Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Polistyran Virus (like FBI virus but Swedish Version)
Message
<blockquote data-quote="prun" data-source="post: 114851" data-attributes="member: 7209"><p>Hi, so I've managed to get this far, hope it helps. Thanks, P :</p><p></p><p>Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2013 (ATTENTION: FRST version is 21 days old)</p><p>Ran by SYSTEM at 03-04-2013 18:17:05</p><p>Running from G:\</p><p>Windows 7 Home Premium (X64) OS Language: English(US) </p><p>The current controlset is ControlSet002</p><p></p><p>==================== Registry (Whitelisted) ===================</p><p></p><p>HKLM\...\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [192520 2010-10-12] (Trend Micro Inc.)</p><p>HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322176 2012-02-16] (ASUSTek Computer Inc.)</p><p>HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-24] (ASUS)</p><p>HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)</p><p>HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-02] (ASUSTeK Computer Inc.)</p><p>HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)</p><p>HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [151952 2012-11-28] (Apple Inc.)</p><p>HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)</p><p>HKU\Mikael\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [1021840 2012-06-22] (BitTorrent, Inc.)</p><p>HKU\Mikael\...\Run: [Google Update] "C:\Users\Mikael\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-06-22] (Google Inc.)</p><p>HKU\Mikael\...\Run: [Spotify Web Helper] "C:\Users\Mikael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1199576 2012-12-06] (Spotify Ltd)</p><p>HKU\Mikael\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18705664 2013-01-08] (Skype Technologies S.A.)</p><p>HKU\Mikael\...\Run: [DriverScanner] "C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe" delay 20000 [338848 2012-07-10] (Uniblue Systems Limited)</p><p>HKU\Mikael\...\Run: [Browser Infrastructure Helper] C:\Users\Mikael\AppData\Local\Smartbar\Application\SnapDo.exe startup [20992 2013-03-05] (Smartbar)</p><p>HKU\Mikael\...\Winlogon: [Shell] explorer.exe,C:\Users\Mikael\AppData\Roaming\skype.dat [102400 2013-03-20] ()</p><p>Tcpip\Parameters: [DhcpNameServer] 193.150.193.150 83.255.245.11</p><p>Startup: C:\ProgramData\Start Menu\Programs\Startup\FancyStart daemon.lnk</p><p>ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()</p><p>Startup: C:\Users\Mikael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skärmurklipp och start för OneNote 2010.lnk</p><p>ShortcutTarget: Skärmurklipp och start för OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)</p><p></p><p>==================== Services (Whitelisted) ===================</p><p></p><p>4 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros)</p><p>2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2011-11-21] (ASUS)</p><p>4 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [241648 2011-04-20] (CyberLink)</p><p>4 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [241488 2010-09-17] (Trend Micro Inc.)</p><p>4 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [x]</p><p></p><p>==================== Drivers (Whitelisted) =====================</p><p></p><p>1 ATKWMIACPIIO_; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-06] (ASUS)</p><p>3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )</p><p>3 Tdsshbecr; C:\Windows\System32\DRIVERS\shbecr.sys [50176 2008-09-28] (Todos Data System AB)</p><p>2 tmactmon; C:\Windows\System32\Drivers\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.)</p><p>2 tmcomm; C:\Windows\System32\Drivers\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.)</p><p>2 tmevtmgr; C:\Windows\System32\Drivers\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.)</p><p>1 tmtdi; C:\Windows\System32\Drivers\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.)</p><p></p><p>==================== NetSvcs (Whitelisted) ====================</p><p></p><p></p><p>==================== One Month Created Files and Folders ========</p><p></p><p>2013-04-03 18:16 - 2013-04-03 18:16 - 00000000 ____D C:\FRST</p><p>2013-03-20 11:00 - 2013-03-20 09:18 - 00102400 ___RA C:\Users\Mikael\AppData\Roaming\skype.dat</p><p>2013-03-20 09:34 - 2013-03-20 09:34 - 00003352 ____N C:\bootsqm.dat</p><p>2013-03-20 09:23 - 2013-03-20 13:36 - 00000004 ____A C:\Users\Mikael\AppData\Roaming\skype.ini</p><p>2013-03-20 07:42 - 2013-03-20 07:42 - 00002351 ____A C:\Users\Mikael\Desktop\Search.lnk</p><p>2013-03-19 12:19 - 2013-03-20 07:42 - 00000000 ____D C:\Users\Mikael\AppData\Local\Smartbar</p><p>2013-03-19 12:17 - 2013-03-19 12:17 - 00001241 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk</p><p>2013-03-19 12:16 - 2013-03-19 12:16 - 00000000 ____D C:\ProgramData\Uniblue</p><p>2013-03-19 12:15 - 2013-03-20 13:46 - 00000342 ____A C:\Windows\Tasks\DriverScanner.job</p><p>2013-03-19 12:15 - 2013-03-19 12:15 - 00001191 ____A C:\Users\Public\Desktop\DriverScanner.lnk</p><p>2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Uniblue</p><p>2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Program Files (x86)\Uniblue</p><p>2013-03-19 12:14 - 2013-03-19 12:14 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\OpenCandy</p><p>2013-03-18 04:54 - 2013-03-18 04:54 - 00000000 ____D C:\Users\Mikael\AppData\Local\Adobe</p><p>2013-03-18 04:50 - 2013-03-20 13:34 - 00000990 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job</p><p>2013-03-18 04:50 - 2013-03-20 09:00 - 00000994 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job</p><p>2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\ProgramData\Google</p><p>2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files\Google</p><p>2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files (x86)\Google</p><p>2013-03-18 04:49 - 2013-03-18 04:49 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk</p><p>2013-03-18 04:48 - 2013-03-19 12:21 - 00000000 ____D C:\ProgramData\Adobe</p><p>2013-03-17 12:07 - 2013-03-17 12:07 - 00000000 ____D C:\Users\Mikael\AppData\Local\{959F1B82-8ADA-40B3-8FED-B7C142DA09A4}</p><p>2013-03-15 00:26 - 2013-02-01 23:31 - 17815040 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:58 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:57 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:48 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:47 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl</p><p>2013-03-15 00:26 - 2013-02-01 22:47 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:46 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:43 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:42 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:42 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe</p><p>2013-03-15 00:26 - 2013-02-01 22:41 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:40 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:39 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb</p><p>2013-03-15 00:26 - 2013-02-01 22:38 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll</p><p>2013-03-15 00:26 - 2013-02-01 22:34 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll</p><p>2013-03-15 00:26 - 2013-02-01 20:09 - 12321792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:42 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:38 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl</p><p>2013-03-15 00:26 - 2013-02-01 19:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:26 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:26 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:26 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe</p><p>2013-03-15 00:26 - 2013-02-01 19:25 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:23 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb</p><p>2013-03-15 00:26 - 2013-02-01 19:23 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:23 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll</p><p>2013-03-15 00:26 - 2013-02-01 19:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll</p><p>2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight</p><p>2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight</p><p>2013-03-08 00:31 - 2013-03-08 00:31 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk</p><p>2013-03-06 06:23 - 2013-03-07 01:30 - 00000000 ____D C:\Users\Mikael\AppData\Local\{EE2978B1-1F90-4870-BA3E-33B36625CC80}</p><p></p><p>==================== One Month Modified Files and Folders =======</p><p></p><p>2013-04-03 18:16 - 2013-04-03 18:16 - 00000000 ____D C:\FRST</p><p>2013-03-20 13:46 - 2013-03-19 12:15 - 00000342 ____A C:\Windows\Tasks\DriverScanner.job</p><p>2013-03-20 13:46 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT</p><p>2013-03-20 13:46 - 2009-07-13 20:51 - 00091044 ____A C:\Windows\setupact.log</p><p>2013-03-20 13:36 - 2013-03-20 09:23 - 00000004 ____A C:\Users\Mikael\AppData\Roaming\skype.ini</p><p>2013-03-20 13:35 - 2012-08-29 03:07 - 00000868 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job</p><p>2013-03-20 13:34 - 2013-03-18 04:50 - 00000990 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job</p><p>2013-03-20 13:34 - 2012-06-22 06:48 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\uTorrent</p><p>2013-03-20 13:34 - 2012-06-03 02:18 - 00000000 ___HD C:\ASUS.DAT</p><p>2013-03-20 13:34 - 2012-04-11 02:20 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe</p><p>2013-03-20 13:18 - 2012-04-11 01:57 - 01593307 ____A C:\Windows\WindowsUpdate.log</p><p>2013-03-20 12:48 - 2011-02-18 19:49 - 00673156 ____A C:\Windows\System32\perfh01D.dat</p><p>2013-03-20 12:48 - 2011-02-18 19:49 - 00145266 ____A C:\Windows\System32\perfc01D.dat</p><p>2013-03-20 12:48 - 2009-07-13 21:13 - 01604140 ____A C:\Windows\System32\PerfStringBackup.INI</p><p>2013-03-20 09:42 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0</p><p>2013-03-20 09:42 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0</p><p>2013-03-20 09:34 - 2013-03-20 09:34 - 00003352 ____N C:\bootsqm.dat</p><p>2013-03-20 09:18 - 2013-03-20 11:00 - 00102400 ___RA C:\Users\Mikael\AppData\Roaming\skype.dat</p><p>2013-03-20 09:00 - 2013-03-18 04:50 - 00000994 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job</p><p>2013-03-20 08:29 - 2012-06-22 06:53 - 00001008 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405421564-331882077-3349474539-1001UA.job</p><p>2013-03-20 07:42 - 2013-03-20 07:42 - 00002351 ____A C:\Users\Mikael\Desktop\Search.lnk</p><p>2013-03-20 07:42 - 2013-03-19 12:19 - 00000000 ____D C:\Users\Mikael\AppData\Local\Smartbar</p><p>2013-03-20 07:40 - 2012-10-08 15:32 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Skype</p><p>2013-03-20 04:29 - 2012-06-22 06:52 - 00000956 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405421564-331882077-3349474539-1001Core.job</p><p>2013-03-19 12:21 - 2013-03-18 04:48 - 00000000 ____D C:\ProgramData\Adobe</p><p>2013-03-19 12:20 - 2011-10-20 01:30 - 00150674 ____A C:\Windows\PFRO.log</p><p>2013-03-19 12:18 - 2012-06-22 02:29 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\DVDVideoSoft</p><p>2013-03-19 12:17 - 2013-03-19 12:17 - 00001241 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk</p><p>2013-03-19 12:17 - 2012-06-22 02:30 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft</p><p>2013-03-19 12:16 - 2013-03-19 12:16 - 00000000 ____D C:\ProgramData\Uniblue</p><p>2013-03-19 12:15 - 2013-03-19 12:15 - 00001191 ____A C:\Users\Public\Desktop\DriverScanner.lnk</p><p>2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Uniblue</p><p>2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Program Files (x86)\Uniblue</p><p>2013-03-19 12:14 - 2013-03-19 12:14 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\OpenCandy</p><p>2013-03-18 05:20 - 2012-07-17 14:36 - 00000000 ____D C:\Users\Mikael\AppData\Local\CrashDumps</p><p>2013-03-18 04:54 - 2013-03-18 04:54 - 00000000 ____D C:\Users\Mikael\AppData\Local\Adobe</p><p>2013-03-18 04:54 - 2012-06-10 04:00 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Adobe</p><p>2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\ProgramData\Google</p><p>2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files\Google</p><p>2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files (x86)\Google</p><p>2013-03-18 04:49 - 2013-03-18 04:49 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk</p><p>2013-03-18 04:49 - 2013-01-17 13:31 - 00000000 ____D C:\Program Files (x86)\Adobe</p><p>2013-03-17 12:07 - 2013-03-17 12:07 - 00000000 ____D C:\Users\Mikael\AppData\Local\{959F1B82-8ADA-40B3-8FED-B7C142DA09A4}</p><p>2013-03-15 01:31 - 2012-12-23 11:56 - 00000000 ____D C:\Windows\rescache</p><p>2013-03-15 00:37 - 2012-06-12 02:03 - 00000000 ____D C:\ProgramData\Microsoft Help</p><p>2013-03-15 00:30 - 2012-07-08 03:10 - 72013344 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe</p><p>2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight</p><p>2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight</p><p>2013-03-14 04:15 - 2012-08-29 03:07 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe</p><p>2013-03-14 04:15 - 2012-08-29 03:07 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl</p><p>2013-03-10 16:36 - 2012-09-13 03:56 - 00000000 ____D C:\Users\Mikael\Desktop\Songs</p><p>2013-03-08 00:31 - 2013-03-08 00:31 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk</p><p>2013-03-08 00:31 - 2012-10-08 15:32 - 00000000 ___RD C:\Program Files (x86)\Skype</p><p>2013-03-08 00:31 - 2012-10-08 15:31 - 00000000 ____D C:\ProgramData\Skype</p><p>2013-03-07 01:30 - 2013-03-06 06:23 - 00000000 ____D C:\Users\Mikael\AppData\Local\{EE2978B1-1F90-4870-BA3E-33B36625CC80}</p><p></p><p></p><p>==================== Known DLLs (Whitelisted) =================</p><p></p><p></p><p>==================== Bamital & volsnap Check =================</p><p></p><p>C:\Windows\System32\winlogon.exe => MD5 is legit</p><p>C:\Windows\System32\wininit.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\wininit.exe => MD5 is legit</p><p>C:\Windows\explorer.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\explorer.exe => MD5 is legit</p><p>C:\Windows\System32\svchost.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\svchost.exe => MD5 is legit</p><p>C:\Windows\System32\services.exe => MD5 is legit</p><p>C:\Windows\System32\User32.dll => MD5 is legit</p><p>C:\Windows\SysWOW64\User32.dll => MD5 is legit</p><p>C:\Windows\System32\userinit.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\userinit.exe => MD5 is legit</p><p>C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit</p><p></p><p>==================== EXE ASSOCIATION =====================</p><p></p><p>HKLM\...\.exe: exefile => OK</p><p>HKLM\...\exefile\DefaultIcon: %1 => OK</p><p>HKLM\...\exefile\open\command: "%1" %* => OK</p><p></p><p>==================== Restore Points =========================</p><p></p><p></p><p>==================== Memory info =========================== </p><p></p><p>Percentage of memory in use: 15%</p><p>Total physical RAM: 3691.7 MB</p><p>Available physical RAM: 3135.11 MB</p><p>Total Pagefile: 3689.85 MB</p><p>Available Pagefile: 3124.38 MB</p><p>Total Virtual: 8192 MB</p><p>Available Virtual: 8191.88 MB</p><p></p><p>==================== Partitions =============================</p><p></p><p>1 Drive c: (OS) (Fixed) (Total:128.18 GB) (Free:8.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)]</p><p>2 Drive d: (DATA) (Fixed) (Total:144.91 GB) (Free:123.45 GB) NTFS</p><p>5 Drive g: (KINGSTON) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT</p><p>6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS</p><p></p><p> Disk ### Status Size Free Dyn Gpt</p><p> -------- ------------- ------- ------- --- ---</p><p> Disk 0 Online 298 GB 0 B </p><p> Disk 1 No Media 0 B 0 B </p><p> Disk 2 Online 1909 MB 0 B </p><p></p><p>Partitions of Disk 0:</p><p>===============</p><p></p><p>Disk ID: 125FC5E1</p><p></p><p> Partition ### Type Size Offset</p><p> ------------- ---------------- ------- -------</p><p> Partition 1 Primary 25 GB 1024 KB</p><p> Partition 2 Primary 128 GB 25 GB</p><p> Partition 3 Primary 144 GB 153 GB</p><p></p><p>==================================================================================</p><p></p><p>Disk: 0</p><p>Partition 1</p><p>Type : 1C</p><p>Hidden: Yes</p><p>Active: No</p><p></p><p>There is no volume associated with this partition.</p><p></p><p>=========================================================</p><p></p><p>Disk: 0</p><p>Partition 2</p><p>Type : 07</p><p>Hidden: No</p><p>Active: Yes</p><p></p><p> Volume ### Ltr Label Fs Type Size Status Info</p><p> ---------- --- ----------- ----- ---------- ------- --------- --------</p><p>* Volume 1 C OS NTFS Partition 128 GB Healthy </p><p></p><p>=========================================================</p><p></p><p>Disk: 0</p><p>Partition 3</p><p>Type : 07</p><p>Hidden: No</p><p>Active: No</p><p></p><p> Volume ### Ltr Label Fs Type Size Status Info</p><p> ---------- --- ----------- ----- ---------- ------- --------- --------</p><p>* Volume 2 D DATA NTFS Partition 144 GB Healthy </p><p></p><p>=========================================================</p><p></p><p>Partitions of Disk 2:</p><p>===============</p><p></p><p>Disk ID: 00000000</p><p></p><p> Partition ### Type Size Offset</p><p> ------------- ---------------- ------- -------</p><p> Partition 1 Primary 1905 MB 4032 KB</p><p></p><p>==================================================================================</p><p></p><p>Disk: 2</p><p>Partition 1</p><p>Type : 06</p><p>Hidden: No</p><p>Active: Yes</p><p></p><p> Volume ### Ltr Label Fs Type Size Status Info</p><p> ---------- --- ----------- ----- ---------- ------- --------- --------</p><p>* Volume 4 G KINGSTON FAT Removable 1905 MB Healthy </p><p></p><p>=========================================================</p><p>============================== MBR Partition Table ==================</p><p></p><p>==============================</p><p>Partitions of Disk 0:</p><p>===============</p><p>Disk ID: 125FC5E1</p><p></p><p>Partition 1:</p><p>=========</p><p>Hex: 002021001CFEFFFF0008000000002003</p><p>Active: NO</p><p>Type: 1C</p><p>Size: 25 GB</p><p></p><p>Partition 2:</p><p>=========</p><p>Hex: 80FEFFFF07FEFFFF0008200300B80510</p><p>Active: YES</p><p>Type: 07 (NTFS)</p><p>Size: 128 GB</p><p></p><p>Partition 3:</p><p>=========</p><p>Hex: 00FEFFFF07FEFFFF00C0251300281D12</p><p>Active: NO</p><p>Type: 07 (NTFS)</p><p>Size: 145 GB</p><p></p><p>==============================</p><p>Partitions of Disk 2:</p><p>===============</p><p>Disk ID: 00000000</p><p></p><p>Partition 1:</p><p>=========</p><p>Hex: 80010C0F060F60D3801F000080883B00</p><p>Active: YES</p><p>Type: 06</p><p>Size: 2 GB</p><p></p><p></p><p>Last Boot: 2013-03-15 01:24</p><p></p><p>==================== End Of Log =============================</p></blockquote><p></p>
[QUOTE="prun, post: 114851, member: 7209"] Hi, so I've managed to get this far, hope it helps. Thanks, P : Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2013 (ATTENTION: FRST version is 21 days old) Ran by SYSTEM at 03-04-2013 18:17:05 Running from G:\ Windows 7 Home Premium (X64) OS Language: English(US) The current controlset is ControlSet002 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [192520 2010-10-12] (Trend Micro Inc.) HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322176 2012-02-16] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-24] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-02] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [151952 2012-11-28] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated) HKU\Mikael\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [1021840 2012-06-22] (BitTorrent, Inc.) HKU\Mikael\...\Run: [Google Update] "C:\Users\Mikael\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-06-22] (Google Inc.) HKU\Mikael\...\Run: [Spotify Web Helper] "C:\Users\Mikael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1199576 2012-12-06] (Spotify Ltd) HKU\Mikael\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18705664 2013-01-08] (Skype Technologies S.A.) HKU\Mikael\...\Run: [DriverScanner] "C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe" delay 20000 [338848 2012-07-10] (Uniblue Systems Limited) HKU\Mikael\...\Run: [Browser Infrastructure Helper] C:\Users\Mikael\AppData\Local\Smartbar\Application\SnapDo.exe startup [20992 2013-03-05] (Smartbar) HKU\Mikael\...\Winlogon: [Shell] explorer.exe,C:\Users\Mikael\AppData\Roaming\skype.dat [102400 2013-03-20] () Tcpip\Parameters: [DhcpNameServer] 193.150.193.150 83.255.245.11 Startup: C:\ProgramData\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe () Startup: C:\Users\Mikael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skärmurklipp och start för OneNote 2010.lnk ShortcutTarget: Skärmurklipp och start för OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Services (Whitelisted) =================== 4 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros) 2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2011-11-21] (ASUS) 4 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [241648 2011-04-20] (CyberLink) 4 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [241488 2010-09-17] (Trend Micro Inc.) 4 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [x] ==================== Drivers (Whitelisted) ===================== 1 ATKWMIACPIIO_; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-06] (ASUS) 3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( ) 3 Tdsshbecr; C:\Windows\System32\DRIVERS\shbecr.sys [50176 2008-09-28] (Todos Data System AB) 2 tmactmon; C:\Windows\System32\Drivers\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.) 2 tmcomm; C:\Windows\System32\Drivers\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.) 2 tmevtmgr; C:\Windows\System32\Drivers\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.) 1 tmtdi; C:\Windows\System32\Drivers\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.) ==================== NetSvcs (Whitelisted) ==================== ==================== One Month Created Files and Folders ======== 2013-04-03 18:16 - 2013-04-03 18:16 - 00000000 ____D C:\FRST 2013-03-20 11:00 - 2013-03-20 09:18 - 00102400 ___RA C:\Users\Mikael\AppData\Roaming\skype.dat 2013-03-20 09:34 - 2013-03-20 09:34 - 00003352 ____N C:\bootsqm.dat 2013-03-20 09:23 - 2013-03-20 13:36 - 00000004 ____A C:\Users\Mikael\AppData\Roaming\skype.ini 2013-03-20 07:42 - 2013-03-20 07:42 - 00002351 ____A C:\Users\Mikael\Desktop\Search.lnk 2013-03-19 12:19 - 2013-03-20 07:42 - 00000000 ____D C:\Users\Mikael\AppData\Local\Smartbar 2013-03-19 12:17 - 2013-03-19 12:17 - 00001241 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-03-19 12:16 - 2013-03-19 12:16 - 00000000 ____D C:\ProgramData\Uniblue 2013-03-19 12:15 - 2013-03-20 13:46 - 00000342 ____A C:\Windows\Tasks\DriverScanner.job 2013-03-19 12:15 - 2013-03-19 12:15 - 00001191 ____A C:\Users\Public\Desktop\DriverScanner.lnk 2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Uniblue 2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Program Files (x86)\Uniblue 2013-03-19 12:14 - 2013-03-19 12:14 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\OpenCandy 2013-03-18 04:54 - 2013-03-18 04:54 - 00000000 ____D C:\Users\Mikael\AppData\Local\Adobe 2013-03-18 04:50 - 2013-03-20 13:34 - 00000990 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-03-18 04:50 - 2013-03-20 09:00 - 00000994 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\ProgramData\Google 2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files\Google 2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files (x86)\Google 2013-03-18 04:49 - 2013-03-18 04:49 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-03-18 04:48 - 2013-03-19 12:21 - 00000000 ____D C:\ProgramData\Adobe 2013-03-17 12:07 - 2013-03-17 12:07 - 00000000 ____D C:\Users\Mikael\AppData\Local\{959F1B82-8ADA-40B3-8FED-B7C142DA09A4} 2013-03-15 00:26 - 2013-02-01 23:31 - 17815040 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-15 00:26 - 2013-02-01 22:58 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-15 00:26 - 2013-02-01 22:57 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-15 00:26 - 2013-02-01 22:48 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-15 00:26 - 2013-02-01 22:47 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-15 00:26 - 2013-02-01 22:47 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-15 00:26 - 2013-02-01 22:46 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-15 00:26 - 2013-02-01 22:43 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-15 00:26 - 2013-02-01 22:42 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-15 00:26 - 2013-02-01 22:42 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-15 00:26 - 2013-02-01 22:41 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-15 00:26 - 2013-02-01 22:40 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-15 00:26 - 2013-02-01 22:39 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-15 00:26 - 2013-02-01 22:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-15 00:26 - 2013-02-01 22:38 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-15 00:26 - 2013-02-01 22:34 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-15 00:26 - 2013-02-01 20:09 - 12321792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-03-15 00:26 - 2013-02-01 19:42 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-03-15 00:26 - 2013-02-01 19:38 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-03-15 00:26 - 2013-02-01 19:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-03-15 00:26 - 2013-02-01 19:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-03-15 00:26 - 2013-02-01 19:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-03-15 00:26 - 2013-02-01 19:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-03-15 00:26 - 2013-02-01 19:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-03-15 00:26 - 2013-02-01 19:26 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-03-15 00:26 - 2013-02-01 19:26 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-03-15 00:26 - 2013-02-01 19:26 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-03-15 00:26 - 2013-02-01 19:25 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-03-15 00:26 - 2013-02-01 19:23 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-03-15 00:26 - 2013-02-01 19:23 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-03-15 00:26 - 2013-02-01 19:23 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-03-15 00:26 - 2013-02-01 19:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-03-08 00:31 - 2013-03-08 00:31 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk 2013-03-06 06:23 - 2013-03-07 01:30 - 00000000 ____D C:\Users\Mikael\AppData\Local\{EE2978B1-1F90-4870-BA3E-33B36625CC80} ==================== One Month Modified Files and Folders ======= 2013-04-03 18:16 - 2013-04-03 18:16 - 00000000 ____D C:\FRST 2013-03-20 13:46 - 2013-03-19 12:15 - 00000342 ____A C:\Windows\Tasks\DriverScanner.job 2013-03-20 13:46 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-03-20 13:46 - 2009-07-13 20:51 - 00091044 ____A C:\Windows\setupact.log 2013-03-20 13:36 - 2013-03-20 09:23 - 00000004 ____A C:\Users\Mikael\AppData\Roaming\skype.ini 2013-03-20 13:35 - 2012-08-29 03:07 - 00000868 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-03-20 13:34 - 2013-03-18 04:50 - 00000990 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-03-20 13:34 - 2012-06-22 06:48 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\uTorrent 2013-03-20 13:34 - 2012-06-03 02:18 - 00000000 ___HD C:\ASUS.DAT 2013-03-20 13:34 - 2012-04-11 02:20 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe 2013-03-20 13:18 - 2012-04-11 01:57 - 01593307 ____A C:\Windows\WindowsUpdate.log 2013-03-20 12:48 - 2011-02-18 19:49 - 00673156 ____A C:\Windows\System32\perfh01D.dat 2013-03-20 12:48 - 2011-02-18 19:49 - 00145266 ____A C:\Windows\System32\perfc01D.dat 2013-03-20 12:48 - 2009-07-13 21:13 - 01604140 ____A C:\Windows\System32\PerfStringBackup.INI 2013-03-20 09:42 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-03-20 09:42 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-03-20 09:34 - 2013-03-20 09:34 - 00003352 ____N C:\bootsqm.dat 2013-03-20 09:18 - 2013-03-20 11:00 - 00102400 ___RA C:\Users\Mikael\AppData\Roaming\skype.dat 2013-03-20 09:00 - 2013-03-18 04:50 - 00000994 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-03-20 08:29 - 2012-06-22 06:53 - 00001008 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405421564-331882077-3349474539-1001UA.job 2013-03-20 07:42 - 2013-03-20 07:42 - 00002351 ____A C:\Users\Mikael\Desktop\Search.lnk 2013-03-20 07:42 - 2013-03-19 12:19 - 00000000 ____D C:\Users\Mikael\AppData\Local\Smartbar 2013-03-20 07:40 - 2012-10-08 15:32 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Skype 2013-03-20 04:29 - 2012-06-22 06:52 - 00000956 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405421564-331882077-3349474539-1001Core.job 2013-03-19 12:21 - 2013-03-18 04:48 - 00000000 ____D C:\ProgramData\Adobe 2013-03-19 12:20 - 2011-10-20 01:30 - 00150674 ____A C:\Windows\PFRO.log 2013-03-19 12:18 - 2012-06-22 02:29 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\DVDVideoSoft 2013-03-19 12:17 - 2013-03-19 12:17 - 00001241 ____A C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-03-19 12:17 - 2012-06-22 02:30 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-03-19 12:16 - 2013-03-19 12:16 - 00000000 ____D C:\ProgramData\Uniblue 2013-03-19 12:15 - 2013-03-19 12:15 - 00001191 ____A C:\Users\Public\Desktop\DriverScanner.lnk 2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Uniblue 2013-03-19 12:15 - 2013-03-19 12:15 - 00000000 ____D C:\Program Files (x86)\Uniblue 2013-03-19 12:14 - 2013-03-19 12:14 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\OpenCandy 2013-03-18 05:20 - 2012-07-17 14:36 - 00000000 ____D C:\Users\Mikael\AppData\Local\CrashDumps 2013-03-18 04:54 - 2013-03-18 04:54 - 00000000 ____D C:\Users\Mikael\AppData\Local\Adobe 2013-03-18 04:54 - 2012-06-10 04:00 - 00000000 ____D C:\Users\Mikael\AppData\Roaming\Adobe 2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\ProgramData\Google 2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files\Google 2013-03-18 04:50 - 2013-03-18 04:50 - 00000000 ____D C:\Program Files (x86)\Google 2013-03-18 04:49 - 2013-03-18 04:49 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-03-18 04:49 - 2013-01-17 13:31 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-03-17 12:07 - 2013-03-17 12:07 - 00000000 ____D C:\Users\Mikael\AppData\Local\{959F1B82-8ADA-40B3-8FED-B7C142DA09A4} 2013-03-15 01:31 - 2012-12-23 11:56 - 00000000 ____D C:\Windows\rescache 2013-03-15 00:37 - 2012-06-12 02:03 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-03-15 00:30 - 2012-07-08 03:10 - 72013344 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-03-15 00:23 - 2013-03-15 00:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-03-14 04:15 - 2012-08-29 03:07 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-03-14 04:15 - 2012-08-29 03:07 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-03-10 16:36 - 2012-09-13 03:56 - 00000000 ____D C:\Users\Mikael\Desktop\Songs 2013-03-08 00:31 - 2013-03-08 00:31 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk 2013-03-08 00:31 - 2012-10-08 15:32 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-03-08 00:31 - 2012-10-08 15:31 - 00000000 ____D C:\ProgramData\Skype 2013-03-07 01:30 - 2013-03-06 06:23 - 00000000 ____D C:\Users\Mikael\AppData\Local\{EE2978B1-1F90-4870-BA3E-33B36625CC80} ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 15% Total physical RAM: 3691.7 MB Available physical RAM: 3135.11 MB Total Pagefile: 3689.85 MB Available Pagefile: 3124.38 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:128.18 GB) (Free:8.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 2 Drive d: (DATA) (Fixed) (Total:144.91 GB) (Free:123.45 GB) NTFS 5 Drive g: (KINGSTON) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT 6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt -------- ------------- ------- ------- --- --- Disk 0 Online 298 GB 0 B Disk 1 No Media 0 B 0 B Disk 2 Online 1909 MB 0 B Partitions of Disk 0: =============== Disk ID: 125FC5E1 Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 25 GB 1024 KB Partition 2 Primary 128 GB 25 GB Partition 3 Primary 144 GB 153 GB ================================================================================== Disk: 0 Partition 1 Type : 1C Hidden: Yes Active: No There is no volume associated with this partition. ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 C OS NTFS Partition 128 GB Healthy ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 D DATA NTFS Partition 144 GB Healthy ========================================================= Partitions of Disk 2: =============== Disk ID: 00000000 Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 1905 MB 4032 KB ================================================================================== Disk: 2 Partition 1 Type : 06 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 G KINGSTON FAT Removable 1905 MB Healthy ========================================================= ============================== MBR Partition Table ================== ============================== Partitions of Disk 0: =============== Disk ID: 125FC5E1 Partition 1: ========= Hex: 002021001CFEFFFF0008000000002003 Active: NO Type: 1C Size: 25 GB Partition 2: ========= Hex: 80FEFFFF07FEFFFF0008200300B80510 Active: YES Type: 07 (NTFS) Size: 128 GB Partition 3: ========= Hex: 00FEFFFF07FEFFFF00C0251300281D12 Active: NO Type: 07 (NTFS) Size: 145 GB ============================== Partitions of Disk 2: =============== Disk ID: 00000000 Partition 1: ========= Hex: 80010C0F060F60D3801F000080883B00 Active: YES Type: 06 Size: 2 GB Last Boot: 2013-03-15 01:24 ==================== End Of Log ============================= [/QUOTE]
Insert quotes…
Verification
Post reply
Top