We were able to use the Wdw 7 Install CD to run FARBAR. We saw your post for using Combofix, but have NOT yet executed those instructions because this run of FARBAR worked.
Here is the resulting FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 01-07-2012
Ran by SYSTEM at 04-07-2012 09:01:23
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [OfficeScanNT Monitor] "c:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow [1099088 2010-06-25] (Trend Micro Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [136216 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [171032 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [170520 2010-08-25] (Intel Corporation)
HKLM\...\Run: [VX1000] C:\Windows\vVX1000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [] [x]
HKLM\...\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [348624 2012-05-08] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui [136416 2011-05-04] (Memeo Inc.)
HKLM\...\Run: [Memeo AutoSync] C:\Program Files\Memeo\AutoSync\MemeoLauncher2.exe --silent [144608 2011-05-04] (Memeo Inc.)
HKLM\...\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [79112 2011-06-01] ()
HKLM\...\Run: [imtcol] rundll32.exe "C:\Users\Diane\AppData\Roaming\imtcol.dll",AddColumn [120832 2012-06-24] (Duplex Secure Ltd.)
HKLM\...\Run: [setsil] "C:\Windows\System32\rundll32.exe" "C:\Users\Diane\AppData\Roaming\setsil.dll",LoadVolumeFromFileInMemory [352768 2012-06-24] ()
HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKU\Diane\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [3905408 2012-06-11] (SUPERAntiSpyware.com)
HKU\Diane\...\Run: [Google Update] "C:\Users\Diane\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-03-26] (Google Inc.)
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [X]
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll [X]
Winlogon\Notify\GoToAssist Express Customer: C:\Program Files\Citrix\GoToAssist Express Customer\274\g2ax_winlogon.dll [X]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 66.60.130.158
================================ Services (Whitelisted) ==================
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE.EXE" [116608 2011-08-11] (SUPERAntiSpyware.com)
2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [86224 2012-05-08] (Avira Operations GmbH & Co. KG)
2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [110032 2012-05-08] (Avira Operations GmbH & Co. KG)
2 BPowMon; C:\Program Files\Broadcom\BPowMon\BPowMon.exe [79168 2009-08-17] (Broadcom Corp.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 GoToAssist Express Customer; "C:\Program Files\Citrix\GoToAssist Express Customer\274\g2ax_service.exe" "Start=service" [161144 2011-04-13] (Citrix Online, a division of Citrix Systems, Inc.)
2 MemeoBackgroundService; C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe [25824 2011-05-04] (Memeo)
3 osppsvc; "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" [4640000 2010-01-09] (Microsoft Corporation)
2 SeagateDashboardService; C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [14088 2011-06-01] (Memeo)
2 ntrtscan; "c:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe" [x]
2 svcGenericHost; "c:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe" [x]
2 tmlisten; "c:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe" [x]
3 TmPfw; "c:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe" [x]
3 TmProxy; "c:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe" [x]
========================== Drivers (Whitelisted) =============
2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-05-08] (Avira GmbH)
1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-05-08] (Avira GmbH)
1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2011-09-16] (Avira GmbH)
3 k57nd60x; C:\Windows\System32\DRIVERS\k57nd60x.sys [273960 2009-08-21] (Broadcom Corporation)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH)
2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [158224 2009-07-06] (Trend Micro Inc.)
2 TmFilter; \??\c:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys [230928 2010-05-10] (Trend Micro Inc.)
1 tmlwf; C:\Windows\System32\DRIVERS\tmlwf.sys [146448 2009-07-15] (Trend Micro Inc.)
2 TmPreFilter; \??\c:\Program Files\Trend Micro\Client Server Security Agent\TmPreFlt.sys [36368 2010-05-10] (Trend Micro Inc.)
1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [89872 2009-07-15] (Trend Micro Inc.)
2 tmwfp; C:\Windows\System32\DRIVERS\tmwfp.sys [283152 2009-07-15] (Trend Micro Inc.)
3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
3 vpcuxd; C:\Windows\system32\drivers\vpcuxd.sys [12800 2010-11-20] (Microsoft Corporation)
1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
2 VSApiNt; \??\c:\Program Files\Trend Micro\Client Server Security Agent\VSApiNt.sys [1322808 2010-05-10] (Trend Micro Inc.)
3 VX1000; C:\Windows\System32\DRIVERS\VX1000.sys [1961072 2010-05-20] (Microsoft Corporation)
3 catchme; \??\C:\Users\Diane\AppData\Local\Temp\catchme.sys [x]
3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHDA.sys [x]
3 PCDSRVC{E9D79540-57D5953E-06020101}_0; \??\c:\program files\dell support center\pcdsrvc.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-04 09:00 - 2012-07-04 09:01 - 00000000 ____D C:\FRST
2012-07-03 07:04 - 2012-07-03 07:04 - 00057560 ____A C:\Users\Diane\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-03 07:03 - 2012-07-04 07:47 - 00000906 ____A C:\Windows\setupact.log
2012-07-03 07:03 - 2012-07-03 07:03 - 00266896 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-03 07:03 - 2012-07-03 07:03 - 00000000 ____A C:\Windows\setuperr.log
2012-06-30 15:56 - 2012-06-30 15:56 - 00001600 ____A C:\Users\Diane\Desktop\ark.txt
2012-06-30 15:21 - 2012-06-30 15:21 - 03485774 ____A C:\Users\Diane\Desktop\PandaPC.nfo
2012-06-30 15:18 - 2012-06-30 15:18 - 00302592 ____A C:\Users\Diane\Desktop\rlrx2uk8.exe
2012-06-30 15:15 - 2012-06-30 15:15 - 00607260 ____R (Swearware) C:\Users\Diane\Desktop\dds.scr
2012-06-25 15:51 - 2012-06-25 15:51 - 00000000 ____D C:\rsit
2012-06-25 13:36 - 2012-06-25 13:36 - 00000000 ____A C:\Users\Diane\defogger_reenable
2012-06-25 11:51 - 2012-06-25 11:51 - 00001304 ____A C:\Users\Diane\Desktop\Notepad.lnk
2012-06-25 11:21 - 2012-06-25 15:54 - 00000000 ____D C:\Users\Diane\Downloads\Cleaning
2012-06-25 06:45 - 2012-06-25 06:51 - 00000000 ___SD C:\ComboFix
2012-06-24 22:58 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-06-24 22:58 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-06-24 22:58 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-06-24 22:58 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-06-24 22:58 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-06-24 22:58 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-06-24 22:58 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-06-24 22:58 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-06-24 22:44 - 2012-06-24 22:57 - 00000000 ____D C:\Qoobox
2012-06-24 22:42 - 2012-06-24 22:48 - 00000000 ____D C:\Windows\erdnt
2012-06-24 22:41 - 2012-06-24 22:41 - 04567243 ____R (Swearware) C:\Users\Diane\Downloads\ComboFix.exe
2012-06-24 22:27 - 2012-06-24 22:27 - 02128472 ____A (Kaspersky Lab ZAO) C:\Users\Diane\Desktop\tdsskiller.exe
2012-06-24 22:05 - 2012-06-24 22:19 - 00000000 ____D C:\Program Files\Exterminate It!
2012-06-24 22:05 - 2012-06-24 22:05 - 00001045 ____A C:\Users\Public\Desktop\Exterminate It!.lnk
2012-06-24 21:50 - 2012-06-24 21:50 - 00001248 ____A C:\Users\Diane\Desktop\ProcExplorer.lnk
2012-06-24 18:22 - 2012-07-03 07:08 - 00279337 ____A C:\Windows\WindowsUpdate.log
2012-06-24 15:26 - 2012-06-24 15:26 - 00352768 ____A C:\Users\Diane\AppData\Roaming\setsil.dll
2012-06-24 15:26 - 2012-06-24 15:26 - 00000000 ____D C:\Windows\scoped_dir_32204
2012-06-24 15:26 - 2012-06-24 15:26 - 00000000 ____D C:\Users\Diane\AppData\Local\{FAC50208-BE53-11E1-8270-B8AC6F996F26}
2012-06-24 15:25 - 2012-06-24 15:25 - 00120832 ____A (Duplex Secure Ltd.) C:\Users\Diane\AppData\Roaming\imtcol.dll
2012-06-24 12:45 - 2012-06-24 12:53 - 00000256 ____A C:\Users\All Users\kefotInIfmoOt9
2012-06-24 12:45 - 2012-06-24 12:45 - 00000152 ____A C:\Users\All Users\-kefotInIfmoOt9r
2012-06-24 12:45 - 2012-06-24 12:45 - 00000000 ____A C:\Users\All Users\-kefotInIfmoOt9
2012-06-21 05:57 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 05:57 - 2012-06-02 14:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 05:57 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 05:57 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 05:57 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 05:57 - 2012-06-02 14:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-20 14:25 - 2012-06-24 14:33 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-06-20 14:25 - 2012-06-20 14:25 - 00001967 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-06-20 07:47 - 2012-06-20 09:35 - 00000000 ___HD C:\Users\Diane\Documents\RECIPES
2012-06-14 05:03 - 2012-05-14 19:03 - 00981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 05:03 - 2012-05-14 19:00 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 05:03 - 2012-05-14 17:05 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-14 05:03 - 2012-04-30 20:44 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-14 05:03 - 2012-04-27 19:17 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-14 05:03 - 2012-04-25 20:45 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-14 05:03 - 2012-04-25 20:45 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-14 05:03 - 2012-04-25 20:41 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-14 05:03 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-14 05:03 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-14 05:03 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-14 05:03 - 2012-04-19 21:00 - 01231360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 05:03 - 2012-04-19 21:00 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 05:03 - 2012-04-19 20:57 - 06027776 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 05:03 - 2012-04-19 20:57 - 00627712 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-06-14 05:03 - 2012-04-19 20:57 - 00067584 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 05:03 - 2012-04-19 20:56 - 11020800 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 05:03 - 2012-04-19 20:56 - 02073600 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 05:03 - 2012-04-19 20:56 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 05:03 - 2012-04-19 19:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 05:03 - 2012-04-16 20:34 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 05:03 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
============ 3 Months Modified Files ========================
2012-07-04 07:47 - 2012-07-03 07:03 - 00000906 ____A C:\Windows\setupact.log
2012-07-04 07:46 - 2011-10-08 20:09 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-04 07:46 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-03 07:08 - 2012-06-24 18:22 - 00279337 ____A C:\Windows\WindowsUpdate.log
2012-07-03 07:08 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-03 07:08 - 2009-07-13 20:34 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-03 07:07 - 2011-04-18 11:05 - 00000031 ____A C:\tmuninst.ini
2012-07-03 07:04 - 2012-07-03 07:04 - 00057560 ____A C:\Users\Diane\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-03 07:03 - 2012-07-03 07:03 - 00266896 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-03 07:03 - 2012-07-03 07:03 - 00000000 ____A C:\Windows\setuperr.log
2012-06-30 16:12 - 2011-03-26 17:03 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138447411-1991068916-1511503196-1000UA.job
2012-06-30 15:56 - 2012-06-30 15:56 - 00001600 ____A C:\Users\Diane\Desktop\ark.txt
2012-06-30 15:21 - 2012-06-30 15:21 - 03485774 ____A C:\Users\Diane\Desktop\PandaPC.nfo
2012-06-30 15:18 - 2012-06-30 15:18 - 00302592 ____A C:\Users\Diane\Desktop\rlrx2uk8.exe
2012-06-30 15:15 - 2012-06-30 15:15 - 00607260 ____R (Swearware) C:\Users\Diane\Desktop\dds.scr
2012-06-30 15:10 - 2012-04-05 14:05 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-06-30 13:34 - 2011-10-08 20:09 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-30 13:12 - 2011-03-26 17:03 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1138447411-1991068916-1511503196-1000Core.job
2012-06-25 13:36 - 2012-06-25 13:36 - 00000000 ____A C:\Users\Diane\defogger_reenable
2012-06-25 11:51 - 2012-06-25 11:51 - 00001304 ____A C:\Users\Diane\Desktop\Notepad.lnk
2012-06-25 11:21 - 2011-03-11 16:56 - 00742066 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-24 22:41 - 2012-06-24 22:41 - 04567243 ____R (Swearware) C:\Users\Diane\Downloads\ComboFix.exe
2012-06-24 22:27 - 2012-06-24 22:27 - 02128472 ____A (Kaspersky Lab ZAO) C:\Users\Diane\Desktop\tdsskiller.exe
2012-06-24 22:05 - 2012-06-24 22:05 - 00001045 ____A C:\Users\Public\Desktop\Exterminate It!.lnk
2012-06-24 21:50 - 2012-06-24 21:50 - 00001248 ____A C:\Users\Diane\Desktop\ProcExplorer.lnk
2012-06-24 19:19 - 2011-03-11 17:02 - 00111152 ____A C:\Windows\System32\TmInstall.log
2012-06-24 15:26 - 2012-06-24 15:26 - 00352768 ____A C:\Users\Diane\AppData\Roaming\setsil.dll
2012-06-24 15:25 - 2012-06-24 15:25 - 00120832 ____A (Duplex Secure Ltd.) C:\Users\Diane\AppData\Roaming\imtcol.dll
2012-06-24 12:53 - 2012-06-24 12:45 - 00000256 ____A C:\Users\All Users\kefotInIfmoOt9
2012-06-24 12:45 - 2012-06-24 12:45 - 00000152 ____A C:\Users\All Users\-kefotInIfmoOt9r
2012-06-24 12:45 - 2012-06-24 12:45 - 00000000 ____A C:\Users\All Users\-kefotInIfmoOt9
2012-06-21 11:34 - 2011-04-17 14:39 - 00005120 ____A C:\Users\Diane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-20 14:25 - 2012-06-20 14:25 - 00001967 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-06-19 10:12 - 2012-04-05 14:05 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-15 05:40 - 2012-04-09 13:31 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-06-15 05:40 - 2011-09-07 05:50 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-06-15 02:10 - 2011-03-29 18:55 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-11 21:13 - 2011-03-26 17:04 - 00002407 ____A C:\Users\Diane\Desktop\Google Chrome.lnk
2012-06-02 14:19 - 2012-06-21 05:57 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:57 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 05:57 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:57 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:12 - 2012-06-21 05:57 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 05:57 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-29 06:00 - 2011-06-14 14:38 - 00148992 __ASH C:\Users\Diane\Documents\Thumbs.db
2012-05-14 19:03 - 2012-06-14 05:03 - 00981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 19:00 - 2012-06-14 05:03 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 17:05 - 2012-06-14 05:03 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-08 05:24 - 2012-02-16 07:22 - 00137928 ____A (Avira GmbH) C:\Windows\System32\Drivers\avipbb.sys
2012-05-08 05:24 - 2012-02-16 07:22 - 00083392 ____A (Avira GmbH) C:\Windows\System32\Drivers\avgntflt.sys
2012-04-30 20:44 - 2012-06-14 05:03 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:17 - 2012-06-14 05:03 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 20:45 - 2012-06-14 05:03 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-14 05:03 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-14 05:03 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 20:36 - 2012-06-14 05:03 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-06-14 05:03 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-06-14 05:03 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-19 21:00 - 2012-06-14 05:03 - 01231360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-04-19 21:00 - 2012-06-14 05:03 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-04-19 20:57 - 2012-06-14 05:03 - 06027776 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-04-19 20:57 - 2012-06-14 05:03 - 00627712 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-04-19 20:57 - 2012-06-14 05:03 - 00067584 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-04-19 20:56 - 2012-06-14 05:03 - 11020800 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-04-19 20:56 - 2012-06-14 05:03 - 02073600 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-04-19 20:56 - 2012-06-14 05:03 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-04-19 19:16 - 2012-06-14 05:03 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-04-16 20:34 - 2012-06-14 05:03 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-04-09 13:24 - 2012-04-09 13:24 - 00001755 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-04-08 07:41 - 2012-04-08 07:41 - 00738926 ___AH C:\Users\Diane\Documents\AllKids2.rtf
2012-04-08 07:39 - 2012-04-08 07:39 - 00734682 ___AH C:\Users\Diane\Documents\AllKids1.rtf
2012-04-08 07:34 - 2012-04-08 07:34 - 00717938 ___AH C:\Users\Diane\Documents\KikiAlishaPics2.rtf
2012-04-08 07:29 - 2012-04-08 07:29 - 00691423 ___AH C:\Users\Diane\Documents\KikiAlishaPics1.rtf
2012-04-08 06:49 - 2012-04-08 06:49 - 00262262 ___AH C:\Users\Diane\Documents\KikiAlishaBatman2.rtf
2012-04-07 03:26 - 2012-06-14 05:03 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
ZeroAccess:
C:\Windows\Installer\{c4d025a9-6177-a39c-16ac-9c884dadcd2a}
C:\Windows\Installer\{c4d025a9-6177-a39c-16ac-9c884dadcd2a}\L
C:\Windows\Installer\{c4d025a9-6177-a39c-16ac-9c884dadcd2a}\U
ZeroAccess:
C:\Users\Diane\AppData\Local\{c4d025a9-6177-a39c-16ac-9c884dadcd2a}
C:\Users\Diane\AppData\Local\{c4d025a9-6177-a39c-16ac-9c884dadcd2a}\L
C:\Users\Diane\AppData\Local\{c4d025a9-6177-a39c-16ac-9c884dadcd2a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 4060.8 MB
Available physical RAM: 3367.3 MB
Total Pagefile: 4059.08 MB
Available Pagefile: 3388.61 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:218.63 GB) (Free:134.46 GB) NTFS
2 Drive e: (WIN_7_PROFESSIONAL) (CDROM) (Total:4.78 GB) (Free:0 GB) UDF
3 Drive f: (USB20FD) (Removable) (Total:3.77 GB) (Free:3.77 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (RECOVERY) (Fixed) (Total:14.15 GB) (Free:8.79 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 Online 3864 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 14 GB 40 MB
Partition 3 Primary 218 GB 14 GB
Partition 4 Primary 1609 KB 232 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 218 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 17 (Suspicious Type)
Hidden: Yes
Active: Yes
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3863 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F USB20FD FAT32 Removable 3863 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-27 23:10
======================= End Of Log ==========================