this is the FRST.txt:
Scan result of Farbar Recovery Scan Tool Version: 05-08-2012 03
Ran by SYSTEM at 07-08-2012 01:28:08
Running from G:\
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [4035152 2011-09-22] (ESET)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r [2792448 2011-10-06] (VIA)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKU\User\...\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [842048 2011-03-17] (DT Soft Ltd)
HKU\User\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [641400 2011-10-23] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.2.214 10.1.2.253 10.1.2.117
==================== Services (Whitelisted) ======
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [974944 2011-09-22] (ESET)
3 WatAdminSvc; C:\Windows\System32\Wat\WatAdminSvc.exe [1255736 2011-10-06] ()
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [272448 2011-10-09] (DT Soft Ltd)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-09] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-04] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [137144 2011-08-04] (ESET)
3 RTL85n64; C:\Windows\System32\Drivers\RTL85n64.sys [378368 2009-06-10] (Realtek)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [867064 2011-10-09] (Duplex Secure Ltd.)
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:25 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-08-06 20:24 - 2012-08-06 20:25 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-05 23:53 - 2012-08-06 00:07 - 00000000 ____D C:\Users\All Users\0C1CFB130009EDE70303F307F875EF60
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
============ 3 Months Modified Files ========================
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:21 - 2011-01-22 02:56 - 00742532 ____A C:\Windows\System32\perfh00A.dat
2012-08-06 22:21 - 2011-01-22 02:56 - 00156638 ____A C:\Windows\System32\perfc00A.dat
2012-08-06 22:21 - 2009-07-13 21:13 - 01669088 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-06 22:20 - 2009-07-13 20:51 - 00342817 ____A C:\Windows\setupact.log
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 21:24 - 2012-05-29 12:08 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:24 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-06 20:22 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 10:25 - 2011-10-05 09:22 - 01246669 ____A C:\Windows\WindowsUpdate.log
2012-08-05 16:49 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At10.job
2012-08-05 16:49 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At5.job
2012-08-05 16:45 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At9.job
2012-08-05 16:45 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At4.job
2012-08-05 16:41 - 2011-10-13 16:41 - 00000000 __ASH C:\Windows\skd2ic.exe
2012-08-05 16:41 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At8.job
2012-08-05 16:41 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At3.job
2012-08-05 16:37 - 2011-10-13 16:37 - 00000000 __ASH C:\Windows\pcidvc.exe
2012-08-05 16:37 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At7.job
2012-08-05 16:37 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At2.job
2012-08-05 16:33 - 2011-10-09 17:32 - 00000324 ____A C:\Windows\Tasks\At6.job
2012-08-05 16:33 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At1.job
2012-08-04 16:45 - 2011-10-13 16:45 - 00000000 __ASH C:\Windows\trci32.exe
2012-08-03 18:24 - 2012-05-29 12:08 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 18:24 - 2011-10-05 20:37 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-07 10:14 - 2012-07-07 10:14 - 00001124 ____A C:\Users\Public\Desktop\Talk Now!.lnk
2012-06-20 12:53 - 2010-11-20 19:47 - 00010518 ____A C:\Windows\PFRO.log
2012-06-04 23:12 - 2012-06-04 23:12 - 00000000 ____A C:\Users\User\Downloads\blackra1n.log
2012-06-04 23:11 - 2012-06-04 23:11 - 00608256 ____A C:\Users\User\Downloads\blackra1n.exe
2012-06-04 22:54 - 2012-06-04 22:54 - 00156160 ____A (iH8sn0w Dev team) C:\Users\User\Downloads\f0recast-1.0.2.exe
2012-06-03 22:59 - 2012-06-03 22:53 - 253340786 ____A C:\Users\User\Downloads\iPhone1,2_3.1.2_7D11_Restore.ipsw
2012-06-03 22:51 - 2012-06-03 22:51 - 04570608 ____A C:\Users\User\Downloads\Spirit.exe
2012-06-01 12:45 - 2012-06-01 12:45 - 00111792 ____A C:\Users\User\Downloads\Men.In.Black.3.2012.PROPER.TS.Xvid.New.Video.UnKnOwN.torrent
2012-06-01 12:44 - 2012-06-01 12:44 - 00049412 ____A C:\Users\User\Desktop\Gone.(2012).BluRay.1080p.x264.DTS-LTRG.torrent
2012-06-01 10:31 - 2011-10-06 01:27 - 00002519 ____A C:\Users\Public\Desktop\Skype.lnk
2012-05-31 09:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 18:10 - 2012-05-29 18:07 - 00001975 ____A C:\Users\Public\Desktop\YourFile Downloader.lnk
2012-05-29 18:09 - 2012-05-29 18:09 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a(1).exe
2012-05-29 18:07 - 2012-05-29 18:07 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a.exe
2012-05-12 16:33 - 2011-10-13 16:33 - 00000000 __ASH C:\Windows\elogic.exe
ZeroAccess:
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\00000001.@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\800000cb.@
ZeroAccess:
C:\Users\User\AppData\Local\254514f5
C:\Users\User\AppData\Local\254514f5\@
C:\Users\User\AppData\Local\254514f5\U
ZeroAccess:
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3837.09 MB
Available physical RAM: 3289.77 MB
Total Pagefile: 3835.29 MB
Available Pagefile: 3281.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.81 GB) (Free:11.32 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:232.79 GB) (Free:225.71 GB) NTFS
4 Drive f: (World Talk) (CDROM) (Total:0.38 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 232 GB 0 B
Disk 2 Online 3835 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 111 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 111 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 232 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Reservado p NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 232 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3827 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-27 23:07
======================= End Of Log ==========================
and this is the Search.txt
Scan result of Farbar Recovery Scan Tool Version: 05-08-2012 03
Ran by SYSTEM at 07-08-2012 01:28:08
Running from G:\
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [4035152 2011-09-22] (ESET)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r [2792448 2011-10-06] (VIA)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKU\User\...\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [842048 2011-03-17] (DT Soft Ltd)
HKU\User\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [641400 2011-10-23] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.2.214 10.1.2.253 10.1.2.117
==================== Services (Whitelisted) ======
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [974944 2011-09-22] (ESET)
3 WatAdminSvc; C:\Windows\System32\Wat\WatAdminSvc.exe [1255736 2011-10-06] ()
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [272448 2011-10-09] (DT Soft Ltd)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-09] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-04] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [137144 2011-08-04] (ESET)
3 RTL85n64; C:\Windows\System32\Drivers\RTL85n64.sys [378368 2009-06-10] (Realtek)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [867064 2011-10-09] (Duplex Secure Ltd.)
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:25 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-08-06 20:24 - 2012-08-06 20:25 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-05 23:53 - 2012-08-06 00:07 - 00000000 ____D C:\Users\All Users\0C1CFB130009EDE70303F307F875EF60
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
============ 3 Months Modified Files ========================
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:21 - 2011-01-22 02:56 - 00742532 ____A C:\Windows\System32\perfh00A.dat
2012-08-06 22:21 - 2011-01-22 02:56 - 00156638 ____A C:\Windows\System32\perfc00A.dat
2012-08-06 22:21 - 2009-07-13 21:13 - 01669088 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-06 22:20 - 2009-07-13 20:51 - 00342817 ____A C:\Windows\setupact.log
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 21:24 - 2012-05-29 12:08 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:24 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-06 20:22 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 10:25 - 2011-10-05 09:22 - 01246669 ____A C:\Windows\WindowsUpdate.log
2012-08-05 16:49 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At10.job
2012-08-05 16:49 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At5.job
2012-08-05 16:45 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At9.job
2012-08-05 16:45 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At4.job
2012-08-05 16:41 - 2011-10-13 16:41 - 00000000 __ASH C:\Windows\skd2ic.exe
2012-08-05 16:41 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At8.job
2012-08-05 16:41 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At3.job
2012-08-05 16:37 - 2011-10-13 16:37 - 00000000 __ASH C:\Windows\pcidvc.exe
2012-08-05 16:37 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At7.job
2012-08-05 16:37 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At2.job
2012-08-05 16:33 - 2011-10-09 17:32 - 00000324 ____A C:\Windows\Tasks\At6.job
2012-08-05 16:33 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At1.job
2012-08-04 16:45 - 2011-10-13 16:45 - 00000000 __ASH C:\Windows\trci32.exe
2012-08-03 18:24 - 2012-05-29 12:08 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 18:24 - 2011-10-05 20:37 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-07 10:14 - 2012-07-07 10:14 - 00001124 ____A C:\Users\Public\Desktop\Talk Now!.lnk
2012-06-20 12:53 - 2010-11-20 19:47 - 00010518 ____A C:\Windows\PFRO.log
2012-06-04 23:12 - 2012-06-04 23:12 - 00000000 ____A C:\Users\User\Downloads\blackra1n.log
2012-06-04 23:11 - 2012-06-04 23:11 - 00608256 ____A C:\Users\User\Downloads\blackra1n.exe
2012-06-04 22:54 - 2012-06-04 22:54 - 00156160 ____A (iH8sn0w Dev team) C:\Users\User\Downloads\f0recast-1.0.2.exe
2012-06-03 22:59 - 2012-06-03 22:53 - 253340786 ____A C:\Users\User\Downloads\iPhone1,2_3.1.2_7D11_Restore.ipsw
2012-06-03 22:51 - 2012-06-03 22:51 - 04570608 ____A C:\Users\User\Downloads\Spirit.exe
2012-06-01 12:45 - 2012-06-01 12:45 - 00111792 ____A C:\Users\User\Downloads\Men.In.Black.3.2012.PROPER.TS.Xvid.New.Video.UnKnOwN.torrent
2012-06-01 12:44 - 2012-06-01 12:44 - 00049412 ____A C:\Users\User\Desktop\Gone.(2012).BluRay.1080p.x264.DTS-LTRG.torrent
2012-06-01 10:31 - 2011-10-06 01:27 - 00002519 ____A C:\Users\Public\Desktop\Skype.lnk
2012-05-31 09:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 18:10 - 2012-05-29 18:07 - 00001975 ____A C:\Users\Public\Desktop\YourFile Downloader.lnk
2012-05-29 18:09 - 2012-05-29 18:09 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a(1).exe
2012-05-29 18:07 - 2012-05-29 18:07 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a.exe
2012-05-12 16:33 - 2011-10-13 16:33 - 00000000 __ASH C:\Windows\elogic.exe
ZeroAccess:
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\00000001.@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\800000cb.@
ZeroAccess:
C:\Users\User\AppData\Local\254514f5
C:\Users\User\AppData\Local\254514f5\@
C:\Users\User\AppData\Local\254514f5\U
ZeroAccess:
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3837.09 MB
Available physical RAM: 3289.77 MB
Total Pagefile: 3835.29 MB
Available Pagefile: 3281.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.81 GB) (Free:11.32 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:232.79 GB) (Free:225.71 GB) NTFS
4 Drive f: (World Talk) (CDROM) (Total:0.38 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 232 GB 0 B
Disk 2 Online 3835 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 111 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 111 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 232 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Reservado p NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 232 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3827 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-27 23:07
======================= End Of Log ==========================
thank you
Scan result of Farbar Recovery Scan Tool Version: 05-08-2012 03
Ran by SYSTEM at 07-08-2012 01:28:08
Running from G:\
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [4035152 2011-09-22] (ESET)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r [2792448 2011-10-06] (VIA)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKU\User\...\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [842048 2011-03-17] (DT Soft Ltd)
HKU\User\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [641400 2011-10-23] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.2.214 10.1.2.253 10.1.2.117
==================== Services (Whitelisted) ======
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [974944 2011-09-22] (ESET)
3 WatAdminSvc; C:\Windows\System32\Wat\WatAdminSvc.exe [1255736 2011-10-06] ()
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [272448 2011-10-09] (DT Soft Ltd)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-09] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-04] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [137144 2011-08-04] (ESET)
3 RTL85n64; C:\Windows\System32\Drivers\RTL85n64.sys [378368 2009-06-10] (Realtek)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [867064 2011-10-09] (Duplex Secure Ltd.)
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:25 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-08-06 20:24 - 2012-08-06 20:25 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-05 23:53 - 2012-08-06 00:07 - 00000000 ____D C:\Users\All Users\0C1CFB130009EDE70303F307F875EF60
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
============ 3 Months Modified Files ========================
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:21 - 2011-01-22 02:56 - 00742532 ____A C:\Windows\System32\perfh00A.dat
2012-08-06 22:21 - 2011-01-22 02:56 - 00156638 ____A C:\Windows\System32\perfc00A.dat
2012-08-06 22:21 - 2009-07-13 21:13 - 01669088 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-06 22:20 - 2009-07-13 20:51 - 00342817 ____A C:\Windows\setupact.log
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 21:24 - 2012-05-29 12:08 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:24 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-06 20:22 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 10:25 - 2011-10-05 09:22 - 01246669 ____A C:\Windows\WindowsUpdate.log
2012-08-05 16:49 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At10.job
2012-08-05 16:49 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At5.job
2012-08-05 16:45 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At9.job
2012-08-05 16:45 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At4.job
2012-08-05 16:41 - 2011-10-13 16:41 - 00000000 __ASH C:\Windows\skd2ic.exe
2012-08-05 16:41 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At8.job
2012-08-05 16:41 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At3.job
2012-08-05 16:37 - 2011-10-13 16:37 - 00000000 __ASH C:\Windows\pcidvc.exe
2012-08-05 16:37 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At7.job
2012-08-05 16:37 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At2.job
2012-08-05 16:33 - 2011-10-09 17:32 - 00000324 ____A C:\Windows\Tasks\At6.job
2012-08-05 16:33 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At1.job
2012-08-04 16:45 - 2011-10-13 16:45 - 00000000 __ASH C:\Windows\trci32.exe
2012-08-03 18:24 - 2012-05-29 12:08 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 18:24 - 2011-10-05 20:37 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-07 10:14 - 2012-07-07 10:14 - 00001124 ____A C:\Users\Public\Desktop\Talk Now!.lnk
2012-06-20 12:53 - 2010-11-20 19:47 - 00010518 ____A C:\Windows\PFRO.log
2012-06-04 23:12 - 2012-06-04 23:12 - 00000000 ____A C:\Users\User\Downloads\blackra1n.log
2012-06-04 23:11 - 2012-06-04 23:11 - 00608256 ____A C:\Users\User\Downloads\blackra1n.exe
2012-06-04 22:54 - 2012-06-04 22:54 - 00156160 ____A (iH8sn0w Dev team) C:\Users\User\Downloads\f0recast-1.0.2.exe
2012-06-03 22:59 - 2012-06-03 22:53 - 253340786 ____A C:\Users\User\Downloads\iPhone1,2_3.1.2_7D11_Restore.ipsw
2012-06-03 22:51 - 2012-06-03 22:51 - 04570608 ____A C:\Users\User\Downloads\Spirit.exe
2012-06-01 12:45 - 2012-06-01 12:45 - 00111792 ____A C:\Users\User\Downloads\Men.In.Black.3.2012.PROPER.TS.Xvid.New.Video.UnKnOwN.torrent
2012-06-01 12:44 - 2012-06-01 12:44 - 00049412 ____A C:\Users\User\Desktop\Gone.(2012).BluRay.1080p.x264.DTS-LTRG.torrent
2012-06-01 10:31 - 2011-10-06 01:27 - 00002519 ____A C:\Users\Public\Desktop\Skype.lnk
2012-05-31 09:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 18:10 - 2012-05-29 18:07 - 00001975 ____A C:\Users\Public\Desktop\YourFile Downloader.lnk
2012-05-29 18:09 - 2012-05-29 18:09 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a(1).exe
2012-05-29 18:07 - 2012-05-29 18:07 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a.exe
2012-05-12 16:33 - 2011-10-13 16:33 - 00000000 __ASH C:\Windows\elogic.exe
ZeroAccess:
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\00000001.@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\800000cb.@
ZeroAccess:
C:\Users\User\AppData\Local\254514f5
C:\Users\User\AppData\Local\254514f5\@
C:\Users\User\AppData\Local\254514f5\U
ZeroAccess:
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3837.09 MB
Available physical RAM: 3289.77 MB
Total Pagefile: 3835.29 MB
Available Pagefile: 3281.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.81 GB) (Free:11.32 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:232.79 GB) (Free:225.71 GB) NTFS
4 Drive f: (World Talk) (CDROM) (Total:0.38 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 232 GB 0 B
Disk 2 Online 3835 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 111 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 111 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 232 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Reservado p NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 232 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3827 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-27 23:07
======================= End Of Log ==========================
and this is the Search.txt
Scan result of Farbar Recovery Scan Tool Version: 05-08-2012 03
Ran by SYSTEM at 07-08-2012 01:28:08
Running from G:\
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [4035152 2011-09-22] (ESET)
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r [2792448 2011-10-06] (VIA)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKU\User\...\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [842048 2011-03-17] (DT Soft Ltd)
HKU\User\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [641400 2011-10-23] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.2.214 10.1.2.253 10.1.2.117
==================== Services (Whitelisted) ======
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [974944 2011-09-22] (ESET)
3 WatAdminSvc; C:\Windows\System32\Wat\WatAdminSvc.exe [1255736 2011-10-06] ()
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [272448 2011-10-09] (DT Soft Ltd)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-09] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-04] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [137144 2011-08-04] (ESET)
3 RTL85n64; C:\Windows\System32\Drivers\RTL85n64.sys [378368 2009-06-10] (Realtek)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [867064 2011-10-09] (Duplex Secure Ltd.)
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:25 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-08-06 20:24 - 2012-08-06 20:25 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-05 23:53 - 2012-08-06 00:07 - 00000000 ____D C:\Users\All Users\0C1CFB130009EDE70303F307F875EF60
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
============ 3 Months Modified Files ========================
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:22 - 2009-07-13 20:45 - 00021280 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 22:21 - 2011-01-22 02:56 - 00742532 ____A C:\Windows\System32\perfh00A.dat
2012-08-06 22:21 - 2011-01-22 02:56 - 00156638 ____A C:\Windows\System32\perfc00A.dat
2012-08-06 22:21 - 2009-07-13 21:13 - 01669088 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-06 22:20 - 2009-07-13 20:51 - 00342817 ____A C:\Windows\setupact.log
2012-08-06 21:53 - 2012-08-06 21:53 - 01439659 ____A (Farbar) C:\Users\User\Downloads\FRST64.exe
2012-08-06 21:24 - 2012-05-29 12:08 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-06 20:25 - 2012-08-06 20:25 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-06 20:25 - 2012-08-06 20:24 - 19198344 ____A (Panda Security ) C:\Users\User\Downloads\PandaCloudCleaner.exe
2012-08-06 20:22 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 10:25 - 2011-10-05 09:22 - 01246669 ____A C:\Windows\WindowsUpdate.log
2012-08-05 16:49 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At10.job
2012-08-05 16:49 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At5.job
2012-08-05 16:45 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At9.job
2012-08-05 16:45 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At4.job
2012-08-05 16:41 - 2011-10-13 16:41 - 00000000 __ASH C:\Windows\skd2ic.exe
2012-08-05 16:41 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At8.job
2012-08-05 16:41 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At3.job
2012-08-05 16:37 - 2011-10-13 16:37 - 00000000 __ASH C:\Windows\pcidvc.exe
2012-08-05 16:37 - 2011-10-09 17:33 - 00000324 ____A C:\Windows\Tasks\At7.job
2012-08-05 16:37 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At2.job
2012-08-05 16:33 - 2011-10-09 17:32 - 00000324 ____A C:\Windows\Tasks\At6.job
2012-08-05 16:33 - 2011-10-09 17:14 - 00000324 ____A C:\Windows\Tasks\At1.job
2012-08-04 16:45 - 2011-10-13 16:45 - 00000000 __ASH C:\Windows\trci32.exe
2012-08-03 18:24 - 2012-05-29 12:08 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 18:24 - 2011-10-05 20:37 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-02 22:11 - 2012-08-02 22:11 - 00000195 ____A C:\Users\User\Downloads\wmpfirefoxplugin.exe
2012-07-19 15:28 - 2012-07-19 15:28 - 00003536 ____A C:\Users\User\Downloads\smime.p7s
2012-07-15 17:26 - 2012-07-15 17:26 - 00004608 ____A C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-07 10:14 - 2012-07-07 10:14 - 00001124 ____A C:\Users\Public\Desktop\Talk Now!.lnk
2012-06-20 12:53 - 2010-11-20 19:47 - 00010518 ____A C:\Windows\PFRO.log
2012-06-04 23:12 - 2012-06-04 23:12 - 00000000 ____A C:\Users\User\Downloads\blackra1n.log
2012-06-04 23:11 - 2012-06-04 23:11 - 00608256 ____A C:\Users\User\Downloads\blackra1n.exe
2012-06-04 22:54 - 2012-06-04 22:54 - 00156160 ____A (iH8sn0w Dev team) C:\Users\User\Downloads\f0recast-1.0.2.exe
2012-06-03 22:59 - 2012-06-03 22:53 - 253340786 ____A C:\Users\User\Downloads\iPhone1,2_3.1.2_7D11_Restore.ipsw
2012-06-03 22:51 - 2012-06-03 22:51 - 04570608 ____A C:\Users\User\Downloads\Spirit.exe
2012-06-01 12:45 - 2012-06-01 12:45 - 00111792 ____A C:\Users\User\Downloads\Men.In.Black.3.2012.PROPER.TS.Xvid.New.Video.UnKnOwN.torrent
2012-06-01 12:44 - 2012-06-01 12:44 - 00049412 ____A C:\Users\User\Desktop\Gone.(2012).BluRay.1080p.x264.DTS-LTRG.torrent
2012-06-01 10:31 - 2011-10-06 01:27 - 00002519 ____A C:\Users\Public\Desktop\Skype.lnk
2012-05-31 09:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 18:10 - 2012-05-29 18:07 - 00001975 ____A C:\Users\Public\Desktop\YourFile Downloader.lnk
2012-05-29 18:09 - 2012-05-29 18:09 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a(1).exe
2012-05-29 18:07 - 2012-05-29 18:07 - 03930504 ____A (http://yourfiledownloader.com) C:\Users\User\Downloads\Eyal_Golan_-_Nagat_Li_Balev_-_320kbps_downloader_128a.exe
2012-05-12 16:33 - 2011-10-13 16:33 - 00000000 __ASH C:\Windows\elogic.exe
ZeroAccess:
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\00000001.@
C:\Windows\Installer\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U\800000cb.@
ZeroAccess:
C:\Users\User\AppData\Local\254514f5
C:\Users\User\AppData\Local\254514f5\@
C:\Users\User\AppData\Local\254514f5\U
ZeroAccess:
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\@
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\L
C:\Users\User\AppData\Local\{c828d0ef-bc69-0696-b2de-8222c1a679c9}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3837.09 MB
Available physical RAM: 3289.77 MB
Total Pagefile: 3835.29 MB
Available Pagefile: 3281.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.81 GB) (Free:11.32 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive e: () (Fixed) (Total:232.79 GB) (Free:225.71 GB) NTFS
4 Drive f: (World Talk) (CDROM) (Total:0.38 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 232 GB 0 B
Disk 2 Online 3835 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 111 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 111 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 232 GB 101 MB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Reservado p NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 232 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3827 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-27 23:07
======================= End Of Log ==========================
thank you