Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Cannot Remove FBI CYBERCRIME DIVISION virus (MoneyPak Scam)
Message
<blockquote data-quote="john R" data-source="post: 135802" data-attributes="member: 12418"><p><strong><strong></strong></strong></p><p><strong><strong><hr /><p></strong></strong></p><p><strong><strong>Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03</strong></strong></p><p><strong><strong>Ran by spike (administrator) on spike-PC on 17-09-2013 00:11:19</strong></strong></p><p><strong><strong>Running from E:\</strong></strong></p><p><strong><strong>Microsoft Windows 7 Home Premium (X86) OS Language: English(US)</strong></strong></p><p><strong><strong>Internet Explorer Version 8</strong></strong></p><p><strong><strong>Boot Mode: Normal</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Processes (Whitelisted) ===================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Registry (Whitelisted) ==================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Internet (Whitelisted) ====================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>========================== Services (Whitelisted) =================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Drivers (Whitelisted) ====================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== NetSvcs (Whitelisted) ===================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== One Month Created Files and Folders ========</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>2013-09-17 02:56 - 2013-09-17 00:09 - 00000000 ____D C:\Windows\Panther</strong></strong></p><p><strong><strong>2013-09-17 02:40 - 2013-09-17 02:40 - 00000000 ____D C:\Windows.old.000</strong></strong></p><p><strong><strong>2013-09-17 02:00 - 2013-09-17 02:55 - 00008192 __RSH C:\BOOTSECT.BAK</strong></strong></p><p><strong><strong>2013-09-17 02:00 - 2013-09-17 00:09 - 00010954 _____ C:\Windows\WindowsUpdate.log</strong></strong></p><p><strong><strong>2013-09-17 02:00 - 2009-07-13 20:38 - 00383562 __RSH C:\bootmgr</strong></strong></p><p><strong><strong>2013-09-17 02:00 - 2008-06-19 15:42 - 00000211 ____H C:\Boot.BAK</strong></strong></p><p><strong><strong>2013-09-17 01:59 - 2013-09-17 01:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf</strong></strong></p><p><strong><strong>2013-09-17 01:57 - 2013-09-17 02:01 - 00001313 _____ C:\Windows\TSSysprep.log</strong></strong></p><p><strong><strong>2013-09-17 01:45 - 2013-09-17 01:45 - 00000000 ____D C:\Windows.old</strong></strong></p><p><strong><strong>2013-09-17 00:11 - 2013-09-17 00:11 - 00000000 ____D C:\FRST</strong></strong></p><p><strong><strong>2013-09-17 00:10 - 2013-09-17 00:10 - 00001413 _____ C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:10 - 00000000 ____D C:\Users\spike</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:09 - 00000020 ___SH C:\Users\spike\ntuser.ini</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 __SHD C:\Recovery</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 ____D C:\Users\spike\AppData\Local\VirtualStore</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2009-07-13 23:42 - 00000000 ___RD C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2009-07-13 23:37 - 00000000 ___RD C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== One Month Modified Files and Folders =======</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>2013-09-17 02:55 - 2013-09-17 02:00 - 00008192 __RSH C:\BOOTSECT.BAK</strong></strong></p><p><strong><strong>2013-09-17 02:55 - 2009-07-13 23:57 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG</strong></strong></p><p><strong><strong>2013-09-17 02:55 - 2009-07-13 23:52 - 00028672 _____ C:\Windows\system32\config\BCD-Template</strong></strong></p><p><strong><strong>2013-09-17 02:40 - 2013-09-17 02:40 - 00000000 ____D C:\Windows.old.000</strong></strong></p><p><strong><strong>2013-09-17 02:08 - 2009-07-13 23:34 - 00012208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0</strong></strong></p><p><strong><strong>2013-09-17 02:08 - 2009-07-13 23:34 - 00012208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0</strong></strong></p><p><strong><strong>2013-09-17 02:08 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\rescache</strong></strong></p><p><strong><strong>2013-09-17 02:07 - 2009-07-13 23:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT</strong></strong></p><p><strong><strong>2013-09-17 02:06 - 2009-07-13 23:39 - 00020466 _____ C:\Windows\setupact.log</strong></strong></p><p><strong><strong>2013-09-17 02:06 - 2009-07-13 23:33 - 00266808 _____ C:\Windows\system32\FNTCACHE.DAT</strong></strong></p><p><strong><strong>2013-09-17 02:02 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\Microsoft.NET</strong></strong></p><p><strong><strong>2013-09-17 02:01 - 2013-09-17 01:57 - 00001313 _____ C:\Windows\TSSysprep.log</strong></strong></p><p><strong><strong>2013-09-17 02:00 - 2004-08-11 17:00 - 00000355 __RSH C:\Boot.ini.saved</strong></strong></p><p><strong><strong>2013-09-17 01:59 - 2013-09-17 01:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf</strong></strong></p><p><strong><strong>2013-09-17 01:57 - 2009-07-13 23:34 - 00001774 _____ C:\Windows\DtcInstall.log</strong></strong></p><p><strong><strong>2013-09-17 01:45 - 2013-09-17 01:45 - 00000000 ____D C:\Windows.old</strong></strong></p><p><strong><strong>2013-09-17 00:11 - 2013-09-17 00:11 - 00000000 ____D C:\FRST</strong></strong></p><p><strong><strong>2013-09-17 00:10 - 2013-09-17 00:10 - 00001413 _____ C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk</strong></strong></p><p><strong><strong>2013-09-17 00:10 - 2013-09-17 00:09 - 00000000 ____D C:\Users\spike</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 02:56 - 00000000 ____D C:\Windows\Panther</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 02:00 - 00010954 _____ C:\Windows\WindowsUpdate.log</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:09 - 00000020 ___SH C:\Users\spike\ntuser.ini</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 __SHD C:\Recovery</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 ____D C:\Users\spike\AppData\Local\VirtualStore</strong></strong></p><p><strong><strong>2013-09-17 00:09 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\system32\Recovery</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Bamital & volsnap Check =================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>C:\Windows\explorer.exe => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\winlogon.exe => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\wininit.exe => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\svchost.exe => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\services.exe => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\User32.dll => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\userinit.exe => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit</strong></strong></p><p><strong><strong>C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>LastRegBack: 2013-09-17 01:56</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== End Of Log ============================</strong></strong></p><p><strong><strong><hr /><p></strong></strong></p><p><strong><strong>Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-09-2013 03</strong></strong></p><p><strong><strong>Ran by spike at 2013-09-17 00:11:48</strong></strong></p><p><strong><strong>Running from E:\</strong></strong></p><p><strong><strong>Boot Mode: Normal</strong></strong></p><p><strong><strong>==========================================================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Installed Programs =======================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Restore Points =========================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Hosts content: ==========================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Scheduled Tasks (whitelisted) =============</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started</strong></strong></p><p><strong><strong>Task: {191232AD-26C4-49F7-BBEF-4B28DE2DEA14} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => C:\Program Files\Windows Defender\MpCmdRun.exe [2009-07-13] (Microsoft Corporation)</strong></strong></p><p><strong><strong>Task: {DED983CA-C2B2-4F3B-BD78-0A6450DE3F95} - System32\Tasks\Microsoft\Windows Defender\Mp Scheduled Scan => C:\Program Files\Windows Defender\MpCmdRun.exe [2009-07-13] (Microsoft Corporation)</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Loaded Modules (whitelisted) =============</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>2009-07-13 18:21 - 2009-07-13 20:15 - 00016384 _____ (Microsoft Corporation) C:\Windows\ehome\ehssetup.dll</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Faulty Device Manager Devices =============</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Name: Base System Device</strong></strong></p><p><strong><strong>Description: Base System Device</strong></strong></p><p><strong><strong>Class Guid: </strong></strong></p><p><strong><strong>Manufacturer: </strong></strong></p><p><strong><strong>Service: </strong></strong></p><p><strong><strong>Problem: : The drivers for this device are not installed. (Code 28)</strong></strong></p><p><strong><strong>Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Name: Base System Device</strong></strong></p><p><strong><strong>Description: Base System Device</strong></strong></p><p><strong><strong>Class Guid: </strong></strong></p><p><strong><strong>Manufacturer: </strong></strong></p><p><strong><strong>Service: </strong></strong></p><p><strong><strong>Problem: : The drivers for this device are not installed. (Code 28)</strong></strong></p><p><strong><strong>Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Name: Base System Device</strong></strong></p><p><strong><strong>Description: Base System Device</strong></strong></p><p><strong><strong>Class Guid: </strong></strong></p><p><strong><strong>Manufacturer: </strong></strong></p><p><strong><strong>Service: </strong></strong></p><p><strong><strong>Problem: : The drivers for this device are not installed. (Code 28)</strong></strong></p><p><strong><strong>Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Event log errors: =========================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Application errors:</strong></strong></p><p><strong><strong>==================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>System errors:</strong></strong></p><p><strong><strong>=============</strong></strong></p><p><strong><strong>Error: (09/17/2013 02:05:04 AM) (Source: Service Control Manager) (User: )</strong></strong></p><p><strong><strong>Description: The Windows Search service terminated with the following error: </strong></strong></p><p><strong><strong>%%19</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Microsoft Office Sessions:</strong></strong></p><p><strong><strong>=========================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Memory info =========================== </strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Percentage of memory in use: 19%</strong></strong></p><p><strong><strong>Total physical RAM: 3062.04 MB</strong></strong></p><p><strong><strong>Available physical RAM: 2451.91 MB</strong></strong></p><p><strong><strong>Total Pagefile: 6122.36 MB</strong></strong></p><p><strong><strong>Available Pagefile: 5464.83 MB</strong></strong></p><p><strong><strong>Total Virtual: 2047.88 MB</strong></strong></p><p><strong><strong>Available Virtual: 1882.25 MB</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== Drives ================================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Drive c: () (Fixed) (Total:230.3 GB) (Free:162.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)]</strong></strong></p><p><strong><strong>Drive e: () (Removable) (Total:1.88 GB) (Free:1.76 GB) FAT</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== MBR & Partition Table ==================</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>========================================================</strong></strong></p><p><strong><strong>Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 41AB2316)</strong></strong></p><p><strong><strong>Partition 1: (Not Active) - (Size=86 MB) - (Type=DE)</strong></strong></p><p><strong><strong>Partition 2: (Active) - (Size=230 GB) - (Type=07 NTFS)</strong></strong></p><p><strong><strong>Partition 3: (Not Active) - (Size=2 GB) - (Type=OF Extended)</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>========================================================</strong></strong></p><p><strong><strong>Disk: 1 (Size: 2 GB) (Disk ID: FCD4315B)</strong></strong></p><p><strong><strong>Partition 1: (Not Active) - (Size=2 GB) - (Type=06)</strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>==================== End Of Log ============================</strong></strong></p></blockquote><p></p>
[QUOTE="john R, post: 135802, member: 12418"] [b][b] [hr] Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03 Ran by spike (administrator) on spike-PC on 17-09-2013 00:11:19 Running from E:\ Microsoft Windows 7 Home Premium (X86) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== ==================== Registry (Whitelisted) ================== ==================== Internet (Whitelisted) ==================== ========================== Services (Whitelisted) ================= ==================== Drivers (Whitelisted) ==================== R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-17 02:56 - 2013-09-17 00:09 - 00000000 ____D C:\Windows\Panther 2013-09-17 02:40 - 2013-09-17 02:40 - 00000000 ____D C:\Windows.old.000 2013-09-17 02:00 - 2013-09-17 02:55 - 00008192 __RSH C:\BOOTSECT.BAK 2013-09-17 02:00 - 2013-09-17 00:09 - 00010954 _____ C:\Windows\WindowsUpdate.log 2013-09-17 02:00 - 2009-07-13 20:38 - 00383562 __RSH C:\bootmgr 2013-09-17 02:00 - 2008-06-19 15:42 - 00000211 ____H C:\Boot.BAK 2013-09-17 01:59 - 2013-09-17 01:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-09-17 01:57 - 2013-09-17 02:01 - 00001313 _____ C:\Windows\TSSysprep.log 2013-09-17 01:45 - 2013-09-17 01:45 - 00000000 ____D C:\Windows.old 2013-09-17 00:11 - 2013-09-17 00:11 - 00000000 ____D C:\FRST 2013-09-17 00:10 - 2013-09-17 00:10 - 00001413 _____ C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-17 00:09 - 2013-09-17 00:10 - 00000000 ____D C:\Users\spike 2013-09-17 00:09 - 2013-09-17 00:09 - 00000020 ___SH C:\Users\spike\ntuser.ini 2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 __SHD C:\Recovery 2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 ____D C:\Users\spike\AppData\Local\VirtualStore 2013-09-17 00:09 - 2009-07-13 23:42 - 00000000 ___RD C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-09-17 00:09 - 2009-07-13 23:37 - 00000000 ___RD C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance ==================== One Month Modified Files and Folders ======= 2013-09-17 02:55 - 2013-09-17 02:00 - 00008192 __RSH C:\BOOTSECT.BAK 2013-09-17 02:55 - 2009-07-13 23:57 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG 2013-09-17 02:55 - 2009-07-13 23:52 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2013-09-17 02:40 - 2013-09-17 02:40 - 00000000 ____D C:\Windows.old.000 2013-09-17 02:08 - 2009-07-13 23:34 - 00012208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-17 02:08 - 2009-07-13 23:34 - 00012208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-17 02:08 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\rescache 2013-09-17 02:07 - 2009-07-13 23:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-17 02:06 - 2009-07-13 23:39 - 00020466 _____ C:\Windows\setupact.log 2013-09-17 02:06 - 2009-07-13 23:33 - 00266808 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-17 02:02 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-17 02:01 - 2013-09-17 01:57 - 00001313 _____ C:\Windows\TSSysprep.log 2013-09-17 02:00 - 2004-08-11 17:00 - 00000355 __RSH C:\Boot.ini.saved 2013-09-17 01:59 - 2013-09-17 01:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2013-09-17 01:57 - 2009-07-13 23:34 - 00001774 _____ C:\Windows\DtcInstall.log 2013-09-17 01:45 - 2013-09-17 01:45 - 00000000 ____D C:\Windows.old 2013-09-17 00:11 - 2013-09-17 00:11 - 00000000 ____D C:\FRST 2013-09-17 00:10 - 2013-09-17 00:10 - 00001413 _____ C:\Users\spike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-17 00:10 - 2013-09-17 00:09 - 00000000 ____D C:\Users\spike 2013-09-17 00:09 - 2013-09-17 02:56 - 00000000 ____D C:\Windows\Panther 2013-09-17 00:09 - 2013-09-17 02:00 - 00010954 _____ C:\Windows\WindowsUpdate.log 2013-09-17 00:09 - 2013-09-17 00:09 - 00000020 ___SH C:\Users\spike\ntuser.ini 2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 __SHD C:\Recovery 2013-09-17 00:09 - 2013-09-17 00:09 - 00000000 ____D C:\Users\spike\AppData\Local\VirtualStore 2013-09-17 00:09 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\system32\Recovery ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!. LastRegBack: 2013-09-17 01:56 ==================== End Of Log ============================ [hr] Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-09-2013 03 Ran by spike at 2013-09-17 00:11:48 Running from E:\ Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {191232AD-26C4-49F7-BBEF-4B28DE2DEA14} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => C:\Program Files\Windows Defender\MpCmdRun.exe [2009-07-13] (Microsoft Corporation) Task: {DED983CA-C2B2-4F3B-BD78-0A6450DE3F95} - System32\Tasks\Microsoft\Windows Defender\Mp Scheduled Scan => C:\Program Files\Windows Defender\MpCmdRun.exe [2009-07-13] (Microsoft Corporation) ==================== Loaded Modules (whitelisted) ============= 2009-07-13 18:21 - 2009-07-13 20:15 - 00016384 _____ (Microsoft Corporation) C:\Windows\ehome\ehssetup.dll ==================== Faulty Device Manager Devices ============= Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (09/17/2013 02:05:04 AM) (Source: Service Control Manager) (User: ) Description: The Windows Search service terminated with the following error: %%19 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 19% Total physical RAM: 3062.04 MB Available physical RAM: 2451.91 MB Total Pagefile: 6122.36 MB Available Pagefile: 5464.83 MB Total Virtual: 2047.88 MB Available Virtual: 1882.25 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:230.3 GB) (Free:162.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: () (Removable) (Total:1.88 GB) (Free:1.76 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 41AB2316) Partition 1: (Not Active) - (Size=86 MB) - (Type=DE) Partition 2: (Active) - (Size=230 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=2 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: FCD4315B) Partition 1: (Not Active) - (Size=2 GB) - (Type=06) ==================== End Of Log ============================[/hr][/hr][/b][/b] [/QUOTE]
Insert quotes…
Verification
Post reply
Top