Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2013
Ran by gskainth (administrator) on 17-08-2013 22:11:26
Running from C:\Users\gskainth\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Firebird Project) C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\IERA\IERA64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Pelmorex Media Inc.) C:\Users\gskainth\AppData\Local\The Weather Network\weathereye.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dolby Laboratories Inc.) C:\DOLBY PCEE4\pcee4.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe
(Sierra Wireless Inc.) C:\Program Files (x86)\Rogers\Rogers Connection Manager\WaHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Firebird Project) C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11785832 2011-03-10] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-09] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated)
HKCU\...\Run: [WeatherEye] - C:\Users\gskainth\AppData\Local\The Weather Network\WeatherEye.exe [310920 2012-08-30] (Pelmorex Media Inc.)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
MountPoints2: E - E:\autorun.exe
MountPoints2: {9e771140-fb9e-11e2-949d-c0f8da7f8ba8} - E:\WIN\setup.exe -ap
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-02-18] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TRUUpdater] - C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe [329072 2011-11-03] (Sierra Wireless, Inc.)
HKLM-x32\...\Run: [WatcherHelper] - C:\Program Files (x86)\Rogers\Rogers Connection Manager\WaHelper.exe [140656 2011-08-04] (Sierra Wireless Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-27] (Egis Technology Inc.)
HKU\Default\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} [x]
HKU\Default User\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} [x]
HKU\Guest\...\Run: [WeatherEye] - C:\Users\Guest\AppData\Local\The Weather Network\WeatherEye.exe [x]
HKU\Guest\...\Run: [Exetender] - "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup [x]
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=10/08/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://acer.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=10/08/2013
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=10/08/2013
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=10/08/2013
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=10/08/2013
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=10/08/2013
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-x32: No Name - {02edb56b-9b33-435b-b7df-b2843273a694} - No File
BHO-x32: No Name - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll No File
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {6EC74131-08B2-4F67-A9BC-5914EF1EDB97} - No File
Toolbar: HKCU - No Name - {02EDB56B-9B33-435B-B7DF-B2843273A694} - No File
DPF: HKLM-x32 {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Bejeweled%203/Images/stg_drm.ocx
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Bejeweled%203/Images/armhelper.ocx
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/RACtrl.cab
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 64.59.176.13 64.59.177.226
Tcpip\..\Interfaces\{00645C10-F0C3-4CAF-AC11-185A15DFB214}: [NameServer]64.71.255.198 64.71.255.253
Tcpip\..\Interfaces\{95EA9B33-E0E9-4C40-9C3E-BBF6200B7F8B}: [NameServer]64.71.255.198 64.71.255.253
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @checkpoint.com/FFApi - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\gskainth\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\gskainth\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\gskainth\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\gskainth\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\gskainth\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\gskainth\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: trtv3 - C:\Users\gskainth\AppData\Roaming\Mozilla\Firefox\profiles\extensions\
trtv3@trtv.com.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [
virtualKeyboard@kaspersky.ru] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\
virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [
linkfilter@kaspersky.ru] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\
linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
Chrome:
=======
CHR HomePage: hxxp://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=CA&userid=a61b348d-26ad-4d75-8ae9-69f89f7bf682&searchtype=hp&installDate=18/05/2013
CHR Extension: (Torrent Search) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee\1.2.0.3_0
CHR Extension: (Google Docs) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (TV) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh\1.0.12_0
CHR Extension: (YouTube) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (PartyCloud) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\defekohaofmambflfpfoojkmfdpcbgko\4.1_0
CHR Extension: (Bikini TV) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcanljafkhmmideajcgekocpbdhkened\2.5.2_0
CHR Extension: (YouTube Feed) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghmclllfjjmmdmhjobjdgfnggfhljboa\1.3.4.1_0
CHR Extension: (Crazy Shooting) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbhccdddhenjmeamogpjhicnoffdood\1.0.0_0
CHR Extension: (Until AM) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\kodigjkcpaoeodlnmcnekemakpnmegnk\0.203_0
CHR Extension: (Traffic Talent) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfgegdofhghiobhllaniipmplkbligpi\1_0
CHR Extension: (Gmail) - C:\Users\gskainth\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [bicnnkjibmphdeigoodpjlcklcnaobdj] - C:\Program Files (x86)\TornTV.com\torntv10.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 FirebirdGuardianDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe [98304 2010-09-17] (Firebird Project)
R3 FirebirdServerDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe [3735552 2010-09-17] (Firebird Project)
R2 IERA; C:\Program Files (x86)\Sierra Wireless Inc\IERA\IERA64.exe [202096 2011-06-16] (Sierra Wireless, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 SwiCardDetectSvc; C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [321392 2011-11-03] (Sierra Wireless, Inc.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-05-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-05-27] (Avira Operations GmbH & Co. KG)
S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [36680 2013-08-14] ()
S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [36680 2013-08-14] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 swg3kser00; C:\Windows\System32\DRIVERS\swg3kser00.sys [258432 2011-05-13] (Sierra Wireless Incorporated)
S3 swiwdmbx; C:\Windows\System32\DRIVERS\swiwdmbx64.sys [109312 2011-05-16] (Sierra Wireless Inc.)
S3 SWNC8UA3; C:\Windows\System32\DRIVERS\swnc8ua3.sys [297472 2011-05-28] (Sierra Wireless Inc.)
S3 libusb0; system32\drivers\libusb0.sys [x]
S3 SWUMX20; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-17 22:10 - 2013-08-17 22:10 - 01575580 _____ (Farbar) C:\Users\gskainth\Downloads\FRST64.exe
2013-08-14 23:20 - 2013-08-14 23:20 - 00036680 _____ C:\Windows\system32\Drivers\mbamchameleon.sys
2013-08-14 21:32 - 2013-08-14 21:32 - 00071304 _____ C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2013-08-14 20:27 - 2013-07-26 00:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 20:27 - 2013-07-26 00:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 20:27 - 2013-07-26 00:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 20:27 - 2013-07-26 00:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 20:27 - 2013-07-26 00:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 20:27 - 2013-07-25 22:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 20:27 - 2013-07-25 22:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 20:27 - 2013-07-25 22:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 20:27 - 2013-07-25 22:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 20:27 - 2013-07-25 22:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 20:27 - 2013-07-25 22:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 20:27 - 2013-07-25 21:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 20:27 - 2013-07-25 21:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 20:27 - 2013-07-25 20:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 20:21 - 2013-08-14 20:22 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 19:49 - 2013-08-14 19:49 - 00071304 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-08-14 19:34 - 2013-08-14 19:45 - 00000000 ____D C:\Users\gskainth\Desktop\RK_Quarantine
2013-08-14 19:00 - 2013-07-25 04:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 19:00 - 2013-07-25 03:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 19:00 - 2013-07-18 20:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 19:00 - 2013-07-18 20:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 19:00 - 2013-07-09 00:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 19:00 - 2013-07-09 00:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 19:00 - 2013-07-09 00:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 19:00 - 2013-07-09 00:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 19:00 - 2013-07-09 00:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 19:00 - 2013-07-08 23:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 19:00 - 2013-07-08 23:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 19:00 - 2013-07-08 23:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 19:00 - 2013-07-08 23:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 19:00 - 2013-07-08 23:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 18:59 - 2013-07-09 01:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 18:59 - 2013-07-09 00:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 18:59 - 2013-07-09 00:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 18:59 - 2013-07-09 00:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 18:59 - 2013-07-09 00:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 18:59 - 2013-07-08 23:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 18:59 - 2013-07-08 23:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 18:59 - 2013-07-08 21:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 18:59 - 2013-07-08 21:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 18:59 - 2013-07-08 21:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 18:59 - 2013-07-08 21:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 18:59 - 2013-07-06 01:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 18:59 - 2013-06-14 23:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-12 23:41 - 2013-08-12 23:54 - 06651392 _____ C:\Users\gskainth\Desktop\Test_Landmarks completed_Excel.xls
2013-08-11 21:02 - 2013-08-11 21:03 - 00000000 ____D C:\Users\gskainth\Desktop\apartments from india
2013-08-11 20:22 - 2013-08-11 20:23 - 00000000 ____D C:\Users\gskainth\Desktop\landmark orderly ram
2013-08-11 20:18 - 2013-08-11 20:19 - 00000000 ____D C:\Users\gskainth\Desktop\winnipeg all original
2013-08-11 20:18 - 2013-08-11 20:18 - 00000000 ____D C:\Users\gskainth\Downloads\WinnipegAll
2013-08-11 20:17 - 2013-08-11 20:17 - 00973457 _____ C:\Users\gskainth\Downloads\WinnipegAll.zip
2013-08-11 20:14 - 2013-08-11 20:15 - 00000000 ____D C:\Users\gskainth\Desktop\winnipeg allmodiefied by india
2013-08-11 20:14 - 2013-08-11 20:14 - 01946102 _____ C:\Users\gskainth\Downloads\Test_Landmarks completed.csv
2013-08-11 20:13 - 2013-08-11 20:14 - 03583488 _____ C:\Users\gskainth\Downloads\Test_Landmarks completed.xls
2013-08-11 20:05 - 2013-08-11 20:05 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-08-11 19:28 - 2013-08-11 19:32 - 00000000 ____D C:\Users\gskainth\Desktop\sorted data
2013-08-11 01:39 - 2013-08-11 01:39 - 00000376 _____ C:\Windows\ODBC.INI
2013-08-11 01:38 - 2013-08-11 01:38 - 00000000 ____D C:\Program Files (x86)\Microsoft ActiveSync
2013-08-10 15:28 - 2013-08-10 15:28 - 00001268 _____ C:\Users\gskainth\Desktop\Revo Uninstaller.lnk
2013-08-10 12:48 - 2013-08-10 15:28 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-08-10 12:29 - 2013-08-10 12:29 - 00003338 _____ C:\Windows\System32\Tasks\{768CC937-BBBF-494F-BC1B-B6F190365CAE}
2013-08-10 12:19 - 2013-08-10 12:19 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Optimizer Pro
2013-08-10 12:13 - 2013-08-10 12:14 - 00002582 _____ C:\Users\gskainth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-08-10 12:11 - 2013-08-10 12:11 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\WinRAR
2013-08-10 12:11 - 2013-08-10 12:11 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-08-10 12:11 - 2013-08-10 12:11 - 00000000 ____D C:\Program Files\WinRAR
2013-08-10 10:50 - 2013-08-10 13:14 - 00000000 ____D C:\Users\gskainth\Desktop\New folder (2)
2013-08-10 09:02 - 2013-08-10 09:05 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-08-10 09:02 - 2013-08-10 09:02 - 00000000 ____D C:\Users\gskainth\Documents\Microsoft Office 2007 Enterprise + Serial Key - {RedDragon}
2013-08-10 09:02 - 2013-08-10 09:02 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-08-10 08:55 - 2013-08-10 08:55 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Oracle
2013-08-10 08:52 - 2013-08-10 08:52 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-10 08:52 - 2013-08-10 08:52 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-10 08:52 - 2013-08-10 08:52 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-10 08:52 - 2013-08-10 08:52 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-10 08:52 - 2013-08-10 08:52 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-08 21:06 - 2013-08-08 21:06 - 00000000 ____D C:\Users\gskainth\AppData\Local\{AA39F34C-6F13-47FD-AE3F-071C5B8745A7}
2013-08-08 06:27 - 2013-08-08 06:29 - 00000000 ____D C:\Users\gskainth\AppData\Local\{3C2F7639-C843-4034-9793-32431ADABB51}
2013-08-07 22:13 - 2013-08-07 22:13 - 00012116 _____ C:\Users\gskainth\Desktop\employees.htm
2013-08-07 20:58 - 2013-08-07 20:58 - 00000000 ____D C:\Users\gskainth\AppData\Local\{6A67CCC3-A3C0-44AD-B8A2-D4BFE3FF6ED2}
2013-08-04 17:16 - 2013-08-04 17:18 - 00000000 ____D C:\Users\gskainth\Desktop\schedules
2013-08-03 23:21 - 2013-08-03 23:23 - 01248931 _____ C:\Users\gskainth\Desktop\WinnipegAll.xlsx
2013-08-03 00:02 - 2013-08-03 00:02 - 00688992 ____R (Swearware) C:\Users\gskainth\Desktop\dds.com
2013-08-03 00:01 - 2013-08-03 00:01 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Malwarebytes
2013-08-03 00:00 - 2013-08-03 00:00 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-03 00:00 - 2013-08-03 00:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 00:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-02 23:40 - 2013-08-10 12:13 - 00000000 ____D C:\Program Files (x86)\Conduit
2013-08-02 13:12 - 2013-08-02 13:12 - 00002178 _____ C:\Users\Public\Desktop\Rogers Connection Manager.lnk
2013-08-02 13:12 - 2013-08-02 13:12 - 00000000 ____D C:\Program Files (x86)\Rogers
2013-08-02 13:11 - 2013-08-02 13:13 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Sierra Wireless
2013-08-02 13:11 - 2013-08-02 13:12 - 00000000 ____D C:\Program Files (x86)\Sierra Wireless Inc
2013-08-02 13:11 - 2013-08-02 13:11 - 00000000 ____D C:\ProgramData\Sierra Wireless
2013-08-02 13:11 - 2011-05-28 13:45 - 00297472 _____ (Sierra Wireless Inc.) C:\Windows\system32\Drivers\swnc8ua3.sys
2013-08-02 13:11 - 2011-05-16 13:44 - 00109312 _____ (Sierra Wireless Inc.) C:\Windows\system32\Drivers\swiwdmbx64.sys
2013-08-02 13:11 - 2011-05-13 15:54 - 00258432 _____ (Sierra Wireless Incorporated) C:\Windows\system32\Drivers\swg3kser00.sys
2013-07-29 22:15 - 2013-07-29 22:15 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\DownLite
2013-07-29 22:13 - 2013-08-11 02:00 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Azureus
2013-07-29 22:13 - 2013-07-29 22:13 - 00001852 _____ C:\Users\Public\Desktop\Vuze.lnk
2013-07-29 22:13 - 2013-07-29 22:13 - 00000000 ____D C:\Users\gskainth\.swt
2013-07-29 22:12 - 2013-07-29 22:13 - 00000000 ____D C:\Program Files (x86)\Vuze
2013-07-29 21:49 - 2013-07-29 21:49 - 00002956 _____ C:\Windows\System32\Tasks\{54BE7F6F-C6DB-43B5-9612-7310C4B132EE}
2013-07-29 21:49 - 2013-07-29 21:49 - 00002956 _____ C:\Windows\System32\Tasks\{40B03322-4137-4492-AB63-403BDBE67148}
2013-07-29 21:10 - 2013-08-07 07:54 - 00000000 ____D C:\Users\gskainth\Desktop\New folder
2013-07-28 23:08 - 2013-08-17 21:23 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-28 23:08 - 2013-08-17 19:13 - 00000902 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-28 23:08 - 2013-08-11 01:25 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-28 23:08 - 2013-07-28 23:08 - 00003898 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-28 23:08 - 2013-07-28 23:08 - 00003646 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-28 18:56 - 2013-07-28 20:23 - 07557120 _____ C:\Users\gskainth\Documents\Call Center.ssf
2013-07-28 18:56 - 2013-07-28 18:56 - 00000000 ____D C:\ProgramData\Business Management Systems
2013-07-28 01:09 - 2013-07-28 01:09 - 00000000 ____D C:\Users\gskainth\AppData\Local\Business_Management_Syste
2013-07-21 23:35 - 2013-08-11 01:25 - 00000000 ____D C:\Users\gskainth\AppData\Local\Google
2013-07-21 23:34 - 2013-07-21 23:35 - 00000000 ____D C:\Users\gskainth\AppData\Local\Deployment
2013-07-21 23:34 - 2013-07-21 23:34 - 00000000 ____D C:\Users\gskainth\AppData\Local\Apps\2.0
2013-07-21 21:22 - 2013-07-21 21:22 - 00000000 ____D C:\Users\gskainth\AppData\Local\{83C37563-7F13-4BDF-B64F-16E55EDEB4A1}
==================== One Month Modified Files and Folders =======
2013-08-17 22:10 - 2013-08-17 22:10 - 01575580 _____ (Farbar) C:\Users\gskainth\Downloads\FRST64.exe
2013-08-17 21:49 - 2013-05-27 18:18 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-17 21:31 - 2009-07-13 23:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-17 21:31 - 2009-07-13 23:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-17 21:24 - 2011-08-11 17:22 - 00000000 ____D C:\ProgramData\clear.fi
2013-08-17 21:23 - 2013-07-28 23:08 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-17 21:22 - 2011-08-11 17:08 - 00000000 ____D C:\Users\gskainth\AppData\Local\VirtualStore
2013-08-17 21:22 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-17 21:22 - 2009-07-13 23:51 - 00086764 _____ C:\Windows\setupact.log
2013-08-17 20:11 - 2011-06-05 08:43 - 01085277 _____ C:\Windows\WindowsUpdate.log
2013-08-17 19:13 - 2013-07-28 23:08 - 00000902 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-17 18:15 - 2010-11-20 22:47 - 00385382 _____ C:\Windows\PFRO.log
2013-08-14 23:20 - 2013-08-14 23:20 - 00036680 _____ C:\Windows\system32\Drivers\mbamchameleon.sys
2013-08-14 22:43 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2013-08-14 21:32 - 2013-08-14 21:32 - 00071304 _____ C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2013-08-14 20:24 - 2009-07-14 00:13 - 00732510 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-14 20:22 - 2013-08-14 20:21 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 20:21 - 2011-08-30 18:04 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 19:49 - 2013-08-14 19:49 - 00071304 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-08-14 19:45 - 2013-08-14 19:34 - 00000000 ____D C:\Users\gskainth\Desktop\RK_Quarantine
2013-08-12 23:54 - 2013-08-12 23:41 - 06651392 _____ C:\Users\gskainth\Desktop\Test_Landmarks completed_Excel.xls
2013-08-12 08:11 - 2009-07-13 23:45 - 00326560 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-11 21:03 - 2013-08-11 21:02 - 00000000 ____D C:\Users\gskainth\Desktop\apartments from india
2013-08-11 20:23 - 2013-08-11 20:22 - 00000000 ____D C:\Users\gskainth\Desktop\landmark orderly ram
2013-08-11 20:19 - 2013-08-11 20:18 - 00000000 ____D C:\Users\gskainth\Desktop\winnipeg all original
2013-08-11 20:18 - 2013-08-11 20:18 - 00000000 ____D C:\Users\gskainth\Downloads\WinnipegAll
2013-08-11 20:17 - 2013-08-11 20:17 - 00973457 _____ C:\Users\gskainth\Downloads\WinnipegAll.zip
2013-08-11 20:15 - 2013-08-11 20:14 - 00000000 ____D C:\Users\gskainth\Desktop\winnipeg allmodiefied by india
2013-08-11 20:14 - 2013-08-11 20:14 - 01946102 _____ C:\Users\gskainth\Downloads\Test_Landmarks completed.csv
2013-08-11 20:14 - 2013-08-11 20:13 - 03583488 _____ C:\Users\gskainth\Downloads\Test_Landmarks completed.xls
2013-08-11 20:05 - 2013-08-11 20:05 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-08-11 20:05 - 2011-08-11 17:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-08-11 19:32 - 2013-08-11 19:28 - 00000000 ____D C:\Users\gskainth\Desktop\sorted data
2013-08-11 02:00 - 2013-07-29 22:13 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Azureus
2013-08-11 01:59 - 2012-01-13 23:25 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\SoftGrid Client
2013-08-11 01:59 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-08-11 01:39 - 2013-08-11 01:39 - 00000376 _____ C:\Windows\ODBC.INI
2013-08-11 01:38 - 2013-08-11 01:38 - 00000000 ____D C:\Program Files (x86)\Microsoft ActiveSync
2013-08-11 01:38 - 2010-11-21 02:16 - 00000000 ____D C:\Windows\ShellNew
2013-08-11 01:34 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system
2013-08-11 01:25 - 2013-07-28 23:08 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-11 01:25 - 2013-07-21 23:35 - 00000000 ____D C:\Users\gskainth\AppData\Local\Google
2013-08-11 00:40 - 2011-06-05 08:59 - 00001024 ___RH C:\Users\Public\Documents\NTILiveUpdateV9.dll
2013-08-11 00:40 - 2011-06-05 08:58 - 00001024 ___RH C:\Users\Public\Documents\NTIMMV9Acer.dll
2013-08-10 16:01 - 2012-01-13 05:50 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\VideoBuzz
2013-08-10 15:28 - 2013-08-10 15:28 - 00001268 _____ C:\Users\gskainth\Desktop\Revo Uninstaller.lnk
2013-08-10 15:28 - 2013-08-10 12:48 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-08-10 13:14 - 2013-08-10 10:50 - 00000000 ____D C:\Users\gskainth\Desktop\New folder (2)
2013-08-10 12:38 - 2012-01-13 05:50 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2013-08-10 12:29 - 2013-08-10 12:29 - 00003338 _____ C:\Windows\System32\Tasks\{768CC937-BBBF-494F-BC1B-B6F190365CAE}
2013-08-10 12:19 - 2013-08-10 12:19 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Optimizer Pro
2013-08-10 12:15 - 2011-08-11 17:08 - 00000000 ___HD C:\Users\gskainth
2013-08-10 12:14 - 2013-08-10 12:13 - 00002582 _____ C:\Users\gskainth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-08-10 12:13 - 2013-08-02 23:40 - 00000000 ____D C:\Program Files (x86)\Conduit
2013-08-10 12:11 - 2013-08-10 12:11 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\WinRAR
2013-08-10 12:11 - 2013-08-10 12:11 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-08-10 12:11 - 2013-08-10 12:11 - 00000000 ____D C:\Program Files\WinRAR
2013-08-10 09:05 - 2013-08-10 09:02 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-08-10 09:02 - 2013-08-10 09:02 - 00000000 ____D C:\Users\gskainth\Documents\Microsoft Office 2007 Enterprise + Serial Key - {RedDragon}
2013-08-10 09:02 - 2013-08-10 09:02 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-08-10 08:55 - 2013-08-10 08:55 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Oracle
2013-08-10 08:52 - 2013-08-10 08:52 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-10 08:52 - 2013-08-10 08:52 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-10 08:52 - 2013-08-10 08:52 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-10 08:52 - 2013-08-10 08:52 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-10 08:52 - 2013-08-10 08:52 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-10 08:52 - 2013-04-21 12:48 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-10 08:52 - 2011-08-11 17:58 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-09 23:11 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-08 21:06 - 2013-08-08 21:06 - 00000000 ____D C:\Users\gskainth\AppData\Local\{AA39F34C-6F13-47FD-AE3F-071C5B8745A7}
2013-08-08 06:29 - 2013-08-08 06:27 - 00000000 ____D C:\Users\gskainth\AppData\Local\{3C2F7639-C843-4034-9793-32431ADABB51}
2013-08-07 22:13 - 2013-08-07 22:13 - 00012116 _____ C:\Users\gskainth\Desktop\employees.htm
2013-08-07 20:58 - 2013-08-07 20:58 - 00000000 ____D C:\Users\gskainth\AppData\Local\{6A67CCC3-A3C0-44AD-B8A2-D4BFE3FF6ED2}
2013-08-07 07:54 - 2013-07-29 21:10 - 00000000 ____D C:\Users\gskainth\Desktop\New folder
2013-08-06 22:41 - 2011-08-16 18:49 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Mozilla
2013-08-06 22:25 - 2013-07-07 19:49 - 00000000 ____D C:\Program Files (x86)\DRoster
2013-08-05 09:08 - 2009-07-14 00:08 - 00032564 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-04 17:18 - 2013-08-04 17:16 - 00000000 ____D C:\Users\gskainth\Desktop\schedules
2013-08-03 23:23 - 2013-08-03 23:21 - 01248931 _____ C:\Users\gskainth\Desktop\WinnipegAll.xlsx
2013-08-03 00:40 - 2013-07-06 09:46 - 00000000 ____D C:\ProgramData\firebird
2013-08-03 00:02 - 2013-08-03 00:02 - 00688992 ____R (Swearware) C:\Users\gskainth\Desktop\dds.com
2013-08-03 00:01 - 2013-08-03 00:01 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Malwarebytes
2013-08-03 00:00 - 2013-08-03 00:00 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-03 00:00 - 2013-08-03 00:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-02 13:13 - 2013-08-02 13:11 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\Sierra Wireless
2013-08-02 13:12 - 2013-08-02 13:12 - 00002178 _____ C:\Users\Public\Desktop\Rogers Connection Manager.lnk
2013-08-02 13:12 - 2013-08-02 13:12 - 00000000 ____D C:\Program Files (x86)\Rogers
2013-08-02 13:12 - 2013-08-02 13:11 - 00000000 ____D C:\Program Files (x86)\Sierra Wireless Inc
2013-08-02 13:11 - 2013-08-02 13:11 - 00000000 ____D C:\ProgramData\Sierra Wireless
2013-07-29 22:15 - 2013-07-29 22:15 - 00000000 ____D C:\Users\gskainth\AppData\Roaming\DownLite
2013-07-29 22:13 - 2013-07-29 22:13 - 00001852 _____ C:\Users\Public\Desktop\Vuze.lnk
2013-07-29 22:13 - 2013-07-29 22:13 - 00000000 ____D C:\Users\gskainth\.swt
2013-07-29 22:13 - 2013-07-29 22:12 - 00000000 ____D C:\Program Files (x86)\Vuze
2013-07-29 21:49 - 2013-07-29 21:49 - 00002956 _____ C:\Windows\System32\Tasks\{54BE7F6F-C6DB-43B5-9612-7310C4B132EE}
2013-07-29 21:49 - 2013-07-29 21:49 - 00002956 _____ C:\Windows\System32\Tasks\{40B03322-4137-4492-AB63-403BDBE67148}
2013-07-28 23:08 - 2013-07-28 23:08 - 00003898 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-28 23:08 - 2013-07-28 23:08 - 00003646 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-28 20:23 - 2013-07-28 18:56 - 07557120 _____ C:\Users\gskainth\Documents\Call Center.ssf
2013-07-28 18:56 - 2013-07-28 18:56 - 00000000 ____D C:\ProgramData\Business Management Systems
2013-07-28 01:09 - 2013-07-28 01:09 - 00000000 ____D C:\Users\gskainth\AppData\Local\Business_Management_Syste
2013-07-26 00:13 - 2013-08-14 20:27 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 00:13 - 2013-08-14 20:27 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 00:13 - 2013-08-14 20:27 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 00:12 - 2013-08-14 20:27 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 00:12 - 2013-08-14 20:27 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-25 22:35 - 2013-08-14 20:27 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-25 22:13 - 2013-08-14 20:27 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-25 22:13 - 2013-08-14 20:27 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-25 22:12 - 2013-08-14 20:27 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-25 22:11 - 2013-08-14 20:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-25 22:11 - 2013-08-14 20:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-25 21:49 - 2013-08-14 20:27 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-25 21:39 - 2013-08-14 20:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-25 20:59 - 2013-08-14 20:27 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-25 04:25 - 2013-08-14 19:00 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-25 03:57 - 2013-08-14 19:00 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-21 23:35 - 2013-07-21 23:34 - 00000000 ____D C:\Users\gskainth\AppData\Local\Deployment
2013-07-21 23:34 - 2013-07-21 23:34 - 00000000 ____D C:\Users\gskainth\AppData\Local\Apps\2.0
2013-07-21 21:22 - 2013-07-21 21:22 - 00000000 ____D C:\Users\gskainth\AppData\Local\{83C37563-7F13-4BDF-B64F-16E55EDEB4A1}
2013-07-18 20:58 - 2013-08-14 19:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-07-18 20:41 - 2013-08-14 19:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
Files to move or delete:
====================
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install\{bda4f5ac-389f-645b-5c3c-87463bee4c98}
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-12 22:41
==================== End Of Log ============================