New
#31
VistaKing: Farbar is now running scan...
will post results.
VistaKing: Farbar is now running scan...
will post results.
Sweet ! Upload the FRST.txt and Addition.txt file on your next reply . The files should be located inside the Flash drive
it said the text exceeds the character limit of a post by 3686 characters.!lol. Any suggestions?
and the Addition.txt file did not generate.
figured out a way half now half later:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-06-2013
Ran by SYSTEM on 08-06-2013 20:30:39
Running from F:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 [x]
HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [x]
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [x]
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [x]
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [x]
HKLM\...\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Winlogon: [Shell] explorer.exe [x ] ()
HKU\fedaru\...\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe /minimized [34929728 2013-05-01] (ooVoo LLC)
Lsa: [Authentication Packages]
Lsa: [Notification Packages]
Startup: C:\Users\fedaru\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
ShortcutTarget: MagicDisc.lnk -> C:\Program Files (x86)\MagicDisc\MagicDisc.exe (No File)
==================== Services (Whitelisted) =================
S3 clr_optimization_v2.0.50727_32; %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [x]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [x]
==================== Drivers (Whitelisted) ====================
S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2013-04-24] ( )
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-08 20:22 - 2013-06-08 20:22 - 00000000 ____D C:\FRST
2013-06-08 07:44 - 2013-06-08 07:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware-it
2013-06-08 07:44 - 2013-06-08 07:44 - 00001134 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-06-08 07:44 - 2013-04-04 10:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-07 04:49 - 2013-06-07 04:49 - 00003288 ____N C:\bootsqm.dat
2013-06-07 04:21 - 2013-06-07 04:21 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-06-02 17:10 - 2013-06-02 17:10 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Malwarebytes
2013-06-02 17:09 - 2013-06-07 16:01 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-02 17:09 - 2013-06-02 17:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-02 13:53 - 2013-06-02 13:53 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\GFI Software
2013-06-02 13:49 - 2013-06-02 13:52 - 00000000 ____D C:\ProgramData\GFI Software
2013-06-02 13:49 - 2013-06-02 13:49 - 00000000 ____D C:\Program Files (x86)\GFI Software
2013-06-02 13:47 - 2013-06-02 13:47 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-05-31 05:44 - 2013-05-31 05:44 - 00000000 ____D C:\Users\fedaru\AppData\LocalGoogle
2013-05-29 07:25 - 2013-05-29 07:25 - 00000190 ____A C:\Users\fedaru\Downloads\acad.err
2013-05-29 07:06 - 2013-05-29 07:06 - 00419360 ____A C:\Users\fedaru\Downloads\510-12 S.52ND ST.dwg
2013-05-29 07:05 - 2013-05-29 07:05 - 00376447 ____A C:\Users\fedaru\Downloads\2419 e. allegheny ave. (fixed) (1).dwg
2013-05-29 07:04 - 2013-05-29 07:04 - 00365479 ____A C:\Users\fedaru\Downloads\pharmacy(2004ver.).dwg
2013-05-29 07:03 - 2013-05-29 07:03 - 00717302 ____A C:\Users\fedaru\Downloads\2419 e. allegheny ave. (fixed).dwg
2013-05-29 07:01 - 2013-05-29 07:01 - 00473475 ____A C:\Users\fedaru\Downloads\2003 REVISION E. ALLEGHENY AVENUE (1).dwg
2013-05-28 07:19 - 2013-05-28 07:19 - 00121075 ____A C:\Users\fedaru\Downloads\AF84E9FDA6BA2805F8973488868DB60938B8E5DF.torrent
2013-05-28 07:11 - 2013-05-28 07:11 - 00015237 ____A C:\Users\fedaru\Downloads\4A7E6FDCCCF5276B03C8F35AF41A63AA3A42D61A.torrent
2013-05-28 07:10 - 2013-05-28 07:10 - 00030265 ____A C:\Users\fedaru\Downloads\23E27F6EBD448B375A6E8AAAEDA8B250E8DECADB.torrent
2013-05-28 07:09 - 2013-05-28 07:09 - 00075177 ____A C:\Users\fedaru\Downloads\125D672C83DC55DF86D1CFF2F24E445B1E4055D0.torrent
2013-05-28 06:01 - 2013-05-29 07:25 - 00000000 ____D C:\Users\fedaru\AppData\Local\cache
2013-05-28 05:43 - 2013-06-07 16:15 - 00000000 ____D C:\ProgramData\FLEXnet
2013-05-28 05:35 - 2013-05-28 05:35 - 00000153 ____A C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2013-05-28 05:35 - 2013-05-28 05:35 - 00000000 ____D C:\Users\fedaru\Documents\Inventor Server SDK ACAD 2013
2013-05-28 05:34 - 2013-06-07 15:53 - 00000000 ____D C:\Users\fedaru\AppData\Local\Autodesk
2013-05-28 05:34 - 2013-05-28 05:34 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-05-28 05:29 - 2013-06-07 16:15 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-05-28 05:29 - 2013-05-28 05:37 - 00000000 ____D C:\Program Files\Autodesk
2013-05-28 05:25 - 2013-05-28 05:25 - 00000000 ____D C:\Program Files (x86)\Autodesk
2013-05-28 05:10 - 2013-06-07 15:55 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Autodesk
2013-05-28 05:10 - 2013-05-29 07:23 - 00000000 ____D C:\ProgramData\Autodesk
2013-05-28 04:58 - 2013-06-07 16:34 - 00000000 ____D C:\Users\fedaru\Desktop\New folder (2)
2013-05-28 04:56 - 2013-05-28 04:56 - 00000000 ____D C:\Users\fedaru\New folder
2013-05-22 08:54 - 2013-06-07 16:34 - 00000000 ____D C:\Users\fedaru\Desktop\New folder
2013-05-17 06:09 - 2013-05-17 06:09 - 00002259 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-05-17 06:07 - 2013-06-08 07:39 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-17 06:07 - 2013-05-20 08:12 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-16 13:31 - 2013-06-07 16:34 - 00000000 ____D C:\Users\fedaru\.android
2013-05-16 13:31 - 2013-06-07 16:31 - 00000000 ____D C:\Users\fedaru\workspace
2013-05-16 05:32 - 2013-05-16 05:32 - 00473475 ____A C:\Users\fedaru\Downloads\2003 REVISION E. ALLEGHENY AVENUE.dwg
2013-05-15 23:46 - 2013-05-15 23:47 - 00262144 ____A C:\Windows\Minidump\051613-25006-01.dmp
2013-05-14 03:11 - 2013-06-07 16:30 - 00000000 ____D C:\Users\fedaru\Desktop\kompozer
2013-05-14 03:09 - 2013-06-07 16:35 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\KompoZer
2013-05-14 03:09 - 2013-05-14 03:09 - 00001317 ____A C:\Users\Public\Desktop\HTML-Kit Tools.lnk
2013-05-14 03:09 - 2013-05-14 03:09 - 00000000 ____D C:\Program Files (x86)\HTML-Kit
2013-05-14 03:07 - 2013-05-14 03:07 - 00001307 ____A C:\Users\Public\Desktop\HTML-Kit.lnk
2013-05-14 03:07 - 2013-05-14 03:07 - 00000000 ____D C:\Program Files (x86)\Chami
2013-05-12 09:46 - 2013-05-12 09:46 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\EurekaLog
2013-05-11 13:11 - 2013-06-07 16:30 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Notepad++
2013-05-11 13:11 - 2013-05-11 13:11 - 00000000 ____D C:\Program Files (x86)\Notepad++
2013-05-11 11:22 - 2013-05-11 11:22 - 00000000 ____D C:\Users\fedaru\Documents\My ooVoo
2013-05-11 11:13 - 2013-05-11 11:13 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\ooVoo Details
2013-05-11 11:12 - 2013-05-11 11:12 - 00001857 ____A C:\Users\Public\Desktop\ooVoo.lnk
2013-05-11 11:12 - 2013-05-11 11:12 - 00000000 ____D C:\Program Files (x86)\ooVoo
2013-05-09 07:41 - 2013-05-09 07:41 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-05-09 07:41 - 2013-05-09 07:41 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-05-09 07:41 - 2013-05-09 07:41 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-05-09 07:41 - 2013-05-09 07:41 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-05-09 07:41 - 2013-05-09 07:41 - 00000000 ____D C:\Program Files\Java
2013-05-09 07:19 - 2013-06-07 16:34 - 00000000 ____D C:\Program Files (x86)\GameOfLife
2013-05-09 07:19 - 2013-05-09 07:21 - 33119648 ____A (Oracle Corporation) C:\Users\fedaru\Downloads\jre-7u21-windows-x64.exe
2013-05-09 05:08 - 2013-05-09 05:08 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Itibiti
2013-05-09 05:07 - 2013-05-09 05:07 - 00000000 ____D C:\Program Files (x86)\Itibiti Soft Phone
2013-05-09 04:56 - 2013-06-07 16:34 - 00000000 ____D C:\Program Files (x86)\PortGo Softphone
2013-05-09 04:56 - 2013-05-09 04:56 - 00001055 ____A C:\Users\Public\Desktop\PortGo Softphone.lnk
2013-05-09 04:56 - 2013-05-09 04:56 - 00000000 ____D C:\Users\fedaru\AppData\Local\PortGo
2013-05-09 04:47 - 2013-06-08 07:52 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2684324202-3900709444-3821784649-1000UA.job
2013-05-09 04:47 - 2013-05-17 04:52 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2684324202-3900709444-3821784649-1000Core.job
==================== One Month Modified Files and Folders =======
continued...
==================== One Month Modified Files and Folders =======
2013-06-08 20:22 - 2013-06-08 20:22 - 00000000 ____D C:\FRST
2013-06-08 11:17 - 2010-11-20 19:47 - 02195692 ____A C:\Windows\PFRO.log
2013-06-08 07:52 - 2013-06-08 07:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware-it
2013-06-08 07:52 - 2013-05-09 04:47 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2684324202-3900709444-3821784649-1000UA.job
2013-06-08 07:52 - 2013-04-24 08:21 - 00000000 ____D C:\Program Files (x86)\Bluetooth Suite
2013-06-08 07:51 - 2013-05-03 14:46 - 00000000 ____D C:\Program Files (x86)\Opera
2013-06-08 07:51 - 2013-04-24 13:44 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\uTorrent
2013-06-08 07:51 - 2013-04-24 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-08 07:51 - 2013-04-24 09:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-08 07:51 - 2013-04-24 08:56 - 02089983 ____A C:\Windows\WindowsUpdate.log
2013-06-08 07:51 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\com
2013-06-08 07:51 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-06-08 07:46 - 2009-07-13 20:45 - 00021840 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-08 07:46 - 2009-07-13 20:45 - 00021840 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-08 07:45 - 2009-07-13 21:13 - 00713888 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-08 07:44 - 2013-06-08 07:44 - 00001134 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-06-08 07:42 - 2013-04-24 09:13 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Mozilla
2013-06-08 07:39 - 2013-05-17 06:07 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-08 07:39 - 2013-04-24 06:20 - 00000000 ____D C:\users\fedaru
2013-06-08 07:39 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-08 07:39 - 2009-07-13 20:51 - 00008516 ____A C:\Windows\setupact.log
2013-06-07 16:35 - 2013-05-14 03:09 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\KompoZer
2013-06-07 16:35 - 2013-04-30 09:14 - 00000000 ____D C:\Users\fedaru\Desktop\Pro.Jammin
2013-06-07 16:35 - 2013-04-30 08:59 - 00000000 ____D C:\Users\fedaru\Desktop\Pentesting
2013-06-07 16:35 - 2013-04-24 13:46 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\vlc
2013-06-07 16:35 - 2013-04-24 13:00 - 00000000 ____D C:\Users\fedaru\Documents\Windows Updates Downloader
2013-06-07 16:35 - 2009-07-13 19:20 - 00000000 __RSD C:\Windows\Media
2013-06-07 16:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\L2Schemas
2013-06-07 16:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\AppCompat
2013-06-07 16:34 - 2013-05-28 04:58 - 00000000 ____D C:\Users\fedaru\Desktop\New folder (2)
2013-06-07 16:34 - 2013-05-22 08:54 - 00000000 ____D C:\Users\fedaru\Desktop\New folder
2013-06-07 16:34 - 2013-05-16 13:31 - 00000000 ____D C:\Users\fedaru\.android
2013-06-07 16:34 - 2013-05-09 07:19 - 00000000 ____D C:\Program Files (x86)\GameOfLife
2013-06-07 16:34 - 2013-05-09 04:56 - 00000000 ____D C:\Program Files (x86)\PortGo Softphone
2013-06-07 16:34 - 2013-05-03 13:10 - 00000000 ____D C:\Users\fedaru\AppData\Local\Apps\2.0
2013-06-07 16:34 - 2013-04-24 12:57 - 00000000 ____D C:\Program Files\Windows Updates Downloader
2013-06-07 16:34 - 2013-04-24 08:27 - 00000000 ____D C:\ProgramData\P4G
2013-06-07 16:34 - 2013-04-24 08:23 - 00000000 ____D C:\ProgramData\Atheros
2013-06-07 16:34 - 2013-04-24 08:13 - 00000000 ____D C:\Users\fedaru\AppData\Local\Downloaded Installations
2013-06-07 16:34 - 2009-07-13 19:20 - 00000000 ___HD C:\Windows\System32\GroupPolicy
2013-06-07 16:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-06-07 16:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-06-07 16:34 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-06-07 16:31 - 2013-05-16 13:31 - 00000000 ____D C:\Users\fedaru\workspace
2013-06-07 16:31 - 2013-04-30 10:58 - 00000000 ____D C:\Users\fedaru\Desktop\Utilities
2013-06-07 16:30 - 2013-05-14 03:11 - 00000000 ____D C:\Users\fedaru\Desktop\kompozer
2013-06-07 16:30 - 2013-05-11 13:11 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Notepad++
2013-06-07 16:30 - 2013-05-03 14:46 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Opera
2013-06-07 16:30 - 2013-04-30 08:34 - 00000000 ____D C:\Users\fedaru\Desktop\Android App Development
2013-06-07 16:30 - 2013-04-24 14:18 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Foxit Software
2013-06-07 16:30 - 2013-04-24 11:06 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Macromedia
2013-06-07 16:29 - 2013-05-03 14:46 - 00000000 ____D C:\Users\fedaru\AppData\Local\Opera
2013-06-07 16:29 - 2013-04-24 09:13 - 00000000 ____D C:\Users\fedaru\AppData\Local\Mozilla
2013-06-07 16:28 - 2013-05-03 13:01 - 00000000 ____D C:\Users\fedaru\AppData\Local\Google
2013-06-07 16:28 - 2013-04-25 12:45 - 00000000 ____D C:\Users\fedaru\AppData\Local\Microsoft Games
2013-06-07 16:28 - 2013-04-24 11:27 - 00000000 ____D C:\Users\fedaru\AppData\Local\ASUS
2013-06-07 16:27 - 2013-05-03 13:01 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-07 16:27 - 2013-04-24 14:18 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-06-07 16:15 - 2013-05-28 05:43 - 00000000 ____D C:\ProgramData\FLEXnet
2013-06-07 16:15 - 2013-05-28 05:29 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2013-06-07 16:01 - 2013-06-02 17:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-07 15:55 - 2013-05-28 05:10 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Autodesk
2013-06-07 15:53 - 2013-05-28 05:34 - 00000000 ____D C:\Users\fedaru\AppData\Local\Autodesk
2013-06-07 04:49 - 2013-06-07 04:49 - 00003288 ____N C:\bootsqm.dat
2013-06-07 04:21 - 2013-06-07 04:21 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2013-06-04 16:32 - 2013-04-24 11:51 - 00000000 ____D C:\Users\fedaru\AppData\Local\CrashDumps
2013-06-02 17:10 - 2013-06-02 17:10 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Malwarebytes
2013-06-02 17:09 - 2013-06-02 17:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-02 13:53 - 2013-06-02 13:53 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\GFI Software
2013-06-02 13:52 - 2013-06-02 13:49 - 00000000 ____D C:\ProgramData\GFI Software
2013-06-02 13:49 - 2013-06-02 13:49 - 00000000 ____D C:\Program Files (x86)\GFI Software
2013-06-02 13:47 - 2013-06-02 13:47 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-05-31 05:44 - 2013-05-31 05:44 - 00000000 ____D C:\Users\fedaru\AppData\LocalGoogle
2013-05-29 07:25 - 2013-05-29 07:25 - 00000190 ____A C:\Users\fedaru\Downloads\acad.err
2013-05-29 07:25 - 2013-05-28 06:01 - 00000000 ____D C:\Users\fedaru\AppData\Local\cache
2013-05-29 07:23 - 2013-05-28 05:10 - 00000000 ____D C:\ProgramData\Autodesk
2013-05-29 07:06 - 2013-05-29 07:06 - 00419360 ____A C:\Users\fedaru\Downloads\510-12 S.52ND ST.dwg
2013-05-29 07:05 - 2013-05-29 07:05 - 00376447 ____A C:\Users\fedaru\Downloads\2419 e. allegheny ave. (fixed) (1).dwg
2013-05-29 07:04 - 2013-05-29 07:04 - 00365479 ____A C:\Users\fedaru\Downloads\pharmacy(2004ver.).dwg
2013-05-29 07:03 - 2013-05-29 07:03 - 00717302 ____A C:\Users\fedaru\Downloads\2419 e. allegheny ave. (fixed).dwg
2013-05-29 07:01 - 2013-05-29 07:01 - 00473475 ____A C:\Users\fedaru\Downloads\2003 REVISION E. ALLEGHENY AVENUE (1).dwg
2013-05-29 06:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\LiveKernelReports
2013-05-28 07:19 - 2013-05-28 07:19 - 00121075 ____A C:\Users\fedaru\Downloads\AF84E9FDA6BA2805F8973488868DB60938B8E5DF.torrent
2013-05-28 07:11 - 2013-05-28 07:11 - 00015237 ____A C:\Users\fedaru\Downloads\4A7E6FDCCCF5276B03C8F35AF41A63AA3A42D61A.torrent
2013-05-28 07:10 - 2013-05-28 07:10 - 00030265 ____A C:\Users\fedaru\Downloads\23E27F6EBD448B375A6E8AAAEDA8B250E8DECADB.torrent
2013-05-28 07:09 - 2013-05-28 07:09 - 00075177 ____A C:\Users\fedaru\Downloads\125D672C83DC55DF86D1CFF2F24E445B1E4055D0.torrent
2013-05-28 05:43 - 2013-04-24 06:54 - 00090032 ____A C:\Users\fedaru\AppData\Local\GDIPFONTCACHEV1.DAT
2013-05-28 05:37 - 2013-05-28 05:29 - 00000000 ____D C:\Program Files\Autodesk
2013-05-28 05:35 - 2013-05-28 05:35 - 00000153 ____A C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2013-05-28 05:35 - 2013-05-28 05:35 - 00000000 ____D C:\Users\fedaru\Documents\Inventor Server SDK ACAD 2013
2013-05-28 05:34 - 2013-05-28 05:34 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2013-05-28 05:25 - 2013-05-28 05:25 - 00000000 ____D C:\Program Files (x86)\Autodesk
2013-05-28 04:56 - 2013-05-28 04:56 - 00000000 ____D C:\Users\fedaru\New folder
2013-05-20 08:25 - 2013-04-24 11:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-20 08:12 - 2013-05-17 06:07 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-19 06:41 - 2009-07-13 19:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-05-17 06:09 - 2013-05-17 06:09 - 00002259 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-05-17 04:52 - 2013-05-09 04:47 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2684324202-3900709444-3821784649-1000Core.job
2013-05-16 11:14 - 2013-05-03 12:52 - 00000000 ____D C:\ProgramData\Adobe
2013-05-16 05:32 - 2013-05-16 05:32 - 00473475 ____A C:\Users\fedaru\Downloads\2003 REVISION E. ALLEGHENY AVENUE.dwg
2013-05-15 23:47 - 2013-05-15 23:46 - 00262144 ____A C:\Windows\Minidump\051613-25006-01.dmp
2013-05-15 23:46 - 2013-04-24 14:08 - 393522314 ____A C:\Windows\MEMORY.DMP
2013-05-15 23:46 - 2013-04-24 14:08 - 00000000 ____D C:\Windows\Minidump
2013-05-14 03:09 - 2013-05-14 03:09 - 00001317 ____A C:\Users\Public\Desktop\HTML-Kit Tools.lnk
2013-05-14 03:09 - 2013-05-14 03:09 - 00000000 ____D C:\Program Files (x86)\HTML-Kit
2013-05-14 03:07 - 2013-05-14 03:07 - 00001307 ____A C:\Users\Public\Desktop\HTML-Kit.lnk
2013-05-14 03:07 - 2013-05-14 03:07 - 00000000 ____D C:\Program Files (x86)\Chami
2013-05-12 09:46 - 2013-05-12 09:46 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\EurekaLog
2013-05-11 13:11 - 2013-05-11 13:11 - 00000000 ____D C:\Program Files (x86)\Notepad++
2013-05-11 11:22 - 2013-05-11 11:22 - 00000000 ____D C:\Users\fedaru\Documents\My ooVoo
2013-05-11 11:13 - 2013-05-11 11:13 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\ooVoo Details
2013-05-11 11:12 - 2013-05-11 11:12 - 00001857 ____A C:\Users\Public\Desktop\ooVoo.lnk
2013-05-11 11:12 - 2013-05-11 11:12 - 00000000 ____D C:\Program Files (x86)\ooVoo
2013-05-11 10:03 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-05-09 07:41 - 2013-05-09 07:41 - 00311200 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-05-09 07:41 - 2013-05-09 07:41 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-05-09 07:41 - 2013-05-09 07:41 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-05-09 07:41 - 2013-05-09 07:41 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-05-09 07:41 - 2013-05-09 07:41 - 00000000 ____D C:\Program Files\Java
2013-05-09 07:41 - 2013-04-30 17:39 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-05-09 07:41 - 2013-04-30 17:39 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-05-09 07:21 - 2013-05-09 07:19 - 33119648 ____A (Oracle Corporation) C:\Users\fedaru\Downloads\jre-7u21-windows-x64.exe
2013-05-09 05:08 - 2013-05-09 05:08 - 00000000 ____D C:\Users\fedaru\AppData\Roaming\Itibiti
2013-05-09 05:07 - 2013-05-09 05:07 - 00000000 ____D C:\Program Files (x86)\Itibiti Soft Phone
2013-05-09 04:56 - 2013-05-09 04:56 - 00001055 ____A C:\Users\Public\Desktop\PortGo Softphone.lnk
2013-05-09 04:56 - 2013-05-09 04:56 - 00000000 ____D C:\Users\fedaru\AppData\Local\PortGo
2013-05-09 04:56 - 2013-04-24 06:20 - 00000000 ____D C:\Users\fedaru\AppData\Local\VirtualStore
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe IS MISSING <==== ATTENTION!.
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-05-20 08:47:26
Restore point made on: 2013-05-22 09:56:26
Restore point made on: 2013-05-22 15:39:52
Restore point made on: 2013-05-28 05:16:59
Restore point made on: 2013-05-28 05:26:59
Restore point made on: 2013-06-01 02:59:24
Restore point made on: 2013-06-07 03:46:58
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 4000.13 MB
Available physical RAM: 3397.3 MB
Total Pagefile: 3998.32 MB
Available Pagefile: 3388.75 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:268.65 GB) (Free:200.09 GB) NTFS (Disk=0 Partition=1)
Drive d: (New Volume) (Fixed) (Total:29.3 GB) (Free:28.61 GB) NTFS (Disk=0 Partition=2)
Drive f: (PENDRIVE) (Removable) (Total:3.74 GB) (Free:0.63 GB) FAT32 (Disk=1 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: E1F56F1D)
Partition 1: (Active) - (Size=269 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=29 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 0191018E)
Partition 1: (Active) - (Size=4 GB) - (Type=0C)
LastRegBack: 2013-06-02 20:10
==================== End Of Log ============================
Rerun FRST
Inside the Search box type explorer.exe
Click Search button and post the log (Search.txt) it makes to your reply.
OK. Will post back with results.
Farbar Recovery Scan Tool (x64) Version: 08-06-2013
Ran by SYSTEM at 2013-06-08 21:49:58
Running from F:\
Boot Mode: Recovery
================== Search: "explorer.exe" ===================
C:\Windows\explorer.exe
[2013-04-30 11:15] - [2011-02-24 22:19] - 2871808 ____A (Microsoft Corporation) 332FEAB1435662FC6C672E25BEB37BE3
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2013-04-30 11:15] - [2011-02-25 21:19] - 2616320 ____A (Microsoft Corporation) 0FB9C74046656D1579A64660AD67B746
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2013-04-30 11:15] - [2011-02-24 21:30] - 2616320 ____N (Microsoft Corporation) 8B88EBBB05A0E56B7DCC708498C02B3E
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010-11-20 19:24] - [2010-11-20 19:24] - 2616320 ____A (Microsoft Corporation) 40D777B7A95E00593EB1568C68514493
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2013-04-30 11:15] - [2011-02-25 22:14] - 2871808 ____A (Microsoft Corporation) 3B69712041F3D63605529BD66DC00C48
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2013-04-30 11:15] - [2011-02-24 22:19] - 2871808 ____A (Microsoft Corporation) 332FEAB1435662FC6C672E25BEB37BE3
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010-11-20 19:24] - [2010-11-20 19:24] - 2872320 ____A (Microsoft Corporation) AC4C51EB24AA95B77F705AB159189E24
====== End Of Search ======
Save the attached file ( Fixlist.txt ) to the root of your Flash drive.
Run FRST64.exe once more . Once the program has launched click on the FIX button . It will then create a text file called Fixlog.txt
Upload the Fixlog.txt
Contents of Fixlist.txt
replace C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe C:\Windows\SysWOW64\explorer.exe