Hej,
Det lader til, at jeg har fået samme problem, som Thosen49, dog er jeg stadig i tvivl omkring løsningen af problemet.
Min computer lukker ned efter jeg lige har logget på, og der kommer også her en dialogboks frem, hvor der står: “Windows har funder et alvorligt problem og genstartes automatisk om et minut. Gem dit arbejde nu”
Jeg har windows 7 - og 64 bit. Og jeg har allerede lavet en farbar recovery scan tool nedenfor, håber I kan være behjælpelige:
Scan result of Farbar Recovery Scan Tool Version: 15-07-2012
Ran by SYSTEM at 18-07-2012 16:05:13
Running from H:\
Windows 7 Home Premium (X64) OS Language: Danish
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-08-25] (Intel Corporation)
HKLM\...\Run: [MSC] “C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe” [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe” [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe” [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] “D:\iTunes\iTunesHelper.exe” [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 212.10.10.4 212.10.24.252 212.10.10.5
==================== Services (Whitelisted) ======
2 MsMpSvc; “C:\Program Files\Microsoft Security Client\MsMpEng.exe” [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; “C:\Program Files\Microsoft Security Client\NisSrv.exe” [291696 2012-03-26] (Microsoft Corporation)
2 vToolbarUpdater11.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe [935480 2012-06-05] ()
========================== Drivers (Whitelisted) =============
3 libusb0; C:\Windows\System32\Drivers\libusb0.sys [32256 2009-07-07] (http://libusb-win32.sourceforge.net)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-18 14:40 - 2012-07-18 14:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.43D2CADD91E5F7B2
2012-07-18 14:39 - 2012-07-18 14:40 - 04581501 ____R (Swearware) C:\Users\acer\Downloads\ComboFix(4).exe
2012-07-18 14:37 - 2012-07-18 14:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE7754A08E60CAA3
2012-07-18 14:36 - 2012-07-18 14:36 - 04581501 ____A (Swearware) C:\Users\acer\Downloads\ComboFix(3).exe
2012-07-18 14:33 - 2012-07-18 14:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62D0ECAAE8E9AD17
2012-07-18 14:30 - 2012-07-18 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E49C580268C2058
2012-07-18 14:29 - 2012-07-18 14:29 - 04581501 ____A (Swearware) C:\Users\acer\Downloads\ComboFix(2).exe
2012-07-18 14:26 - 2012-07-18 14:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.298BF240F243E602
2012-07-18 14:22 - 2012-07-18 14:22 - 04581501 ____A (Swearware) C:\Users\acer\Downloads\ComboFix.exe
2012-07-18 14:22 - 2012-07-18 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF192BD2FF7ACE56
2012-07-18 14:19 - 2012-07-18 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.70BC4822B9CE499D
2012-07-18 14:15 - 2012-07-18 14:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F8C8C0634FE94FAB
2012-07-18 14:12 - 2012-07-18 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E5A98A3ECA9B123A
2012-07-18 14:09 - 2012-07-18 14:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD86DBE3FB7A2E95
2012-07-18 14:05 - 2012-07-18 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9259C3D5A159192C
2012-07-18 14:02 - 2012-07-18 14:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F76A878F8B499051
2012-07-18 13:57 - 2012-07-18 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.378A9A77F622A390
2012-07-18 13:54 - 2012-07-18 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9269F1E955419B46
2012-07-18 13:50 - 2012-07-18 13:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C54107CB4E2D0137
2012-07-18 13:47 - 2012-07-18 14:40 - 00000000 ___SD C:\32788R22FWJFW
2012-07-18 13:47 - 2012-07-18 13:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77FC8534ED7BD9D8
2012-07-18 13:47 - 2012-07-18 13:47 - 00000000 ____D C:\Windows\erdnt
2012-07-18 13:47 - 2012-07-18 13:47 - 00000000 ____D C:\Qoobox
2012-07-18 13:44 - 2012-07-18 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E62FE73948325E3E
2012-07-18 13:44 - 2012-07-18 13:41 - 04581501 ____R (Swearware) C:\Users\acer\Desktop\ComboFix.exe
2012-07-18 07:43 - 2012-07-18 07:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0ACFA960C448648C
2012-07-18 07:40 - 2012-07-18 07:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C783AB4F26538DF9
2012-07-18 07:36 - 2012-07-18 07:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E8A979791C1B741
2012-07-18 07:33 - 2012-07-18 07:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0EFA911E55EEEDF6
2012-07-18 07:29 - 2012-07-18 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4F183292C0508F9
2012-07-18 07:25 - 2012-07-18 07:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9802838B2CAC6A1
2012-07-16 16:32 - 2012-07-16 16:32 - 00000000 ____D C:\FRST
2012-07-16 15:56 - 2012-07-16 15:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27E841921B95863D
2012-07-16 15:52 - 2012-07-16 15:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2E4A3804778A2C9
2012-07-16 15:48 - 2012-07-16 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.01B1BF4A3DC6F449
2012-07-16 14:58 - 2012-07-16 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C8A31849ADCBA067
2012-07-15 18:45 - 2012-07-15 18:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B11F0FF636DB9E8
2012-07-15 18:41 - 2012-07-15 18:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BDCE1C881BF0921D
2012-07-15 18:37 - 2012-07-15 18:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9BFB9427F04CBDFE
2012-07-15 18:33 - 2012-07-15 18:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.07112C6502A27372
2012-07-15 18:29 - 2012-07-15 18:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15AC4D009DECF303
2012-07-15 18:24 - 2012-07-15 18:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4EF7D6D2C96AE080
2012-07-15 18:18 - 2012-07-15 18:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF54AAD0FCC7B93D
2012-07-15 18:14 - 2012-07-15 18:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F3B40E8493CDA7EE
2012-07-15 14:32 - 2012-07-15 14:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B3D6DE6A756A990B
2012-07-15 14:24 - 2012-07-15 14:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D28E6CE1A7B1573
2012-07-15 14:16 - 2012-07-15 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.223ECBC430C8E2B2
2012-07-15 14:12 - 2012-07-15 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E116B12B9BF53F93
2012-07-15 14:06 - 2012-07-15 14:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E9E350263A1479E
2012-07-15 13:53 - 2012-07-15 13:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.762BF33417600E08
2012-07-15 13:53 - 2012-07-15 13:40 - 01436595 ____A (Farbar) C:\Users\acer\Desktop\FRST64.exe
2012-07-15 13:49 - 2012-07-15 13:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AFA37D17DA3F6D7
2012-07-15 13:44 - 2012-07-15 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9D85EA22E6EB8C1
2012-07-11 14:30 - 2012-07-11 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.86D103BA368995CF
2012-07-11 14:26 - 2012-07-11 14:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C37C41A2AFCF489A
2012-07-11 14:23 - 2012-07-11 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DEC0F3B881DED418
2012-07-11 14:19 - 2012-07-11 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14F3D44A36B6C90F
2012-07-11 14:16 - 2012-07-11 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CCAAB0B7863BB133
2012-07-11 14:12 - 2012-07-11 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D7D5486E532E276E
2012-07-11 14:08 - 2012-07-11 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C45D02C1E6A43FFD
2012-07-11 14:05 - 2012-07-11 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A528C77B145BCDD
2012-07-11 14:01 - 2012-07-11 14:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.057F20D1E19C8D57
2012-07-11 13:58 - 2012-07-11 13:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FE9DF54AA16C84
2012-07-11 13:54 - 2012-07-11 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E9CA8C5B7C54177
2012-07-11 13:50 - 2012-07-11 13:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5C9BB2EC0498098
2012-07-11 13:46 - 2012-07-11 13:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E65B6066AC1D6948
2012-07-11 13:43 - 2012-07-11 13:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA2D400D3094535B
2012-07-10 20:05 - 2012-07-10 20:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9FE56F43148CD7D
2012-07-10 20:01 - 2012-07-10 20:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D298A2CF1948F40F
2012-07-10 19:57 - 2012-07-10 19:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9E4D36F3F5E7C71
2012-07-10 19:53 - 2012-07-10 19:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A6792AD168918E59
2012-07-10 19:49 - 2012-07-10 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.698A2E69B01F165D
2012-07-08 20:04 - 2012-07-08 20:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-08 20:03 - 2012-07-08 20:04 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-08 20:03 - 2012-07-08 20:03 - 12632960 ____A (Microsoft Corporation) C:\Users\acer\Downloads\mseinstall.exe
2012-07-08 19:54 - 2012-07-08 19:54 - 00000000 ____D C:\Users\acer\AppData\Local\Mozilla
2012-07-08 19:52 - 2012-07-08 19:52 - 00067872 ____A C:\Users\acer\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-08 19:52 - 2012-07-08 19:52 - 00005765 ____A C:\Windows\SysWOW64\commonpriv.log
2012-07-08 19:52 - 2012-07-08 19:52 - 00000000 ____D C:\Users\acer\AppData\Local\VirtualStore
2012-07-08 19:52 - 2012-07-08 19:52 - 00000000 ____A C:\Windows\SysWOW64\commonpriv.log.lock
2012-06-19 20:29 - 2011-09-20 16:26 - 00039580 ____A C:\Users\acer\Desktop\Værdiansættelse.xlsx
============ 3 Months Modified Files ========================
2012-07-18 14:42 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-18 14:42 - 2009-07-14 05:51 - 00145408 ____A C:\Windows\setupact.log
2012-07-18 14:40 - 2012-07-18 14:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.43D2CADD91E5F7B2
2012-07-18 14:40 - 2012-07-18 14:39 - 04581501 ____R (Swearware) C:\Users\acer\Downloads\ComboFix(4).exe
2012-07-18 14:37 - 2012-07-18 14:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE7754A08E60CAA3
2012-07-18 14:36 - 2012-07-18 14:36 - 04581501 ____A (Swearware) C:\Users\acer\Downloads\ComboFix(3).exe
2012-07-18 14:33 - 2012-07-18 14:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62D0ECAAE8E9AD17
2012-07-18 14:30 - 2012-07-18 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E49C580268C2058
2012-07-18 14:29 - 2012-07-18 14:29 - 04581501 ____A (Swearware) C:\Users\acer\Downloads\ComboFix(2).exe
2012-07-18 14:26 - 2012-07-18 14:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.298BF240F243E602
2012-07-18 14:22 - 2012-07-18 14:22 - 04581501 ____A (Swearware) C:\Users\acer\Downloads\ComboFix.exe
2012-07-18 14:22 - 2012-07-18 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF192BD2FF7ACE56
2012-07-18 14:19 - 2012-07-18 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.70BC4822B9CE499D
2012-07-18 14:15 - 2012-07-18 14:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F8C8C0634FE94FAB
2012-07-18 14:12 - 2012-07-18 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E5A98A3ECA9B123A
2012-07-18 14:09 - 2012-07-18 14:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD86DBE3FB7A2E95
2012-07-18 14:05 - 2012-07-18 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9259C3D5A159192C
2012-07-18 14:02 - 2012-07-18 14:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F76A878F8B499051
2012-07-18 13:57 - 2012-07-18 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.378A9A77F622A390
2012-07-18 13:54 - 2012-07-18 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9269F1E955419B46
2012-07-18 13:50 - 2012-07-18 13:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C54107CB4E2D0137
2012-07-18 13:47 - 2012-07-18 13:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77FC8534ED7BD9D8
2012-07-18 13:45 - 2009-07-14 08:34 - 00474348 ____A C:\Windows\System32\perfh006.dat
2012-07-18 13:45 - 2009-07-14 08:34 - 00082090 ____A C:\Windows\System32\perfc006.dat
2012-07-18 13:45 - 2009-07-14 06:13 - 01276860 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-18 13:44 - 2012-07-18 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E62FE73948325E3E
2012-07-18 13:41 - 2012-07-18 13:44 - 04581501 ____R (Swearware) C:\Users\acer\Desktop\ComboFix.exe
2012-07-18 07:43 - 2012-07-18 07:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0ACFA960C448648C
2012-07-18 07:40 - 2012-07-18 07:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C783AB4F26538DF9
2012-07-18 07:36 - 2012-07-18 07:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E8A979791C1B741
2012-07-18 07:33 - 2012-07-18 07:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0EFA911E55EEEDF6
2012-07-18 07:29 - 2012-07-18 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4F183292C0508F9
2012-07-18 07:25 - 2012-07-18 07:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9802838B2CAC6A1
2012-07-16 15:56 - 2012-07-16 15:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27E841921B95863D
2012-07-16 15:52 - 2012-07-16 15:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2E4A3804778A2C9
2012-07-16 15:48 - 2012-07-16 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.01B1BF4A3DC6F449
2012-07-16 14:58 - 2012-07-16 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C8A31849ADCBA067
2012-07-15 18:45 - 2012-07-15 18:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B11F0FF636DB9E8
2012-07-15 18:41 - 2012-07-15 18:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BDCE1C881BF0921D
2012-07-15 18:37 - 2012-07-15 18:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9BFB9427F04CBDFE
2012-07-15 18:35 - 2009-07-14 06:08 - 00032550 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-15 18:33 - 2012-07-15 18:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.07112C6502A27372
2012-07-15 18:29 - 2012-07-15 18:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15AC4D009DECF303
2012-07-15 18:24 - 2012-07-15 18:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4EF7D6D2C96AE080
2012-07-15 18:18 - 2012-07-15 18:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF54AAD0FCC7B93D
2012-07-15 18:14 - 2012-07-15 18:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F3B40E8493CDA7EE
2012-07-15 14:32 - 2012-07-15 14:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B3D6DE6A756A990B
2012-07-15 14:24 - 2012-07-15 14:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D28E6CE1A7B1573
2012-07-15 14:16 - 2012-07-15 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.223ECBC430C8E2B2
2012-07-15 14:12 - 2012-07-15 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E116B12B9BF53F93
2012-07-15 14:06 - 2012-07-15 14:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E9E350263A1479E
2012-07-15 13:53 - 2012-07-15 13:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.762BF33417600E08
2012-07-15 13:49 - 2012-07-15 13:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AFA37D17DA3F6D7
2012-07-15 13:44 - 2012-07-15 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9D85EA22E6EB8C1
2012-07-15 13:40 - 2012-07-15 13:53 - 01436595 ____A (Farbar) C:\Users\acer\Desktop\FRST64.exe
2012-07-11 14:30 - 2012-07-11 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.86D103BA368995CF
2012-07-11 14:26 - 2012-07-11 14:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C37C41A2AFCF489A
2012-07-11 14:23 - 2012-07-11 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DEC0F3B881DED418
2012-07-11 14:19 - 2012-07-11 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14F3D44A36B6C90F
2012-07-11 14:16 - 2012-07-11 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CCAAB0B7863BB133
2012-07-11 14:12 - 2012-07-11 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D7D5486E532E276E
2012-07-11 14:08 - 2012-07-11 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C45D02C1E6A43FFD
2012-07-11 14:05 - 2012-07-11 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A528C77B145BCDD
2012-07-11 14:01 - 2012-07-11 14:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.057F20D1E19C8D57
2012-07-11 13:58 - 2012-07-11 13:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FE9DF54AA16C84
2012-07-11 13:54 - 2012-07-11 13:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E9CA8C5B7C54177
2012-07-11 13:50 - 2012-07-11 13:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5C9BB2EC0498098
2012-07-11 13:46 - 2012-07-11 13:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E65B6066AC1D6948
2012-07-11 13:43 - 2012-07-11 13:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA2D400D3094535B
2012-07-10 20:05 - 2012-07-10 20:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9FE56F43148CD7D
2012-07-10 20:01 - 2012-07-10 20:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D298A2CF1948F40F
2012-07-10 20:00 - 2010-05-07 09:34 - 01855274 ____A C:\Windows\WindowsUpdate.log
2012-07-10 19:57 - 2012-07-10 19:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9E4D36F3F5E7C71
2012-07-10 19:53 - 2012-07-10 19:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A6792AD168918E59
2012-07-10 19:49 - 2012-07-10 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.698A2E69B01F165D
2012-07-08 20:09 - 2009-07-14 05:45 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-08 20:09 - 2009-07-14 05:45 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-08 20:04 - 2011-01-25 20:46 - 01296860 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-08 20:04 - 2011-01-25 20:46 - 00001912 ____A C:\Windows\epplauncher.mif
2012-07-08 20:03 - 2012-07-08 20:03 - 12632960 ____A (Microsoft Corporation) C:\Users\acer\Downloads\mseinstall.exe
2012-07-08 19:57 - 2010-05-20 21:14 - 00054304 ____A C:\Windows\PFRO.log
2012-07-08 19:52 - 2012-07-08 19:52 - 00067872 ____A C:\Users\acer\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-08 19:52 - 2012-07-08 19:52 - 00005765 ____A C:\Windows\SysWOW64\commonpriv.log
2012-07-08 19:52 - 2012-07-08 19:52 - 00000000 ____A C:\Windows\SysWOW64\commonpriv.log.lock
2012-07-04 19:50 - 2010-08-06 08:54 - 00786943 ____A C:\Users\acer\danid.log
2012-06-18 15:32 - 2012-01-23 13:35 - 00002014 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-06-13 09:04 - 2009-07-14 05:45 - 00306640 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 07:55 - 2010-05-23 13:25 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-08 14:40 - 2011-06-21 17:20 - 00001013 ____A C:\Users\acer\Desktop\Dropbox.lnk
2012-06-06 21:13 - 2010-08-06 08:54 - 01059270 ____A C:\Users\acer\danid.log.1
2012-06-05 20:19 - 2012-06-05 20:19 - 03879712 ____A (AVG Technologies) C:\Users\acer\Downloads\avg_free_stb_all_2012_2178_cnet.exe
2012-06-05 19:57 - 2012-06-05 19:57 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-05 19:57 - 2011-06-07 21:04 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-04 14:02 - 2012-06-04 14:01 - 76761968 ____A (Apple Inc.) C:\Users\acer\Downloads\iTunes64Setup(2).exe
2012-06-04 10:51 - 2012-06-04 10:50 - 76761968 ____A (Apple Inc.) C:\Users\acer\Downloads\iTunes64Setup.exe
2012-06-04 10:07 - 2012-06-04 10:06 - 74982768 ____A (Apple Inc.) C:\Users\acer\Downloads\iTunesSetup(2).exe
2012-05-18 03:47 - 2012-06-13 07:45 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-18 03:16 - 2012-06-13 07:45 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-18 03:06 - 2012-06-13 07:45 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-18 02:59 - 2012-06-13 07:46 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-18 02:59 - 2012-06-13 07:46 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-18 02:58 - 2012-06-13 07:46 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-18 02:58 - 2012-06-13 07:45 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-18 02:56 - 2012-06-13 07:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-18 02:55 - 2012-06-13 07:46 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-18 02:55 - 2012-06-13 07:45 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-18 02:54 - 2012-06-13 07:46 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-18 02:51 - 2012-06-13 07:46 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-18 02:51 - 2012-06-13 07:46 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-18 02:47 - 2012-06-13 07:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-18 00:11 - 2012-06-13 07:45 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 23:48 - 2012-06-13 07:45 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 23:45 - 2012-06-13 07:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 23:36 - 2012-06-13 07:46 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 23:35 - 2012-06-13 07:46 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 23:35 - 2012-06-13 07:45 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 23:33 - 2012-06-13 07:46 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 23:31 - 2012-06-13 07:45 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 23:29 - 2012-06-13 07:46 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 23:29 - 2012-06-13 07:45 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 23:27 - 2012-06-13 07:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 23:25 - 2012-06-13 07:46 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 23:24 - 2012-06-13 07:46 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 23:20 - 2012-06-13 07:46 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:32 - 2012-06-12 19:52 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-04 12:06 - 2012-06-12 19:52 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 11:03 - 2012-06-12 19:52 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 11:03 - 2012-06-12 19:52 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 06:40 - 2012-06-12 19:52 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-28 04:55 - 2012-06-12 19:52 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 06:41 - 2012-06-12 19:52 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 06:41 - 2012-06-12 19:52 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 06:34 - 2012-06-12 19:52 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 06:37 - 2012-06-12 19:51 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 06:37 - 2012-06-12 19:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 06:37 - 2012-06-12 19:51 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-24 05:36 - 2012-06-12 19:51 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-24 05:36 - 2012-06-12 19:51 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-24 05:36 - 2012-06-12 19:51 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{eef30b76-5c69-6924-8fc8-5f1985968b27}
C:\Windows\Installer\{eef30b76-5c69-6924-8fc8-5f1985968b27}\L
C:\Windows\Installer\{eef30b76-5c69-6924-8fc8-5f1985968b27}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: “%1” %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 4027.79 MB
Available physical RAM: 3430.78 MB
Total Pagefile: 4025.94 MB
Available Pagefile: 3422.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:100.48 GB) (Free:51.94 GB) NTFS
2 Drive e: () (Fixed) (Total:355.41 GB) (Free:350.99 GB) NTFS
3 Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:2.03 GB) FAT32
5 Drive h: () (Removable) (Total:1.86 GB) (Free:1.85 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Str. Ledig Dyn GPT
——————————- ———- ———- —- —-
Disk 0 Online 465 GB 0 B
Disk 1 Online 1912 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Str. Forskydning
——————- ———————————- —————-
Partition 1 Genoprettelse 9 GB 1024 KB
Partition 2 Prim‘r 100 MB 9 GB
Partition 3 Prim‘r 100 GB 9 GB
Partition 4 Prim‘r 355 GB 110 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Skjult: Ja
Aktiv : Nej
Forskydning i byte: 1048576
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 4 F PQSERVICE FAT32 Partition 9 GB I orden Skjult
==================================================================================
Disk: 0
Partition 2
Type : 07
Skjult: Nej
Aktiv : Ja
Forskydning i byte: 10486808576
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 1 Y NTFS Partition 100 MB I orden
==================================================================================
Disk: 0
Partition 3
Type : 07
Skjult: Nej
Aktiv : Nej
Forskydning i byte: 10591666176
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 2 C NTFS Partition 100 GB I orden
==================================================================================
Disk: 0
Partition 4
Type : 07
Skjult: Nej
Aktiv : Nej
Forskydning i byte: 118484893696
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 3 E NTFS Partition 355 GB I orden
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Str. Forskydning
——————- ———————————- —————-
Partition 1 Prim‘r 1911 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Skjult: Nej
Aktiv : Ja
Forskydning i byte: 32768
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 5 H FAT32 Flytbar 1911 MB I orden
==================================================================================
==========================================================
Last Boot: 2012-06-20 16:27
======================= End Of Log ==========================
