Gibbie2010
Posts: 19 +0
Thank you in advance for any help that can be provided to read my computer of this virus. Looking at what others have provided here are some logs that should get things started again thank you.
Farbar Recovery Scan Tool Version: 20-07-2012 01 Ran by SYSTEM at 2012-07-23 13:06:58 Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600 .16385_none_2b54b20ee6fa07b1\services.exe [2009-07-13 15:19] - [2009-07-13 17:39] -0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe [2009-07-13 15:19] - [2012-07-23 09:45] -0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ====
Scan result of Farbar Recovery Scan Tool Version: 20-07-2012 01 Ran by SYSTEM at 23-07-2012 13:05:14 Running from G:\Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [] [x] HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167704 2011-07-02] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [392472 2011-07-02] (Intel Corporation) HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [416024 2011-07-02] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11775592 2011-01-26] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 /MAXX3 [2188904 2011-01-18] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated) HKLM\...\Run: [ThpSrv] C:\windows\system32\thpsrv /logon [x] HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-06-01] (Intel(R) Corporation) HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulat or.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [TOSHIBA Face Recognition] %ProgramFiles%\Toshiba\SmartFaceV\SmartFace VWatcher.exe [x] HKLM\...\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe" [3453440 2010-07-27] (Alcatel-Lucent) HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.) HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Guest\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Matt\...\Run: [OnlineBackupScheduler] C:\Program Files\Online Backup\OnlineBackup.exe [594760 2012-01-02] (SwapDrive, Inc.) HKU\Test\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 68.94.157.1 Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File) Startup: C:\Users\Guest\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File) Startup: C:\Users\Test\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
==================== Services (Whitelisted) ======
2 McciServiceHost; "C:\Program Files (x86)\Common Files\Motive\McciServiceHost.exe" [315392 2011-09-09] (Alcatel-Lucent) 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation) 2 MSSQL$JFASDATA; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sJFASDATA [29293408 2010-12-10] (Microsoft Corporation) 3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-06-01] () 3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation) 2 pcCMService; "C:\Program Files (x86)\Common Files\Motive\pcCMService.exe" [361472 2012-03-13] (Alcatel-Lucent) 2 pcCMService64; "C:\Program Files\Common Files\Motive\pcCMService.exe" [441344 2012-03-13] (Alcatel-Lucent) 2 pcServiceHost; "C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe" [342016 2012-03-12] (Alcatel-Lucent) 2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2011-02-01] (Intel Corporation) 2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc [x] 3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc [x]
========================== Drivers (Whitelisted) =============
3 MREMP50a64; \?? \C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [43008 2012-03-12] (Printing Communications Assoc., Inc. (PCAUSA)) 3 MRESP50a64; \?? \C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [40960 2012-03-12] (Printing Communications Assoc., Inc. (PCAUSA)) 3 intaud_WaveExtensible; C:\Windows\System32\drivers\intelaud.sys [x] 3 iwdbus; C:\Windows\System32\DRIVERS\iwdbus.sys [x] 3 MREMPR5; \?? \C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x] 3 MRENDIS5; \?? \C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-23 09:54 - 2012-07-23 09:54 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27FCB1F964 9EFA45 2012-07-23 09:54 - 2012-07-23 09:54 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jrtuzlow.sys 2012-07-23 09:54 - 2012-07-23 09:54 -00001199 ____A C:\Users\Matt\Desktop\SpeedyPC Pro.lnk 2012-07-23 09:54 - 2012-07-23 09:54 -00000514 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000442 ____A C:\Windows\Tasks\SpeedyPC Registration3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Users\Matt\AppData\Roaming\SpeedyPC Software 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Users\Matt\AppData\Roaming\DriverCure 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Users\All Users\SpeedyPC Software 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Program Files (x86)\SpeedyPC Software 2012-07-23 09:51 - 2012-07-23 09:51 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF1A68E065 31B227 2012-07-23 09:51 - 2012-07-23 09:42 -04986272 ____A (SpeedyPC Software) C:\Users\Matt\Desktop\SpeedyPC Pro Installer.exe 2012-07-23 09:51 - 2012-07-23 09:42 -00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Matt\Desktop\SpyHunter-Installer.exe 2012-07-23 09:51 - 2012-07-23 09:42 -00001205 ____A C:\Users\Matt\Desktop\FixNCR.reg 2012-07-23 09:49 - 2012-07-23 09:49 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F6AA54C375 5B43AF 2012-07-23 09:49 - 2012-07-23 09:49 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ydrabcyg.sys 2012-07-23 09:24 - 2012-07-23 09:24 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1BC39042E E1DB4D 2012-07-23 09:23 - 2012-07-23 09:23 -00000000 ____D C:\Users\Test\AppData\Roaming\Malwarebytes 2012-07-23 09:21 - 2012-07-23 09:21 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ADFD90B538 AD9186 2012-07-23 09:21 - 2012-07-23 09:21 -00000020 ___SH C:\Users\Test\ntuser.ini 2012-07-23 09:21 - 2012-07-23 09:21 -00000000 ____D C:\users\Test 2012-07-23 09:21 - 2012-01-02 21:12 -00000000 ____D C:\Users\Test\AppData\Local\Microsoft Help 2012-07-23 09:19 - 2012-07-23 09:19 -00000055 ____A C:\Users\Matt\AppData\Roaming\mbam.context. scan 2012-07-23 09:18 - 2012-07-23 09:18 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC6231E7D3 AB7C96 2012-07-23 09:13 - 2012-07-23 09:13 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC67C1E0E8 0D2902 2012-07-23 09:08 - 2012-07-23 09:08 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC1C68D988 9ABAAC 2012-07-23 09:07 - 2012-07-23 09:07 -00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-23 09:03 - 2012-07-23 09:03 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.259D0EB373 DE7FBC 2012-07-23 09:03 - 2012-07-23 09:03 -00000000 ____D C:\Users\Matt\AppData\Roaming\Malwarebytes 2012-07-23 08:57 - 2012-07-23 09:07 -00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-07-23 08:57 - 2012-07-23 08:57 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CC5A8000C9 74C40F 2012-07-23 08:57 - 2012-07-23 08:57 -00000000 ____D C:\Users\All Users\Malwarebytes 2012-07-23 08:57 - 2012-07-23 08:53 -10063000 ____A (Malwarebytes Corporation ) C:\Users\Matt\Desktop\mbam-setup-1.61.0.1400.exe 2012-07-23 08:57 - 2012-07-23 08:53 -04731392 ____A (AVAST Software) C:\Users\Matt\Desktop\aswMBR.exe 2012-07-23 08:57 - 2012-07-23 08:52 -02048818 ____A C:\Users\Matt\Desktop\FakeAVRemover_1.0.0.1 019.zip 2012-07-23 08:57 - 2012-07-03 10:46 -00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-23 08:31 - 2012-07-23 08:31 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.267BA0BB35 EADDA6 2012-07-23 08:20 - 2012-07-23 08:20 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF3969B095 093C1E 2012-07-23 08:15 - 2012-07-23 08:15 -00000000 ____D C:\Program Files\Microsoft Security Client 2012-07-23 08:15 - 2012-07-23 08:15 -00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2012-07-23 08:14 - 2012-07-23 08:14 -00000000 ____D C:\29231c812236543437df 2012-07-22 18:35 - 2012-07-22 18:35 -00000000 __SHD C:\Windows\System32\%APPDATA% 2012-07-15 17:01 - 2012-07-15 17:01 -00000000 ____D C:\Program Files (x86)\Coupons 2012-07-13 13:34 - 2012-07-13 13:34 -00011714 ____A C:\Users\Matt\Desktop\Book1.xlsx 2012-07-13 09:16 - 2012-07-13 09:16 -00842520 ____A C:\Windows\Minidump\071312-29749-01.dmp 2012-07-13 04:52 - 2012-06-11 19:08 -03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-13 04:48 - 2012-06-02 04:49 -17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-07-13 04:48 - 2012-06-02 04:17 -10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-07-13 04:48 - 2012-06-02 04:12 -02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-07-13 04:48 - 2012-06-02 04:05 -01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-07-13 04:48 - 2012-06-02 04:05 -01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-07-13 04:48 - 2012-06-02 04:04 -01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-07-13 04:48 - 2012-06-02 04:04 -00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-07-13 04:48 - 2012-06-02 04:03 -00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-07-13 04:48 - 2012-06-02 04:01 -00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-07-13 04:48 - 2012-06-02 04:00 -00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-07-13 04:48 - 2012-06-02 03:59 -02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-07-13 04:48 - 2012-06-02 03:57 -02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-07-13 04:48 - 2012-06-02 03:57 -00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-07-13 04:48 - 2012-06-02 03:54 -00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-07-13 04:48 - 2012-06-02 01:07 -12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-07-13 04:48 - 2012-06-02 00:43 -09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-07-13 04:48 - 2012-06-02 00:33 -01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-07-13 04:48 - 2012-06-02 00:26 -01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-07-13 04:48 - 2012-06-02 00:25 -01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-07-13 04:48 - 2012-06-02 00:25 -01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-07-13 04:48 - 2012-06-02 00:23 -00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-07-13 04:48 - 2012-06-02 00:21 -00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-07-13 04:48 - 2012-06-02 00:20 -00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-07-13 04:48 - 2012-06-02 00:19 -01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-07-13 04:48 - 2012-06-02 00:19 -00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-07-13 04:48 - 2012-06-02 00:17 -00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-07-13 04:48 - 2012-06-02 00:16 -02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-07-13 04:48 - 2012-06-02 00:14 -00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-07-13 04:47 - 2012-06-08 21:43 -14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-07-13 04:47 - 2012-06-08 20:41 -12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-07-13 04:47 - 2012-06-05 22:06 -02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-07-13 04:47 - 2012-06-05 22:06 -01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-07-13 04:47 - 2012-06-05 22:02 -01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-07-13 04:47 - 2012-06-05 21:05 -01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-07-13 04:47 - 2012-06-05 21:05 -01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-07-13 04:47 - 2012-06-05 21:03 -00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-07-13 04:47 - 2012-06-01 21:50 -00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-07-13 04:47 - 2012-06-01 21:48 -00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-07-13 04:47 - 2012-06-01 21:48 -00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-07-13 04:47 - 2012-06-01 21:45 -00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-07-13 04:47 - 2012-06-01 21:44 -00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-07-13 04:47 - 2012-06-01 20:40 -00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-07-13 04:47 - 2012-06-01 20:40 -00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-07-13 04:47 - 2012-06-01 20:39 -00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-07-13 04:47 - 2012-06-01 20:34 -00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-07-13 04:47 - 2010-06-25 19:55 -00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll 2012-07-13 04:47 - 2010-06-25 19:24 -00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2012-06-25 12:47 - 2012-06-02 14:19 -02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-25 12:47 - 2012-06-02 14:19 -00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-25 12:47 - 2012-06-02 14:19 -00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-25 12:47 - 2012-06-02 14:19 -00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-25 12:47 - 2012-06-02 14:19 -00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-25 12:47 - 2012-06-02 14:15 -02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-25 12:47 - 2012-06-02 14:15 -00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-25 12:46 - 2012-06-02 12:19 -00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-25 12:46 - 2012-06-02 12:15 -00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
============ 3 Months Modified Files ========================
2012-07-23 09:54 - 2012-07-23 09:54 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27FCB1F964 9EFA45 2012-07-23 09:54 - 2012-07-23 09:54 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jrtuzlow.sys 2012-07-23 09:54 - 2012-07-23 09:54 -00001199 ____A C:\Users\Matt\Desktop\SpeedyPC Pro.lnk 2012-07-23 09:54 - 2012-07-23 09:54 -00000514 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000442 ____A C:\Windows\Tasks\SpeedyPC Registration3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job 2012-07-23 09:51 - 2012-07-23 09:51 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF1A68E065 31B227 2012-07-23 09:49 - 2012-07-23 09:49 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F6AA54C375 5B43AF 2012-07-23 09:49 - 2012-07-23 09:49 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ydrabcyg.sys 2012-07-23 09:45 - 2011-11-22 20:04 -00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCor e.job 2012-07-23 09:45 - 2009-07-13 15:19 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe 2012-07-23 09:44 - 2009-07-13 21:08 -00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-23 09:44 - 2009-07-13 20:51 -00053731 ____A C:\Windows\setupact.log 2012-07-23 09:42 - 2012-07-23 09:51 -04986272 ____A (SpeedyPC Software) C:\Users\Matt\Desktop\SpeedyPC Pro Installer.exe 2012-07-23 09:42 - 2012-07-23 09:51 -00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Matt\Desktop\SpyHunter-Installer.exe 2012-07-23 09:42 - 2012-07-23 09:51 -00001205 ____A C:\Users\Matt\Desktop\FixNCR.reg 2012-07-23 09:24 - 2012-07-23 09:24 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1BC39042E E1DB4D 2012-07-23 09:21 - 2012-07-23 09:21 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ADFD90B538 AD9186 2012-07-23 09:21 - 2012-07-23 09:21 -00000020 ___SH C:\Users\Test\ntuser.ini 2012-07-23 09:19 - 2012-07-23 09:19 -00000055 ____A C:\Users\Matt\AppData\Roaming\mbam.context. scan 2012-07-23 09:18 - 2012-07-23 09:18 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC6231E7D3 AB7C96 2012-07-23 09:13 - 2012-07-23 09:13 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC67C1E0E8 0D2902 2012-07-23 09:11 - 2010-11-20 19:47 -00689316 ____A C:\Windows\PFRO.log 2012-07-23 09:08 - 2012-07-23 09:08 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC1C68D988 9ABAAC 2012-07-23 09:07 - 2012-07-23 09:07 -00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-23 09:03 - 2012-07-23 09:03 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.259D0EB373 DE7FBC 2012-07-23 08:57 - 2012-07-23 08:57 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CC5A8000C9 74C40F 2012-07-23 08:53 - 2012-07-23 08:57 -10063000 ____A (Malwarebytes Corporation ) C:\Users\Matt\Desktop\mbam-setup-1.61.0.1400.exe 2012-07-23 08:53 - 2012-07-23 08:57 -04731392 ____A (AVAST Software) C:\Users\Matt\Desktop\aswMBR.exe 2012-07-23 08:52 - 2012-07-23 08:57 -02048818 ____A C:\Users\Matt\Desktop\FakeAVRemover_1.0.0.1 019.zip 2012-07-23 08:31 - 2012-07-23 08:31 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.267BA0BB35 EADDA6 2012-07-23 08:31 - 2009-07-13 20:45 -00025120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-23 08:31 - 2009-07-13 20:45 -00025120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-23 08:28 - 2009-07-13 21:13 -00795390 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-23 08:20 - 2012-07-23 08:20 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF3969B095 093C1E 2012-07-23 08:16 - 2011-11-22 19:38 -01546909 ____A C:\Windows\WindowsUpdate.log 2012-07-23 08:15 - 2012-01-03 09:56 -00809540 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-07-23 08:14 - 2011-11-22 20:04 -00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA. job 2012-07-15 11:16 - 2009-09-13 09:48 -00042496 ____A C:\Users\Matt\Documents\PW.XLS 2012-07-15 06:17 - 2012-01-02 22:36 -00059392 ____A C:\Users\Matt\Documents\#2.xls 2012-07-13 13:34 - 2012-07-13 13:34 -00011714 ____A C:\Users\Matt\Desktop\Book1.xlsx 2012-07-13 09:16 - 2012-07-13 09:16 -00842520 ____A C:\Windows\Minidump\071312-29749-01.dmp 2012-07-13 09:16 - 2012-06-18 07:45 -419843784 ____A C:\Windows\MEMORY.DMP 2012-07-13 05:54 - 2012-04-03 06:22 -00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-07-13 05:54 - 2011-07-26 23:11 -00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-07-13 05:53 - 2009-07-13 20:45 -00418744 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-13 04:52 - 2009-07-13 18:34 -00000478 ____A C:\Windows\win.ini 2012-07-13 04:49 - 2012-01-02 23:13 -59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-07-03 10:46 - 2012-07-23 08:57 -00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-06-27 07:35 - 2012-01-29 06:24 -00022955 ____A C:\Users\Matt\AppData\Roaming\Comma Separated Values (Windows).ADR 2012-06-20 08:56 - 2012-01-29 20:25 -00071104 ____A () C:\Windows\CouponPrinter.ocx 2012-06-18 07:45 - 2012-06-18 07:45 -00835616 ____A C:\Windows\Minidump\061812-23025-01.dmp 2012-06-12 11:03 - 2011-07-26 23:18 -00203897 ____A C:\Windows\DirectX.log 2012-06-11 19:08 - 2012-07-13 04:52 -03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-09 13:55 - 2012-06-09 08:37 -00013907 ____A C:\Users\Matt\Documents\DUI Summary.xlsx 2012-06-08 21:43 - 2012-07-13 04:47 -14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-08 20:41 - 2012-07-13 04:47 -12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-06-05 22:06 - 2012-07-13 04:47 -02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-05 22:06 - 2012-07-13 04:47 -01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-05 22:02 - 2012-07-13 04:47 -01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-06-05 21:05 - 2012-07-13 04:47 -01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-06-05 21:05 - 2012-07-13 04:47 -01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-06-05 21:03 - 2012-07-13 04:47 -00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-06-02 14:19 - 2012-06-25 12:47 -02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-25 12:47 -00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-25 12:47 -00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-25 12:47 -00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-25 12:47 -00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:15 - 2012-06-25 12:47 -02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:15 - 2012-06-25 12:47 -00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 12:19 - 2012-06-25 12:46 -00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 12:15 - 2012-06-25 12:46 -00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-02 04:49 - 2012-07-13 04:48 -17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-02 04:17 - 2012-07-13 04:48 -10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-02 04:12 - 2012-07-13 04:48 -02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-02 04:05 - 2012-07-13 04:48 -01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-02 04:05 - 2012-07-13 04:48 -01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-02 04:04 - 2012-07-13 04:48 -01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-02 04:04 - 2012-07-13 04:48 -00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-02 04:03 - 2012-07-13 04:48 -00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-02 04:01 - 2012-07-13 04:48 -00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-02 04:00 - 2012-07-13 04:48 -00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-02 03:59 - 2012-07-13 04:48 -02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-02 03:57 - 2012-07-13 04:48 -02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-02 03:57 - 2012-07-13 04:48 -00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-02 03:54 - 2012-07-13 04:48 -00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-02 01:07 - 2012-07-13 04:48 -12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-02 00:43 - 2012-07-13 04:48 -09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-02 00:33 - 2012-07-13 04:48 -01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-02 00:26 - 2012-07-13 04:48 -01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-02 00:25 - 2012-07-13 04:48 -01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-02 00:25 - 2012-07-13 04:48 -01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-02 00:23 - 2012-07-13 04:48 -00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-02 00:21 - 2012-07-13 04:48 -00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-02 00:20 - 2012-07-13 04:48 -00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-02 00:19 - 2012-07-13 04:48 -01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-02 00:19 - 2012-07-13 04:48 -00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-02 00:17 - 2012-07-13 04:48 -00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-02 00:16 - 2012-07-13 04:48 -02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-02 00:14 - 2012-07-13 04:48 -00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-01 21:50 - 2012-07-13 04:47 -00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-06-01 21:48 - 2012-07-13 04:47 -00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-06-01 21:48 - 2012-07-13 04:47 -00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-01 21:45 - 2012-07-13 04:47 -00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-01 21:44 - 2012-07-13 04:47 -00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-06-01 20:40 - 2012-07-13 04:47 -00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-06-01 20:40 - 2012-07-13 04:47 -00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-06-01 20:39 - 2012-07-13 04:47 -00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-06-01 20:34 - 2012-07-13 04:47 -00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-05-31 09:25 - 2010-11-20 19:27 -00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2012-05-04 03:06 - 2012-06-13 16:28 -05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-05-04 03:00 - 2012-06-13 16:28 -00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2012-05-04 02:03 - 2012-06-13 16:28 -03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-05-04 02:03 - 2012-06-13 16:28 -03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-05-04 01:59 - 2012-06-13 16:28 -00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2012-04-30 21:40 - 2012-06-13 16:28 -00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-04-30 05:05 - 2009-07-13 21:08 -00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-04-27 19:55 - 2012-06-13 16:28 -00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-04-27 12:29 - 2012-04-26 09:48 -00242176 ____A C:\Users\Matt\Documents\Biz Cards.pub 2012-04-25 21:41 - 2012-06-13 16:28 -00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-04-25 21:41 - 2012-06-13 16:28 -00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-04-25 21:34 - 2012-06-13 16:28 -00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
ZeroAccess: C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537} C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\@ C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\L C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\n C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\U C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\U\00000001.@
ZeroAccess: C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537} C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\@ C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\L C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!. C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11% Total physical RAM: 6050.69 MB Available physical RAM: 5375.12 MB Total Pagefile: 6048.89 MB Available Pagefile: 5361.4 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:579.61 GB) (Free:238.29 GB) NTFS ==>[System with boot components (obtained from reading drive)] 2 Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: (MotoCast) (CDROM) (Total:0.07 GB) (Free:0 GB) CDFS 5 Drive g: (MOT) (Removable) (Total:8 GB) (Free:7.86 GB) FAT32 6 Drive h: (MOT) (Removable) (Total:14.88 GB) (Free:14.5 GB) FAT32 7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt -------- ------------- ------- ---------- ---Disk 0 Online 596 GB 0 B Disk 1 Online 8 GB 0 B Disk 2 Online 14 GB 0 B
Partitions of Disk 0: ===============
Partition ### Type Size Offset ------------- ---------------- --------------Partition 1 Recovery 1500 MB 1024 KB Partition 2 Primary 579 GB 1501 MB Partition 3 Primary 15 GB 581 GB
=========================================== =======================================
Disk: 0 Partition 1 Type : 27 Hidden: Yes Active: Yes
Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- --------* Volume 3 D System NTFS Partition 1500 MB Healthy Hidden
=========================================== =======================================
Disk: 0 Partition 2 Type : 07 Hidden: No Active: No
Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- --------* Volume 2 C NTFS Partition 579 GB Healthy
=========================================== =======================================
Disk: 0 Partition 3 Type : 17 (Suspicious Type) Hidden: Yes Active: No
There is no volume associated with this partition.
=========================================== =======================================
Partitions of Disk 1: ===============
Partition ### Type Size Offset ------------- ---------------- --------------* Partition 1 Primary 8 GB 0 B
=========================================== =======================================
Disk: 1 There is no partition selected.
There is no partition selected. Please select a partition and try again.
=========================================== =======================================
Partitions of Disk 2: ===============
Partition ### Type Size Offset ------------- ---------------- --------------Partition 1 Primary 14 GB 1024 KB
=========================================== =======================================
Disk: 2 Partition 1 Type : 0C Hidden: No Active: Yes
Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- --------* Volume 5 H MOT FAT32 Removable 14 GB Healthy
=========================================== =======================================
=========================================== ===============
Last Boot: 2012-07-18 09:38
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 20-07-2012 01 Ran by SYSTEM at 2012-07-23 13:06:58 Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600 .16385_none_2b54b20ee6fa07b1\services.exe [2009-07-13 15:19] - [2009-07-13 17:39] -0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe [2009-07-13 15:19] - [2012-07-23 09:45] -0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ====
Scan result of Farbar Recovery Scan Tool Version: 20-07-2012 01 Ran by SYSTEM at 23-07-2012 13:05:14 Running from G:\Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [] [x] HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167704 2011-07-02] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [392472 2011-07-02] (Intel Corporation) HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [416024 2011-07-02] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11775592 2011-01-26] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 /MAXX3 [2188904 2011-01-18] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated) HKLM\...\Run: [ThpSrv] C:\windows\system32\thpsrv /logon [x] HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-06-01] (Intel(R) Corporation) HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulat or.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [TOSHIBA Face Recognition] %ProgramFiles%\Toshiba\SmartFaceV\SmartFace VWatcher.exe [x] HKLM\...\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe" [3453440 2010-07-27] (Alcatel-Lucent) HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.) HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Guest\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Matt\...\Run: [OnlineBackupScheduler] C:\Program Files\Online Backup\OnlineBackup.exe [594760 2012-01-02] (SwapDrive, Inc.) HKU\Test\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 68.94.157.1 Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File) Startup: C:\Users\Guest\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File) Startup: C:\Users\Test\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
==================== Services (Whitelisted) ======
2 McciServiceHost; "C:\Program Files (x86)\Common Files\Motive\McciServiceHost.exe" [315392 2011-09-09] (Alcatel-Lucent) 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation) 2 MSSQL$JFASDATA; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sJFASDATA [29293408 2010-12-10] (Microsoft Corporation) 3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-06-01] () 3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation) 2 pcCMService; "C:\Program Files (x86)\Common Files\Motive\pcCMService.exe" [361472 2012-03-13] (Alcatel-Lucent) 2 pcCMService64; "C:\Program Files\Common Files\Motive\pcCMService.exe" [441344 2012-03-13] (Alcatel-Lucent) 2 pcServiceHost; "C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe" [342016 2012-03-12] (Alcatel-Lucent) 2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2011-02-01] (Intel Corporation) 2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc [x] 3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc [x]
========================== Drivers (Whitelisted) =============
3 MREMP50a64; \?? \C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [43008 2012-03-12] (Printing Communications Assoc., Inc. (PCAUSA)) 3 MRESP50a64; \?? \C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [40960 2012-03-12] (Printing Communications Assoc., Inc. (PCAUSA)) 3 intaud_WaveExtensible; C:\Windows\System32\drivers\intelaud.sys [x] 3 iwdbus; C:\Windows\System32\DRIVERS\iwdbus.sys [x] 3 MREMPR5; \?? \C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x] 3 MRENDIS5; \?? \C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-23 09:54 - 2012-07-23 09:54 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27FCB1F964 9EFA45 2012-07-23 09:54 - 2012-07-23 09:54 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jrtuzlow.sys 2012-07-23 09:54 - 2012-07-23 09:54 -00001199 ____A C:\Users\Matt\Desktop\SpeedyPC Pro.lnk 2012-07-23 09:54 - 2012-07-23 09:54 -00000514 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000442 ____A C:\Windows\Tasks\SpeedyPC Registration3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Users\Matt\AppData\Roaming\SpeedyPC Software 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Users\Matt\AppData\Roaming\DriverCure 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Users\All Users\SpeedyPC Software 2012-07-23 09:54 - 2012-07-23 09:54 -00000000 ____D C:\Program Files (x86)\SpeedyPC Software 2012-07-23 09:51 - 2012-07-23 09:51 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF1A68E065 31B227 2012-07-23 09:51 - 2012-07-23 09:42 -04986272 ____A (SpeedyPC Software) C:\Users\Matt\Desktop\SpeedyPC Pro Installer.exe 2012-07-23 09:51 - 2012-07-23 09:42 -00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Matt\Desktop\SpyHunter-Installer.exe 2012-07-23 09:51 - 2012-07-23 09:42 -00001205 ____A C:\Users\Matt\Desktop\FixNCR.reg 2012-07-23 09:49 - 2012-07-23 09:49 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F6AA54C375 5B43AF 2012-07-23 09:49 - 2012-07-23 09:49 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ydrabcyg.sys 2012-07-23 09:24 - 2012-07-23 09:24 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1BC39042E E1DB4D 2012-07-23 09:23 - 2012-07-23 09:23 -00000000 ____D C:\Users\Test\AppData\Roaming\Malwarebytes 2012-07-23 09:21 - 2012-07-23 09:21 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ADFD90B538 AD9186 2012-07-23 09:21 - 2012-07-23 09:21 -00000020 ___SH C:\Users\Test\ntuser.ini 2012-07-23 09:21 - 2012-07-23 09:21 -00000000 ____D C:\users\Test 2012-07-23 09:21 - 2012-01-02 21:12 -00000000 ____D C:\Users\Test\AppData\Local\Microsoft Help 2012-07-23 09:19 - 2012-07-23 09:19 -00000055 ____A C:\Users\Matt\AppData\Roaming\mbam.context. scan 2012-07-23 09:18 - 2012-07-23 09:18 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC6231E7D3 AB7C96 2012-07-23 09:13 - 2012-07-23 09:13 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC67C1E0E8 0D2902 2012-07-23 09:08 - 2012-07-23 09:08 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC1C68D988 9ABAAC 2012-07-23 09:07 - 2012-07-23 09:07 -00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-23 09:03 - 2012-07-23 09:03 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.259D0EB373 DE7FBC 2012-07-23 09:03 - 2012-07-23 09:03 -00000000 ____D C:\Users\Matt\AppData\Roaming\Malwarebytes 2012-07-23 08:57 - 2012-07-23 09:07 -00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-07-23 08:57 - 2012-07-23 08:57 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CC5A8000C9 74C40F 2012-07-23 08:57 - 2012-07-23 08:57 -00000000 ____D C:\Users\All Users\Malwarebytes 2012-07-23 08:57 - 2012-07-23 08:53 -10063000 ____A (Malwarebytes Corporation ) C:\Users\Matt\Desktop\mbam-setup-1.61.0.1400.exe 2012-07-23 08:57 - 2012-07-23 08:53 -04731392 ____A (AVAST Software) C:\Users\Matt\Desktop\aswMBR.exe 2012-07-23 08:57 - 2012-07-23 08:52 -02048818 ____A C:\Users\Matt\Desktop\FakeAVRemover_1.0.0.1 019.zip 2012-07-23 08:57 - 2012-07-03 10:46 -00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-23 08:31 - 2012-07-23 08:31 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.267BA0BB35 EADDA6 2012-07-23 08:20 - 2012-07-23 08:20 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF3969B095 093C1E 2012-07-23 08:15 - 2012-07-23 08:15 -00000000 ____D C:\Program Files\Microsoft Security Client 2012-07-23 08:15 - 2012-07-23 08:15 -00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2012-07-23 08:14 - 2012-07-23 08:14 -00000000 ____D C:\29231c812236543437df 2012-07-22 18:35 - 2012-07-22 18:35 -00000000 __SHD C:\Windows\System32\%APPDATA% 2012-07-15 17:01 - 2012-07-15 17:01 -00000000 ____D C:\Program Files (x86)\Coupons 2012-07-13 13:34 - 2012-07-13 13:34 -00011714 ____A C:\Users\Matt\Desktop\Book1.xlsx 2012-07-13 09:16 - 2012-07-13 09:16 -00842520 ____A C:\Windows\Minidump\071312-29749-01.dmp 2012-07-13 04:52 - 2012-06-11 19:08 -03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-13 04:48 - 2012-06-02 04:49 -17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-07-13 04:48 - 2012-06-02 04:17 -10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-07-13 04:48 - 2012-06-02 04:12 -02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-07-13 04:48 - 2012-06-02 04:05 -01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-07-13 04:48 - 2012-06-02 04:05 -01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-07-13 04:48 - 2012-06-02 04:04 -01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-07-13 04:48 - 2012-06-02 04:04 -00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-07-13 04:48 - 2012-06-02 04:03 -00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-07-13 04:48 - 2012-06-02 04:01 -00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-07-13 04:48 - 2012-06-02 04:00 -00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-07-13 04:48 - 2012-06-02 03:59 -02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-07-13 04:48 - 2012-06-02 03:57 -02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-07-13 04:48 - 2012-06-02 03:57 -00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-07-13 04:48 - 2012-06-02 03:54 -00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-07-13 04:48 - 2012-06-02 01:07 -12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-07-13 04:48 - 2012-06-02 00:43 -09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-07-13 04:48 - 2012-06-02 00:33 -01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-07-13 04:48 - 2012-06-02 00:26 -01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-07-13 04:48 - 2012-06-02 00:25 -01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-07-13 04:48 - 2012-06-02 00:25 -01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-07-13 04:48 - 2012-06-02 00:23 -00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-07-13 04:48 - 2012-06-02 00:21 -00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-07-13 04:48 - 2012-06-02 00:20 -00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-07-13 04:48 - 2012-06-02 00:19 -01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-07-13 04:48 - 2012-06-02 00:19 -00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-07-13 04:48 - 2012-06-02 00:17 -00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-07-13 04:48 - 2012-06-02 00:16 -02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-07-13 04:48 - 2012-06-02 00:14 -00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-07-13 04:47 - 2012-06-08 21:43 -14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-07-13 04:47 - 2012-06-08 20:41 -12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-07-13 04:47 - 2012-06-05 22:06 -02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-07-13 04:47 - 2012-06-05 22:06 -01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-07-13 04:47 - 2012-06-05 22:02 -01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-07-13 04:47 - 2012-06-05 21:05 -01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-07-13 04:47 - 2012-06-05 21:05 -01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-07-13 04:47 - 2012-06-05 21:03 -00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-07-13 04:47 - 2012-06-01 21:50 -00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-07-13 04:47 - 2012-06-01 21:48 -00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-07-13 04:47 - 2012-06-01 21:48 -00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-07-13 04:47 - 2012-06-01 21:45 -00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-07-13 04:47 - 2012-06-01 21:44 -00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-07-13 04:47 - 2012-06-01 20:40 -00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-07-13 04:47 - 2012-06-01 20:40 -00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-07-13 04:47 - 2012-06-01 20:39 -00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-07-13 04:47 - 2012-06-01 20:34 -00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-07-13 04:47 - 2010-06-25 19:55 -00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll 2012-07-13 04:47 - 2010-06-25 19:24 -00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2012-06-25 12:47 - 2012-06-02 14:19 -02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-25 12:47 - 2012-06-02 14:19 -00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-25 12:47 - 2012-06-02 14:19 -00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-25 12:47 - 2012-06-02 14:19 -00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-25 12:47 - 2012-06-02 14:19 -00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-25 12:47 - 2012-06-02 14:15 -02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-25 12:47 - 2012-06-02 14:15 -00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-25 12:46 - 2012-06-02 12:19 -00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-25 12:46 - 2012-06-02 12:15 -00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
============ 3 Months Modified Files ========================
2012-07-23 09:54 - 2012-07-23 09:54 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.27FCB1F964 9EFA45 2012-07-23 09:54 - 2012-07-23 09:54 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jrtuzlow.sys 2012-07-23 09:54 - 2012-07-23 09:54 -00001199 ____A C:\Users\Matt\Desktop\SpeedyPC Pro.lnk 2012-07-23 09:54 - 2012-07-23 09:54 -00000514 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000442 ____A C:\Windows\Tasks\SpeedyPC Registration3.job 2012-07-23 09:54 - 2012-07-23 09:54 -00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job 2012-07-23 09:51 - 2012-07-23 09:51 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF1A68E065 31B227 2012-07-23 09:49 - 2012-07-23 09:49 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F6AA54C375 5B43AF 2012-07-23 09:49 - 2012-07-23 09:49 -00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ydrabcyg.sys 2012-07-23 09:45 - 2011-11-22 20:04 -00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCor e.job 2012-07-23 09:45 - 2009-07-13 15:19 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe 2012-07-23 09:44 - 2009-07-13 21:08 -00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-23 09:44 - 2009-07-13 20:51 -00053731 ____A C:\Windows\setupact.log 2012-07-23 09:42 - 2012-07-23 09:51 -04986272 ____A (SpeedyPC Software) C:\Users\Matt\Desktop\SpeedyPC Pro Installer.exe 2012-07-23 09:42 - 2012-07-23 09:51 -00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Matt\Desktop\SpyHunter-Installer.exe 2012-07-23 09:42 - 2012-07-23 09:51 -00001205 ____A C:\Users\Matt\Desktop\FixNCR.reg 2012-07-23 09:24 - 2012-07-23 09:24 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B1BC39042E E1DB4D 2012-07-23 09:21 - 2012-07-23 09:21 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ADFD90B538 AD9186 2012-07-23 09:21 - 2012-07-23 09:21 -00000020 ___SH C:\Users\Test\ntuser.ini 2012-07-23 09:19 - 2012-07-23 09:19 -00000055 ____A C:\Users\Matt\AppData\Roaming\mbam.context. scan 2012-07-23 09:18 - 2012-07-23 09:18 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC6231E7D3 AB7C96 2012-07-23 09:13 - 2012-07-23 09:13 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC67C1E0E8 0D2902 2012-07-23 09:11 - 2010-11-20 19:47 -00689316 ____A C:\Windows\PFRO.log 2012-07-23 09:08 - 2012-07-23 09:08 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AC1C68D988 9ABAAC 2012-07-23 09:07 - 2012-07-23 09:07 -00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-23 09:03 - 2012-07-23 09:03 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.259D0EB373 DE7FBC 2012-07-23 08:57 - 2012-07-23 08:57 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CC5A8000C9 74C40F 2012-07-23 08:53 - 2012-07-23 08:57 -10063000 ____A (Malwarebytes Corporation ) C:\Users\Matt\Desktop\mbam-setup-1.61.0.1400.exe 2012-07-23 08:53 - 2012-07-23 08:57 -04731392 ____A (AVAST Software) C:\Users\Matt\Desktop\aswMBR.exe 2012-07-23 08:52 - 2012-07-23 08:57 -02048818 ____A C:\Users\Matt\Desktop\FakeAVRemover_1.0.0.1 019.zip 2012-07-23 08:31 - 2012-07-23 08:31 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.267BA0BB35 EADDA6 2012-07-23 08:31 - 2009-07-13 20:45 -00025120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-23 08:31 - 2009-07-13 20:45 -00025120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-23 08:28 - 2009-07-13 21:13 -00795390 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-23 08:20 - 2012-07-23 08:20 -00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AF3969B095 093C1E 2012-07-23 08:16 - 2011-11-22 19:38 -01546909 ____A C:\Windows\WindowsUpdate.log 2012-07-23 08:15 - 2012-01-03 09:56 -00809540 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-07-23 08:14 - 2011-11-22 20:04 -00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA. job 2012-07-15 11:16 - 2009-09-13 09:48 -00042496 ____A C:\Users\Matt\Documents\PW.XLS 2012-07-15 06:17 - 2012-01-02 22:36 -00059392 ____A C:\Users\Matt\Documents\#2.xls 2012-07-13 13:34 - 2012-07-13 13:34 -00011714 ____A C:\Users\Matt\Desktop\Book1.xlsx 2012-07-13 09:16 - 2012-07-13 09:16 -00842520 ____A C:\Windows\Minidump\071312-29749-01.dmp 2012-07-13 09:16 - 2012-06-18 07:45 -419843784 ____A C:\Windows\MEMORY.DMP 2012-07-13 05:54 - 2012-04-03 06:22 -00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-07-13 05:54 - 2011-07-26 23:11 -00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-07-13 05:53 - 2009-07-13 20:45 -00418744 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-13 04:52 - 2009-07-13 18:34 -00000478 ____A C:\Windows\win.ini 2012-07-13 04:49 - 2012-01-02 23:13 -59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-07-03 10:46 - 2012-07-23 08:57 -00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-06-27 07:35 - 2012-01-29 06:24 -00022955 ____A C:\Users\Matt\AppData\Roaming\Comma Separated Values (Windows).ADR 2012-06-20 08:56 - 2012-01-29 20:25 -00071104 ____A () C:\Windows\CouponPrinter.ocx 2012-06-18 07:45 - 2012-06-18 07:45 -00835616 ____A C:\Windows\Minidump\061812-23025-01.dmp 2012-06-12 11:03 - 2011-07-26 23:18 -00203897 ____A C:\Windows\DirectX.log 2012-06-11 19:08 - 2012-07-13 04:52 -03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-09 13:55 - 2012-06-09 08:37 -00013907 ____A C:\Users\Matt\Documents\DUI Summary.xlsx 2012-06-08 21:43 - 2012-07-13 04:47 -14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-08 20:41 - 2012-07-13 04:47 -12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-06-05 22:06 - 2012-07-13 04:47 -02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-05 22:06 - 2012-07-13 04:47 -01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-05 22:02 - 2012-07-13 04:47 -01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-06-05 21:05 - 2012-07-13 04:47 -01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-06-05 21:05 - 2012-07-13 04:47 -01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-06-05 21:03 - 2012-07-13 04:47 -00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-06-02 14:19 - 2012-06-25 12:47 -02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-25 12:47 -00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-25 12:47 -00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-25 12:47 -00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-25 12:47 -00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:15 - 2012-06-25 12:47 -02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:15 - 2012-06-25 12:47 -00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 12:19 - 2012-06-25 12:46 -00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 12:15 - 2012-06-25 12:46 -00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-02 04:49 - 2012-07-13 04:48 -17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-02 04:17 - 2012-07-13 04:48 -10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-02 04:12 - 2012-07-13 04:48 -02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-02 04:05 - 2012-07-13 04:48 -01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-02 04:05 - 2012-07-13 04:48 -01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-02 04:04 - 2012-07-13 04:48 -01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-02 04:04 - 2012-07-13 04:48 -00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-02 04:03 - 2012-07-13 04:48 -00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-02 04:01 - 2012-07-13 04:48 -00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-02 04:00 - 2012-07-13 04:48 -00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-02 03:59 - 2012-07-13 04:48 -02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-02 03:57 - 2012-07-13 04:48 -02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-02 03:57 - 2012-07-13 04:48 -00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-02 03:54 - 2012-07-13 04:48 -00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-02 01:07 - 2012-07-13 04:48 -12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-02 00:43 - 2012-07-13 04:48 -09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-02 00:33 - 2012-07-13 04:48 -01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-02 00:26 - 2012-07-13 04:48 -01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-02 00:25 - 2012-07-13 04:48 -01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-02 00:25 - 2012-07-13 04:48 -01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-02 00:23 - 2012-07-13 04:48 -00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-02 00:21 - 2012-07-13 04:48 -00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-02 00:20 - 2012-07-13 04:48 -00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-02 00:19 - 2012-07-13 04:48 -01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-02 00:19 - 2012-07-13 04:48 -00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-02 00:17 - 2012-07-13 04:48 -00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-02 00:16 - 2012-07-13 04:48 -02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-02 00:14 - 2012-07-13 04:48 -00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-01 21:50 - 2012-07-13 04:47 -00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-06-01 21:48 - 2012-07-13 04:47 -00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-06-01 21:48 - 2012-07-13 04:47 -00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-01 21:45 - 2012-07-13 04:47 -00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-01 21:44 - 2012-07-13 04:47 -00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-06-01 20:40 - 2012-07-13 04:47 -00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-06-01 20:40 - 2012-07-13 04:47 -00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-06-01 20:39 - 2012-07-13 04:47 -00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-06-01 20:34 - 2012-07-13 04:47 -00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-05-31 09:25 - 2010-11-20 19:27 -00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2012-05-04 03:06 - 2012-06-13 16:28 -05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-05-04 03:00 - 2012-06-13 16:28 -00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2012-05-04 02:03 - 2012-06-13 16:28 -03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-05-04 02:03 - 2012-06-13 16:28 -03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-05-04 01:59 - 2012-06-13 16:28 -00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2012-04-30 21:40 - 2012-06-13 16:28 -00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-04-30 05:05 - 2009-07-13 21:08 -00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-04-27 19:55 - 2012-06-13 16:28 -00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-04-27 12:29 - 2012-04-26 09:48 -00242176 ____A C:\Users\Matt\Documents\Biz Cards.pub 2012-04-25 21:41 - 2012-06-13 16:28 -00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-04-25 21:41 - 2012-06-13 16:28 -00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-04-25 21:34 - 2012-06-13 16:28 -00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
ZeroAccess: C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537} C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\@ C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\L C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\n C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\U C:\Windows\Installer\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\U\00000001.@
ZeroAccess: C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537} C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\@ C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\L C:\Users\Matt\AppData\Local\{244fbb2e-a9d1-97b2-fe37-35e9f150b537}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!. C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11% Total physical RAM: 6050.69 MB Available physical RAM: 5375.12 MB Total Pagefile: 6048.89 MB Available Pagefile: 5361.4 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:579.61 GB) (Free:238.29 GB) NTFS ==>[System with boot components (obtained from reading drive)] 2 Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: (MotoCast) (CDROM) (Total:0.07 GB) (Free:0 GB) CDFS 5 Drive g: (MOT) (Removable) (Total:8 GB) (Free:7.86 GB) FAT32 6 Drive h: (MOT) (Removable) (Total:14.88 GB) (Free:14.5 GB) FAT32 7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt -------- ------------- ------- ---------- ---Disk 0 Online 596 GB 0 B Disk 1 Online 8 GB 0 B Disk 2 Online 14 GB 0 B
Partitions of Disk 0: ===============
Partition ### Type Size Offset ------------- ---------------- --------------Partition 1 Recovery 1500 MB 1024 KB Partition 2 Primary 579 GB 1501 MB Partition 3 Primary 15 GB 581 GB
=========================================== =======================================
Disk: 0 Partition 1 Type : 27 Hidden: Yes Active: Yes
Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- --------* Volume 3 D System NTFS Partition 1500 MB Healthy Hidden
=========================================== =======================================
Disk: 0 Partition 2 Type : 07 Hidden: No Active: No
Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- --------* Volume 2 C NTFS Partition 579 GB Healthy
=========================================== =======================================
Disk: 0 Partition 3 Type : 17 (Suspicious Type) Hidden: Yes Active: No
There is no volume associated with this partition.
=========================================== =======================================
Partitions of Disk 1: ===============
Partition ### Type Size Offset ------------- ---------------- --------------* Partition 1 Primary 8 GB 0 B
=========================================== =======================================
Disk: 1 There is no partition selected.
There is no partition selected. Please select a partition and try again.
=========================================== =======================================
Partitions of Disk 2: ===============
Partition ### Type Size Offset ------------- ---------------- --------------Partition 1 Primary 14 GB 1024 KB
=========================================== =======================================
Disk: 2 Partition 1 Type : 0C Hidden: No Active: Yes
Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- --------* Volume 5 H MOT FAT32 Removable 14 GB Healthy
=========================================== =======================================
=========================================== ===============
Last Boot: 2012-07-18 09:38
======================= End Of Log ==========================