Local\{6fca6a87-7ed2-144a-f90a-7090a8acec9b}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-09 23:08:06
Restore point made on: 2012-08-17 01:38:54
Restore point made on: 2012-08-25 22:51:15
Restore point made on: 2012-09-13 01:30:14
Restore point made on: 2012-09-21 00:14:01
==================== Memory info ===========================
Percentage of memory in use: 21%
Total physical RAM: 1786.9 MB
Available physical RAM: 1405.46 MB
Total Pagefile: 1786.9 MB
Available Pagefile: 1411.51 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.95 MB
==================== Partitions =============================
1 Drive c: (S3A8954D004) (Fixed) (Total:286.31 GB) (Free:159.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.29 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive g: (RSHA541) (Removable) (Total:3.7 GB) (Free:2.48 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 Online 3801 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 1500 MB 1024 KB
Partition 2 Primary 286 GB 1501 MB
Partition 3 Primary 10 GB 287 GB
=========================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System NTFS Partition 1500 MB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C S3A8954D004 NTFS Partition 286 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3800 MB 40 KB
=========================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G RSHA541 FAT32 Removable 3800 MB Healthy
=========================================================
Last Boot: 2012-09-17 01:13
==================== End Of Log ============================