2012-11-15 09:55 - 2012-11-15 09:55 - 00454960 ____A C:\Windows\Minidump\111512-17066-01.dmp
2012-11-14 15:00 - 2012-11-14 15:00 - 00454960 ____A C:\Windows\Minidump\111412-16738-01.dmp
2012-11-13 20:06 - 2012-11-13 20:06 - 00454960 ____A C:\Windows\Minidump\111312-15366-01.dmp
2012-11-13 01:14 - 2012-11-19 06:19 - 00000424 ____A C:\Windows\Tasks\RegCure Pro.job
2012-11-13 01:14 - 2012-11-13 01:14 - 00000000 ____D C:\Program Files (x86)\ParetoLogic
2012-11-13 01:13 - 2012-11-13 01:13 - 00454960 ____A C:\Windows\Minidump\111312-15646-01.dmp
2012-11-12 06:19 - 2012-11-12 06:20 - 00454960 ____A C:\Windows\Minidump\111212-16021-01.dmp
2012-11-10 22:37 - 2012-11-10 22:37 - 00454960 ____A C:\Windows\Minidump\111112-15678-01.dmp
2012-11-10 16:49 - 2012-11-10 16:49 - 00454960 ____A C:\Windows\Minidump\111012-18501-01.dmp
2012-11-10 09:39 - 2012-11-10 09:39 - 00454960 ____A C:\Windows\Minidump\111012-21247-01.dmp
==================== One Month Modified Files and Folders =======
2012-12-10 09:33 - 2012-12-10 09:33 - 00000000 ____D C:\FRST
2012-12-10 07:17 - 2012-09-04 05:20 - 00011492 ____A C:\Windows\setupact.log
2012-12-09 19:03 - 2011-04-26 10:02 - 00001536 ____A C:\Users\All Users\hpqp.ini
2012-12-09 19:00 - 2012-12-08 20:57 - 00000338 ____A C:\Windows\Tasks\GlaryInitialize.job
2012-12-09 19:00 - 2012-08-22 03:45 - 00000508 ____A C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2012-12-09 19:00 - 2011-05-29 09:05 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-12-09 18:59 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-09 18:12 - 2012-12-09 18:12 - 00000000 ____D C:\Users\Chuck Laptop\Desktop\Loggers
2012-12-09 17:17 - 2012-12-09 18:18 - 00545819 ____A C:\Users\Chuck Laptop\Desktop\adwcleaner.exe
2012-12-09 13:44 - 2012-09-04 05:23 - 01389689 ____A C:\Windows\WindowsUpdate.log
2012-12-09 13:22 - 2011-05-29 09:05 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-12-09 12:49 - 2012-06-17 18:57 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-12-09 12:45 - 2009-07-13 20:45 - 00023248 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-12-09 12:45 - 2009-07-13 20:45 - 00023248 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-12-09 03:46 - 2012-12-09 03:46 - 00000000 ____D C:\Program Files\Defraggler
2012-12-08 21:20 - 2009-07-13 21:13 - 00733832 ____A C:\Windows\System32\PerfStringBackup.INI
2012-12-08 21:12 - 2011-04-26 08:37 - 00000000 ____D C:\users\Chuck Laptop
2012-12-08 21:12 - 2009-07-13 18:34 - 90963968 ____A C:\Windows\System32\config\SOFTWARE.gbck
2012-12-08 21:12 - 2009-07-13 18:34 - 14417920 ____A C:\Windows\System32\config\SYSTEM.gbck
2012-12-08 21:12 - 2009-07-13 18:34 - 05767168 ____A C:\Windows\System32\config\DEFAULT.gbck
2012-12-08 21:12 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SECURITY.gbck
2012-12-08 21:12 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SAM.gbck
2012-12-08 21:02 - 2012-12-08 20:57 - 00000000 ____D C:\Users\Chuck Laptop\AppData\Roaming\GlarySoft
2012-12-08 20:57 - 2012-12-08 20:57 - 00000000 ____D C:\Program Files (x86)\Glary Utilities
2012-12-08 20:08 - 2012-12-08 20:08 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-12-08 20:07 - 2012-12-08 20:07 - 00000000 ____D C:\Users\All Users\AVAST Software
2012-12-08 20:07 - 2012-12-08 20:07 - 00000000 ____D C:\Program Files\AVAST Software
2012-12-06 15:23 - 2012-12-09 18:34 - 00696379 ____A (Farbar) C:\Users\Chuck Laptop\Desktop\FSS.exe
2012-11-21 19:12 - 2012-11-21 19:12 - 00454960 ____A C:\Windows\Minidump\112112-17846-01.dmp
2012-11-21 19:12 - 2012-09-06 17:31 - 439602414 ____A C:\Windows\MEMORY.DMP
2012-11-21 19:12 - 2012-04-02 13:02 - 00000000 ____D C:\Windows\Minidump
2012-11-21 19:12 - 2009-07-13 21:08 - 00032656 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-11-21 18:38 - 2012-09-05 17:31 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-11-21 18:36 - 2012-09-04 00:01 - 00000482 ____A C:\Windows\Tasks\ParetoLogic Registration3.job
2012-11-21 13:23 - 2012-11-21 13:22 - 00000000 ____D C:\Samsung Galaxy S3 ToolKit
2012-11-21 13:16 - 2012-11-21 13:13 - 119496104 ____A (SkipSoft, markskippen@gmail.com) C:\Users\Chuck Laptop\Downloads\SGS3_International_ToolKit_v6.0.exe
2012-11-19 08:08 - 2011-04-29 09:28 - 66395536 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-11-19 06:19 - 2012-11-13 01:14 - 00000424 ____A C:\Windows\Tasks\RegCure Pro.job
2012-11-18 21:24 - 2012-11-18 21:24 - 00454960 ____A C:\Windows\Minidump\111812-27362-01.dmp
2012-11-18 19:41 - 2012-11-18 19:40 - 00454960 ____A C:\Windows\Minidump\111812-26130-01.dmp
2012-11-18 14:31 - 2012-11-18 14:31 - 00454960 ____A C:\Windows\Minidump\111812-18033-01.dmp
2012-11-17 19:28 - 2012-11-17 19:28 - 00454960 ____A C:\Windows\Minidump\111712-17940-01.dmp
2012-11-17 19:11 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-11-17 00:34 - 2012-11-17 00:34 - 00454960 ____A C:\Windows\Minidump\111712-17908-01.dmp
2012-11-16 05:40 - 2009-07-13 20:45 - 00440792 ____A C:\Windows\System32\FNTCACHE.DAT
2012-11-16 05:39 - 2012-09-04 05:20 - 00032092 ____A C:\Windows\PFRO.log
2012-11-16 05:21 - 2011-04-26 10:47 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-11-16 05:00 - 2011-04-26 08:44 - 00119768 ____A C:\Users\Chuck Laptop\AppData\Local\GDIPFONTCACHEV1.DAT
2012-11-16 04:59 - 2012-11-16 04:59 - 00454960 ____A C:\Windows\Minidump\111612-43664-01.dmp
2012-11-16 04:46 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-11-15 09:55 - 2012-11-15 09:55 - 00454960 ____A C:\Windows\Minidump\111512-17066-01.dmp
2012-11-15 09:55 - 2011-05-12 06:06 - 00000360 ____A C:\Windows\Tasks\HPCeeScheduleForChuck Laptop.job
2012-11-14 15:00 - 2012-11-14 15:00 - 00454960 ____A C:\Windows\Minidump\111412-16738-01.dmp
2012-11-13 20:06 - 2012-11-13 20:06 - 00454960 ____A C:\Windows\Minidump\111312-15366-01.dmp
2012-11-13 01:14 - 2012-11-13 01:14 - 00000000 ____D C:\Program Files (x86)\ParetoLogic
2012-11-13 01:13 - 2012-11-13 01:13 - 00454960 ____A C:\Windows\Minidump\111312-15646-01.dmp
2012-11-12 06:20 - 2012-11-12 06:19 - 00454960 ____A C:\Windows\Minidump\111212-16021-01.dmp
2012-11-10 22:37 - 2012-11-10 22:37 - 00454960 ____A C:\Windows\Minidump\111112-15678-01.dmp
2012-11-10 16:49 - 2012-11-10 16:49 - 00454960 ____A C:\Windows\Minidump\111012-18501-01.dmp
2012-11-10 09:39 - 2012-11-10 09:39 - 00454960 ____A C:\Windows\Minidump\111012-21247-01.dmp
ZeroAccess:
c:\Windows\System32\consrv.dll
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM.….exe: exefile => OK
HKLM.…\exefile\DefaultIcon: %1 => OK
HKLM.…\exefile\open\command: “%1” %* => OK
==================== Restore Points =========================
Restore point made on: 2012-12-09 07:46:03
==================== Memory info ===========================
Percentage of memory in use: 20%
Total physical RAM: 2812.2 MB
Available physical RAM: 2234.34 MB
Total Pagefile: 2810.35 MB
Available Pagefile: 2244.68 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:219.44 GB) (Free:55.76 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:13.15 GB) (Free:2.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
4 Drive g: (kwqc_20120831_6p) (CDROM) (Total:0.4 GB) (Free:0 GB) CDFS
5 Drive h: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
6 Drive i: () (Removable) (Total:7.48 GB) (Free:7.24 GB) NTFS
7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
8 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
Disk 0 Online 232 GB 0 B
Disk 1 Online 7657 MB 0 B
Partitions of Disk 0:
Partition ### Type Size Offset
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 219 GB 200 MB
Partition 3 Primary 13 GB 219 GB
Partition 4 Primary 103 MB 232 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
- Volume 2 Y SYSTEM NTFS Partition 199 MB Healthy