[2012/10/10 13:32:07 | 000,000,104 | ---- | C] () – C:\Windows\System32\SBRC.dat
[2012/10/10 11:13:45 | 000,001,828 | ---- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012/10/09 10:09:37 | 000,001,069 | ---- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/08 15:13:59 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2012/10/08 15:13:59 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2012/10/08 13:59:20 | 000,000,098 | ---- | C] () – C:\user.js
[2012/10/08 13:54:35 | 022,617,148 | ---- | C] () – C:\Users\M1\Desktop\vlc-2.0.3-win32.exe
[2012/10/08 11:30:27 | 000,001,081 | ---- | C] () – C:\Users\Public\Desktop\SDP Downloader.lnk
[2012/10/08 11:15:23 | 000,001,035 | ---- | C] () – C:\Users\M1\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2012/10/08 11:15:23 | 000,001,011 | ---- | C] () – C:\Users\M1\Desktop\Orbit.lnk
[2012/10/05 10:40:41 | 000,325,309 | ---- | C] () – C:\Users\M1\Desktop\1.MHTML
[2012/07/24 12:24:25 | 000,007,622 | ---- | C] () – C:\Users\M1\AppData\Local\Resmon.ResmonCfg
[2011/07/26 17:26:46 | 000,974,848 | ---- | C] () – C:\Windows\System32\cis-2.4.dll
[2011/07/26 17:26:46 | 000,081,920 | ---- | C] () – C:\Windows\System32\issacapi_bs-2.3.dll
[2011/07/26 17:26:46 | 000,065,536 | ---- | C] () – C:\Windows\System32\issacapi_pe-2.3.dll
[2011/07/26 17:26:46 | 000,057,344 | ---- | C] () – C:\Windows\System32\issacapi_se-2.3.dll
[2011/07/22 09:52:07 | 000,002,249 | ---- | C] () – C:\Windows\ricdb.ini
[2011/07/21 14:20:23 | 000,004,916 | RHS- | C] () – C:\Users\M1\ntuser.pol
[2011/07/15 18:45:39 | 000,000,687 | ---- | C] () – C:\Windows\saplogon.ini
[2011/07/15 18:07:21 | 000,051,200 | ---- | C] () – C:\Windows\System32\h5tool32.dll
[2011/07/15 18:07:20 | 000,175,616 | ---- | C] () – C:\Windows\System32\h5menu32.dll
[2011/07/15 18:07:20 | 000,095,744 | ---- | C] () – C:\Windows\System32\h5rtf32.dll
[2011/07/15 18:07:17 | 001,064,960 | ---- | C] () – C:\Windows\System32\h5krnl32.dll
[2011/07/15 18:07:16 | 000,188,928 | ---- | C] () – C:\Windows\System32\h5icon32.dll
[2011/07/15 18:06:11 | 000,015,872 | ---- | C] () – C:\Windows\System32\vtssm32.dll
[2011/07/15 17:45:17 | 000,016,101 | ---- | C] () – C:\Windows\cfgall.ini
[2011/07/15 17:33:10 | 000,311,296 | ---- | C] () – C:\Windows\System32\siecaces.dll
[2011/07/15 17:33:10 | 000,184,320 | ---- | C] () – C:\Windows\System32\gmp4_2_1.dll
[2011/07/15 17:33:10 | 000,028,672 | ---- | C] () – C:\Windows\System32\siecacsp.dll
[2011/07/15 16:56:44 | 000,004,764 | ---- | C] () – C:\Windows\System32\CcmFramework.ini
[2011/07/15 16:55:40 | 000,000,405 | ---- | C] () – C:\Windows\SMSCFG.INI
[2011/07/12 15:10:23 | 000,005,849 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/07/12 09:48:35 | 000,524,288 | ---- | C] () – C:\Windows\System32\xvidcore.dll
[2011/07/12 09:48:35 | 000,139,264 | ---- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/02/09 18:25:58 | 000,870,544 | ---- | C] () – C:\Windows\System32\igkrng575.bin
[2011/02/09 18:25:58 | 000,208,896 | ---- | C] () – C:\Windows\System32\iglhsip32.dll
[2011/02/09 18:25:58 | 000,143,360 | ---- | C] () – C:\Windows\System32\iglhcp32.dll
[2011/02/09 18:25:56 | 000,127,896 | ---- | C] () – C:\Windows\System32\igcompkrng575.bin
[2011/02/09 18:25:56 | 000,050,036 | ---- | C] () – C:\Windows\System32\igfcg575m.bin
[2011/02/09 18:25:56 | 000,004,096 | ---- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2011/02/09 18:25:55 | 000,000,151 | ---- | C] () – C:\Windows\System32\GfxUI.exe.config
[2010/11/20 23:29:34 | 000,080,896 | ---- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/20 23:29:26 | 000,066,048 | ---- | C] () – C:\Windows\System32\PrintBrmUi.exe
========== ZeroAccess Check ==========
[2009/07/14 06:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
“” = %SystemRoot%\system32\shell32.dll – [2012/06/09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
“ThreadingModel” = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
“” = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
“ThreadingModel” = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
“” = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
“ThreadingModel” = Both
========== Custom Scans ==========
========== Base Services ==========
SRV - [2009/07/14 03:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\aelupsvc.dll – (AeLookupSvc)
SRV - [2010/11/20 23:29:19 | 000,047,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\appinfo.dll – (Appinfo)
SRV - [2009/07/14 03:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\alg.exe – (ALG)
SRV - [2010/11/20 23:29:08 | 000,585,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\qmgr.dll – (BITS)
SRV - [2010/11/20 23:29:12 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\BFE.DLL – (BFE)
SRV - [2011/11/17 07:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\lsass.exe – (KeyIso)
SRV - [2009/07/14 03:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\es.dll – (EventSystem)
SRV - [2012/07/04 23:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\browser.dll – (Browser)
SRV - [2012/04/24 06:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\cryptsvc.dll – (CryptSvc)
SRV - [2010/11/20 23:29:12 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\rpcss.dll – (DcomLaunch)
SRV - [2010/11/20 23:29:12 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\dhcpcore.dll – (Dhcp)
SRV - [2011/03/03 07:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\dnsrslvr.dll – (Dnscache)
SRV - [2009/07/14 03:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\eapsvc.dll – (EapHost)
SRV - [2009/07/14 03:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\hidserv.dll – (hidserv)
SRV - [2009/07/14 03:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\ipnathlp.dll – (SharedAccess)
SRV - [2010/11/20 23:29:07 | 000,350,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\IPSECSVC.DLL – (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/07/14 03:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\swprv.dll – (swprv)
SRV - [2009/07/14 03:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\mmcss.dll – (MMCSS)
SRV - [2009/07/14 03:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\netman.dll – (Netman)
SRV - [2009/07/14 03:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\netprofm.dll – (netprofm)
SRV - [2010/11/20 23:29:11 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\nlasvc.dll – (NlaSvc)
SRV - [2009/07/14 03:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\nsisvc.dll – (nsi)
SRV - [2011/05/24 12:44:59 | 000,293,376 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\umpnpmgr.dll – (PlugPlay)
SRV - [2012/02/11 07:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\spoolsv.exe – (Spooler)
SRV - [2011/11/17 07:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\lsass.exe – (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009/07/14 03:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\rasauto.dll – (RasAuto)
SRV - [2010/11/20 23:29:24 | 000,286,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\rasmans.dll – (RasMan)
SRV - [2010/11/20 23:29:12 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\rpcss.dll – (RpcSs)
SRV - [2009/07/14 03:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\seclogon.dll – (seclogon)