Scan result of Farbar Recovery Scan Tool Version: 15-03-2012
Ran by SYSTEM at 08-04-2012 15:33:10
Running from L:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [13307496 2011-10-17] (Realtek Semiconductor)
HKLM-x32\...\Run: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe [563744 2010-03-25] ()
HKLM-x32\...\Run: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A [124416 2009-07-20] (IOI)
HKLM-x32\...\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1230704 2011-03-21] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [460872 2012-01-13] (Malwarebytes Corporation)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Runonce: [AvgUninstallURL] cmd.exe /c start
http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OABNAEUASAAtAFIAVgBFAEcAQQAtAFYASgBOAFgAMwAtAFkAMwBEAEwAQQAtADgAVQBFAE4ANgAtADYARQBNAEIAUgA"&"inst=NwA2AC0ANQAxADgAMgAxADcAOAA5ADEALQBYAE8AMwA2ACsAMQAtAEQAMwA4ADEATAArADUALQBUAEIAOQArADIALQBOADEARAArADEALQBQAEwAKwA5AC0ARABEAFQAKwAwAA"&"prod=54"&"ver=9.0.894 [x]
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
==================== Services (Whitelisted) ======
2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [462184 2011-08-30] (Apple Inc.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [652360 2012-01-13] (Malwarebytes Corporation)
3 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [935208 2010-01-15] (Nero AG)
3 npggsvc; C:\Windows\SysWow64\GameMon.des -service [3555568 2010-04-28] (INCA Internet Co., Ltd.)
2 UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2011-08-19] (Logitech Inc.)
========================== Drivers (Whitelisted) =============
0 ahcix64s; C:\Windows\System32\Drivers\ahcix64s.sys [235312 2010-01-05] (Advanced Micro Devices, Inc)
3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [10856960 2012-02-14] (Advanced Micro Devices, Inc.)
2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2012-01-03] (Advanced Micro Devices)
2 AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2012-01-03] (Advanced Micro Devices)
3 ESLvnic1; C:\Windows\System32\DRIVERS\ESLvnic.sys [25528 2011-04-18] (Turtle Entertainment GmbH)
3 LHidFilt; C:\Windows\System32\Drivers\LHidFilt.sys [63568 2010-08-24] (Logitech, Inc.)
3 LMouFilt; C:\Windows\System32\Drivers\LMouFilt.sys [57936 2010-08-24] (Logitech, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [23152 2011-12-10] (Malwarebytes Corporation)
0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2010-11-26] ()
3 TIEHDUSB; C:\Windows\System32\Drivers\TIEHDUSB.sys [128512 2009-09-03] (Texas Instruments)
3 cpuz132; \??\C:\Users\SAL\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
3 dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys [x]
3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-04-08 15:32 - 2012-04-08 15:33 - 0000000 ____D C:\FRST
2012-04-07 14:05 - 2012-04-07 15:44 - 0000000 ____D C:\Program Files (x86)\STOPzilla!
2012-04-07 14:05 - 2012-04-07 14:07 - 0000000 ____D C:\Users\All Users\STOPzilla!
2012-04-07 14:05 - 2012-04-07 14:07 - 0000000 ____D C:\ProgramData\STOPzilla!
2012-04-07 14:03 - 2012-04-07 14:03 - 0109656 ____A C:\Users\SAL\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-07 13:38 - 2012-04-07 13:40 - 0124594 ____A C:\TDSSKiller.2.7.26.0_07.04.2012_14.38.41_log.txt
2012-04-07 13:38 - 2012-04-07 13:38 - 0000348 ____A C:\TDSSKiller.2.7.25.0_07.04.2012_14.38.18_log.txt
2012-04-04 20:07 - 2012-04-04 20:07 - 0000000 ____A C:\Users\SAL\defogger_reenable
2012-04-04 20:06 - 2012-04-07 15:44 - 0000000 ____D C:\Users\SAL\Desktop\Operation Overlord
2012-04-03 15:33 - 2012-04-07 15:44 - 0000000 ____D C:\TDSSKiller
2012-04-02 09:52 - 2012-04-02 15:11 - 0000000 __SHD C:\Users\SAL\AppData\Local\c7c64ac0
2012-03-30 14:15 - 2012-03-30 14:15 - 0000000 ____D C:\Users\SAL\AppData\Local\DDMSettings
2012-03-28 11:41 - 2012-03-28 11:41 - 0099840 ____A (Kaspersky Lab) C:\Windows\System32\charhost64.dll
2012-03-25 18:37 - 2012-04-07 17:36 - 0001152 ____A C:\Windows\PFRO.log
2012-03-25 16:39 - 2012-03-25 16:40 - 3898304 ____A (TeamViewer GmbH) C:\Users\SAL\Downloads\TeamViewer_Setup_en.exe
2012-03-24 11:28 - 2012-03-24 11:28 - 0000000 ____D C:\Users\All Users\ATI
2012-03-24 11:28 - 2012-03-24 11:28 - 0000000 ____D C:\ProgramData\ATI
2012-03-24 11:23 - 2012-03-24 11:23 - 0002014 ____A C:\Users\All Users\Start Menu\Programs\Startup\AML Device Install.lnk
2012-03-24 11:23 - 2012-03-24 11:23 - 0000000 ____D C:\Program Files (x86)\AMD AVT
2012-03-24 11:22 - 2012-03-24 11:22 - 0000000 ____D C:\Program Files\AMD
2012-03-24 11:22 - 2012-03-24 11:22 - 0000000 ____D C:\Program Files (x86)\AMD APP
2012-03-24 11:22 - 2012-03-24 11:22 - 0000000 ____D C:\Program Files (x86)\AMD
2012-03-20 17:26 - 2012-03-20 17:26 - 5590336 ____A (Bandisoft) C:\Users\SAL\Downloads\bdcamsetup.exe
2012-03-20 17:26 - 2012-03-20 17:26 - 0000000 ____D C:\Users\SAL\AppData\Roaming\BANDISOFT
2012-03-20 17:26 - 2012-03-20 17:26 - 0000000 ____D C:\Program Files (x86)\BandiMPEG1
2012-03-20 17:26 - 2012-03-20 17:26 - 0000000 ____D C:\Program Files (x86)\Bandicam
2012-03-20 17:24 - 2012-03-20 17:24 - 0000000 ____D C:\Program Files (x86)\QuickTime
2012-03-19 16:04 - 2012-03-19 16:04 - 0000000 ____D C:\Program Files\iTunes
2012-03-19 16:04 - 2012-03-19 16:04 - 0000000 ____D C:\Program Files\iPod
2012-03-19 16:04 - 2012-03-19 16:04 - 0000000 ____D C:\Program Files (x86)\iTunes
2012-03-15 22:39 - 2012-04-08 14:27 - 0007271 ____A C:\Windows\setupact.log
2012-03-15 22:39 - 2012-03-15 22:39 - 0000000 ____A C:\Windows\setuperr.log
2012-03-14 18:00 - 2012-03-14 18:00 - 16157992 ____A (Mozilla) C:\Users\SAL\Downloads\Firefox Setup 11.0.exe
2012-03-14 11:01 - 2012-03-15 18:41 - 0000000 ____D C:\Windows\Minidump
2012-03-13 12:35 - 2011-11-19 07:20 - 5559152 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-13 12:35 - 2011-11-19 06:50 - 3968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-13 12:35 - 2011-11-19 06:50 - 3913584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-13 11:49 - 2012-02-09 22:36 - 1544192 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-03-13 11:49 - 2012-02-09 21:38 - 1077248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2012-03-13 11:49 - 2012-02-02 20:34 - 3145728 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-13 10:19 - 2012-02-16 22:38 - 1031680 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll
2012-03-13 10:19 - 2012-02-16 21:34 - 0826880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2012-03-13 10:19 - 2012-02-16 20:58 - 0210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-03-13 10:19 - 2012-02-16 20:57 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys
2012-03-13 10:19 - 2012-01-24 22:38 - 0149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-03-13 10:19 - 2012-01-24 22:38 - 0077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-03-13 10:19 - 2012-01-24 22:33 - 0009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
============ 3 Months Modified Files and Folders =============
2012-04-08 15:33 - 2012-04-08 15:32 - 0000000 ____D C:\FRST
2012-04-08 14:28 - 2011-01-10 19:16 - 0000000 ____D C:\Users\SAL\AppData\Roaming\Mumble
2012-04-08 14:27 - 2012-03-15 22:39 - 0007271 ____A C:\Windows\setupact.log
2012-04-08 14:27 - 2010-06-07 22:00 - 524099584 __ASH C:\hiberfil.sys
2012-04-08 14:27 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-04-08 14:24 - 2012-03-06 19:50 - 1107805 ____A C:\Windows\WindowsUpdate.log
2012-04-08 14:24 - 2009-07-13 21:13 - 0784224 ____A C:\Windows\System32\PerfStringBackup.INI
2012-04-08 13:58 - 2010-08-06 21:47 - 0000000 ____D C:\Users\SAL\AppData\Roaming\ijjigame
2012-04-08 13:34 - 2011-08-01 23:47 - 0000000 ____D C:\Users\SAL\AppData\Roaming\Skype
2012-04-08 10:23 - 2009-07-13 20:45 - 0009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-04-08 10:23 - 2009-07-13 20:45 - 0009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-04-07 19:50 - 2011-10-25 19:28 - 0000000 ____D C:\Users\SAL\AppData\Roaming\Xfire
2012-04-07 17:36 - 2012-03-25 18:37 - 0001152 ____A C:\Windows\PFRO.log
2012-04-07 17:34 - 2011-12-16 23:13 - 0000000 ____D C:\Users\SAL\AppData\Local\PMB Files
2012-04-07 15:44 - 2012-04-07 14:05 - 0000000 ____D C:\Program Files (x86)\STOPzilla!
2012-04-07 15:44 - 2012-04-04 20:06 - 0000000 ____D C:\Users\SAL\Desktop\Operation Overlord
2012-04-07 15:44 - 2012-04-03 15:33 - 0000000 ____D C:\TDSSKiller
2012-04-07 15:44 - 2011-12-26 11:56 - 0000000 ____D C:\Windows\System32\Macromed
2012-04-07 15:44 - 2011-12-16 23:13 - 0000000 ____D C:\Users\All Users\PMB Files
2012-04-07 15:44 - 2011-12-16 23:13 - 0000000 ____D C:\ProgramData\PMB Files
2012-04-07 15:44 - 2011-07-13 23:30 - 0000000 ____D C:\Program Files\DivX
2012-04-07 15:44 - 2011-07-13 23:29 - 0000000 ____D C:\Users\All Users\DivX
2012-04-07 15:44 - 2011-07-13 23:29 - 0000000 ____D C:\ProgramData\DivX
2012-04-07 15:44 - 2011-07-13 23:29 - 0000000 ____D C:\Program Files (x86)\DivX
2012-04-07 15:44 - 2011-05-28 03:36 - 0000000 ____D C:\Users\SAL\AppData\Roaming\Logishrd
2012-04-07 15:44 - 2010-08-06 21:45 - 0000000 ____D C:\Users\SAL\AppData\Roaming\Ventrilo
2012-04-07 15:44 - 2009-07-13 23:44 - 0000000 ___RD C:\Users\Public\Recorded TV
2012-04-07 15:44 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\registration
2012-04-07 15:44 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\AppCompat
2012-04-07 15:43 - 2011-01-11 16:43 - 0000000 __RHD C:\MSOCache
2012-04-07 15:43 - 2010-08-18 20:57 - 0000000 ____D C:\Users\All Users\LogiShrd
2012-04-07 15:43 - 2010-08-18 20:57 - 0000000 ____D C:\ProgramData\LogiShrd
2012-04-07 15:43 - 2010-08-06 14:55 - 0000000 ____D C:\Users\SAL\AppData\LocalLow
2012-04-07 15:30 - 2011-10-17 16:51 - 0000000 ____D C:\Users\All Users\Xfire
2012-04-07 15:30 - 2011-10-17 16:51 - 0000000 ____D C:\ProgramData\Xfire
2012-04-07 15:08 - 2010-08-22 17:21 - 0000000 ____A C:\Windows\SysWOW64\wbers.dat.dmp
2012-04-07 14:52 - 2010-08-06 14:55 - 0000000 ____D C:\users\SAL
2012-04-07 14:45 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR
2012-04-07 14:07 - 2012-04-07 14:05 - 0000000 ____D C:\Users\All Users\STOPzilla!
2012-04-07 14:07 - 2012-04-07 14:05 - 0000000 ____D C:\ProgramData\STOPzilla!
2012-04-07 14:03 - 2012-04-07 14:03 - 0109656 ____A C:\Users\SAL\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-07 13:40 - 2012-04-07 13:38 - 0124594 ____A C:\TDSSKiller.2.7.26.0_07.04.2012_14.38.41_log.txt
2012-04-07 13:38 - 2012-04-07 13:38 - 0000348 ____A C:\TDSSKiller.2.7.25.0_07.04.2012_14.38.18_log.txt
2012-04-05 12:29 - 2011-07-26 12:37 - 0000000 ____D C:\Users\SAL\riotsGamesLogs
2012-04-04 20:23 - 2010-08-18 20:59 - 0000000 ____D C:\Program Files\Logitech
2012-04-04 20:07 - 2012-04-04 20:07 - 0000000 ____A C:\Users\SAL\defogger_reenable
2012-04-04 17:02 - 2010-09-06 15:46 - 0000000 ____D C:\Users\SAL\Documents\Business
2012-04-03 15:34 - 2011-12-10 13:21 - 0000000 ____D C:\Users\SAL\Documents\School
2012-04-02 15:11 - 2012-04-02 09:52 - 0000000 __SHD C:\Users\SAL\AppData\Local\c7c64ac0
2012-03-30 14:15 - 2012-03-30 14:15 - 0000000 ____D C:\Users\SAL\AppData\Local\DDMSettings
2012-03-28 11:41 - 2012-03-28 11:41 - 0099840 ____A (Kaspersky Lab) C:\Windows\System32\charhost64.dll
2012-03-25 16:40 - 2012-03-25 16:39 - 3898304 ____A (TeamViewer GmbH) C:\Users\SAL\Downloads\TeamViewer_Setup_en.exe
2012-03-25 16:35 - 2010-10-09 16:10 - 0000000 ____D C:\Users\SAL\AppData\Roaming\TeamViewer
2012-03-24 11:28 - 2012-03-24 11:28 - 0000000 ____D C:\Users\All Users\ATI
2012-03-24 11:28 - 2012-03-24 11:28 - 0000000 ____D C:\ProgramData\ATI
2012-03-24 11:23 - 2012-03-24 11:23 - 0002014 ____A C:\Users\All Users\Start Menu\Programs\Startup\AML Device Install.lnk
2012-03-24 11:23 - 2012-03-24 11:23 - 0000000 ____D C:\Program Files (x86)\AMD AVT
2012-03-24 11:23 - 2011-07-26 19:27 - 0000000 ____D C:\Users\All Users\AMD
2012-03-24 11:23 - 2011-07-26 19:27 - 0000000 ____D C:\ProgramData\AMD
2012-03-24 11:22 - 2012-03-24 11:22 - 0000000 ____D C:\Program Files\AMD
2012-03-24 11:22 - 2012-03-24 11:22 - 0000000 ____D C:\Program Files (x86)\AMD APP
2012-03-24 11:22 - 2012-03-24 11:22 - 0000000 ____D C:\Program Files (x86)\AMD
2012-03-24 11:22 - 2010-08-08 13:06 - 0000000 ____D C:\Program Files\ATI Technologies
2012-03-20 17:28 - 2011-11-13 16:31 - 0000000 ____D C:\Users\SAL\Documents\Recordings
2012-03-20 17:26 - 2012-03-20 17:26 - 5590336 ____A (Bandisoft) C:\Users\SAL\Downloads\bdcamsetup.exe
2012-03-20 17:26 - 2012-03-20 17:26 - 0000000 ____D C:\Users\SAL\AppData\Roaming\BANDISOFT
2012-03-20 17:26 - 2012-03-20 17:26 - 0000000 ____D C:\Program Files (x86)\BandiMPEG1
2012-03-20 17:26 - 2012-03-20 17:26 - 0000000 ____D C:\Program Files (x86)\Bandicam
2012-03-20 17:24 - 2012-03-20 17:24 - 0000000 ____D C:\Program Files (x86)\QuickTime
2012-03-20 12:20 - 2010-10-24 14:31 - 0005295 ____A C:\Users\SAL\Documents\Word Key.txt
2012-03-19 23:03 - 2011-10-14 21:21 - 0000000 ___RD C:\Users\SAL\Dropbox
2012-03-19 23:03 - 2011-10-14 21:19 - 0000000 ____D C:\Users\SAL\AppData\Roaming\Dropbox
2012-03-19 16:04 - 2012-03-19 16:04 - 0000000 ____D C:\Program Files\iTunes
2012-03-19 16:04 - 2012-03-19 16:04 - 0000000 ____D C:\Program Files\iPod
2012-03-19 16:04 - 2012-03-19 16:04 - 0000000 ____D C:\Program Files (x86)\iTunes
2012-03-18 21:00 - 2010-12-25 15:29 - 0000404 ____A C:\Windows\Tasks\SmartDefrag.job
2012-03-15 22:39 - 2012-03-15 22:39 - 0000000 ____A C:\Windows\setuperr.log
2012-03-15 18:41 - 2012-03-14 11:01 - 0000000 ____D C:\Windows\Minidump
2012-03-14 18:01 - 2010-08-06 21:40 - 0000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-03-14 18:00 - 2012-03-14 18:00 - 16157992 ____A (Mozilla) C:\Users\SAL\Downloads\Firefox Setup 11.0.exe
2012-03-14 18:00 - 2010-08-06 22:58 - 0000000 ____D C:\Users\SAL\AppData\Roaming\SoftGrid Client
2012-03-13 12:58 - 2009-07-13 20:45 - 0424536 ____A C:\Windows\System32\FNTCACHE.DAT
2012-03-13 12:34 - 2010-08-09 18:58 - 56297240 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-03-13 12:33 - 2010-04-12 00:56 - 0000000 ____D C:\Users\All Users\Microsoft Help
2012-03-13 12:33 - 2010-04-12 00:56 - 0000000 ____D C:\ProgramData\Microsoft Help
2012-03-12 15:55 - 2011-05-31 00:03 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-03-12 15:31 - 2010-08-06 21:34 - 0000000 ____D C:\Users\SAL\AppData\Local\AIM
2012-03-11 11:20 - 2010-08-06 21:32 - 0000000 ____D C:\Users\SAL\AppData\Local\Google
2012-03-11 00:06 - 2010-08-07 19:18 - 0000000 ___RD C:\Recycle Bin
2012-03-08 14:26 - 2012-03-08 14:26 - 0000000 ____D C:\Program Files (x86)\Cygnus
2012-03-06 19:49 - 2007-07-11 17:49 - 0000000 ____D C:\Windows\Panther
2012-03-05 17:01 - 2010-08-08 18:54 - 0000000 ____D C:\Program Files (x86)\CCleaner
2012-03-01 15:45 - 2011-10-25 19:28 - 0000000 ___SD C:\Program Files (x86)\Xfire
2012-02-29 11:21 - 2012-02-29 11:21 - 0042392 ____A C:\Windows\SysWOW64\xfcodec.dll
2012-02-29 11:21 - 2012-02-29 11:21 - 0028056 ____A C:\Windows\System32\xfcodec64.dll
2012-02-27 23:57 - 2010-08-06 22:57 - 0777948 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-02-24 17:36 - 2011-10-17 16:43 - 0000000 ____D C:\Program Files (x86)\REACTOR
2012-02-24 15:13 - 2009-07-13 21:08 - 0032638 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-02-23 09:18 - 2010-08-06 21:49 - 0279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-02-20 22:28 - 2010-04-12 00:42 - 0000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-02-20 20:58 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\Downloaded Program Files
2012-02-20 20:57 - 2012-02-20 20:54 - 0000000 ____D C:\Program Files (x86)\fbDownloader
2012-02-20 20:57 - 2011-02-23 23:00 - 0000000 ____D C:\Users\SAL\AppData\Local\Conduit
2012-02-20 20:54 - 2012-02-20 20:54 - 0000000 ____D C:\Program Files (x86)\SDIV 2.0
2012-02-20 20:54 - 2012-02-20 20:54 - 0000000 ____D C:\Program Files (x86)\HTTO Group, Ltd
2012-02-20 20:54 - 2012-02-20 20:54 - 0000000 ____D C:\Program Files (x86)\Conduit
2012-02-20 20:42 - 2012-02-20 20:42 - 0000064 ____A C:\Windows\GPlrLanc.dat
2012-02-16 22:38 - 2012-03-13 10:19 - 1031680 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll
2012-02-16 21:34 - 2012-03-13 10:19 - 0826880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2012-02-16 20:58 - 2012-03-13 10:19 - 0210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-02-16 20:57 - 2012-03-13 10:19 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys
2012-02-15 14:34 - 2010-04-12 01:00 - 0000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-02-15 10:02 - 2010-08-06 14:56 - 0000174 ___SH C:\Users\SAL\Start Menu\Programs\Startup\desktop.ini
2012-02-15 10:02 - 2010-08-06 14:56 - 0000174 ___SH C:\Users\SAL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2012-02-15 00:16 - 2011-01-11 15:28 - 0000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-02-14 21:05 - 2012-02-14 21:05 - 16507904 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-02-14 21:05 - 2012-02-14 21:05 - 0069632 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-02-14 21:05 - 2012-02-14 21:05 - 0061952 ____A C:\Windows\System32\OVDecode64.dll
2012-02-14 21:05 - 2012-02-14 21:05 - 0059904 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-02-14 21:05 - 2012-02-14 21:05 - 0054784 ____A C:\Windows\SysWOW64\OVDecode.dll
2012-02-14 21:04 - 2012-02-14 21:04 - 13238272 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-02-14 21:03 - 2012-02-14 21:03 - 0054272 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-02-14 21:03 - 2012-02-14 21:03 - 0048128 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-02-14 19:48 - 2012-02-14 19:48 - 10856960 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-02-14 19:21 - 2012-02-14 19:21 - 25839104 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-02-14 19:19 - 2012-02-14 19:19 - 0235072 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-02-14 19:19 - 2012-02-14 19:19 - 0235072 ____A C:\Windows\System32\atiapfxx.blb
2012-02-14 19:18 - 2012-02-14 19:18 - 0159744 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-02-14 19:18 - 2011-12-05 19:17 - 0791040 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-02-14 19:17 - 2010-04-12 01:29 - 0957952 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-02-14 19:13 - 2012-02-14 19:13 - 0496128 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-02-14 19:13 - 2012-02-14 19:13 - 0442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-02-14 19:13 - 2012-02-14 19:13 - 0235520 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-02-14 19:11 - 2012-02-14 19:11 - 0120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-02-14 19:10 - 2012-02-14 19:10 - 0059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-02-14 19:10 - 2012-02-14 19:10 - 0043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-02-14 19:10 - 2012-02-14 19:10 - 0021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-02-14 19:07 - 2011-12-05 19:06 - 6200320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-02-14 18:58 - 2012-02-14 18:58 - 19392000 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-02-14 18:52 - 2010-04-12 01:29 - 7646208 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-02-14 18:41 - 2012-02-14 18:41 - 1113088 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6v.dll
2012-02-14 18:40 - 2012-02-14 18:40 - 4958208 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-02-14 18:40 - 2012-02-14 18:40 - 1828864 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll
2012-02-14 18:36 - 2012-02-14 18:36 - 2425664 ____A C:\Windows\System32\atiumd6a.cap
2012-02-14 18:36 - 2012-02-14 18:36 - 0204952 ____A C:\Windows\SysWOW64\ativvsvl.dat
2012-02-14 18:36 - 2012-02-14 18:36 - 0204952 ____A C:\Windows\System32\ativvsvl.dat
2012-02-14 18:36 - 2012-02-14 18:36 - 0157144 ____A C:\Windows\SysWOW64\ativvsva.dat
2012-02-14 18:36 - 2012-02-14 18:36 - 0157144 ____A C:\Windows\System32\ativvsva.dat
2012-02-14 18:34 - 2012-02-14 18:34 - 13859840 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-02-14 18:34 - 2012-02-14 18:34 - 0051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-02-14 18:34 - 2012-02-14 18:34 - 0046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-02-14 18:34 - 2012-02-14 18:34 - 0044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-02-14 18:34 - 2012-02-14 18:34 - 0044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-02-14 18:34 - 2011-12-05 18:33 - 5954048 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-02-14 18:29 - 2012-02-14 18:29 - 11561984 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-02-14 18:29 - 2011-12-05 18:28 - 5062656 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-02-14 18:28 - 2012-02-14 18:28 - 2427392 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-02-14 18:25 - 2012-02-14 18:25 - 7551488 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-02-14 18:16 - 2010-04-12 01:29 - 0058880 ____A (AMD) C:\Windows\System32\coinst.dll
2012-02-14 18:14 - 2012-02-14 18:14 - 0512000 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-02-14 18:13 - 2012-02-14 18:13 - 0356352 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-02-14 18:13 - 2012-02-14 18:13 - 0327680 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-02-14 18:13 - 2012-02-14 18:13 - 0039936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-02-14 18:13 - 2012-02-14 18:13 - 0033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-02-14 18:13 - 2012-02-14 18:13 - 0017408 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-02-14 18:13 - 2012-02-14 18:13 - 0014336 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-02-14 18:13 - 2012-02-14 18:13 - 0014336 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-02-14 18:12 - 2012-02-14 18:12 - 0039936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-02-14 18:12 - 2011-12-05 18:11 - 0033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-02-14 18:12 - 2011-12-05 18:11 - 0030208 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-02-14 18:12 - 2010-04-12 01:29 - 0043008 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-02-14 18:11 - 2012-02-14 18:11 - 0054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-02-14 18:11 - 2012-02-14 18:11 - 0054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-02-14 18:11 - 2012-02-14 18:11 - 0053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-02-14 18:11 - 2012-02-14 18:11 - 0053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-02-14 18:11 - 2012-02-14 18:11 - 0053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-02-13 21:24 - 2010-08-18 20:58 - 0000000 ____D C:\Program Files\Common Files\Logishrd
2012-02-12 22:10 - 2010-08-16 17:04 - 0000000 ____D C:\Users\SAL\AppData\Local\Adobe
2012-02-12 22:10 - 2010-04-12 01:08 - 0000000 ____D C:\Users\All Users\Adobe
2012-02-12 22:10 - 2010-04-12 01:08 - 0000000 ____D C:\ProgramData\Adobe
2012-02-12 22:10 - 2010-04-12 01:08 - 0000000 ____D C:\Program Files (x86)\Adobe
2012-02-09 22:36 - 2012-03-13 11:49 - 1544192 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-02-09 21:38 - 2012-03-13 11:49 - 1077248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2012-02-07 21:26 - 2012-02-07 21:26 - 0000017 ____A C:\Users\SAL\AppData\Local\resmon.resmoncfg
2012-02-05 13:44 - 2010-08-06 22:59 - 0000000 ____D C:\Users\SAL\AppData\Roaming\SystemRequirementsLab
2012-02-05 13:44 - 2010-08-06 22:59 - 0000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2012-02-02 20:34 - 2012-03-13 11:49 - 3145728 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-02-01 09:52 - 2011-11-13 20:22 - 0000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-31 05:02 - 2012-01-31 05:02 - 0021504 ____A C:\Windows\System32\kdbsdk64.dll
2012-01-31 05:00 - 2012-01-31 05:00 - 0016896 ____A C:\Windows\SysWOW64\kdbsdk32.dll
2012-01-28 13:00 - 2010-08-08 13:06 - 0000000 ____D C:\AMD
2012-01-26 14:29 - 2010-04-12 01:09 - 0000000 ____D C:\Users\All Users\Norton
2012-01-26 14:29 - 2010-04-12 01:09 - 0000000 ____D C:\ProgramData\Norton
2012-01-25 23:02 - 2010-04-12 01:09 - 0000000 ____D C:\Windows\SysWOW64\Macromed
2012-01-24 22:38 - 2012-03-13 10:19 - 0149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-01-24 22:38 - 2012-03-13 10:19 - 0077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-01-24 22:33 - 2012-03-13 10:19 - 0009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-01-10 13:10 - 2012-01-10 13:10 - 0601728 ____A C:\Windows\System32\atiicdxx.dat
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 6127.76 MB
Available physical RAM: 5303.4 MB
Total Pagefile: 6125.91 MB
Available Pagefile: 5283.76 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Gateway) (Fixed) (Total:911.35 GB) (Free:846.95 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:20 GB) (Free:9.3 GB) NTFS ==>[System with boot components (obtained from reading drive)]
9 Drive l: (USB20FD) (Removable) (Total:7.45 GB) (Free:7.41 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 Online 7648 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 20 GB 1024 KB
Partition 2 Primary 100 MB 20 GB
Partition 3 Primary 911 GB 20 GB
======================================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 20 GB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Gateway NTFS Partition 911 GB Healthy
======================================================================================================
Partitions of Disk 6:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7647 MB 40 KB
======================================================================================================
Disk: 6
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 9 L USB20FD FAT32 Removable 7647 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-04-03 14:04
======================= End Of Log ==========================