Yesterday I was infected with Live Security Platinum, wich I've never heard about but I was able to get rid of it with Malwarebytes' Anti-Malware. After that I noticed that Microsoft Security Essentials needed an update, so I updated it. Problem is, after 30 minutes or so I get the "windows has encountered a critical error and will restart automatically in one minute. Please save your work." message. MSE detected 2 Trojans, C:\Windows\System32\services.exe and services731.
Now every time I start up my computer, after some seconds I get the same message and my computer restarts in 1 minute. I tried some solutions to fix this, including using the "shutdown -a" shortcut and choosing Disable Automatic Restart On System Failure in the Advanced Boot Options menu.
None of that worked.
My problem is identical to the topic "Virus + critical error shutdown" started by cbritton7, about a month ago (
http://www.bleepingcomputer.com/forums/topic458922.html).
I'm running Windows7 32bit Home Premium.
Farbar Recovery Scan Tool scan log:Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 31-07-2012 23:30:52
Running from E:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
================================ Services (Whitelisted) ==================
2 AdvancedSystemCareService5; C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe [913752 2012-03-14] (IObit)
2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [291840 2012-06-11] (Advanced Micro Devices, Inc.)
2 AsSysCtrlService; C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-08-19] (ASUSTeK Computer Inc.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2012-05-10] ()
2 RalinkRegistryWriter; "C:\Program Files\Edimax\Common\RaRegistry.exe" [185632 2009-12-16] (Ralink Technology, Corp.)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-05-02] (Skype Technologies)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
2 AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] ()
1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11448 2009-07-06] ()
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
1 prodrv06; C:\Windows\System32\drivers\prodrv06.sys [80576 2004-10-07] (Protection Technology)
0 prohlp02; C:\Windows\System32\drivers\prohlp02.sys [115744 2004-10-07] (Protection Technology)
3 pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [16472 2011-09-02] ()
3 pwdspio; \??\C:\Windows\system32\pwdspio.sys [11104 2011-09-02] ()
0 sfhlp01; C:\Windows\System32\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2011-12-30] (Duplex Secure Ltd.)
3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [x]
3 XDva398; \??\C:\Windows\system32\XDva398.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-30 09:27 - 2012-07-30 09:27 - 00000000 ____D C:\FRST
2012-07-30 09:17 - 2012-07-30 09:17 - 00000021 ____A C:\Users\Utilizador\AppData\Roaming\mbam.context.scan
2012-07-30 08:57 - 2012-07-30 08:57 - 00000000 ____D C:\Windows\pss
2012-07-30 08:48 - 2012-07-30 08:49 - 00000928 ____A C:\Users\Utilizador\Desktop\shutdown -a.lnk
2012-07-30 08:48 - 2012-07-30 08:48 - 00000000 ____D C:\Users\Utilizador\Desktop\Nova pasta
2012-07-30 08:38 - 2012-07-30 08:38 - 00000528 ____A C:\Users\Utilizador\Desktop\shutdown.lnk
2012-07-29 16:25 - 2012-07-29 16:25 - 10299264 ____A (Microsoft Corporation) C:\Users\Utilizador\Downloads\mseinstall.exe
2012-07-29 15:44 - 2012-07-29 15:45 - 25175732 ____A C:\Users\Utilizador\Desktop\Crimson_Tide_v2-2-12798-2-2.rar
2012-07-29 14:36 - 2012-07-29 14:36 - 00000878 ____A C:\Windows\PFRO.log
2012-07-29 14:32 - 2012-07-29 14:32 - 00000137 ____A C:\Users\Utilizador\Desktop\XuanLong.txt
2012-07-29 14:10 - 2012-07-29 14:10 - 00001027 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-29 14:09 - 2012-07-29 14:10 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Utilizador\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-29 13:42 - 2012-07-29 13:59 - 00000000 ____D C:\Users\All Users\C2116798A819B937A14FF0154F147CE7
2012-07-29 10:25 - 2012-07-31 14:18 - 00001232 ____A C:\Windows\setupact.log
2012-07-29 10:25 - 2012-07-29 10:25 - 00000000 ____A C:\Windows\setuperr.log
2012-07-26 16:51 - 2012-07-26 16:52 - 00000212 ____A C:\Users\Utilizador\Desktop\aseverdgv.txt
2012-07-24 12:52 - 2012-07-24 12:52 - 00039435 ____A C:\Users\Utilizador\Desktop\TK_Dodge-20923-0-3.7z
2012-07-22 19:11 - 2012-07-22 19:11 - 00000145 ____A C:\Users\Utilizador\Documents\TMFOREVERACCOUNT.txt
2012-07-22 19:08 - 2012-07-22 19:18 - 00000000 ____D C:\Users\All Users\TmForever
2012-07-22 15:03 - 2012-07-22 15:22 - 530600781 ____A C:\Users\Utilizador\Downloads\tmnationsforever_setup.exe
2012-07-20 20:00 - 2012-07-20 20:00 - 00000000 ____D C:\Users\Utilizador\Documents\WB Games
2012-07-20 07:39 - 2012-07-20 07:39 - 00007878 ____A C:\Users\Utilizador\Desktop\ReciboPedido.aspx.htm
2012-07-20 07:39 - 2012-07-20 07:39 - 00000000 ____D C:\Users\Utilizador\Desktop\ReciboPedido.aspx_ficheiros
2012-07-18 06:34 - 2012-07-18 06:35 - 00000000 ____D C:\Users\Utilizador\Documents\Ficheiros do Outlook
2012-07-18 04:36 - 2012-07-22 15:03 - 00000000 ____D C:\Program Files\JDownloader
2012-07-18 04:35 - 2012-07-18 04:35 - 00081488 ____A (AppWork UG (haftungsbeschränkt)) C:\Users\Utilizador\Downloads\JDwonloader.exe
2012-07-18 04:31 - 2012-07-18 04:35 - 00000000 ____D C:\Program Files\RapidShare Downloader
2012-07-16 19:21 - 2012-07-16 19:21 - 00000000 ____D C:\Users\Utilizador\Desktop\[Nipponsei] Yuru Yuri 2 ED Single - 100% Chuugakusei [Nanamorichu Goraku Bu]
2012-07-16 19:19 - 2012-07-16 19:19 - 00000000 ____D C:\Users\Utilizador\Desktop\[Nipponsei] Yuru Yuri 2 OP Single - Yes! Yuyuyu Yuru Yuri [Nanamorichu Goraku Bu]
2012-07-10 16:22 - 2012-07-29 14:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-07-10 16:22 - 2012-07-10 16:22 - 00000000 ____D C:\Users\Utilizador\AppData\Roaming\Malwarebytes
2012-07-10 16:22 - 2012-07-10 16:22 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-10 16:22 - 2012-07-03 04:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-08 15:08 - 2012-07-08 15:08 - 00000000 ____D C:\Users\Public\Documents\Explorer Suite Signatures
2012-07-08 15:08 - 2012-07-08 15:08 - 00000000 ____D C:\Program Files\NTCore
2012-07-08 12:02 - 2012-07-08 12:02 - 00000000 ____D C:\Users\Utilizador\AppData\Roaming\ts3overlay
2012-07-08 12:00 - 2012-07-08 12:14 - 00000000 ____D C:\Users\Utilizador\AppData\Roaming\TS3Client
============ 3 Months Modified Files ========================
2012-07-31 14:18 - 2012-07-29 10:25 - 00001232 ____A C:\Windows\setupact.log
2012-07-31 14:18 - 2011-12-28 10:18 - 00001004 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-31 14:18 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-30 13:16 - 2011-12-28 12:06 - 01547024 ____A C:\Windows\WindowsUpdate.log
2012-07-30 09:17 - 2012-07-30 09:17 - 00000021 ____A C:\Users\Utilizador\AppData\Roaming\mbam.context.scan
2012-07-30 08:49 - 2012-07-30 08:48 - 00000928 ____A C:\Users\Utilizador\Desktop\shutdown -a.lnk
2012-07-30 08:38 - 2012-07-30 08:38 - 00000528 ____A C:\Users\Utilizador\Desktop\shutdown.lnk
2012-07-30 08:29 - 2011-12-28 06:30 - 00002243 ____A C:\Windows\epplauncher.mif
2012-07-29 16:57 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-29 16:35 - 2011-12-28 10:18 - 00001008 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-29 16:26 - 2011-12-28 06:03 - 01666040 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-29 16:26 - 2009-07-14 00:31 - 00720682 ____A C:\Windows\System32\prfh0816.dat
2012-07-29 16:26 - 2009-07-14 00:31 - 00152564 ____A C:\Windows\System32\prfc0816.dat
2012-07-29 16:25 - 2012-07-29 16:25 - 10299264 ____A (Microsoft Corporation) C:\Users\Utilizador\Downloads\mseinstall.exe
2012-07-29 15:45 - 2012-07-29 15:44 - 25175732 ____A C:\Users\Utilizador\Desktop\Crimson_Tide_v2-2-12798-2-2.rar
2012-07-29 15:30 - 2012-02-28 21:44 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-29 14:43 - 2009-07-13 20:34 - 00018928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 14:43 - 2009-07-13 20:34 - 00018928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 14:36 - 2012-07-29 14:36 - 00000878 ____A C:\Windows\PFRO.log
2012-07-29 14:32 - 2012-07-29 14:32 - 00000137 ____A C:\Users\Utilizador\Desktop\XuanLong.txt
2012-07-29 14:10 - 2012-07-29 14:10 - 00001027 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-29 14:10 - 2012-07-29 14:09 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Utilizador\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-29 13:42 - 2012-02-28 21:44 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-29 13:42 - 2012-02-28 21:44 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-29 10:25 - 2012-07-29 10:25 - 00000000 ____A C:\Windows\setuperr.log
2012-07-28 20:03 - 2012-01-02 12:11 - 00108032 ____A C:\Users\Utilizador\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-26 16:52 - 2012-07-26 16:51 - 00000212 ____A C:\Users\Utilizador\Desktop\aseverdgv.txt
2012-07-24 12:52 - 2012-07-24 12:52 - 00039435 ____A C:\Users\Utilizador\Desktop\TK_Dodge-20923-0-3.7z
2012-07-22 19:11 - 2012-07-22 19:11 - 00000145 ____A C:\Users\Utilizador\Documents\TMFOREVERACCOUNT.txt
2012-07-22 15:22 - 2012-07-22 15:03 - 530600781 ____A C:\Users\Utilizador\Downloads\tmnationsforever_setup.exe
2012-07-20 07:39 - 2012-07-20 07:39 - 00007878 ____A C:\Users\Utilizador\Desktop\ReciboPedido.aspx.htm
2012-07-18 16:13 - 2012-02-28 21:29 - 02849488 ____A (DownloadBoosters LLC) C:\Users\Utilizador\Documents\update133.exe
2012-07-18 04:35 - 2012-07-18 04:35 - 00081488 ____A (AppWork UG (haftungsbeschränkt)) C:\Users\Utilizador\Downloads\JDwonloader.exe
2012-07-03 04:46 - 2012-07-10 16:22 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 14:58 - 2012-03-02 19:32 - 00281288 ____A C:\Windows\System32\PnkBstrB.xtr
2012-07-02 14:58 - 2012-03-02 19:13 - 00138992 ____A C:\Windows\System32\Drivers\PnkBstrK.sys
2012-07-02 14:58 - 2012-03-02 19:12 - 00281288 ____A C:\Windows\System32\PnkBstrB.exe
2012-07-02 10:15 - 2012-03-02 19:12 - 00281288 ____A C:\Windows\System32\PnkBstrB.ex0
2012-06-23 15:36 - 2012-06-23 15:32 - 44723745 ____A C:\Users\Utilizador\Desktop\[Nipponsei] Sankarea ED Single - Above your hand [Annabel].zip
2012-06-20 07:06 - 2009-07-13 20:53 - 00032568 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-11 10:58 - 2012-06-11 10:58 - 08733696 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-06-11 10:35 - 2012-06-11 10:35 - 00058880 ____A (AMD) C:\Windows\System32\coinst_8.98.dll
2012-06-11 10:00 - 2012-06-11 10:00 - 20467712 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atioglxx.dll
2012-06-11 09:26 - 2012-06-11 09:26 - 00263840 ____A C:\Windows\System32\atiapfxx.blb
2012-06-11 09:25 - 2012-06-11 09:25 - 00163840 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-06-11 09:24 - 2011-12-28 06:25 - 00924160 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx32.dll
2012-06-11 09:20 - 2012-06-11 09:20 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-06-11 09:19 - 2012-06-11 09:19 - 00468992 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-06-11 09:19 - 2012-06-11 09:19 - 00217600 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-06-11 09:17 - 2012-06-11 09:17 - 00163840 ____A (AMD) C:\Windows\System32\atitmmxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\System32\ati2edxx.dll
2012-06-11 09:17 - 2012-06-11 09:17 - 00020992 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-06-11 09:16 - 2011-12-28 06:25 - 06301696 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx32.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt.dll
2012-06-11 08:45 - 2012-06-11 08:45 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl.dll
2012-06-11 08:45 - 2012-03-08 20:23 - 05480448 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumdag.dll
2012-06-11 08:43 - 2012-03-08 20:23 - 04729344 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumdva.dll
2012-06-11 08:41 - 2012-06-11 08:41 - 02971136 ____A C:\Windows\System32\atiumdva.cap
2012-06-11 08:40 - 2012-06-11 08:40 - 13277696 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00368640 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atigktxx.dll
2012-06-11 08:26 - 2012-06-11 08:26 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-06-11 08:25 - 2012-06-11 08:25 - 00295936 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-06-11 08:25 - 2011-12-28 06:25 - 00042496 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxpag.dll
2012-06-11 08:24 - 2012-06-11 08:24 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-06-11 08:24 - 2012-03-08 19:56 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9pag.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc32.dll
2012-06-11 08:23 - 2012-06-11 08:23 - 00056832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom32.dll
2012-06-11 04:50 - 2012-06-11 04:50 - 00159232 ____A C:\Windows\System32\clinfo.exe
2012-06-11 04:50 - 2012-06-11 04:50 - 00065024 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo.dll
2012-06-11 04:50 - 2012-06-11 04:50 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode.dll
2012-06-11 04:49 - 2012-06-11 04:49 - 13008896 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl.dll
2012-06-08 06:34 - 2012-06-08 06:34 - 00000066 ____A C:\Windows\wininit.ini
2012-06-07 12:03 - 2009-07-13 20:33 - 03771072 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-07 05:51 - 2012-06-07 05:51 - 03970928 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-06-07 05:51 - 2012-06-07 05:51 - 03915632 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-07 05:51 - 2012-06-07 05:51 - 02351104 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-07 05:51 - 2012-06-07 05:51 - 00056688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-06-07 05:50 - 2012-06-07 05:50 - 01303408 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-06-07 05:50 - 2012-06-07 05:50 - 00187248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-06-07 05:45 - 2012-06-07 05:45 - 01170944 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2012-06-07 05:45 - 2012-06-07 05:45 - 01077248 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-06-07 05:45 - 2012-06-07 05:45 - 00739840 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2012-06-07 05:45 - 2012-06-07 05:45 - 00218624 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll
2012-06-07 05:45 - 2012-06-07 05:45 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll
2012-06-07 05:18 - 2012-06-07 05:18 - 52211712 ____A C:\Windows\System32\config\SOFTWARE.iobit
2012-06-07 05:18 - 2012-06-07 05:18 - 19406848 ____A C:\Windows\System32\config\SYSTEM.iobit
2012-06-07 05:18 - 2012-06-07 05:18 - 00204800 ____A C:\Windows\System32\config\DEFAULT.iobit
2012-06-07 05:18 - 2012-06-07 05:18 - 00061440 ____A C:\Windows\System32\config\SAM.iobit
2012-06-07 05:18 - 2012-06-07 05:18 - 00028672 ____A C:\Windows\System32\config\SECURITY.iobit
2012-05-27 15:44 - 2012-05-27 15:07 - 167483972 ____A C:\Users\Utilizador\Desktop\BadAppleScreensaver.rar
2012-05-21 17:06 - 2012-05-21 05:33 - 68234668 ____A C:\Users\Utilizador\Desktop\[Nipponsei] Fate Zero OP Single - oath sign [LiSA].zip
2012-05-21 05:57 - 2012-05-21 05:33 - 42869575 ____A C:\Users\Utilizador\Desktop\[Nipponsei] Fate Zero ED Single - MEMORIA [Aoi Eir].zip
2012-05-16 17:18 - 2012-05-16 17:15 - 56812674 ____A C:\Users\Utilizador\Desktop\[Nipponsei] Acchi Kocchi OP Single - Acchi de Kocchi de [Various].zip
2012-05-16 17:18 - 2012-05-16 17:15 - 55020341 ____A C:\Users\Utilizador\Desktop\[Nipponsei] Acchi Kocchi ED Single - Te wo Gyu bleepe ne [Ookubo Rumi].zip
2012-05-13 15:25 - 2012-05-13 15:38 - 00132880 ____A (Microsoft Corporation) C:\Windows\MSINET.OCX
2012-05-10 13:33 - 2012-03-02 19:13 - 00138904 ____A C:\Users\Utilizador\AppData\Roaming\PnkBstrK.sys
2012-05-10 13:33 - 2012-03-02 19:12 - 00076888 ____A C:\Windows\System32\PnkBstrA.exe
2012-05-08 15:53 - 2012-05-08 15:49 - 115678040 ____A (Advanced Micro Devices, Inc.) C:\Users\Utilizador\Downloads\12-4_vista_win7_32_dd_ccc.exe
ZeroAccess:
C:\Windows\Installer\{15260e81-448c-073d-39f1-09ffa7872a77}
C:\Windows\Installer\{15260e81-448c-073d-39f1-09ffa7872a77}\@
C:\Windows\Installer\{15260e81-448c-073d-39f1-09ffa7872a77}\L
C:\Windows\Installer\{15260e81-448c-073d-39f1-09ffa7872a77}\n
C:\Windows\Installer\{15260e81-448c-073d-39f1-09ffa7872a77}\U
C:\Windows\Installer\{15260e81-448c-073d-39f1-09ffa7872a77}\U\00000001.@
ZeroAccess:
C:\Users\Utilizador\AppData\Local\{15260e81-448c-073d-39f1-09ffa7872a77}
C:\Users\Utilizador\AppData\Local\{15260e81-448c-073d-39f1-09ffa7872a77}\@
C:\Users\Utilizador\AppData\Local\{15260e81-448c-073d-39f1-09ffa7872a77}\L
C:\Users\Utilizador\AppData\Local\{15260e81-448c-073d-39f1-09ffa7872a77}\n
C:\Users\Utilizador\AppData\Local\{15260e81-448c-073d-39f1-09ffa7872a77}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe
[2012-02-22 09:09] - [2011-02-25 21:51] - 2614784 ____A (Microsoft Corporation) 255CF508D7CFB10E0794D6AC93280BD8
C:\Windows\System32\winlogon.exe
[2010-07-07 09:50] - [2010-07-07 09:50] - 0285696 ____A (Microsoft Corporation)
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-07-29 16:57] - 0259072 ____A (Microsoft Corporation)
C:\Windows\System32\User32.dll
[2010-07-07 10:00] - [2010-07-07 10:00] - 0811520 ____A (Microsoft Corporation) A59E558BEA7D9607E86E8BDE68E2488F
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2010-07-07 10:18] - [2010-07-07 10:18] - 0245128 ____A (Microsoft Corporation) F09688701E36722B4C1560456F481285
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 4093.31 MB
Available physical RAM: 3597.04 MB
Total Pagefile: 3843.26 MB
Available Pagefile: 3671.64 MB
Total Virtual: 2047.88 MB
Available Virtual: 1990.35 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:465.76 GB) (Free:51.24 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (2007.11.03_2329) (CDROM) (Total:0.12 GB) (Free:0 GB) UDF
3 Drive e: (LEANDRO_PEN) (Removable) (Total:0.24 GB) (Free:0.24 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 466 GB 1017 KB
Disk 1 Online 244 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 466 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 C NTFS Partition 466 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 243 MB 2048 B
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E LEANDRO_PEN FAT Removable 243 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 06:03
======================= End Of Log ==========================