Jump to content

FBI virus with Safe Mode diasabled


Recommended Posts

I have the FBI virus. I followed the first steps that were noted in previous posts all the way up to the point where the reply was specific to the person who posted the original thread.

here is a copy of the FRST scan

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2013

Ran by SYSTEM on 20-04-2013 17:02:08

Running from E:\

Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)

Internet Explorer Version 9

Boot Mode: Recovery

The current controlset is ControlSet001

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2531624 2010-12-17] (Synaptics Incorporated)

HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6611048 2011-02-18] (Realtek Semiconductor)

HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3 [2188904 2011-01-18] (Realtek Semiconductor)

HKLM\...\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()

HKLM\...\Run: [NtrigApplet] C:\Program Files\N-trig\DuoSense Control Apps\NtrigApplet.exe [2563072 2012-07-04] (N-trig LLC)

HKLM\...\Run: [bTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [10357008 2011-10-18] (Intel Corporation)

HKLM\...\Run: [intelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-11-01] (Intel® Corporation)

HKLM\...\Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe [4479648 2011-01-25] (Dell Inc.)

HKLM\...\Run: [intelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-11-29] ()

HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [483424 2012-02-01] ()

HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [MCTDUtil] C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe Launch SuperUtil [195200 2011-05-03] ()

HKLM\...\Run: [FDispPos] C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe Launch FixPos [195200 2011-05-03] ()

HKLM\...\Run: [HP Color LaserJet CM2320 MFP Series Fax] C:\Program Files (x86)\HP\HP Color LaserJet CM2320 MFP Series\hppfaxprintersrv.exe "HP Color LaserJet CM2320 MFP Series Fax" [3700736 2009-09-22] (Hewlett-Packard Company)

HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [38112 2012-12-18] (Adobe Systems Incorporated)

HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)

HKLM-x32\...\Run: [stickyNotesWidget] "c:\Program Files (x86)\Dell Touch Software Suite\StickyNotes\notes_startup_widgets.exe" "c:\Program Files (x86)\Dell Touch Software Suite\StickyNotes\start.umj" [666344 2011-03-18] ()

HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)

HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)

HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()

HKLM-x32\...\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [1534504 2013-01-14] (McAfee, Inc.)

HKLM-x32\...\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900 [67496 2012-08-21] ()

HKLM-x32\...\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup [968048 2012-02-01] ()

HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [520330 2011-08-12] (Creative Technology Ltd)

HKLM-x32\...\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)

HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)

HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)

HKLM-x32\...\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [204136 2012-09-12] (Logitech Inc.)

HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe" [3478752 2012-09-23] (Adobe Systems Inc.)

HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-18] (Apple Inc.)

HKLM-x32\...\Run: [] [x]

HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-24] (Apple Inc.)

HKLM-x32\...\Run: [HPUsageTracking] "C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\" [24576 2009-05-11] (Hewlett-Packard Company)

HKLM-x32\...\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)

HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1646216 2013-03-31] (Ask)

HKU\Chris Saad\...\Run: [Google Update] "C:\Users\Chris Saad\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-10] (Google Inc.)

HKU\Chris Saad\...\Run: [googletalk] C:\Users\Chris Saad\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)

HKU\Chris Saad\...\Run: [Akamai NetSession Interface] "C:\Users\Chris Saad\AppData\Local\Akamai\netsession_win.exe" [4480768 2013-01-26] (Akamai Technologies, Inc.)

HKU\Chris Saad\...\Run: [skyDrive] "C:\Users\Chris Saad\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background [256600 2013-03-19] (Microsoft Corporation)

HKU\Chris Saad\...\Run: [CardScan AutoSync] [x]

HKU\Chris Saad\...\RunOnce: [uninstall C:\Users\Chris Saad\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chris Saad\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_1\amd64" [x]

HKU\Chris Saad\...\Winlogon: [shell] explorer.exe,C:\Users\Chris Saad\AppData\Roaming\skype.dat [90112 2012-07-04] ()

AppInit_DLLs: C:\Windows\system32\nvinitx.dll [250504 2013-03-14] (NVIDIA Corporation)

Startup: C:ProgramData\Start Menu\Programs\Startup\Google Calendar Sync.lnk

ShortcutTarget: Google Calendar Sync.lnk -> C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)

Startup: C:ProgramData\Start Menu\Programs\Startup\Logitech Media Server Tray Tool.lnk

ShortcutTarget: Logitech Media Server Tray Tool.lnk -> C:\Program Files (x86)\Squeezebox\SqueezeTray.exe (Logitech Inc.)

Startup: C:ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe (McAfee, Inc.)

Startup: C:\Users\Chris Saad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk

ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) =================

S4 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [8515544 2012-07-30] (DisplayLink Corp.)

S2 GManager; C:\Windows\system32\GManager.exe [313432 2012-08-28] ()

S3 McAWFwk; c:\PROGRA~1\mcafee\msc\mcawfwk.exe [224704 2011-03-08] (McAfee, Inc.)

S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe [227232 2010-09-02] (McAfee, Inc.)

S2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [383608 2012-11-16] (McAfee, Inc.)

S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.)

S2 MCTDesktopSvr; C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe [199296 2011-05-03] ()

S2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.)

S2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.)

S2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)

S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-11-01] ()

S2 NasPmService; C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe [251760 2012-07-13] (BUFFALO INC.)

S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]

==================== Drivers (Whitelisted) ====================

S3 AVer7231_x64; C:\Windows\System32\DRIVERS\AVer7231_x64.sys [1800576 2010-08-27] (AVerMedia TECHNOLOGIES, Inc.)

S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.)

S3 DisplayLinkUsbPort; C:\Windows\System32\DRIVERS\DisplayLinkUsbPort_6.3.40660.0.sys [17408 2012-07-30] (http://libusb-win32.sourceforge.net)

S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)

S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.)

S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.)

S3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.)

S0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.)

S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.)

S0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.)

S3 NtrigDigitizerUSBLowerFilter; C:\Windows\System32\DRIVERS\NtrigDigitizerUSBLowerFilter.sys [13776 2010-08-16] (Windows ® Codename Longhorn DDK provider)

S1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284448 2013-03-14] (NVIDIA Corporation)

S3 t1pusb64; C:\Windows\System32\drivers\t1pusb64.sys [178656 2012-09-28] (Magic Control Technology Corp.)

S3 mctkmd; \SystemRoot\system32\drivers\mctkmd64.sys [x]

S0 mctkmdldr; system32\drivers\mctkmdldr64.sys [x]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-04-20 16:15 - 2013-04-20 16:15 - 00000000 ____D C:\FRST

2013-04-20 11:43 - 2013-04-20 12:55 - 00000004 ____A C:\Users\Chris Saad\Application Data\skype.ini

2013-04-20 11:43 - 2013-04-20 12:55 - 00000004 ____A C:\Users\Chris Saad\AppData\Roaming\skype.ini

2013-04-20 11:38 - 2013-04-20 11:38 - 00090112 ____A C:\Users\Chris Saad\Downloads\AdobeFlashPlayer_11.8.301.exe

2013-04-20 09:37 - 2013-04-20 09:37 - 00670936 ____A C:\Windows\Minidump\042013-16177-01.dmp

2013-04-19 10:22 - 2013-04-19 11:00 - 380301584 ____A C:\Users\Chris Saad\Downloads\AIO_CDB_FSW_Full_Win_WW_130_141.exe

2013-04-17 06:25 - 2013-04-17 06:25 - 00000000 ____D C:\Program Files (x86)\Ask.com

2013-04-17 06:15 - 2013-04-17 06:15 - 00903072 ____A (Oracle Corporation) C:\Users\Chris Saad\Downloads\chromeinstall-7u21.exe

2013-04-17 06:15 - 2013-04-17 06:14 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe

2013-04-17 06:15 - 2013-04-17 06:14 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2013-04-17 06:15 - 2013-04-17 06:14 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2013-04-17 06:15 - 2013-04-17 06:14 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2013-04-16 04:55 - 2013-04-16 04:59 - 299662170 ____A C:\Users\Chris Saad\Downloads\Tribal_Leadership_Audiobook.zip

2013-04-15 09:24 - 2013-04-15 09:24 - 00017150 ____A C:\Users\Chris Saad\Desktop\TERMS AND CONDITIONS 04-15-2013.docm

2013-04-15 06:19 - 2013-04-15 06:19 - 00052736 ____A C:\Users\Chris Saad\Downloads\C_Contract.rpt

2013-04-15 06:19 - 2013-04-15 06:19 - 00052736 ____A C:\Users\Chris Saad\Downloads\C_Contract (1).rpt

2013-04-15 06:15 - 2013-04-15 06:15 - 00015872 ____A C:\Users\Chris Saad\Downloads\Contract Information Sheet 03-20-07.XLT

2013-04-15 06:13 - 2013-04-15 06:13 - 00031232 ____A C:\Users\Chris Saad\Downloads\AAAA CONTRACT SHORT FORM BLANK MA-salescheck.xls

2013-04-15 03:28 - 2013-04-19 10:20 - 00019465 ____A C:\Users\Chris Saad\Desktop\warranty final 04-16-2013.dotm

2013-04-11 15:17 - 2013-04-11 15:17 - 00000000 ____D C:\Windows\SysWOW64\NV

2013-04-11 15:17 - 2013-04-11 15:17 - 00000000 ____D C:\Windows\System32\NV

2013-04-11 15:14 - 2013-04-20 12:54 - 00000000 ____D C:ProgramData\NVIDIA

2013-04-11 15:14 - 2013-04-20 12:54 - 00000000 ____D C:ProgramData\Application Data\NVIDIA

2013-04-11 15:14 - 2013-04-11 15:14 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini

2013-04-11 15:14 - 2013-04-11 15:14 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies

2013-04-11 15:14 - 2013-04-11 15:09 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\SoftThinks

2013-04-11 15:14 - 2013-04-11 15:09 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\Application Data\SoftThinks

2013-04-11 15:14 - 2013-04-11 15:09 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\SoftThinks

2013-04-11 15:14 - 2013-01-17 06:16 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\Google

2013-04-11 15:14 - 2013-01-17 06:16 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\Application Data\Google

2013-04-11 15:14 - 2013-01-17 06:16 - 00000000 ____D C:\Users\UpdatusUser\AppData\LocalGoogle

2013-04-11 15:14 - 2013-01-17 06:16 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google

2013-04-11 15:14 - 2012-07-14 23:02 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\Microsoft Help

2013-04-11 15:14 - 2012-07-14 23:02 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\Application Data\Microsoft Help

2013-04-11 15:14 - 2012-07-14 23:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help

2013-04-11 15:14 - 2012-07-04 15:13 - 00000000 ____D C:\Users\UpdatusUser\Application Data\Macromedia

2013-04-11 15:14 - 2012-07-04 15:13 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia

2013-04-11 15:13 - 2013-04-11 15:13 - 00000000 ____D C:ProgramData\NVIDIA Corporation

2013-04-11 15:13 - 2013-04-11 15:13 - 00000000 ____D C:ProgramData\Application Data\NVIDIA Corporation

2013-04-11 15:13 - 2013-03-14 21:53 - 00061216 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll

2013-04-11 15:13 - 2013-03-14 21:53 - 00053024 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 06398240 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 03477280 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 02555680 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 01016096 ____A (NVIDIA Corporation) C:\Windows\System32\nv3dappshext.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 00877856 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

2013-04-11 15:13 - 2013-03-14 20:16 - 00237856 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 00076064 ____A (NVIDIA Corporation) C:\Windows\System32\nv3dappshextr.dll

2013-04-11 15:13 - 2013-03-14 20:16 - 00063776 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll

2013-04-11 15:13 - 2013-03-13 08:24 - 03065455 ____A C:\Windows\System32\nvcoproc.bin

2013-04-11 15:06 - 2013-03-14 21:53 - 26956576 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 25256736 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 20542752 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 17990800 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 17560352 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 15508512 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 15042928 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 13088000 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 11048736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys

2013-04-11 15:06 - 2013-03-14 21:53 - 09414456 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 07959000 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 07573816 ____A (NVIDIA Corporation) C:\Windows\System32\nvopencl.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 06271872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 02913056 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 02864144 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 02728736 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 02539128 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 02355488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 01995552 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 01807136 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco6431422.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 01510176 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispgenco6431422.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 01118776 ____A (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 00968408 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 00284448 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvkflt.sys

2013-04-11 15:06 - 2013-03-14 21:53 - 00250504 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 00205184 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll

2013-04-11 15:06 - 2013-03-14 21:53 - 00030496 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvpciflt.sys

2013-04-11 15:06 - 2013-03-14 21:53 - 00017738 ____A C:\Windows\System32\nvinfo.pb

2013-04-11 15:06 - 2012-12-18 21:42 - 00031672 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll

2013-04-11 15:06 - 2012-12-18 21:41 - 00194488 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys

2013-04-11 15:06 - 2012-12-18 00:31 - 01510328 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll

2013-04-11 14:23 - 2013-04-11 14:23 - 00000165 ___AH C:\Users\Chris Saad\Desktop\~$office 365 employee chart.xlsx

2013-04-11 06:46 - 2013-02-21 22:57 - 17817088 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-04-11 06:46 - 2013-02-21 22:29 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2013-04-11 06:46 - 2013-02-21 22:27 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2013-04-11 06:46 - 2013-02-21 22:21 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2013-04-11 06:46 - 2013-02-21 22:20 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll

2013-04-11 06:46 - 2013-02-21 22:19 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl

2013-04-11 06:46 - 2013-02-21 22:18 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll

2013-04-11 06:46 - 2013-02-21 22:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2013-04-11 06:46 - 2013-02-21 22:15 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll

2013-04-11 06:46 - 2013-02-21 22:15 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll

2013-04-11 06:46 - 2013-02-21 22:15 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe

2013-04-11 06:46 - 2013-02-21 22:14 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2013-04-11 06:46 - 2013-02-21 22:13 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2013-04-11 06:46 - 2013-02-21 22:13 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll

2013-04-11 06:46 - 2013-02-21 22:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-04-11 06:46 - 2013-02-21 22:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll

2013-04-11 06:46 - 2013-02-21 20:05 - 12324352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2013-04-11 06:46 - 2013-02-21 19:47 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2013-04-11 06:46 - 2013-02-21 19:46 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2013-04-11 06:46 - 2013-02-21 19:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2013-04-11 06:46 - 2013-02-21 19:38 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2013-04-11 06:46 - 2013-02-21 19:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2013-04-11 06:46 - 2013-02-21 19:36 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2013-04-11 06:46 - 2013-02-21 19:35 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2013-04-11 06:46 - 2013-02-21 19:34 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2013-04-11 06:46 - 2013-02-21 19:34 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2013-04-11 06:46 - 2013-02-21 19:34 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2013-04-11 06:46 - 2013-02-21 19:33 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2013-04-11 06:46 - 2013-02-21 19:32 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2013-04-11 06:46 - 2013-02-21 19:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2013-04-11 06:46 - 2013-02-21 19:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2013-04-11 06:46 - 2013-02-21 19:28 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2013-04-10 05:10 - 2013-02-14 22:08 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll

2013-04-10 05:10 - 2013-02-14 22:06 - 03717632 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll

2013-04-10 05:10 - 2013-02-14 22:02 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll

2013-04-10 05:10 - 2013-02-14 20:37 - 03217408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll

2013-04-10 05:10 - 2013-02-14 20:34 - 00131584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll

2013-04-10 05:10 - 2013-02-14 19:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll

2013-04-10 05:09 - 2013-03-18 22:04 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe

2013-04-10 05:09 - 2013-03-18 21:46 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll

2013-04-10 05:09 - 2013-03-18 21:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe

2013-04-10 05:09 - 2013-03-18 21:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe

2013-04-10 05:09 - 2013-03-18 20:47 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll

2013-04-10 05:09 - 2013-03-18 19:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe

2013-04-10 05:09 - 2013-03-01 22:04 - 01655656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys

2013-04-10 05:09 - 2013-02-28 19:36 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-04-10 05:09 - 2013-01-23 22:01 - 00223752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys

2013-04-09 11:05 - 2013-04-09 11:05 - 00001054 ____A C:\Users\Chris Saad\Desktop\Logitech Media Server.lnk

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:ProgramData\Squeezebox

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:ProgramData\Application Data\Squeezebox

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:\updates

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:\Program Files (x86)\Squeezebox

2013-04-09 09:54 - 2013-04-09 09:56 - 58564896 ____A (Logitech ) C:\Users\Chris Saad\Downloads\LogitechMediaServer-7.7.2.exe

2013-04-09 08:17 - 2013-04-15 16:45 - 00019618 ____A C:\Users\Chris Saad\Desktop\showroom layout.xlsx

2013-04-09 08:09 - 2013-04-09 08:09 - 04111359 ____A C:\Users\Chris Saad\Downloads\FP28646_ISW-4_drawings.zip

2013-04-08 04:45 - 2013-04-08 04:45 - 00000608 __ASH C:\Windows\System32\winzvprt5.sys

2013-04-08 04:45 - 2013-04-08 04:45 - 00000234 ____A C:\Windows\System32\hppfaxprinter5.ini

2013-04-08 04:45 - 2013-04-08 04:45 - 00000000 ____D C:ProgramData\Documents\HP

2013-04-08 04:45 - 2013-04-08 04:45 - 00000000 ____D C:\Users\Public\Documents\HP

2013-04-08 04:45 - 2009-09-22 16:44 - 00022016 ____N (Hewlett-Packard Company) C:\Windows\System32\hppfaxprintermon5.dll

2013-04-08 04:45 - 2009-09-22 16:44 - 00016384 ____N (Hewlett-Packard Company) C:\Windows\System32\hppfaxprintermonui5.dll

2013-04-08 04:43 - 2013-04-08 04:43 - 00000142 ____A C:\Windows\System32\AddPort.ini

2013-04-08 04:42 - 2013-04-08 04:43 - 00000704 ____A C:\Windows\hpntwksetup.ini

2013-04-08 04:40 - 2013-04-08 04:51 - 00177010 ____A C:\Windows\hppins12.dat

2013-04-08 04:40 - 2009-10-16 11:47 - 00007855 ____N C:\Windows\hppmdl12.dat

2013-04-08 03:56 - 2013-04-08 03:58 - 335035344 ____A C:\Users\Chris Saad\Downloads\CM2320series-win7-full-solution-AM-EMEA1-v3.1.exe

2013-04-06 07:10 - 2012-11-08 16:34 - 00143712 ____A (Magic Control Technology Corporation) C:\Windows\SysWOW64\MCTU.dll

2013-04-06 07:10 - 2012-11-08 14:57 - 00142176 ____A (Magic Control Technology Corporation) C:\Windows\System32\Drivers\mctkmd64.sys

2013-04-06 07:10 - 2012-10-30 12:47 - 00917080 ____A (Magic Control Technology Corporation) C:\Windows\System32\MTrigger2.exe

2013-04-06 07:10 - 2012-09-28 09:48 - 00178656 ____A (Magic Control Technology Corp.) C:\Windows\System32\Drivers\t1pusb64.sys

2013-04-06 07:10 - 2012-08-28 10:20 - 00313432 ____A C:\Windows\System32\GManager.exe

2013-04-06 07:10 - 2012-02-03 14:15 - 00272512 ____A C:\Windows\System32\U2VSvr.exe

2013-04-06 07:10 - 2011-09-09 14:30 - 00440320 ____A (Magic Control Technology Corporation) C:\Windows\System32\SU-T2.exe

2013-04-06 07:10 - 2011-06-27 11:16 - 00272512 ____A C:\Windows\System32\U2VT2Svr.exe

2013-04-06 07:10 - 2011-05-05 10:24 - 00274048 ____A (MCT) C:\Windows\System32\MHK2.DLL

2013-04-06 07:10 - 2011-05-04 16:04 - 01113728 ____A (Magic Control Technology Corporation) C:\Windows\System32\MTri1+64.exe

2013-04-06 07:10 - 2011-05-04 16:04 - 00917120 ____A (Magic Control Technology Corporation) C:\Windows\System32\SilentUtility.exe

2013-04-06 07:10 - 2011-05-04 16:04 - 00195200 ____A C:\Windows\System32\Util.exe

2013-04-06 07:10 - 2011-05-04 16:01 - 00261760 ____A C:\Windows\System32\Util-MTrigger2.exe

2013-04-06 07:10 - 2011-04-08 12:38 - 00019584 ____A (Magic Control Technology Corporation) C:\Windows\System32\Drivers\mctKmdldr64.sys

2013-04-06 07:10 - 2010-11-13 07:22 - 00272760 ____A (MCT) C:\Windows\System32\MCTHOOKKEY.DLL

2013-04-06 07:10 - 2010-10-15 16:44 - 00048170 ____A C:\Windows\System32\MTri1+.ini

2013-04-06 07:10 - 2010-10-15 16:43 - 00048178 ____A C:\Windows\System32\Mtrigger2.ini

2013-04-06 07:10 - 2010-08-20 10:03 - 00336248 ____A (Magic Control Technology Corporation) C:\Windows\System32\mctsetup64.dll

2013-04-06 07:10 - 2008-07-08 13:51 - 00315392 ____A (TODO: <Company name>) C:\Windows\SysWOW64\mctudll.exe

2013-04-06 07:10 - 2008-04-03 10:13 - 00045056 ____A C:\Windows\SysWOW64\mctudll.dll

2013-04-06 07:10 - 2008-03-25 15:39 - 00430080 ____A () C:\Windows\SysWOW64\UDLL.dll

2013-04-06 07:09 - 2012-11-08 16:34 - 00180576 ____A (Magic Control Technology Corporation) C:\Windows\System32\mctux.dll

2013-04-06 07:07 - 2013-04-06 07:07 - 00000000 ____D C:\Users\Chris Saad\Application Data\InstallShield

2013-04-06 07:07 - 2013-04-06 07:07 - 00000000 ____D C:\Users\Chris Saad\AppData\Roaming\InstallShield

2013-04-06 07:07 - 2013-04-06 07:07 - 00000000 ____D C:\Program Files (x86)\MCT Corp

2013-04-06 07:00 - 2013-04-20 12:54 - 00002812 ____A C:\Windows\System32\GManager.ini

2013-04-06 06:57 - 2013-04-06 06:57 - 14386736 ____A (Macrovision Corporation) C:\Users\Chris Saad\Downloads\Eclipse-UV150-UV250-12.01.1108.1177.exe

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumdfb9.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumdfb11.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumdfb10.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumd9.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumd11.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumd10.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\System32\dlumd9.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\System32\dlumd11.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\System32\dlumd10.dll

2013-04-04 03:35 - 2012-07-30 13:13 - 00318840 ____A (DisplayLink Corp.) C:\Windows\System32\Drivers\dlkmd.sys

2013-04-04 03:35 - 2012-07-30 13:13 - 00015224 ____A (DisplayLink Corp.) C:\Windows\System32\Drivers\dlkmdldr.sys

2013-04-04 03:34 - 2013-04-04 03:35 - 00000000 ____D C:\Program Files\DisplayLink Core Software

2013-04-03 17:31 - 2013-04-03 17:31 - 00228864 ____A C:\Users\Chris Saad\Desktop\Audio Concepts P&L.xls

2013-04-03 08:38 - 2013-04-04 13:27 - 00008983 ____A C:\Users\Chris Saad\Desktop\blair savant trip.xlsx

2013-04-03 04:39 - 2013-04-03 04:39 - 00011653 ____A C:\Users\Chris Saad\Desktop\office 365 employee chart.xlsx

2013-04-01 10:05 - 2009-10-14 09:25 - 00157184 ____A (Hewlett-Packard Corporation) C:\Windows\System32\hpcpn093.dll

2013-04-01 10:05 - 2009-10-14 09:16 - 00276480 ____A (Hewlett Packard Corporation) C:\Windows\SysWOW64\hpcc3093.DLL

2013-04-01 10:05 - 2009-02-25 16:08 - 00671816 ____A (HP) C:\Windows\SysWOW64\hpcdmc32.DLL

2013-04-01 10:05 - 2007-07-16 11:29 - 00060440 ____A (Hewlett-Packard) C:\Windows\System32\fxcompchannel_x64.dll

2013-04-01 10:05 - 2007-07-16 11:29 - 00059928 ____A (Hewlett-Packard) C:\Windows\SysWOW64\fxcompchannel.dll

2013-04-01 09:37 - 2009-09-28 11:44 - 01121792 ____A (Hewlett-Packard) C:\Windows\System32\hpptsp05_x64.dll

2013-04-01 09:37 - 2009-09-28 11:37 - 00770048 ____A (Hewlett-Packard) C:\Windows\SysWOW64\hpptsp05.dll

2013-04-01 09:37 - 2009-09-21 15:20 - 00003212 ____A C:\Windows\System32\hppls2320.spf

2013-04-01 09:37 - 2009-08-26 14:15 - 00995840 ____A (Hewlett-Packard) C:\Windows\System32\hpxp2320_x64.dll

2013-04-01 09:37 - 2008-09-30 07:52 - 00747008 ____A (Hewlett-Packard) C:\Windows\System32\hppasc12_x64.dll

2013-04-01 09:37 - 2008-09-30 07:52 - 00165376 ____A (Hewlett-Packard) C:\Windows\System32\hppdpr12_x64.dll

2013-04-01 09:36 - 2013-04-08 04:06 - 00000000 ____D C:\CM_2320_Full_Solution_Win7_3_1_AM-EMEA1

2013-04-01 09:36 - 2008-09-30 07:52 - 00000665 ____A C:\Windows\System32\hppapr12.dat

2013-04-01 09:32 - 2013-04-11 14:58 - 00000000 ____D C:\disk

2013-03-29 03:25 - 2013-03-29 03:25 - 00000000 ____D C:\Users\Chris Saad\Desktop\Manu videos for NA

2013-03-22 16:29 - 2013-03-22 16:29 - 00010589 ____A C:\Users\Chris Saad\Desktop\Book1.xlsx

2013-03-21 19:22 - 2013-03-21 19:22 - 01098888 ____A (AirInstaller Inc.) C:\Users\Chris Saad\Downloads\setup.exe

2013-03-21 18:43 - 2013-03-23 09:31 - 00000000 ____D C:\Program Files (x86)\Iminent

2013-03-21 18:43 - 2013-03-21 19:14 - 00000866 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog

2013-03-21 18:42 - 2013-03-21 19:15 - 00000000 ____D C:ProgramData\Tarma Installer

2013-03-21 18:42 - 2013-03-21 19:15 - 00000000 ____D C:ProgramData\Application Data\Tarma Installer

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\Local Settings\CRE

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\Local Settings\Application Data\CRE

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\Application Data\Conduit

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\AppData\Roaming\Conduit

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\AppData\Local\CRE

2013-03-21 18:41 - 2013-03-21 18:42 - 00000009 ____A C:\END

2013-03-21 18:41 - 2013-03-21 18:41 - 00001105 ____A C:\Users\Chris Saad\Desktop\Flash Player Pro.lnk

2013-03-21 18:41 - 2013-03-21 18:41 - 00000000 ____D C:\Users\Chris Saad\My Documents\Flash Player Pro

2013-03-21 18:41 - 2013-03-21 18:41 - 00000000 ____D C:\Users\Chris Saad\Documents\Flash Player Pro

2013-03-21 18:41 - 2013-03-21 18:41 - 00000000 ____D C:\Program Files (x86)\Flash Player Pro

2013-03-21 18:40 - 2013-03-21 18:40 - 01098888 ____A (AirInstaller Inc.) C:\Users\Chris Saad\Downloads\Upgrade.exe

==================== One Month Modified Files and Folders =======

2013-04-20 16:15 - 2013-04-20 16:15 - 00000000 ____D C:\FRST

2013-04-20 12:55 - 2013-04-20 11:43 - 00000004 ____A C:\Users\Chris Saad\Application Data\skype.ini

2013-04-20 12:55 - 2013-04-20 11:43 - 00000004 ____A C:\Users\Chris Saad\AppData\Roaming\skype.ini

2013-04-20 12:55 - 2012-07-04 14:48 - 00000000 ____D C:\Users\Default\Local Settings\SoftThinks

2013-04-20 12:55 - 2012-07-04 14:48 - 00000000 ____D C:\Users\Default\Local Settings\Application Data\SoftThinks

2013-04-20 12:55 - 2012-07-04 14:48 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks

2013-04-20 12:55 - 2012-07-04 14:48 - 00000000 ____D C:\Users\Default User\Local Settings\SoftThinks

2013-04-20 12:55 - 2012-07-04 14:48 - 00000000 ____D C:\Users\Default User\Local Settings\Application Data\SoftThinks

2013-04-20 12:55 - 2012-07-04 14:48 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks

2013-04-20 12:55 - 2012-07-04 14:44 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup

2013-04-20 12:54 - 2013-04-11 15:14 - 00000000 ____D C:ProgramData\NVIDIA

2013-04-20 12:54 - 2013-04-11 15:14 - 00000000 ____D C:ProgramData\Application Data\NVIDIA

2013-04-20 12:54 - 2013-04-06 07:00 - 00002812 ____A C:\Windows\System32\GManager.ini

2013-04-20 12:54 - 2012-10-28 16:54 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-04-20 12:54 - 2012-10-20 10:53 - 00069741 ____A C:\Windows\setupact.log

2013-04-20 12:54 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2013-04-20 12:40 - 2012-07-04 14:02 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job

2013-04-20 12:39 - 2009-07-13 20:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-04-20 12:39 - 2009-07-13 20:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-04-20 12:36 - 2009-07-13 21:13 - 00796698 ____A C:\Windows\System32\PerfStringBackup.INI

2013-04-20 12:35 - 2012-07-04 15:53 - 01722037 ____A C:\Windows\WindowsUpdate.log

2013-04-20 12:24 - 2012-11-25 19:06 - 00000000 ___RD C:\Users\Chris Saad\SkyDrive

2013-04-20 11:43 - 2012-07-19 03:41 - 00000000 ____D C:\Users\Chris Saad\Desktop\stuff

2013-04-20 11:38 - 2013-04-20 11:38 - 00090112 ____A C:\Users\Chris Saad\Downloads\AdobeFlashPlayer_11.8.301.exe

2013-04-20 11:32 - 2012-10-28 16:54 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-04-20 11:32 - 2012-07-10 16:53 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1567758817-3846694028-185324655-1002UA.job

2013-04-20 11:32 - 2012-07-04 15:09 - 00000000 ____D C:ProgramData\Sonic

2013-04-20 11:32 - 2012-07-04 15:09 - 00000000 ____D C:ProgramData\Application Data\Sonic

2013-04-20 09:37 - 2013-04-20 09:37 - 00670936 ____A C:\Windows\Minidump\042013-16177-01.dmp

2013-04-20 09:37 - 2012-11-11 10:28 - 856880770 ____A C:\Windows\MEMORY.DMP

2013-04-20 09:37 - 2012-09-14 10:15 - 00000000 ____D C:\Windows\Minidump

2013-04-20 06:22 - 2012-07-13 15:54 - 00000000 ____D C:\Users\Chris Saad\Local Settings\Nero

2013-04-20 06:22 - 2012-07-13 15:54 - 00000000 ____D C:\Users\Chris Saad\Local Settings\Application Data\Nero

2013-04-20 06:22 - 2012-07-13 15:54 - 00000000 ____D C:\Users\Chris Saad\AppData\Local\Nero

2013-04-19 12:53 - 2012-07-11 07:33 - 00002080 ___AH C:\Users\Chris Saad\My Documents\Default.rdp

2013-04-19 12:53 - 2012-07-11 07:33 - 00002080 ___AH C:\Users\Chris Saad\Documents\Default.rdp

2013-04-19 12:10 - 2012-07-10 16:53 - 00000876 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1567758817-3846694028-185324655-1002Core.job

2013-04-19 11:00 - 2013-04-19 10:22 - 380301584 ____A C:\Users\Chris Saad\Downloads\AIO_CDB_FSW_Full_Win_WW_130_141.exe

2013-04-19 10:25 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp

2013-04-19 10:20 - 2013-04-15 03:28 - 00019465 ____A C:\Users\Chris Saad\Desktop\warranty final 04-16-2013.dotm

2013-04-17 08:33 - 2012-10-11 10:13 - 00033732 ____A C:\Users\Chris Saad\Desktop\Master Truck Stock List.xlsx

2013-04-17 06:25 - 2013-04-17 06:25 - 00000000 ____D C:\Program Files (x86)\Ask.com

2013-04-17 06:25 - 2013-02-06 05:35 - 00000000 ____D C:\Firefox

2013-04-17 06:15 - 2013-04-17 06:15 - 00903072 ____A (Oracle Corporation) C:\Users\Chris Saad\Downloads\chromeinstall-7u21.exe

2013-04-17 06:14 - 2013-04-17 06:15 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe

2013-04-17 06:14 - 2013-04-17 06:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2013-04-17 06:14 - 2013-04-17 06:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2013-04-17 06:14 - 2013-04-17 06:15 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2013-04-17 06:14 - 2012-10-06 17:11 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll

2013-04-17 06:14 - 2012-10-06 17:11 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll

2013-04-16 11:36 - 2012-07-12 08:00 - 00000000 ____D C:\Users\Chris Saad\My Documents\My Scans

2013-04-16 11:36 - 2012-07-12 08:00 - 00000000 ____D C:\Users\Chris Saad\Documents\My Scans

2013-04-16 04:59 - 2013-04-16 04:55 - 299662170 ____A C:\Users\Chris Saad\Downloads\Tribal_Leadership_Audiobook.zip

2013-04-16 02:41 - 2012-07-04 15:11 - 00000000 ____D C:\Program Files (x86)\McAfee

2013-04-16 02:41 - 2010-11-20 19:47 - 00126964 ____A C:\Windows\PFRO.log

2013-04-15 16:45 - 2013-04-09 08:17 - 00019618 ____A C:\Users\Chris Saad\Desktop\showroom layout.xlsx

2013-04-15 13:46 - 2012-07-11 09:00 - 00000000 ____D C:\Users\Chris Saad\Application Data\Skype

2013-04-15 13:46 - 2012-07-11 09:00 - 00000000 ____D C:\Users\Chris Saad\AppData\Roaming\Skype

2013-04-15 09:24 - 2013-04-15 09:24 - 00017150 ____A C:\Users\Chris Saad\Desktop\TERMS AND CONDITIONS 04-15-2013.docm

2013-04-15 06:19 - 2013-04-15 06:19 - 00052736 ____A C:\Users\Chris Saad\Downloads\C_Contract.rpt

2013-04-15 06:19 - 2013-04-15 06:19 - 00052736 ____A C:\Users\Chris Saad\Downloads\C_Contract (1).rpt

2013-04-15 06:15 - 2013-04-15 06:15 - 00015872 ____A C:\Users\Chris Saad\Downloads\Contract Information Sheet 03-20-07.XLT

2013-04-15 06:13 - 2013-04-15 06:13 - 00031232 ____A C:\Users\Chris Saad\Downloads\AAAA CONTRACT SHORT FORM BLANK MA-salescheck.xls

2013-04-11 15:17 - 2013-04-11 15:17 - 00000000 ____D C:\Windows\SysWOW64\NV

2013-04-11 15:17 - 2013-04-11 15:17 - 00000000 ____D C:\Windows\System32\NV

2013-04-11 15:14 - 2013-04-11 15:14 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini

2013-04-11 15:14 - 2013-04-11 15:14 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies

2013-04-11 15:14 - 2012-07-04 15:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation

2013-04-11 15:14 - 2012-07-04 15:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation

2013-04-11 15:13 - 2013-04-11 15:13 - 00000000 ____D C:ProgramData\NVIDIA Corporation

2013-04-11 15:13 - 2013-04-11 15:13 - 00000000 ____D C:ProgramData\Application Data\NVIDIA Corporation

2013-04-11 15:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\Help

2013-04-11 15:09 - 2013-04-11 15:14 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\SoftThinks

2013-04-11 15:09 - 2013-04-11 15:14 - 00000000 ____D C:\Users\UpdatusUser\Local Settings\Application Data\SoftThinks

2013-04-11 15:09 - 2013-04-11 15:14 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\SoftThinks

2013-04-11 14:58 - 2013-04-01 09:32 - 00000000 ____D C:\disk

2013-04-11 14:44 - 2009-07-13 20:45 - 00460824 ____A C:\Windows\System32\FNTCACHE.DAT

2013-04-11 14:23 - 2013-04-11 14:23 - 00000165 ___AH C:\Users\Chris Saad\Desktop\~$office 365 employee chart.xlsx

2013-04-11 06:47 - 2012-07-11 08:40 - 00000000 ____D C:ProgramData\Microsoft Help

2013-04-11 06:47 - 2012-07-11 08:40 - 00000000 ____D C:ProgramData\Application Data\Microsoft Help

2013-04-09 11:05 - 2013-04-09 11:05 - 00001054 ____A C:\Users\Chris Saad\Desktop\Logitech Media Server.lnk

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:ProgramData\Squeezebox

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:ProgramData\Application Data\Squeezebox

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:\updates

2013-04-09 11:05 - 2013-04-09 11:05 - 00000000 ____D C:\Program Files (x86)\Squeezebox

2013-04-09 09:56 - 2013-04-09 09:54 - 58564896 ____A (Logitech ) C:\Users\Chris Saad\Downloads\LogitechMediaServer-7.7.2.exe

2013-04-09 08:09 - 2013-04-09 08:09 - 04111359 ____A C:\Users\Chris Saad\Downloads\FP28646_ISW-4_drawings.zip

2013-04-09 02:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports

2013-04-08 15:03 - 2012-07-12 07:33 - 00000000 ____D C:ProgramData\HP

2013-04-08 15:03 - 2012-07-12 07:33 - 00000000 ____D C:ProgramData\Application Data\HP

2013-04-08 15:03 - 2012-07-11 03:30 - 00000000 ____D C:ProgramData\Hewlett-Packard

2013-04-08 15:03 - 2012-07-11 03:30 - 00000000 ____D C:ProgramData\Application Data\Hewlett-Packard

2013-04-08 05:59 - 2012-07-10 16:46 - 00120208 ____A C:\Users\Chris Saad\Local Settings\GDIPFONTCACHEV1.DAT

2013-04-08 05:59 - 2012-07-10 16:46 - 00120208 ____A C:\Users\Chris Saad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2013-04-08 05:59 - 2012-07-10 16:46 - 00120208 ____A C:\Users\Chris Saad\AppData\Local\GDIPFONTCACHEV1.DAT

2013-04-08 04:51 - 2013-04-08 04:40 - 00177010 ____A C:\Windows\hppins12.dat

2013-04-08 04:46 - 2012-07-12 07:37 - 00000000 ____D C:\Program Files (x86)\Yahoo!

2013-04-08 04:46 - 2012-07-12 07:34 - 00000000 ____D C:\Program Files (x86)\HP

2013-04-08 04:46 - 2012-07-12 07:33 - 00008595 ____A C:ProgramData\hpzinstall.log

2013-04-08 04:46 - 2012-07-12 07:33 - 00008595 ____A C:ProgramData\Application Data\hpzinstall.log

2013-04-08 04:46 - 2009-07-13 18:34 - 00000545 ____A C:\Windows\win.ini

2013-04-08 04:45 - 2013-04-08 04:45 - 00000608 __ASH C:\Windows\System32\winzvprt5.sys

2013-04-08 04:45 - 2013-04-08 04:45 - 00000234 ____A C:\Windows\System32\hppfaxprinter5.ini

2013-04-08 04:45 - 2013-04-08 04:45 - 00000000 ____D C:ProgramData\Documents\HP

2013-04-08 04:45 - 2013-04-08 04:45 - 00000000 ____D C:\Users\Public\Documents\HP

2013-04-08 04:43 - 2013-04-08 04:43 - 00000142 ____A C:\Windows\System32\AddPort.ini

2013-04-08 04:43 - 2013-04-08 04:42 - 00000704 ____A C:\Windows\hpntwksetup.ini

2013-04-08 04:06 - 2013-04-01 09:36 - 00000000 ____D C:\CM_2320_Full_Solution_Win7_3_1_AM-EMEA1

2013-04-08 03:58 - 2013-04-08 03:56 - 335035344 ____A C:\Users\Chris Saad\Downloads\CM2320series-win7-full-solution-AM-EMEA1-v3.1.exe

2013-04-07 12:45 - 2012-07-11 09:00 - 00000000 ___RD C:\Program Files (x86)\Skype

2013-04-07 12:45 - 2012-07-04 14:47 - 00000000 ____D C:ProgramData\Skype

2013-04-07 12:45 - 2012-07-04 14:47 - 00000000 ____D C:ProgramData\Application Data\Skype

2013-04-06 07:13 - 2012-07-04 14:27 - 00060788 ____A C:\Windows\DPINST.LOG

2013-04-06 07:09 - 2012-07-04 14:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2013-04-06 07:07 - 2013-04-06 07:07 - 00000000 ____D C:\Users\Chris Saad\Application Data\InstallShield

2013-04-06 07:07 - 2013-04-06 07:07 - 00000000 ____D C:\Users\Chris Saad\AppData\Roaming\InstallShield

2013-04-06 07:07 - 2013-04-06 07:07 - 00000000 ____D C:\Program Files (x86)\MCT Corp

2013-04-06 06:57 - 2013-04-06 06:57 - 14386736 ____A (Macrovision Corporation) C:\Users\Chris Saad\Downloads\Eclipse-UV150-UV250-12.01.1108.1177.exe

2013-04-05 05:02 - 2012-10-10 08:04 - 00001374 ____A C:\Users\Chris Saad\Desktop\GoToMeeting.lnk

2013-04-04 13:27 - 2013-04-03 08:38 - 00008983 ____A C:\Users\Chris Saad\Desktop\blair savant trip.xlsx

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumdfb9.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumdfb11.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumdfb10.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumd9.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumd11.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\SysWOW64\dlumd10.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\System32\dlumd9.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\System32\dlumd11.dll

2013-04-04 03:35 - 2013-04-04 03:35 - 00000000 ____A C:\Windows\System32\dlumd10.dll

2013-04-04 03:35 - 2013-04-04 03:34 - 00000000 ____D C:\Program Files\DisplayLink Core Software

2013-04-03 17:31 - 2013-04-03 17:31 - 00228864 ____A C:\Users\Chris Saad\Desktop\Audio Concepts P&L.xls

2013-04-03 04:39 - 2013-04-03 04:39 - 00011653 ____A C:\Users\Chris Saad\Desktop\office 365 employee chart.xlsx

2013-04-01 10:07 - 2009-07-13 19:20 - 00000000 ___SD C:ProgramData\Microsoft

2013-04-01 10:07 - 2009-07-13 19:20 - 00000000 ___SD C:ProgramData\Application Data\Microsoft

2013-03-29 03:25 - 2013-03-29 03:25 - 00000000 ____D C:\Users\Chris Saad\Desktop\Manu videos for NA

2013-03-23 09:31 - 2013-03-21 18:43 - 00000000 ____D C:\Program Files (x86)\Iminent

2013-03-22 16:29 - 2013-03-22 16:29 - 00010589 ____A C:\Users\Chris Saad\Desktop\Book1.xlsx

2013-03-21 19:22 - 2013-03-21 19:22 - 01098888 ____A (AirInstaller Inc.) C:\Users\Chris Saad\Downloads\setup.exe

2013-03-21 19:15 - 2013-03-21 18:42 - 00000000 ____D C:ProgramData\Tarma Installer

2013-03-21 19:15 - 2013-03-21 18:42 - 00000000 ____D C:ProgramData\Application Data\Tarma Installer

2013-03-21 19:14 - 2013-03-21 18:43 - 00000866 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\Local Settings\CRE

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\Local Settings\Application Data\CRE

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\Application Data\Conduit

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\AppData\Roaming\Conduit

2013-03-21 18:42 - 2013-03-21 18:42 - 00000000 ____D C:\Users\Chris Saad\AppData\Local\CRE

2013-03-21 18:42 - 2013-03-21 18:41 - 00000009 ____A C:\END

2013-03-21 18:41 - 2013-03-21 18:41 - 00001105 ____A C:\Users\Chris Saad\Desktop\Flash Player Pro.lnk

2013-03-21 18:41 - 2013-03-21 18:41 - 00000000 ____D C:\Users\Chris Saad\My Documents\Flash Player Pro

2013-03-21 18:41 - 2013-03-21 18:41 - 00000000 ____D C:\Users\Chris Saad\Documents\Flash Player Pro

2013-03-21 18:41 - 2013-03-21 18:41 - 00000000 ____D C:\Program Files (x86)\Flash Player Pro

2013-03-21 18:40 - 2013-03-21 18:40 - 01098888 ____A (AirInstaller Inc.) C:\Users\Chris Saad\Downloads\Upgrade.exe

Other Malware:

===========

C:\Users\Chris Saad\AppData\Roaming\skype.dat

C:\Users\Chris Saad\AppData\Roaming\skype.ini

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-04-08 04:41:09

Restore point made on: 2013-04-11 06:45:05

Restore point made on: 2013-04-17 06:14:01

==================== Memory info ===========================

Percentage of memory in use: 10%

Total physical RAM: 8086.17 MB

Available physical RAM: 7255.25 MB

Total Pagefile: 8084.37 MB

Available Pagefile: 7253.18 MB

Total Virtual: 8192 MB

Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:911.88 GB) (Free:658.44 GB) NTFS (Disk=0 Partition=3)

Drive d: (VH-FLAC) (CDROM) (Total:4.23 GB) (Free:0 GB) UDF

Drive e: (KINGSTON) (Removable) (Total:7.21 GB) (Free:7.21 GB) FAT32 (Disk=1 Partition=1)

Drive f: (RECOVERY) (Fixed) (Total:19.53 GB) (Free:9.46 GB) NTFS (Disk=0 Partition=2) ==>[system with boot components (obtained from reading drive)]

Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Disk ### Status Size Free Dyn Gpt

-------- ------------- ------- ------- --- ---

Disk 0 Online 931 GB 2048 KB

Disk 1 Online 7396 MB 0 B

Partitions of Disk 0:

===============

Disk ID: 07F2837E

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 OEM 101 MB 31 KB

Partition 2 Primary 19 GB 104 MB

Partition 3 Primary 911 GB 19 GB

==================================================================================

Disk: 0

Partition 1

Type : DE

Hidden: Yes

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 4 FAT Partition 101 MB Healthy Hidden

=========================================================

Disk: 0

Partition 2

Type : 07

Hidden: No

Active: Yes

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 1 F RECOVERY NTFS Partition 19 GB Healthy

=========================================================

Disk: 0

Partition 3

Type : 07

Hidden: No

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 2 C OS NTFS Partition 911 GB Healthy

=========================================================

Partitions of Disk 1:

===============

Disk ID: 6C942ED5

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 Primary 7396 MB 31 KB

==================================================================================

Disk: 1

Partition 1

Type : 0B

Hidden: No

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 3 E KINGSTON FAT32 Removable 7396 MB Healthy

=========================================================

============================== MBR & Partition Table ==================

====================================================================

Disk: 0 (MBR Code: Windows Vista) (Size: 932 GB) (Disk ID: 07F2837E)

Partition 1: (Not Active) - (Size=102 MB) - (Type=DE)

Partition 2: (Active) - (Size=20 GB) - (Type=07) (NTFS)

Partition 3: (Not Active) - (Size=912 GB) - (Type=07) (NTFS)

====================================================================

Disk: 1 (Size: 7 GB) (Disk ID: 6C942ED5)

Partition 1: (Not Active) - (Size=7 GB) - (Type=0B)

Last Boot: 2013-04-16 08:44

==================== End Of Log ============================

Link to post
Share on other sites

  • Staff

Hello avo2hap

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.

Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!


  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.

    [*]Please do not attach logs or use code boxes, just copy and paste the text.

    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.

    [*]Please read every post completely before doing anything.

    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

    [*]Please provide feedback about your experience as we go.

    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.

NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flash drive as fixlist.txt

 
HKU\Chris Saad\...\Winlogon: [Shell] explorer.exe,C:\Users\Chris Saad\AppData\Roaming\skype.dat [90112 2012-07-04] ()
C:\Users\Chris Saad\AppData\Roaming\skype.dat
C:\Users\Chris Saad\AppData\Roaming\skype.ini

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.

Run FRST again like we did before but this time press the Fix button just once and wait.

The tool will make a log on the flash drive (Fixlog.txt) please post it to your reply.

Also boot the computer into normal mode and let me know how things are looking.

Gringo

Link to post
Share on other sites

i rebooted in normal after the fix, seems to be working fine now. Thanks

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2013

Ran by SYSTEM at 2013-04-20 18:02:22 Run:1

Running from E:\

Boot Mode: Recovery

==============================================

HKEY_USERS\Chris Saad\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell value deleted successfully.

C:\Users\Chris Saad\AppData\Roaming\skype.dat moved successfully.

C:\Users\Chris Saad\AppData\Roaming\skype.ini moved successfully.

==== End of Fixlog ====

Link to post
Share on other sites

  • Staff

Hello avo2hap

These are the programs I would like you to run next, if you have any problems with these just skip it and move on to the next one.

-AdwCleaner-

  • Please download
AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.

--RogueKiller--

  • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
    • Quit all programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • For Vista or Windows 7, right-click and select "Run as Administrator to start"
    • For Windows XP, double-click to start.
    • Wait until Prescan has finished ...
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and copy/paste the content of the Notepad into your next reply.
    • The log should be found in RKreport[1].txt on your Desktop
    • Exit/Close RogueKiller+

Gringo

Link to post
Share on other sites

  • Staff

Greetings

I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools

Gringo

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.