Efter at have prøvet 5-6 gange og fået beskeden “missing operational system” ved gentagne F8 klik, fik jeg endelig adgang til Advanced Boot Options… Her er hvad frst64.exe gav af log:
Scan result of Farbar Recovery Scan Tool Version: 05-08-2012 03
Ran by SYSTEM at 06-08-2012 16:26:00
Running from F:\
Windows 7 Professional Service Pack 1 (X64) OS Language: Danish
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [608112 2011-04-05] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167960 2011-01-14] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2011-01-14] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [418328 2011-01-14] (Intel Corporation)
HKLM\...\Run: [IntelPROSet] “C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe” /tf Intel PROSet/Wireless [1934608 2010-12-23] (Intel(R) Corporation)
HKLM\...\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
HKLM\...\Run: [BullGuard] “C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe” -boot [1863008 2012-07-29] (BullGuard Ltd.)
HKLM\...\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet [1694016 2011-09-07] ()
HKLM\...\Run: [FileOpenBroker] C:\Program Files\FileOpen\Services\FileOpenBroker64.exe [1086848 2012-04-30] (FileOpen Systems Inc.)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] “C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe” [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] “C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe” /mode2 [462993 2010-03-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [RemoteControl9] “C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe” [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] “C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe” [50472 2010-04-29] (CyberLink Corp.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [RoxWatchTray] “C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe” [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] “C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe” [514544 2010-11-17] ()
HKLM-x32\...\Run: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [843712 2012-01-03] (Adobe Systems Incorporated)
HKU\Dennis\...\Run: [Pogoplug Backup] “C:\Program Files (x86)\PogoplugBackup\PogoplugMonitor.exe” [310592 2012-03-08] (Cloud Engines Inc.)
HKU\Dennis\...\Run: [Spotify Web Helper] “C:\Users\Dennis\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe” [932528 2012-06-29] ()
HKU\Dennis\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5661056 2012-07-10] (SUPERAntiSpyware.com)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
Tcpip\Parameters: [DhcpNameServer] 193.162.153.164 194.239.134.83
AppInit_DLLs: C:\Windows\system32\nvinitx.dll BgGamingMonitor.dll
Lsa: [Authentication Packages] msv1_0
wvauth
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk
ShortcutTarget: Dell System Manager.lnk -> C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Services (Whitelisted) ======
2 !SASCORE; “C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE” [140672 2011-08-12] (SUPERAntiSpyware.com)
2 BsBackup; C:\Program Files\BullGuard Ltd\BullGuard\BsBackup.dll [71520 2012-06-14] (BullGuard Ltd.)
2 BsBhvScan; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe [368480 2012-06-14] (BullGuard Ltd.)
2 BsFileScan; C:\Program Files\BullGuard Ltd\BullGuard\BsFileScan.dll [274784 2012-06-14] (BullGuard Ltd.)
2 BsFire; C:\Program Files\BullGuard Ltd\BullGuard\BsFire.dll [575840 2012-06-20] (BullGuard Ltd.)
2 BsMailProxy; C:\Program Files\BullGuard Ltd\BullGuard\BsMailProxy\BsMailProxy.dll [508256 2012-06-20] (BullGuard Ltd.)
2 BsMain; C:\Program Files\BullGuard Ltd\BullGuard\BsMain.dll [281440 2012-06-27] (BullGuard Ltd.)
2 BsScanner; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [199520 2012-06-14] (BullGuard Ltd.)
2 BsUpdate; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [379744 2012-06-20] (BullGuard Ltd.)
2 DokanCEMounter; C:\Program Files (x86)\PogoplugBackup\dokanmnt.exe [115520 2012-03-08] (Cloud Engines)
3 DraftSight API Service; C:\Program Files (x86)\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [78336 2012-01-24] (Dassault Systèmes)
2 FileOpenManagerSvc; “C:\Program Files\FileOpen\Services\FileOpenManagerSvc64.exe” [334720 2012-04-30] (FileOpen Systems Inc.)
2 HBAdmin; C:\Program Files (x86)\Pogoplug\HBPLUG\HBADMIN.exe [891200 2012-01-31] (Cloud Engines, Inc.)
2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] ()
2 RoxWatch12; “C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe” [219632 2010-11-25] (Sonic Solutions)
2 Secunia PSI Agent; “C:\Program Files (x86)\Secunia\PSI\PSIA.exe”—start-service [1326176 2012-07-25] (Secunia)
2 Secunia Update Agent; “C:\Program Files (x86)\Secunia\PSI\sua.exe”—start-service [681056 2012-07-25] (Secunia)
2 simptcp; C:\Windows\SysWow64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
3 stllssvr; “C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe” [74392 2010-11-08] (MicroVision Development, Inc.)
2 tcsd_win32.exe; “C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe” [1629696 2010-07-13] ()
4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
2 UNS; “C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe” [2656280 2011-01-17] (Intel Corporation)
2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation)
========================== Drivers (Whitelisted) =============
1 AFW; C:\Windows\System32\Drivers\AFW.sys [38528 2012-06-20] (Agnitum Ltd.)
3 afwcore; C:\Windows\System32\Drivers\afwcore.sys [445568 2012-06-20] (Agnitum Ltd.)
1 BdSpy; C:\Windows\System32\Drivers\BdSpy.sys [66272 2011-06-15] (BullGuard Ltd.)
2 DokanCEDriver; \??\C:\Program Files (x86)\PogoplugBackup\dokance.sys [66880 2012-03-08] (Cloud Engines)
1 NovaShieldFilterDriver; C:\Windows\System32\DRIVERS\NSKernel.sys [256072 2012-03-05] (NovaShield, Inc.)
1 NovaShieldTDIDriver; C:\Windows\System32\DRIVERS\NSNetmon.sys [25160 2012-03-05] (NovaShield, Inc.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 Trufos; C:\Windows\System32\Drivers\Trufos.sys [290376 2012-03-05] (BitDefender S.R.L.)
3 xcetap0; C:\Windows\System32\Drivers\xcetap0.sys [39232 2012-01-13] (Cloud Engines, Inc.)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 16:25 - 2012-08-06 16:26 - 00000000 ____D C:\FRST
2012-08-05 18:30 - 2012-08-05 18:30 - 00544008 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-08-05 18:30 - 2012-08-05 18:30 - 00191240 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-08-05 18:30 - 2012-08-05 18:30 - 00172296 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-08-05 18:30 - 2012-08-05 18:30 - 00172296 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-08-05 18:30 - 2012-08-05 18:30 - 00000000 ____D C:\Program Files\Java
2012-08-05 18:26 - 2012-08-05 18:26 - 03098616 ____A (Secunia) C:\Users\Dennis\Downloads\PSISetup.exe
2012-08-05 18:26 - 2012-08-05 18:26 - 00000000 ____D C:\Users\Dennis\AppData\Local\Secunia PSI
2012-08-05 18:26 - 2012-08-05 18:26 - 00000000 ____D C:\Program Files (x86)\Secunia
2012-08-05 16:52 - 2012-08-05 16:52 - 18967544 ____A (SUPERAntiSpyware.com) C:\Users\Dennis\Downloads\SUPERAntiSpyware.exe
2012-08-05 16:52 - 2012-08-05 16:52 - 00001810 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-08-05 16:52 - 2012-08-05 16:52 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\SUPERAntiSpyware.com
2012-08-05 16:52 - 2012-08-05 16:52 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-08-05 16:52 - 2012-08-05 16:52 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-08-05 15:38 - 2012-08-05 15:38 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 15:37 - 2012-08-05 15:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes’ Anti-Malware
2012-08-05 15:37 - 2012-08-05 15:37 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Malwarebytes
2012-08-05 15:37 - 2012-08-05 15:37 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-05 15:37 - 2012-07-03 12:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-05 15:37 - 2010-04-29 14:39 - 00038224 ____A (Malwarebytes Corporation) C:\Windows\SysWOW64\Drivers\mbamswissarmy.sys
2012-08-05 15:36 - 2012-08-05 15:36 - 06153352 ____A (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup.exe
2012-08-05 12:38 - 2012-08-05 12:38 - 00000000 ____D C:\Program Files (x86)\ESET
2012-08-05 12:33 - 2012-08-06 15:18 - 00000560 ____A C:\Windows\setupact.log
2012-08-05 12:33 - 2012-08-05 12:33 - 00000000 ____A C:\Windows\setuperr.log
2012-08-05 12:32 - 2012-08-05 16:50 - 00000942 ____A C:\Windows\PFRO.log
2012-08-05 10:47 - 2012-08-05 10:47 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-08-05 10:47 - 2012-08-05 10:47 - 00000000 ____D C:\Program Files\CCleaner
2012-08-05 10:45 - 2012-08-05 18:35 - 00000000 ____D C:\Users\Dennis\Desktop\SWF
2012-08-05 10:38 - 2012-05-04 12:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-08-05 10:38 - 2012-05-04 10:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-08-05 10:04 - 2012-08-05 10:04 - 00016220 ____A C:\WirelessDiagLog.csv
2012-07-16 21:26 - 2012-07-16 21:26 - 00000000 ____D C:\Users\Dennis\Documents\Dell WebCam Central
2012-07-16 21:26 - 2012-07-16 21:26 - 00000000 ____D C:\Users\All Users\Creative
2012-07-11 13:42 - 2012-06-12 04:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 13:39 - 2012-06-02 13:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 13:39 - 2012-06-02 13:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 13:39 - 2012-06-02 13:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 13:39 - 2012-06-02 13:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 13:39 - 2012-06-02 13:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 13:39 - 2012-06-02 13:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 13:39 - 2012-06-02 13:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 13:39 - 2012-06-02 13:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 13:39 - 2012-06-02 13:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 13:39 - 2012-06-02 13:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 13:39 - 2012-06-02 12:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 13:39 - 2012-06-02 12:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 13:39 - 2012-06-02 12:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 13:39 - 2012-06-02 12:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 13:39 - 2012-06-02 10:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 13:39 - 2012-06-02 09:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 13:39 - 2012-06-02 09:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 13:39 - 2012-06-02 09:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 13:39 - 2012-06-02 09:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 13:39 - 2012-06-02 09:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 13:39 - 2012-06-02 09:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 13:39 - 2012-06-02 09:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 13:39 - 2012-06-02 09:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 13:39 - 2012-06-02 09:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 13:39 - 2012-06-02 09:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 13:39 - 2012-06-02 09:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 13:39 - 2012-06-02 09:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 13:39 - 2012-06-02 09:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 06:54 - 2012-06-09 06:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 06:54 - 2012-06-09 05:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 06:54 - 2012-06-06 07:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 06:54 - 2012-06-06 07:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 06:54 - 2012-06-06 07:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 06:54 - 2012-06-06 06:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 06:54 - 2012-06-06 06:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 06:54 - 2012-06-06 06:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 06:54 - 2012-06-02 06:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 06:54 - 2012-06-02 06:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 06:54 - 2012-06-02 06:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 06:54 - 2012-06-02 06:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 06:54 - 2012-06-02 06:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 06:54 - 2012-06-02 05:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 06:54 - 2012-06-02 05:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 06:54 - 2012-06-02 05:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 06:54 - 2012-06-02 05:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 06:54 - 2010-06-26 04:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 06:54 - 2010-06-26 04:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-07 14:45 - 2010-02-23 09:16 - 00294912 ____A (Microsoft Corporation) C:\Windows\System32\browserchoice.exe
============ 3 Months Modified Files ========================
2012-08-06 15:21 - 2011-07-08 16:50 - 01207593 ____A C:\Windows\WindowsUpdate.log
2012-08-06 15:19 - 2011-07-17 20:59 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-06 15:19 - 2011-07-17 19:14 - 00000796 ____A C:\Windows\System32\config\afw_hm.conf
2012-08-06 15:19 - 2011-07-17 19:14 - 00000004 ____A C:\Windows\System32\config\afw_db.conf
2012-08-06 15:18 - 2012-08-05 12:33 - 00000560 ____A C:\Windows\setupact.log
2012-08-06 15:18 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 06:47 - 2009-07-14 05:45 - 00025040 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 06:47 - 2009-07-14 05:45 - 00025040 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-05 21:37 - 2012-04-04 21:03 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-05 21:35 - 2011-07-17 20:59 - 00000932 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-05 18:30 - 2012-08-05 18:30 - 00544008 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-08-05 18:30 - 2012-08-05 18:30 - 00191240 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-08-05 18:30 - 2012-08-05 18:30 - 00172296 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-08-05 18:30 - 2012-08-05 18:30 - 00172296 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-08-05 18:30 - 2011-07-08 22:57 - 00525576 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-08-05 18:26 - 2012-08-05 18:26 - 03098616 ____A (Secunia) C:\Users\Dennis\Downloads\PSISetup.exe
2012-08-05 16:52 - 2012-08-05 16:52 - 18967544 ____A (SUPERAntiSpyware.com) C:\Users\Dennis\Downloads\SUPERAntiSpyware.exe
2012-08-05 16:52 - 2012-08-05 16:52 - 00001810 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-08-05 16:50 - 2012-08-05 12:32 - 00000942 ____A C:\Windows\PFRO.log
2012-08-05 15:38 - 2012-08-05 15:38 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 15:36 - 2012-08-05 15:36 - 06153352 ____A (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup.exe
2012-08-05 12:33 - 2012-08-05 12:33 - 00000000 ____A C:\Windows\setuperr.log
2012-08-05 10:47 - 2012-08-05 10:47 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-08-05 10:04 - 2012-08-05 10:04 - 00016220 ____A C:\WirelessDiagLog.csv
2012-08-04 09:05 - 2011-07-20 13:05 - 00264378 ____A C:\Users\Dennis\danid.log
2012-08-03 12:37 - 2012-04-04 21:03 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 12:37 - 2011-07-17 21:04 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 09:36 - 2012-06-17 17:30 - 00002346 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-28 08:20 - 2012-04-18 20:55 - 00001029 ____A C:\Users\Dennis\Desktop\Dropbox.lnk
2012-07-23 15:14 - 2010-11-21 09:43 - 00507462 ____A C:\Windows\System32\perfh006.dat
2012-07-23 15:14 - 2010-11-21 09:43 - 00097692 ____A C:\Windows\System32\perfc006.dat
2012-07-23 15:14 - 2009-07-14 06:13 - 01373392 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-11 17:22 - 2011-07-20 13:05 - 01052350 ____A C:\Users\Dennis\danid.log.1
2012-07-11 13:44 - 2009-07-14 05:45 - 00433824 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 13:40 - 2011-07-17 19:59 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-06 07:33 - 2009-07-14 06:08 - 00032550 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-03 17:27 - 2012-06-10 11:45 - 00000194 ___AH C:\Users\Dennis\Documents\Drawing1.dwl2
2012-07-03 17:27 - 2012-06-10 11:45 - 00000044 ___AH C:\Users\Dennis\Documents\Drawing1.dwl
2012-07-03 12:46 - 2012-08-05 15:37 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-20 20:14 - 2012-06-20 20:14 - 00000195 ___AH C:\Users\Dennis\Documents\Drawing3.dwl2
2012-06-20 20:14 - 2012-06-20 20:14 - 00000045 ___AH C:\Users\Dennis\Documents\Drawing3.dwl
2012-06-20 19:07 - 2012-06-20 19:07 - 00000195 ___AH C:\Users\Dennis\Documents\Drawing2.dwl2
2012-06-20 19:07 - 2012-06-20 19:07 - 00000045 ___AH C:\Users\Dennis\Documents\Drawing2.dwl
2012-06-20 17:15 - 2012-06-20 17:15 - 00148611 ____A C:\Users\Dennis\Downloads\Fastlock_download.zip
2012-06-20 16:42 - 2011-06-15 11:32 - 00445568 ___RA (Agnitum Ltd.) C:\Windows\System32\Drivers\AfwCore.sys
2012-06-20 16:42 - 2011-06-15 11:32 - 00038528 ___RA (Agnitum Ltd.) C:\Windows\System32\Drivers\Afw.sys
2012-06-12 04:08 - 2012-07-11 13:42 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 06:43 - 2012-07-11 06:54 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-09 05:41 - 2012-07-11 06:54 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-06 07:06 - 2012-07-11 06:54 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 07:06 - 2012-07-11 06:54 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 07:02 - 2012-07-11 06:54 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-06 06:05 - 2012-07-11 06:54 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 06:05 - 2012-07-11 06:54 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-06 06:03 - 2012-07-11 06:54 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-03 13:03 - 2012-04-10 17:12 - 00001945 ____A C:\Users\Public\Desktop\Sonos.lnk
2012-06-02 23:19 - 2012-06-21 20:52 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-21 20:52 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-21 20:52 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-21 20:52 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-21 20:52 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:15 - 2012-06-21 20:52 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:15 - 2012-06-21 20:52 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-21 20:52 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-21 20:52 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 13:49 - 2012-07-11 13:39 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 13:17 - 2012-07-11 13:39 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 13:12 - 2012-07-11 13:39 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 13:05 - 2012-07-11 13:39 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 13:05 - 2012-07-11 13:39 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 13:04 - 2012-07-11 13:39 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 13:04 - 2012-07-11 13:39 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 13:03 - 2012-07-11 13:39 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 13:01 - 2012-07-11 13:39 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 13:00 - 2012-07-11 13:39 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 12:59 - 2012-07-11 13:39 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 12:57 - 2012-07-11 13:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 12:57 - 2012-07-11 13:39 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 12:54 - 2012-07-11 13:39 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 10:07 - 2012-07-11 13:39 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 09:43 - 2012-07-11 13:39 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 09:33 - 2012-07-11 13:39 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 09:26 - 2012-07-11 13:39 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 09:25 - 2012-07-11 13:39 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 09:25 - 2012-07-11 13:39 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 09:23 - 2012-07-11 13:39 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 09:21 - 2012-07-11 13:39 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 09:20 - 2012-07-11 13:39 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 09:19 - 2012-07-11 13:39 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 09:19 - 2012-07-11 13:39 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 09:17 - 2012-07-11 13:39 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 09:16 - 2012-07-11 13:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 09:14 - 2012-07-11 13:39 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-02 06:50 - 2012-07-11 06:54 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 06:48 - 2012-07-11 06:54 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 06:48 - 2012-07-11 06:54 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 06:45 - 2012-07-11 06:54 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 06:44 - 2012-07-11 06:54 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-02 05:40 - 2012-07-11 06:54 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-02 05:40 - 2012-07-11 06:54 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-02 05:39 - 2012-07-11 06:54 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-02 05:34 - 2012-07-11 06:54 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-21 17:40 - 2012-05-21 17:40 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-05-14 17:01 - 2012-05-14 16:43 - 00062230 ____A C:\Windows\SysWOW64\DellSystem.xml
2012-05-14 16:43 - 2012-05-14 16:43 - 00000000 ____A C:\Windows\invcol.tmp
2012-05-14 16:38 - 2012-05-14 16:18 - 00001195 ____A C:\Users\Public\Desktop\Diablo III.lnk
ZeroAccess:
C:\Windows\Installer\{4b15b008-b978-43ff-96e3-a2e116d082af}
C:\Windows\Installer\{4b15b008-b978-43ff-96e3-a2e116d082af}\@
C:\Windows\Installer\{4b15b008-b978-43ff-96e3-a2e116d082af}\L
C:\Windows\Installer\{4b15b008-b978-43ff-96e3-a2e116d082af}\U
C:\Windows\Installer\{4b15b008-b978-43ff-96e3-a2e116d082af}\U\00000001.@
C:\Windows\Installer\{4b15b008-b978-43ff-96e3-a2e116d082af}\U\800000cb.@
ZeroAccess:
C:\Users\Dennis\AppData\Local\{4b15b008-b978-43ff-96e3-a2e116d082af}
C:\Users\Dennis\AppData\Local\{4b15b008-b978-43ff-96e3-a2e116d082af}\@
C:\Users\Dennis\AppData\Local\{4b15b008-b978-43ff-96e3-a2e116d082af}\L
C:\Users\Dennis\AppData\Local\{4b15b008-b978-43ff-96e3-a2e116d082af}\U
C:\Users\Dennis\AppData\Local\{4b15b008-b978-43ff-96e3-a2e116d082af}\U\00000001.@
C:\Users\Dennis\AppData\Local\{4b15b008-b978-43ff-96e3-a2e116d082af}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: “%1” %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8148.9 MB
Available physical RAM: 7318.8 MB
Total Pagefile: 8147.1 MB
Available Pagefile: 7301.73 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:697.86 GB) (Free:619.39 GB) NTFS
3 Drive f: () (Removable) (Total:0.49 GB) (Free:0.49 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:0.73 GB) (Free:0.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Str. Ledig Dyn GPT
——————————- ———- ———- —- —-
Disk 0 Online 698 GB 3072 KB
Disk 1 Online 500 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Str. Forskydning
——————- ———————————- —————-
Partition 1 OEM 39 MB 31 KB
Partition 2 Prim‘r 752 MB 40 MB
Partition 3 Prim‘r 697 GB 792 MB
==================================================================================
Disk: 0
Partition 1
Type : DE
Skjult: Ja
Aktiv : Nej
Forskydning i byte: 32256
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 4 FAT Partition 39 MB I orden Skjult
==================================================================================
Disk: 0
Partition 2
Type : 07
Skjult: Nej
Aktiv : Ja
Forskydning i byte: 41943040
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 1 Y RECOVERY NTFS Partition 752 MB I orden
==================================================================================
Disk: 0
Partition 3
Type : 07
Skjult: Nej
Aktiv : Nej
Forskydning i byte: 830472192
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 2 C OS NTFS Partition 697 GB I orden
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Str. Forskydning
——————- ———————————- —————-
Partition 1 Prim‘r 499 MB 236 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Skjult: Nej
Aktiv : Nej
Forskydning i byte: 241664
Diskenhed Bogs. Navn Fs Type Str. Status Oplysn.
————- —————————- ————————- ————- ————
* Diskenhed 3 F FAT Flytbar 499 MB I orden
==================================================================================
==========================================================
Last Boot: 2012-07-28 09:43
======================= End Of Log ==========================