Shadowhawk642
Posts: 10 +0
I have a couple instances of the sirefif virus showing up on my laptop running Windows Vista 64-bit. I have read through the forums and have run the Farbar tool. Logs posted below...
Scan result of Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 17-08-2012 21:19:22
Running from F:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [237056 2007-12-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [487264 2008-11-04] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [52560 2007-12-06] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [518008 2008-06-02] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [882488 2008-11-17] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] RAVCpl64.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START [x]
HKLM-x32\...\Run: [NDSTray.exe] NDSTray.exe [x]
HKLM-x32\...\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP [422400 2007-04-16] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [SVPWUTIL] "C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" SVPwUTIL [438272 2007-09-19] (TOSHIBA)
HKLM-x32\...\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" [34352 2006-11-06] ()
HKLM-x32\...\Run: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe" [143360 2007-12-13] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe" [188416 2008-07-10] (CyberLink)
HKLM-x32\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [417792 2008-04-29] (Chicony)
HKLM-x32\...\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [1312080 2009-09-10] (Malwarebytes Corporation)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-09-08] (Apple Inc.)
HKLM-x32\...\Run: [AmazonGSDownloaderTray] "C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [326144 2009-10-23] (Amazon.com)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1996200 2012-06-27] (LogMeIn Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
HKU\Storm\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Storm\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\UpdatusUser\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Services (Whitelisted) ======
2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [2369960 2012-06-27] (LogMeIn Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 TNaviSrv; C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312 2008-11-14] (TOSHIBA Corporation)
2 WTouchService; C:\Program Files\WTouch\WTouchService.exe [127272 2009-07-15] (Wacom Technology, Corp.)
2 Norton Internet Security; "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1 [x]
========================== Drivers (Whitelisted) =============
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
0 LPCFilter; C:\Windows\SysWow64\Drivers\LPCFilter.sys [32040 2008-05-07] (COMPAL ELECTRONIC INC.)
2 OpenLibSys; \??\C:\Program Files (x86)\NXP\FM Radio\OpenLibSysX64.sys [14544 2007-10-19] (OpenLibSys.org)
4 tosrfec; C:\Windows\System32\Drivers\tosrfec.sys [18944 2006-10-23] (TOSHIBA Corporation)
1 Beep; [x]
3 catchme; \??\C:\ComboFix\catchme.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 Tosrfcom; [x]
3 TpChoice; C:\Windows\System32\DRIVERS\TpChoice.sys [x]
3 WinRing0_1_2_0; \??\C:\Users\Storm\Downloads\RealTemp_340\WinRing0x64.sys [x]
3 X6va009; \??\C:\Windows\SysWOW64\Drivers\X6va009 [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-17 21:18 - 2012-08-17 21:18 - 00000000 ____D C:\FRST
2012-08-17 20:06 - 2012-08-17 20:06 - 00000134 ____A C:\Users\Storm\Desktop\Programs and Features - Shortcut.lnk
2012-08-17 17:58 - 2012-08-17 17:59 - 00000000 ___SD C:\ComboFix
2012-08-17 17:54 - 2012-08-17 17:54 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.037662617EFA1186
2012-08-17 17:53 - 2012-08-17 18:02 - 00000000 ___SD C:\32788R22FWJFW
2012-08-17 09:21 - 2012-08-17 09:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-16 19:44 - 2012-08-16 20:16 - 00000000 ____D C:\Users\Storm\Desktop\StarStealingPrinceFullwRTPV2.1
2012-08-16 19:20 - 2012-08-16 19:36 - 228696649 ____A C:\Users\Storm\Downloads\StarStealingPrinceFullwRTPV2.1.rar
2012-08-16 12:41 - 2012-08-16 12:41 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-16 12:37 - 2012-08-16 12:37 - 00140827 ____A C:\Windows\SysWOW64\Drivers\str.sys
2012-08-15 21:28 - 2012-07-04 06:33 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-15 15:16 - 2012-06-28 03:37 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-15 15:16 - 2012-06-28 03:37 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-15 15:16 - 2012-06-28 03:37 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-15 15:16 - 2012-06-28 03:35 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-08-15 15:16 - 2012-06-28 03:33 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 06008320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-15 15:16 - 2012-06-28 03:31 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-15 15:16 - 2012-06-28 01:59 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-08-15 15:16 - 2012-06-28 00:19 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-08-15 15:16 - 2012-06-28 00:19 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-15 15:16 - 2012-06-28 00:18 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-08-15 15:16 - 2012-06-28 00:17 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-15 15:16 - 2012-06-27 22:53 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-15 15:16 - 2012-06-27 22:53 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-15 15:16 - 2012-06-27 22:53 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-15 15:16 - 2012-06-27 22:51 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-08-15 15:16 - 2012-06-27 22:48 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-15 15:16 - 2012-06-27 22:48 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-08-15 15:16 - 2012-06-27 22:48 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-08-15 15:16 - 2012-06-27 21:54 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-08-15 15:16 - 2012-06-27 21:11 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-15 15:16 - 2012-06-27 21:11 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-08-15 15:16 - 2012-06-27 21:10 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-15 15:16 - 2012-06-27 21:10 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-08-15 15:16 - 2012-06-16 03:19 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-08-15 15:16 - 2012-06-16 03:14 - 00727040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-15 15:16 - 2012-06-15 23:02 - 00610816 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-15 15:16 - 2012-06-15 22:58 - 00818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-15 15:16 - 2012-05-11 08:34 - 00788480 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-15 15:16 - 2012-05-11 07:57 - 00623616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\localspl.dll
2012-08-15 15:15 - 2012-06-29 08:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-15 15:15 - 2012-06-29 08:01 - 00467968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-15 15:11 - 2012-08-15 15:36 - 00000000 ____D C:\Users\Storm\AppData\Roaming\The Mirror Lied
2012-08-15 14:32 - 2011-09-10 00:40 - 00000000 ____D C:\Users\Storm\Desktop\The Mirror Lied
2012-08-15 14:02 - 2012-08-15 14:27 - 10185946 ____A C:\Users\Storm\Downloads\The_Mirror_Lied-v2.zip
2012-08-14 21:58 - 2012-08-14 22:13 - 136441593 ____A C:\Users\Storm\Downloads\P4U_Complete_Character_Sprites.7z
2012-08-14 21:32 - 2012-08-14 21:34 - 33493196 ____A C:\Users\Storm\Downloads\imageex.7z
2012-08-14 21:27 - 2012-08-14 22:20 - 00000000 ____D C:\Users\Storm\Desktop\P4U
2012-08-14 21:26 - 2012-08-14 21:30 - 47515654 ____A C:\Users\Storm\Downloads\avatar.7z
2012-08-06 18:44 - 2012-08-06 20:38 - 00000000 ____D C:\Users\Storm\Desktop\Bakemonogatari
2012-07-26 13:25 - 2012-07-26 13:26 - 00000000 ____D C:\Users\Storm\Desktop\Supernatural Anime
============ 3 Months Modified Files ========================
2012-08-17 20:15 - 2009-10-19 23:25 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-17 20:14 - 2010-12-28 17:51 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-17 20:14 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-17 20:14 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-17 20:14 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-17 20:08 - 2011-07-09 01:33 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-19539739-2347143033-1963601051-1000UA.job
2012-08-17 20:06 - 2012-08-17 20:06 - 00000134 ____A C:\Users\Storm\Desktop\Programs and Features - Shortcut.lnk
2012-08-17 18:04 - 2009-10-16 03:21 - 00007916 ____A C:\Users\Storm\AppData\Local\d3d9caps.dat
2012-08-17 18:01 - 2010-12-28 17:51 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-17 17:54 - 2012-08-17 17:54 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.037662617EFA1186
2012-08-17 17:54 - 2012-07-12 18:20 - 04733838 ____R (Swearware) C:\Users\Storm\Desktop\ComboFix.exe
2012-08-17 09:22 - 2011-11-03 09:47 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-17 09:22 - 2009-07-29 07:59 - 01108881 ____A C:\Windows\WindowsUpdate.log
2012-08-17 09:21 - 2011-11-03 09:47 - 00781174 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-17 09:14 - 2006-11-02 07:42 - 00032622 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-17 09:13 - 2012-04-18 10:18 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-17 09:13 - 2011-05-12 19:28 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-17 09:13 - 2009-10-14 14:39 - 00085888 ____A C:\Users\Storm\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-17 09:11 - 2006-11-02 07:21 - 00328848 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 19:36 - 2012-08-16 19:20 - 228696649 ____A C:\Users\Storm\Downloads\StarStealingPrinceFullwRTPV2.1.rar
2012-08-16 12:37 - 2012-08-16 12:37 - 00140827 ____A C:\Windows\SysWOW64\Drivers\str.sys
2012-08-16 11:08 - 2011-07-09 01:33 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-19539739-2347143033-1963601051-1000Core.job
2012-08-16 09:24 - 2006-11-02 04:46 - 00766008 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-15 21:24 - 2006-11-02 04:35 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-08-15 14:27 - 2012-08-15 14:02 - 10185946 ____A C:\Users\Storm\Downloads\The_Mirror_Lied-v2.zip
2012-08-14 22:13 - 2012-08-14 21:58 - 136441593 ____A C:\Users\Storm\Downloads\P4U_Complete_Character_Sprites.7z
2012-08-14 21:34 - 2012-08-14 21:32 - 33493196 ____A C:\Users\Storm\Downloads\imageex.7z
2012-08-14 21:30 - 2012-08-14 21:26 - 47515654 ____A C:\Users\Storm\Downloads\avatar.7z
2012-07-29 22:10 - 2009-10-30 11:47 - 00038912 ____A C:\Users\Storm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-14 00:08 - 2012-07-13 21:05 - 158874719 ____A C:\Users\Storm\Downloads\bloodtracks_030712_10378-L4D2.zip
2012-07-13 21:35 - 2012-07-13 21:09 - 158874719 ____A C:\Users\Storm\Downloads\bloodtracks_030712_10378-L4D2 (1).zip
2012-07-12 19:01 - 2012-07-12 18:58 - 12621696 ____A (Microsoft Corporation) C:\Users\Storm\Downloads\mseinstall.exe
2012-07-12 18:56 - 2006-11-02 04:33 - 65536000 ____A C:\Windows\System32\config\software_previous
2012-07-12 18:56 - 2006-11-02 04:33 - 21233664 ____A C:\Windows\System32\config\system_previous
2012-07-12 18:52 - 2006-11-02 04:33 - 56623104 ____A C:\Windows\System32\config\components_previous
2012-07-12 18:52 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-07-12 18:47 - 2008-01-20 19:26 - 00735534 ____A C:\Windows\PFRO.log
2012-07-12 18:47 - 2006-11-02 04:34 - 00000215 ____A C:\Windows\system.ini
2012-07-12 17:49 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-07-12 17:49 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\default_previous
2012-07-09 23:05 - 2012-07-09 23:02 - 09907915 ____A (Adobe Systems, Inc.) C:\Users\Storm\Desktop\katawa_crash_beta_8-36.exe
2012-07-07 20:29 - 2012-07-07 20:29 - 01391104 ____A C:\Users\Storm\Downloads\apploc.msi
2012-07-06 22:00 - 2012-07-06 21:01 - 161912074 ____A C:\Users\Storm\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68] (1).zip
2012-07-06 20:49 - 2012-07-06 20:44 - 04957875 ____A C:\Users\Storm\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68].zip
2012-07-06 20:16 - 2012-07-06 19:42 - 112861440 ____A C:\Users\Storm\Downloads\Supersekritfiles-s.part1.rar
2012-07-06 20:15 - 2012-07-06 19:42 - 154213571 ____A C:\Users\Storm\Downloads\Supersekritfiles-s.part2.rar
2012-07-05 15:25 - 2012-07-05 15:12 - 104921110 ____A C:\Users\Storm\Downloads\lbac_300612_17711-L4D2.zip
2012-07-05 15:15 - 2012-07-05 15:11 - 18411754 ____A C:\Users\Storm\Downloads\vanillaghosthouse_020511_9711-L4D2.zip
2012-07-04 17:59 - 2012-07-04 17:37 - 96140763 ____A C:\Users\Storm\Downloads\Ouran High School Host Club Soundtrack & Character Song 2.zip
2012-07-04 17:42 - 2012-07-04 17:37 - 95248672 ____A C:\Users\Storm\Downloads\Ouran.High.School.Host.Club [Soundtrack.&.Character.Song.1].rar
2012-07-04 17:36 - 2012-07-04 17:35 - 00281448 ____A (Premium) C:\Users\Storm\Downloads\Ouran High School Host Club Soundtrack amp Character Song 2.zip.exe
2012-07-04 06:33 - 2012-08-15 21:28 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-03 20:08 - 2012-07-03 19:02 - 281950221 ____A C:\Users\Storm\Downloads\ihatemountains_290111_5834.zip
2012-07-03 03:55 - 2012-07-03 03:54 - 07524202 ____A C:\Users\Storm\Downloads\mobstadium2012l4d2final_090910_4442-L4D2.zip
2012-07-03 03:53 - 2012-07-03 03:50 - 24160697 ____A C:\Users\Storm\Downloads\spacejockeys_020610_5280-L4D2.zip
2012-07-03 03:52 - 2012-07-03 03:52 - 16769075 ____A C:\Users\Storm\Downloads\wormwoodv2_121210_6925-L4D2.zip
2012-07-03 03:52 - 2012-07-03 03:52 - 12533770 ____A C:\Users\Storm\Downloads\thereturnofthejockeys_280411_10066-L4D2.zip
2012-07-01 13:24 - 2012-06-30 23:18 - 172610288 ____A C:\Users\Storm\Downloads\hauntedforest_v3_230411_6923-L4D2.zip
2012-06-30 23:42 - 2012-06-30 23:29 - 172610288 ____A C:\Users\Storm\Downloads\hauntedforest_v3_230411_6923-L4D2 (1).zip
2012-06-30 11:32 - 2012-06-30 11:32 - 00285920 ____A C:\Windows\Minidump\Mini063012-01.dmp
2012-06-30 11:32 - 2009-10-18 23:50 - 580171102 ____A C:\Windows\MEMORY.DMP
2012-06-29 17:22 - 2012-06-29 17:22 - 00001856 ____A C:\Users\Storm\Desktop\Forget Me Not Annie.lnk
2012-06-29 17:20 - 2009-07-29 08:30 - 00030274 ____A C:\Windows\DirectX.log
2012-06-29 08:20 - 2012-08-15 15:15 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-06-29 08:01 - 2012-08-15 15:15 - 00467968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-06-28 03:37 - 2012-08-15 15:16 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-28 03:37 - 2012-08-15 15:16 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-28 03:37 - 2012-08-15 15:16 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-28 03:35 - 2012-08-15 15:16 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-06-28 03:33 - 2012-08-15 15:16 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 06008320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-28 03:31 - 2012-08-15 15:16 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-28 01:59 - 2012-08-15 15:16 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-06-28 00:19 - 2012-08-15 15:16 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-06-28 00:19 - 2012-08-15 15:16 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-28 00:18 - 2012-08-15 15:16 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-06-28 00:17 - 2012-08-15 15:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-27 22:53 - 2012-08-15 15:16 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-27 22:53 - 2012-08-15 15:16 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-27 22:53 - 2012-08-15 15:16 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-27 22:51 - 2012-08-15 15:16 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-06-27 22:48 - 2012-08-15 15:16 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-27 22:48 - 2012-08-15 15:16 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-06-27 22:48 - 2012-08-15 15:16 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-06-27 21:54 - 2012-08-15 15:16 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-06-27 21:11 - 2012-08-15 15:16 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-27 21:11 - 2012-08-15 15:16 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-06-27 21:10 - 2012-08-15 15:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-27 21:10 - 2012-08-15 15:16 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-06-16 03:19 - 2012-08-15 15:16 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-06-16 03:14 - 2012-08-15 15:16 - 00727040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-15 23:02 - 2012-08-15 15:16 - 00610816 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-06-15 22:58 - 2012-08-15 15:16 - 00818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 13:35 - 2012-06-14 13:22 - 109033102 ____A C:\Users\Storm\Downloads\Ib.rar
2012-06-09 11:50 - 2012-06-09 11:49 - 00464924 ____A C:\Windows\dd_vcredistMSI4394.txt
2012-06-09 11:50 - 2012-06-09 11:49 - 00011638 ____A C:\Windows\dd_vcredistUI4394.txt
2012-06-08 18:07 - 2012-06-08 16:10 - 209715200 ____A C:\Users\Storm\Downloads\dBsoundworks_-_Sup.e.rMe.atB.o.y_OST.2010.320.part1.rar
2012-06-08 14:55 - 2012-06-08 14:51 - 17792029 ____A C:\Users\Storm\Downloads\dBsoundworks_-_Sup.e.rMe.atB.o.y_OST.2010.320.part2.rar
2012-06-08 09:59 - 2012-07-10 15:05 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 09:47 - 2012-07-10 15:05 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-06-07 21:03 - 2012-06-07 20:57 - 00414000 ____A C:\Users\Storm\Downloads\EAX 2.zip
2012-06-07 14:03 - 2012-06-07 14:02 - 00434748 ____A C:\Users\Storm\AppData\Local\dd_vcredistMSI0D63.txt
2012-06-07 14:03 - 2012-06-07 14:02 - 00011444 ____A C:\Users\Storm\AppData\Local\dd_vcredistUI0D63.txt
2012-06-07 14:02 - 2012-06-07 14:02 - 00010552 ____A C:\Users\Storm\AppData\Local\dd_vcredistUI0D64.txt
2012-06-05 08:47 - 2012-07-10 15:05 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 08:47 - 2012-07-10 15:05 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 08:22 - 2012-07-10 15:05 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 08:22 - 2012-07-10 15:05 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-04 07:29 - 2012-07-10 15:05 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-04 01:25 - 2012-06-04 01:25 - 00467414 ____A C:\Windows\dd_vcredistMSI5F4C.txt
2012-06-04 01:25 - 2012-06-04 01:25 - 00011622 ____A C:\Windows\dd_vcredistUI5F4C.txt
2012-06-02 15:53 - 2012-06-02 15:51 - 00428770 ____A C:\Users\Storm\AppData\Local\dd_vcredistMSI5A7A.txt
2012-06-02 15:53 - 2012-06-02 15:51 - 00011462 ____A C:\Users\Storm\AppData\Local\dd_vcredistUI5A7A.txt
2012-06-02 14:19 - 2012-06-21 12:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 12:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-21 12:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 12:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 12:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 14:12 - 2012-06-21 12:05 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 14:12 - 2012-06-21 12:05 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-02 13:14 - 2012-06-02 13:14 - 00000220 ____A C:\Users\Storm\Desktop\Psychonauts.url
2012-06-01 16:22 - 2012-07-10 15:05 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:22 - 2012-07-10 15:05 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:05 - 2012-07-10 15:05 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 16:04 - 2012-07-10 15:05 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 16:03 - 2012-07-10 15:05 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-05-31 22:17 - 2012-05-31 22:17 - 00872126 ____A C:\Users\Storm\Downloads\YUGIOH_5Ds_Characters_Gmod_PASADENAOPOSSUM.7z
2012-05-31 03:37 - 2009-07-29 08:14 - 00000012 ____A C:\Users\Public\fm_user.cfg
2012-05-31 03:37 - 2009-07-29 08:14 - 00000009 ____A C:\Users\Public\fm_favorite.cfg
2012-05-28 16:24 - 2012-05-28 16:24 - 00001856 ____A C:\Users\Storm\Desktop\PARANORMAL - BETA 4.lnk
2012-05-28 16:14 - 2012-05-28 15:58 - 381167200 ____A (Epic Games, Inc.) C:\Users\Storm\Downloads\UDKInstall-Para-BETA4.exe
2012-05-28 15:41 - 2012-05-28 15:39 - 31842315 ____A C:\Users\Storm\Downloads\Team Starkid w. Darren Criss.zip
2012-05-28 15:03 - 2012-05-28 14:55 - 72002374 ____A C:\Users\Storm\Downloads\Team Starkid SPACE Tour.zip
ZeroAccess:
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\@
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\L
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\n
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U\00000001.@
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U\80000000.@
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U\800000cb.@
ZeroAccess:
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\@
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\L
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe BC81150939BD52DBC7A08C245F1FB229 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4059.96 MB
Available physical RAM: 3508.97 MB
Total Pagefile: 3809.45 MB
Available Pagefile: 3483.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (SQ004951V02) (Fixed) (Total:285.88 GB) (Free:87.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.3 GB) NTFS
4 Drive f: () (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 1913 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 1500 MB 1024 KB
Partition 2 Primary 286 GB 1501 MB
Partition 3 Primary 11 GB 287 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E TOSHIBA SYS NTFS Partition 1500 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C SQ004951V02 NTFS Partition 286 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1913 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 F FAT Removable 1913 MB Healthy
==================================================================================
Last Boot: 2012-08-17 09:22
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 17-08-2012 21:19:22
Running from F:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [237056 2007-12-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [487264 2008-11-04] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [52560 2007-12-06] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [518008 2008-06-02] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [882488 2008-11-17] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] RAVCpl64.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START [x]
HKLM-x32\...\Run: [NDSTray.exe] NDSTray.exe [x]
HKLM-x32\...\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP [422400 2007-04-16] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [SVPWUTIL] "C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" SVPwUTIL [438272 2007-09-19] (TOSHIBA)
HKLM-x32\...\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" [34352 2006-11-06] ()
HKLM-x32\...\Run: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe" [143360 2007-12-13] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe" [188416 2008-07-10] (CyberLink)
HKLM-x32\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [417792 2008-04-29] (Chicony)
HKLM-x32\...\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [1312080 2009-09-10] (Malwarebytes Corporation)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-09-08] (Apple Inc.)
HKLM-x32\...\Run: [AmazonGSDownloaderTray] "C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [326144 2009-10-23] (Amazon.com)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1996200 2012-06-27] (LogMeIn Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
HKU\Storm\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Storm\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\UpdatusUser\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [432640 2008-04-24] (TOSHIBA)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Services (Whitelisted) ======
2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [2369960 2012-06-27] (LogMeIn Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 TNaviSrv; C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312 2008-11-14] (TOSHIBA Corporation)
2 WTouchService; C:\Program Files\WTouch\WTouchService.exe [127272 2009-07-15] (Wacom Technology, Corp.)
2 Norton Internet Security; "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1 [x]
========================== Drivers (Whitelisted) =============
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
0 LPCFilter; C:\Windows\SysWow64\Drivers\LPCFilter.sys [32040 2008-05-07] (COMPAL ELECTRONIC INC.)
2 OpenLibSys; \??\C:\Program Files (x86)\NXP\FM Radio\OpenLibSysX64.sys [14544 2007-10-19] (OpenLibSys.org)
4 tosrfec; C:\Windows\System32\Drivers\tosrfec.sys [18944 2006-10-23] (TOSHIBA Corporation)
1 Beep; [x]
3 catchme; \??\C:\ComboFix\catchme.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 Tosrfcom; [x]
3 TpChoice; C:\Windows\System32\DRIVERS\TpChoice.sys [x]
3 WinRing0_1_2_0; \??\C:\Users\Storm\Downloads\RealTemp_340\WinRing0x64.sys [x]
3 X6va009; \??\C:\Windows\SysWOW64\Drivers\X6va009 [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-17 21:18 - 2012-08-17 21:18 - 00000000 ____D C:\FRST
2012-08-17 20:06 - 2012-08-17 20:06 - 00000134 ____A C:\Users\Storm\Desktop\Programs and Features - Shortcut.lnk
2012-08-17 17:58 - 2012-08-17 17:59 - 00000000 ___SD C:\ComboFix
2012-08-17 17:54 - 2012-08-17 17:54 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.037662617EFA1186
2012-08-17 17:53 - 2012-08-17 18:02 - 00000000 ___SD C:\32788R22FWJFW
2012-08-17 09:21 - 2012-08-17 09:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-16 19:44 - 2012-08-16 20:16 - 00000000 ____D C:\Users\Storm\Desktop\StarStealingPrinceFullwRTPV2.1
2012-08-16 19:20 - 2012-08-16 19:36 - 228696649 ____A C:\Users\Storm\Downloads\StarStealingPrinceFullwRTPV2.1.rar
2012-08-16 12:41 - 2012-08-16 12:41 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-16 12:37 - 2012-08-16 12:37 - 00140827 ____A C:\Windows\SysWOW64\Drivers\str.sys
2012-08-15 21:28 - 2012-07-04 06:33 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-15 15:16 - 2012-06-28 03:37 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-15 15:16 - 2012-06-28 03:37 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-15 15:16 - 2012-06-28 03:37 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-15 15:16 - 2012-06-28 03:35 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-08-15 15:16 - 2012-06-28 03:33 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 06008320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-08-15 15:16 - 2012-06-28 03:32 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-15 15:16 - 2012-06-28 03:31 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-08-15 15:16 - 2012-06-28 03:31 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-15 15:16 - 2012-06-28 01:59 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-08-15 15:16 - 2012-06-28 00:19 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-08-15 15:16 - 2012-06-28 00:19 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-15 15:16 - 2012-06-28 00:18 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-08-15 15:16 - 2012-06-28 00:17 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-15 15:16 - 2012-06-27 22:53 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-15 15:16 - 2012-06-27 22:53 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-15 15:16 - 2012-06-27 22:53 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-15 15:16 - 2012-06-27 22:51 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-15 15:16 - 2012-06-27 22:49 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-08-15 15:16 - 2012-06-27 22:48 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-15 15:16 - 2012-06-27 22:48 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-08-15 15:16 - 2012-06-27 22:48 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-08-15 15:16 - 2012-06-27 22:47 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-08-15 15:16 - 2012-06-27 21:54 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-08-15 15:16 - 2012-06-27 21:11 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-15 15:16 - 2012-06-27 21:11 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-08-15 15:16 - 2012-06-27 21:10 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-15 15:16 - 2012-06-27 21:10 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-08-15 15:16 - 2012-06-16 03:19 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-08-15 15:16 - 2012-06-16 03:14 - 00727040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-15 15:16 - 2012-06-15 23:02 - 00610816 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-15 15:16 - 2012-06-15 22:58 - 00818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-15 15:16 - 2012-05-11 08:34 - 00788480 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-15 15:16 - 2012-05-11 07:57 - 00623616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\localspl.dll
2012-08-15 15:15 - 2012-06-29 08:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-15 15:15 - 2012-06-29 08:01 - 00467968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-15 15:11 - 2012-08-15 15:36 - 00000000 ____D C:\Users\Storm\AppData\Roaming\The Mirror Lied
2012-08-15 14:32 - 2011-09-10 00:40 - 00000000 ____D C:\Users\Storm\Desktop\The Mirror Lied
2012-08-15 14:02 - 2012-08-15 14:27 - 10185946 ____A C:\Users\Storm\Downloads\The_Mirror_Lied-v2.zip
2012-08-14 21:58 - 2012-08-14 22:13 - 136441593 ____A C:\Users\Storm\Downloads\P4U_Complete_Character_Sprites.7z
2012-08-14 21:32 - 2012-08-14 21:34 - 33493196 ____A C:\Users\Storm\Downloads\imageex.7z
2012-08-14 21:27 - 2012-08-14 22:20 - 00000000 ____D C:\Users\Storm\Desktop\P4U
2012-08-14 21:26 - 2012-08-14 21:30 - 47515654 ____A C:\Users\Storm\Downloads\avatar.7z
2012-08-06 18:44 - 2012-08-06 20:38 - 00000000 ____D C:\Users\Storm\Desktop\Bakemonogatari
2012-07-26 13:25 - 2012-07-26 13:26 - 00000000 ____D C:\Users\Storm\Desktop\Supernatural Anime
============ 3 Months Modified Files ========================
2012-08-17 20:15 - 2009-10-19 23:25 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-17 20:14 - 2010-12-28 17:51 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-17 20:14 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-17 20:14 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-17 20:14 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-17 20:08 - 2011-07-09 01:33 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-19539739-2347143033-1963601051-1000UA.job
2012-08-17 20:06 - 2012-08-17 20:06 - 00000134 ____A C:\Users\Storm\Desktop\Programs and Features - Shortcut.lnk
2012-08-17 18:04 - 2009-10-16 03:21 - 00007916 ____A C:\Users\Storm\AppData\Local\d3d9caps.dat
2012-08-17 18:01 - 2010-12-28 17:51 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-17 17:54 - 2012-08-17 17:54 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.037662617EFA1186
2012-08-17 17:54 - 2012-07-12 18:20 - 04733838 ____R (Swearware) C:\Users\Storm\Desktop\ComboFix.exe
2012-08-17 09:22 - 2011-11-03 09:47 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-17 09:22 - 2009-07-29 07:59 - 01108881 ____A C:\Windows\WindowsUpdate.log
2012-08-17 09:21 - 2011-11-03 09:47 - 00781174 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-17 09:14 - 2006-11-02 07:42 - 00032622 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-17 09:13 - 2012-04-18 10:18 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-17 09:13 - 2011-05-12 19:28 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-17 09:13 - 2009-10-14 14:39 - 00085888 ____A C:\Users\Storm\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-17 09:11 - 2006-11-02 07:21 - 00328848 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 19:36 - 2012-08-16 19:20 - 228696649 ____A C:\Users\Storm\Downloads\StarStealingPrinceFullwRTPV2.1.rar
2012-08-16 12:37 - 2012-08-16 12:37 - 00140827 ____A C:\Windows\SysWOW64\Drivers\str.sys
2012-08-16 11:08 - 2011-07-09 01:33 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-19539739-2347143033-1963601051-1000Core.job
2012-08-16 09:24 - 2006-11-02 04:46 - 00766008 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-15 21:24 - 2006-11-02 04:35 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-08-15 14:27 - 2012-08-15 14:02 - 10185946 ____A C:\Users\Storm\Downloads\The_Mirror_Lied-v2.zip
2012-08-14 22:13 - 2012-08-14 21:58 - 136441593 ____A C:\Users\Storm\Downloads\P4U_Complete_Character_Sprites.7z
2012-08-14 21:34 - 2012-08-14 21:32 - 33493196 ____A C:\Users\Storm\Downloads\imageex.7z
2012-08-14 21:30 - 2012-08-14 21:26 - 47515654 ____A C:\Users\Storm\Downloads\avatar.7z
2012-07-29 22:10 - 2009-10-30 11:47 - 00038912 ____A C:\Users\Storm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-14 00:08 - 2012-07-13 21:05 - 158874719 ____A C:\Users\Storm\Downloads\bloodtracks_030712_10378-L4D2.zip
2012-07-13 21:35 - 2012-07-13 21:09 - 158874719 ____A C:\Users\Storm\Downloads\bloodtracks_030712_10378-L4D2 (1).zip
2012-07-12 19:01 - 2012-07-12 18:58 - 12621696 ____A (Microsoft Corporation) C:\Users\Storm\Downloads\mseinstall.exe
2012-07-12 18:56 - 2006-11-02 04:33 - 65536000 ____A C:\Windows\System32\config\software_previous
2012-07-12 18:56 - 2006-11-02 04:33 - 21233664 ____A C:\Windows\System32\config\system_previous
2012-07-12 18:52 - 2006-11-02 04:33 - 56623104 ____A C:\Windows\System32\config\components_previous
2012-07-12 18:52 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-07-12 18:47 - 2008-01-20 19:26 - 00735534 ____A C:\Windows\PFRO.log
2012-07-12 18:47 - 2006-11-02 04:34 - 00000215 ____A C:\Windows\system.ini
2012-07-12 17:49 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-07-12 17:49 - 2006-11-02 04:33 - 00262144 ____A C:\Windows\System32\config\default_previous
2012-07-09 23:05 - 2012-07-09 23:02 - 09907915 ____A (Adobe Systems, Inc.) C:\Users\Storm\Desktop\katawa_crash_beta_8-36.exe
2012-07-07 20:29 - 2012-07-07 20:29 - 01391104 ____A C:\Users\Storm\Downloads\apploc.msi
2012-07-06 22:00 - 2012-07-06 21:01 - 161912074 ____A C:\Users\Storm\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68] (1).zip
2012-07-06 20:49 - 2012-07-06 20:44 - 04957875 ____A C:\Users\Storm\Downloads\[4ls]_katawa_shoujo_enigmatic_box_of_sound_[503ACD68].zip
2012-07-06 20:16 - 2012-07-06 19:42 - 112861440 ____A C:\Users\Storm\Downloads\Supersekritfiles-s.part1.rar
2012-07-06 20:15 - 2012-07-06 19:42 - 154213571 ____A C:\Users\Storm\Downloads\Supersekritfiles-s.part2.rar
2012-07-05 15:25 - 2012-07-05 15:12 - 104921110 ____A C:\Users\Storm\Downloads\lbac_300612_17711-L4D2.zip
2012-07-05 15:15 - 2012-07-05 15:11 - 18411754 ____A C:\Users\Storm\Downloads\vanillaghosthouse_020511_9711-L4D2.zip
2012-07-04 17:59 - 2012-07-04 17:37 - 96140763 ____A C:\Users\Storm\Downloads\Ouran High School Host Club Soundtrack & Character Song 2.zip
2012-07-04 17:42 - 2012-07-04 17:37 - 95248672 ____A C:\Users\Storm\Downloads\Ouran.High.School.Host.Club [Soundtrack.&.Character.Song.1].rar
2012-07-04 17:36 - 2012-07-04 17:35 - 00281448 ____A (Premium) C:\Users\Storm\Downloads\Ouran High School Host Club Soundtrack amp Character Song 2.zip.exe
2012-07-04 06:33 - 2012-08-15 21:28 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-03 20:08 - 2012-07-03 19:02 - 281950221 ____A C:\Users\Storm\Downloads\ihatemountains_290111_5834.zip
2012-07-03 03:55 - 2012-07-03 03:54 - 07524202 ____A C:\Users\Storm\Downloads\mobstadium2012l4d2final_090910_4442-L4D2.zip
2012-07-03 03:53 - 2012-07-03 03:50 - 24160697 ____A C:\Users\Storm\Downloads\spacejockeys_020610_5280-L4D2.zip
2012-07-03 03:52 - 2012-07-03 03:52 - 16769075 ____A C:\Users\Storm\Downloads\wormwoodv2_121210_6925-L4D2.zip
2012-07-03 03:52 - 2012-07-03 03:52 - 12533770 ____A C:\Users\Storm\Downloads\thereturnofthejockeys_280411_10066-L4D2.zip
2012-07-01 13:24 - 2012-06-30 23:18 - 172610288 ____A C:\Users\Storm\Downloads\hauntedforest_v3_230411_6923-L4D2.zip
2012-06-30 23:42 - 2012-06-30 23:29 - 172610288 ____A C:\Users\Storm\Downloads\hauntedforest_v3_230411_6923-L4D2 (1).zip
2012-06-30 11:32 - 2012-06-30 11:32 - 00285920 ____A C:\Windows\Minidump\Mini063012-01.dmp
2012-06-30 11:32 - 2009-10-18 23:50 - 580171102 ____A C:\Windows\MEMORY.DMP
2012-06-29 17:22 - 2012-06-29 17:22 - 00001856 ____A C:\Users\Storm\Desktop\Forget Me Not Annie.lnk
2012-06-29 17:20 - 2009-07-29 08:30 - 00030274 ____A C:\Windows\DirectX.log
2012-06-29 08:20 - 2012-08-15 15:15 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-06-29 08:01 - 2012-08-15 15:15 - 00467968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-06-28 03:37 - 2012-08-15 15:16 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-28 03:37 - 2012-08-15 15:16 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-28 03:37 - 2012-08-15 15:16 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-28 03:35 - 2012-08-15 15:16 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-06-28 03:33 - 2012-08-15 15:16 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 06008320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-06-28 03:32 - 2012-08-15 15:16 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-28 03:31 - 2012-08-15 15:16 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-06-28 03:31 - 2012-08-15 15:16 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-28 01:59 - 2012-08-15 15:16 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-06-28 00:19 - 2012-08-15 15:16 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-06-28 00:19 - 2012-08-15 15:16 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-28 00:18 - 2012-08-15 15:16 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-06-28 00:17 - 2012-08-15 15:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-27 22:53 - 2012-08-15 15:16 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-27 22:53 - 2012-08-15 15:16 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-27 22:53 - 2012-08-15 15:16 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-27 22:51 - 2012-08-15 15:16 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-27 22:49 - 2012-08-15 15:16 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-06-27 22:48 - 2012-08-15 15:16 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-27 22:48 - 2012-08-15 15:16 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-06-27 22:48 - 2012-08-15 15:16 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-06-27 22:47 - 2012-08-15 15:16 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-06-27 21:54 - 2012-08-15 15:16 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-06-27 21:11 - 2012-08-15 15:16 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-27 21:11 - 2012-08-15 15:16 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-06-27 21:10 - 2012-08-15 15:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-27 21:10 - 2012-08-15 15:16 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-06-16 03:19 - 2012-08-15 15:16 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-06-16 03:14 - 2012-08-15 15:16 - 00727040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-15 23:02 - 2012-08-15 15:16 - 00610816 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-06-15 22:58 - 2012-08-15 15:16 - 00818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 13:35 - 2012-06-14 13:22 - 109033102 ____A C:\Users\Storm\Downloads\Ib.rar
2012-06-09 11:50 - 2012-06-09 11:49 - 00464924 ____A C:\Windows\dd_vcredistMSI4394.txt
2012-06-09 11:50 - 2012-06-09 11:49 - 00011638 ____A C:\Windows\dd_vcredistUI4394.txt
2012-06-08 18:07 - 2012-06-08 16:10 - 209715200 ____A C:\Users\Storm\Downloads\dBsoundworks_-_Sup.e.rMe.atB.o.y_OST.2010.320.part1.rar
2012-06-08 14:55 - 2012-06-08 14:51 - 17792029 ____A C:\Users\Storm\Downloads\dBsoundworks_-_Sup.e.rMe.atB.o.y_OST.2010.320.part2.rar
2012-06-08 09:59 - 2012-07-10 15:05 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 09:47 - 2012-07-10 15:05 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-06-07 21:04 - 2012-06-07 21:04 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-06-07 21:03 - 2012-06-07 20:57 - 00414000 ____A C:\Users\Storm\Downloads\EAX 2.zip
2012-06-07 14:03 - 2012-06-07 14:02 - 00434748 ____A C:\Users\Storm\AppData\Local\dd_vcredistMSI0D63.txt
2012-06-07 14:03 - 2012-06-07 14:02 - 00011444 ____A C:\Users\Storm\AppData\Local\dd_vcredistUI0D63.txt
2012-06-07 14:02 - 2012-06-07 14:02 - 00010552 ____A C:\Users\Storm\AppData\Local\dd_vcredistUI0D64.txt
2012-06-05 08:47 - 2012-07-10 15:05 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 08:47 - 2012-07-10 15:05 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 08:22 - 2012-07-10 15:05 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 08:22 - 2012-07-10 15:05 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-04 07:29 - 2012-07-10 15:05 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-04 01:25 - 2012-06-04 01:25 - 00467414 ____A C:\Windows\dd_vcredistMSI5F4C.txt
2012-06-04 01:25 - 2012-06-04 01:25 - 00011622 ____A C:\Windows\dd_vcredistUI5F4C.txt
2012-06-02 15:53 - 2012-06-02 15:51 - 00428770 ____A C:\Users\Storm\AppData\Local\dd_vcredistMSI5A7A.txt
2012-06-02 15:53 - 2012-06-02 15:51 - 00011462 ____A C:\Users\Storm\AppData\Local\dd_vcredistUI5A7A.txt
2012-06-02 14:19 - 2012-06-21 12:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 12:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-21 12:05 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-21 12:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 12:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 12:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 14:12 - 2012-06-21 12:05 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 14:12 - 2012-06-21 12:05 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-02 13:14 - 2012-06-02 13:14 - 00000220 ____A C:\Users\Storm\Desktop\Psychonauts.url
2012-06-01 16:22 - 2012-07-10 15:05 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:22 - 2012-07-10 15:05 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:05 - 2012-07-10 15:05 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 16:04 - 2012-07-10 15:05 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 16:03 - 2012-07-10 15:05 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-05-31 22:17 - 2012-05-31 22:17 - 00872126 ____A C:\Users\Storm\Downloads\YUGIOH_5Ds_Characters_Gmod_PASADENAOPOSSUM.7z
2012-05-31 03:37 - 2009-07-29 08:14 - 00000012 ____A C:\Users\Public\fm_user.cfg
2012-05-31 03:37 - 2009-07-29 08:14 - 00000009 ____A C:\Users\Public\fm_favorite.cfg
2012-05-28 16:24 - 2012-05-28 16:24 - 00001856 ____A C:\Users\Storm\Desktop\PARANORMAL - BETA 4.lnk
2012-05-28 16:14 - 2012-05-28 15:58 - 381167200 ____A (Epic Games, Inc.) C:\Users\Storm\Downloads\UDKInstall-Para-BETA4.exe
2012-05-28 15:41 - 2012-05-28 15:39 - 31842315 ____A C:\Users\Storm\Downloads\Team Starkid w. Darren Criss.zip
2012-05-28 15:03 - 2012-05-28 14:55 - 72002374 ____A C:\Users\Storm\Downloads\Team Starkid SPACE Tour.zip
ZeroAccess:
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\@
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\L
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\n
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U\00000001.@
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U\80000000.@
C:\Windows\Installer\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U\800000cb.@
ZeroAccess:
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\@
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\L
C:\Users\Storm\AppData\Local\{b0d01356-c8bc-ebf0-84bf-6423a1f60e01}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe BC81150939BD52DBC7A08C245F1FB229 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4059.96 MB
Available physical RAM: 3508.97 MB
Total Pagefile: 3809.45 MB
Available Pagefile: 3483.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (SQ004951V02) (Fixed) (Total:285.88 GB) (Free:87.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.3 GB) NTFS
4 Drive f: () (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 1913 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 1500 MB 1024 KB
Partition 2 Primary 286 GB 1501 MB
Partition 3 Primary 11 GB 287 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E TOSHIBA SYS NTFS Partition 1500 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C SQ004951V02 NTFS Partition 286 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1913 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 F FAT Removable 1913 MB Healthy
==================================================================================
Last Boot: 2012-08-17 09:22
======================= End Of Log ==========================