Like many here, I too have this sirefef virus (appears to be at least a trojan). My computer keeps restarting after booting. I have a Windows 7 64 bit computer. I followed initial similar instructions in other threads:
"For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.
Plug the flashdrive into the infected PC.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options:
Scan result of Farbar Recovery Scan Tool Version: 30-06-2012 04
Ran by SYSTEM at 30-06-2012 23:48:00
Running from H:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2779432 2011-12-26] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167704 2011-10-20] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [392472 2011-10-20] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [416024 2011-10-20] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12661352 2011-07-31] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VirtualCloneDrive] "D:\Programs\VirtualCloneDrive\VCDDaemon.exe" /s [x]
HKLM-x32\...\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] "D:\Programs\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]
HKU\Robert\...\Run: [MusicManager] "C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [13806592 2012-06-01] (Google Inc.)
HKU\Robert\...\Run: [Unified Remote v2] C:\Program Files (x86)\Unified Remote\RemoteServer.exe [226816 2011-12-02] (Unified Remote)
HKU\Robert\...\Run: [Google Update] "C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-12-25] (Google Inc.)
HKU\Robert\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-19] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\SolidWorks Background Downloader.lnk
ShortcutTarget: SolidWorks Background Downloader.lnk -> C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
Startup: C:\Users\Robert\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 ExpressCache; "C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe" [79664 2011-09-22] (Diskeeper Corporation)
3 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe" [135584 2011-12-09] (Futuremark Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656536 2011-05-05] (Intel Corporation)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
2 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
3 CoordinatorServiceHost; C:\Programs\SolidWorks\swScheduler\DTSCoordinatorService.exe [x]
4 PDMWorks Workgroup Server; C:\Programs\SolidWorks\Vault\pdmwService.exe [x]
2 SplashtopRemoteService; "C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe" [x]
2 SSUService; C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
========================== Drivers (Whitelisted) =============
3 acpials; C:\Windows\System32\Drivers\acpials.sys [9728 2009-07-13] (Microsoft Corporation)
3 anvsnddrv; C:\Windows\System32\Drivers\anvsnddrv.sys [33872 2011-11-28] (AnvSoft Inc.)
3 clwvd; C:\Windows\System32\Drivers\clwvd.sys [31216 2011-08-16] (CyberLink Corporation)
1 excfs; C:\Windows\System32\Drivers\excfs.sys [23344 2011-09-22] (Diskeeper Corporation)
0 excsd; C:\Windows\System32\Drivers\excsd.sys [80688 2011-09-22] (Diskeeper Corporation)
3 FlashUSB; C:\Windows\system32\drivers\FlashUSB_x64.sys [19968 2010-12-20] (Danish Wireless Design A/S)
1 SABI; C:\Windows\System32\Drivers\SABI.sys [13824 2009-05-27] (SAMSUNG ELECTRONICS)
2 SGDrv; C:\Windows\system32\drivers\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)
3 shspusb; C:\Windows\system32\drivers\HSPUSB.sys [24064 2010-12-20] (MobileTop)
3 ssaebus; C:\Windows\System32\Drivers\ssaebus.sys [136264 2010-12-20] (MCCI Corporation)
3 ssaeunic; C:\Windows\System32\Drivers\ssaeunic.sys [178760 2010-12-20] (MCCI Corporation)
3 sscdserd; C:\Windows\System32\Drivers\sscdserd.sys [141384 2010-12-20] (MCCI Corporation)
3 ssceserd; C:\Windows\System32\Drivers\ssceserd.sys [129024 2010-12-20] (MCCI Corporation)
3 ssm_bus; C:\Windows\System32\Drivers\ssm_bus.sys [136192 2010-12-20] (MCCI Corporation)
3 ssm_mdm; C:\Windows\System32\Drivers\ssm_mdm.sys [172032 2010-12-20] (MCCI Corporation)
3 ssuddmgr; C:\Windows\System32\Drivers\ssuddmgr.sys [202560 2011-02-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 ssudobex; C:\Windows\System32\Drivers\ssudobex.sys [202560 2011-02-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 ssudserd; C:\Windows\System32\Drivers\ssudserd.sys [202560 2011-02-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 ss_bbus; C:\Windows\System32\Drivers\ss_bbus.sys [127488 2010-12-20] (MCCI)
3 ss_bserd; C:\Windows\System32\Drivers\ss_bserd.sys [128000 2010-12-20] (MCCI Corporation)
3 ss_bus; C:\Windows\System32\Drivers\ss_bus.sys [127488 2010-12-20] (MCCI Corporation)
3 ViaUsbEtsDriver; C:\Windows\System32\drivers\ViaUsbEts.sys [21760 2008-05-29] (Via Telecom, Inc.)
3 cpuz135; \??\C:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-30 23:47 - 2012-06-30 23:48 - 00000000 ____D C:\FRST
2012-06-30 22:21 - 2012-06-30 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26551EFC42F92159
2012-06-30 22:21 - 2012-06-30 22:21 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ztgdaepm.sys
2012-06-30 22:18 - 2012-06-30 22:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B2FCBDAC23F3B4E
2012-06-30 22:14 - 2012-06-30 22:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5700CA9E4736953
2012-06-30 22:13 - 2012-06-30 22:15 - 00000494 ____A C:\Windows\Tasks\SpeedyPC Registration3.job
2012-06-30 22:13 - 2012-06-30 22:13 - 00000000 ____D C:\Users\Robert\AppData\Roaming\SpeedyPC Software
2012-06-30 22:13 - 2012-06-30 22:13 - 00000000 ____D C:\Users\Robert\AppData\Roaming\DriverCure
2012-06-30 22:12 - 2012-06-30 22:12 - 00001166 ____A C:\Users\Robert\Desktop\SpeedyPC Pro.lnk
2012-06-30 22:12 - 2012-06-30 22:12 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-06-30 22:12 - 2012-06-30 22:12 - 00000000 ____D C:\Program Files (x86)\SpeedyPC Software
2012-06-30 22:11 - 2012-06-30 22:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F905C98B4F5313
2012-06-30 22:08 - 2012-06-30 22:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7AA26374AABF56B
2012-06-30 22:05 - 2012-06-30 22:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B4F9720926DF0A61
2012-06-30 21:59 - 2012-06-30 21:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9716C049E27862B6
2012-06-30 21:53 - 2012-06-30 21:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129217ABB62BD4E1
2012-06-30 21:50 - 2012-06-30 21:50 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-30 21:50 - 2012-06-30 21:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-30 10:01 - 2012-06-30 10:01 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-23 14:44 - 2012-06-23 14:44 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-06-23 14:00 - 2012-06-23 14:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2012-06-23 13:56 - 2009-08-21 00:52 - 00079976 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\xusb21.sys
2012-06-23 13:56 - 2009-08-13 21:40 - 01436920 ____A (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01009.dll
2012-06-23 13:52 - 2012-06-23 13:52 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2012-06-21 09:38 - 2012-06-23 18:15 - 00000000 ____D C:\Windows\rescache
2012-06-21 08:47 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 08:47 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 08:47 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 08:47 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 08:47 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-14 08:25 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 08:25 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 08:25 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 08:25 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 08:25 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 08:25 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 08:25 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 08:25 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 08:25 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 08:25 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 08:25 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 08:25 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 08:25 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 08:25 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 08:25 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 08:25 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 08:25 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 08:25 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 08:25 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 08:25 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 08:25 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 08:25 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 08:25 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 08:25 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 08:25 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 08:25 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 08:25 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 08:25 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 06:41 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 06:41 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 06:41 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 06:41 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 06:41 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 06:41 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 06:41 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 06:41 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 06:41 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 06:41 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 06:41 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 06:41 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 06:41 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 06:41 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 06:41 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 06:41 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 06:41 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
============ 3 Months Modified Files ========================
2012-06-30 22:21 - 2012-06-30 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26551EFC42F92159
2012-06-30 22:21 - 2012-06-30 22:21 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ztgdaepm.sys
2012-06-30 22:19 - 2009-07-13 21:13 - 00783224 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-30 22:18 - 2012-06-30 22:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B2FCBDAC23F3B4E
2012-06-30 22:15 - 2012-06-30 22:13 - 00000494 ____A C:\Windows\Tasks\SpeedyPC Registration3.job
2012-06-30 22:15 - 2012-04-25 11:39 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-30 22:15 - 2011-11-11 12:40 - 00043664 ____A C:\Windows\setupact.log
2012-06-30 22:15 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-30 22:14 - 2012-06-30 22:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5700CA9E4736953
2012-06-30 22:12 - 2012-06-30 22:12 - 00001166 ____A C:\Users\Robert\Desktop\SpeedyPC Pro.lnk
2012-06-30 22:11 - 2012-06-30 22:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F905C98B4F5313
2012-06-30 22:08 - 2012-06-30 22:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7AA26374AABF56B
2012-06-30 22:05 - 2012-06-30 22:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B4F9720926DF0A61
2012-06-30 22:04 - 2011-11-21 10:41 - 01219548 ____A C:\Windows\WindowsUpdate.log
2012-06-30 21:59 - 2012-06-30 21:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9716C049E27862B6
2012-06-30 21:53 - 2012-06-30 21:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129217ABB62BD4E1
2012-06-30 21:52 - 2011-12-25 11:21 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1617886939-4081324411-3031297083-1000UA.job
2012-06-30 21:50 - 2011-11-09 13:59 - 00797374 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-30 21:50 - 2011-11-09 13:59 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-30 21:44 - 2012-04-25 11:39 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-30 12:54 - 2011-12-25 11:23 - 00002375 ____A C:\Users\Robert\Desktop\Google Chrome.lnk
2012-06-30 09:01 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-30 09:01 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-30 07:52 - 2011-12-25 11:21 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1617886939-4081324411-3031297083-1000Core.job
2012-06-23 14:00 - 2012-06-23 14:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2012-06-23 13:52 - 2011-12-26 07:57 - 00139583 ____A C:\Windows\DirectX.log
2012-06-14 08:50 - 2009-07-13 20:45 - 04996032 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 08:30 - 2011-11-09 17:18 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-02 14:19 - 2012-06-21 08:47 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 08:47 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 08:47 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 08:47 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 08:47 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 10:42 - 2011-12-25 14:23 - 00001024 ____A C:\Users\Robert\Desktop\Dropbox.lnk
2012-05-29 19:42 - 2012-05-29 19:42 - 00007605 ____A C:\Users\Robert\AppData\Local\Resmon.ResmonCfg
2012-05-21 21:49 - 2012-05-21 21:49 - 00262144 ____A C:\Windows\Minidump\052112-14835-01.dmp
2012-05-19 13:08 - 2011-12-25 14:13 - 00000914 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-17 18:47 - 2012-06-14 08:25 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 08:25 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 08:25 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 08:25 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 08:25 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 08:25 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 08:25 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 08:25 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 08:25 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 08:25 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 08:25 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 08:25 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 08:25 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 08:25 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 08:25 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 08:25 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 08:25 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 08:25 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 08:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 08:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 08:25 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 08:25 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 08:25 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 08:25 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 08:25 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 08:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 08:25 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 08:25 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 06:41 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-07 17:59 - 2011-12-25 15:13 - 00007124 ____A C:\Windows\PFRO.log
2012-05-05 06:53 - 2012-04-25 12:30 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-05 06:53 - 2012-04-25 11:41 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-05 06:53 - 2011-11-09 18:39 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-04 03:06 - 2012-06-13 06:41 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 06:41 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 06:41 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-02 15:42 - 2012-05-02 15:42 - 04960718 ____A C:\Users\Robert\Downloads\Pazera_Free_MKV_to_AVI_Converter.zip
2012-04-30 21:40 - 2012-06-13 06:41 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 14:13 - 2012-04-30 14:12 - 00013821 ____A C:\Users\Robert\Documents\Install STAR WARS The Old Republic.log
2012-04-29 22:50 - 2012-04-29 22:50 - 00525792 ____A (Microsoft Corporation) C:\Windows\DIFxAPI.dll
2012-04-29 22:50 - 2012-04-29 22:49 - 00002338 ____A C:\RHDSetup.log
2012-04-29 22:50 - 2012-04-29 22:49 - 00000206 ____A C:\setup.log
2012-04-29 19:11 - 2012-04-29 19:11 - 00021712 ____A (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
2012-04-27 19:55 - 2012-06-13 06:41 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 22:50 - 2012-04-25 22:50 - 00000637 ____A C:\Users\Robert\Desktop\Games.lnk
2012-04-25 22:35 - 2012-04-25 22:35 - 00178800 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2012-04-25 21:41 - 2012-06-13 06:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 06:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 06:41 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 11:39 - 2012-04-25 11:39 - 00740104 ____A (Google Inc.) C:\Users\Robert\Downloads\googledrivesync.exe
2012-04-23 21:37 - 2012-06-13 06:41 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 06:41 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 06:41 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 06:41 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 06:41 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 06:41 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 16:17 - 2012-04-03 13:16 - 00000971 ____A C:\Users\Public\Desktop\MATLAB R2011a.lnk
2012-04-18 18:43 - 2012-04-18 18:43 - 05933164 ____A (Jacek Pazera ) C:\Users\Robert\Downloads\Pazera_Free_MP4_to_AVI_Converter.exe
2012-04-07 04:31 - 2012-06-13 06:41 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 06:41 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-04-05 21:34 - 2012-04-05 21:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 00054784 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 00050176 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-04-04 21:54 - 2012-04-04 21:54 - 00001750 ____A C:\Users\Public\Desktop\iTunes.lnk
ZeroAccess:
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\L
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\L\00000004.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\L\55490ac4
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\00000008.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\80000000.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\80000032.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\80000064.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe
[2011-10-16 22:08] - [2011-03-01 00:07] - 0027648 ____A (Microsoft Corporation) 6F68F63794097E54F36474ED4384B759
C:\Windows\SysWOW64\svchost.exe
[2011-10-16 22:08] - [2011-03-01 00:05] - 0021504 ____A (Microsoft Corporation) ECDB182F885292145826C58252B53000
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2011-10-16 22:08] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8105.55 MB
Available physical RAM: 7283.71 MB
Total Pagefile: 8103.75 MB
Available Pagefile: 7277.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Windows) (Fixed) (Total:50 GB) (Free:8.41 GB) NTFS
2 Drive e: (TEMP_PART01) (Fixed) (Total:625.94 GB) (Free:432.39 GB) NTFS
3 Drive f: (SAMSUNG_REC) (Fixed) (Total:22.59 GB) (Free:2.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: (USB20FD) (Removable) (Total:3.77 GB) (Free:3.76 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 7641 MB 0 B
Disk 1 Online 698 GB 0 B
Disk 2 Online 3864 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7639 MB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 73
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 50 GB 101 MB
Partition 3 Primary 625 GB 50 GB
Partition 4 Recovery 22 GB 676 GB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Windows NTFS Partition 50 GB Healthy
==================================================================================
Disk: 1
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E TEMP_PART01 NTFS Partition 625 GB Healthy
==================================================================================
Disk: 1
Partition 4
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F SAMSUNG_REC NTFS Partition 22 GB Healthy Hidden
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3863 MB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H USB20FD FAT32 Removable 3863 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 11:55
======================= End Of Log ==========================
"For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.
Plug the flashdrive into the infected PC.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
- Restart the computer.
- As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
- Use the arrow keys to select the Repair your computer menu item.
- Select US as the keyboard language settings, and then click Next.
- Select the operating system you want to repair, and then click Next.
- Select your user account an click Next.
To enter System Recovery Options by using Windows installation disc:
- Insert the installation disc.
- Restart your computer.
- If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
- Click Repair your computer.
- Select US as the keyboard language settings, and then click Next.
- Select the operating system you want to repair, and then click Next.
- Select your user account and click Next.
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
- Select Command Prompt
- In the command window type in notepad and press Enter.
- The notepad opens. Under File menu select Open.
- Select "Computer" and find your flash drive letter and close the notepad.
- In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive. - The tool will start to run.
- When the tool opens click Yes to disclaimer.
- Press Scan button.
- It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply."
Scan result of Farbar Recovery Scan Tool Version: 30-06-2012 04
Ran by SYSTEM at 30-06-2012 23:48:00
Running from H:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2779432 2011-12-26] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167704 2011-10-20] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [392472 2011-10-20] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [416024 2011-10-20] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12661352 2011-07-31] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VirtualCloneDrive] "D:\Programs\VirtualCloneDrive\VCDDaemon.exe" /s [x]
HKLM-x32\...\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] "D:\Programs\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]
HKU\Robert\...\Run: [MusicManager] "C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [13806592 2012-06-01] (Google Inc.)
HKU\Robert\...\Run: [Unified Remote v2] C:\Program Files (x86)\Unified Remote\RemoteServer.exe [226816 2011-12-02] (Unified Remote)
HKU\Robert\...\Run: [Google Update] "C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-12-25] (Google Inc.)
HKU\Robert\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-19] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\SolidWorks Background Downloader.lnk
ShortcutTarget: SolidWorks Background Downloader.lnk -> C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
Startup: C:\Users\Robert\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 ExpressCache; "C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe" [79664 2011-09-22] (Diskeeper Corporation)
3 Futuremark SystemInfo Service; "C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe" [135584 2011-12-09] (Futuremark Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656536 2011-05-05] (Intel Corporation)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
2 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
3 CoordinatorServiceHost; C:\Programs\SolidWorks\swScheduler\DTSCoordinatorService.exe [x]
4 PDMWorks Workgroup Server; C:\Programs\SolidWorks\Vault\pdmwService.exe [x]
2 SplashtopRemoteService; "C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe" [x]
2 SSUService; C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
========================== Drivers (Whitelisted) =============
3 acpials; C:\Windows\System32\Drivers\acpials.sys [9728 2009-07-13] (Microsoft Corporation)
3 anvsnddrv; C:\Windows\System32\Drivers\anvsnddrv.sys [33872 2011-11-28] (AnvSoft Inc.)
3 clwvd; C:\Windows\System32\Drivers\clwvd.sys [31216 2011-08-16] (CyberLink Corporation)
1 excfs; C:\Windows\System32\Drivers\excfs.sys [23344 2011-09-22] (Diskeeper Corporation)
0 excsd; C:\Windows\System32\Drivers\excsd.sys [80688 2011-09-22] (Diskeeper Corporation)
3 FlashUSB; C:\Windows\system32\drivers\FlashUSB_x64.sys [19968 2010-12-20] (Danish Wireless Design A/S)
1 SABI; C:\Windows\System32\Drivers\SABI.sys [13824 2009-05-27] (SAMSUNG ELECTRONICS)
2 SGDrv; C:\Windows\system32\drivers\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)
3 shspusb; C:\Windows\system32\drivers\HSPUSB.sys [24064 2010-12-20] (MobileTop)
3 ssaebus; C:\Windows\System32\Drivers\ssaebus.sys [136264 2010-12-20] (MCCI Corporation)
3 ssaeunic; C:\Windows\System32\Drivers\ssaeunic.sys [178760 2010-12-20] (MCCI Corporation)
3 sscdserd; C:\Windows\System32\Drivers\sscdserd.sys [141384 2010-12-20] (MCCI Corporation)
3 ssceserd; C:\Windows\System32\Drivers\ssceserd.sys [129024 2010-12-20] (MCCI Corporation)
3 ssm_bus; C:\Windows\System32\Drivers\ssm_bus.sys [136192 2010-12-20] (MCCI Corporation)
3 ssm_mdm; C:\Windows\System32\Drivers\ssm_mdm.sys [172032 2010-12-20] (MCCI Corporation)
3 ssuddmgr; C:\Windows\System32\Drivers\ssuddmgr.sys [202560 2011-02-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 ssudobex; C:\Windows\System32\Drivers\ssudobex.sys [202560 2011-02-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 ssudserd; C:\Windows\System32\Drivers\ssudserd.sys [202560 2011-02-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 ss_bbus; C:\Windows\System32\Drivers\ss_bbus.sys [127488 2010-12-20] (MCCI)
3 ss_bserd; C:\Windows\System32\Drivers\ss_bserd.sys [128000 2010-12-20] (MCCI Corporation)
3 ss_bus; C:\Windows\System32\Drivers\ss_bus.sys [127488 2010-12-20] (MCCI Corporation)
3 ViaUsbEtsDriver; C:\Windows\System32\drivers\ViaUsbEts.sys [21760 2008-05-29] (Via Telecom, Inc.)
3 cpuz135; \??\C:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-30 23:47 - 2012-06-30 23:48 - 00000000 ____D C:\FRST
2012-06-30 22:21 - 2012-06-30 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26551EFC42F92159
2012-06-30 22:21 - 2012-06-30 22:21 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ztgdaepm.sys
2012-06-30 22:18 - 2012-06-30 22:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B2FCBDAC23F3B4E
2012-06-30 22:14 - 2012-06-30 22:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5700CA9E4736953
2012-06-30 22:13 - 2012-06-30 22:15 - 00000494 ____A C:\Windows\Tasks\SpeedyPC Registration3.job
2012-06-30 22:13 - 2012-06-30 22:13 - 00000000 ____D C:\Users\Robert\AppData\Roaming\SpeedyPC Software
2012-06-30 22:13 - 2012-06-30 22:13 - 00000000 ____D C:\Users\Robert\AppData\Roaming\DriverCure
2012-06-30 22:12 - 2012-06-30 22:12 - 00001166 ____A C:\Users\Robert\Desktop\SpeedyPC Pro.lnk
2012-06-30 22:12 - 2012-06-30 22:12 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-06-30 22:12 - 2012-06-30 22:12 - 00000000 ____D C:\Program Files (x86)\SpeedyPC Software
2012-06-30 22:11 - 2012-06-30 22:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F905C98B4F5313
2012-06-30 22:08 - 2012-06-30 22:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7AA26374AABF56B
2012-06-30 22:05 - 2012-06-30 22:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B4F9720926DF0A61
2012-06-30 21:59 - 2012-06-30 21:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9716C049E27862B6
2012-06-30 21:53 - 2012-06-30 21:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129217ABB62BD4E1
2012-06-30 21:50 - 2012-06-30 21:50 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-30 21:50 - 2012-06-30 21:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-30 10:01 - 2012-06-30 10:01 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-23 14:44 - 2012-06-23 14:44 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-06-23 14:00 - 2012-06-23 14:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2012-06-23 13:56 - 2009-08-21 00:52 - 00079976 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\xusb21.sys
2012-06-23 13:56 - 2009-08-13 21:40 - 01436920 ____A (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01009.dll
2012-06-23 13:52 - 2012-06-23 13:52 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2012-06-21 09:38 - 2012-06-23 18:15 - 00000000 ____D C:\Windows\rescache
2012-06-21 08:47 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 08:47 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 08:47 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 08:47 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 08:47 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 08:47 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-14 08:25 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 08:25 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 08:25 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 08:25 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 08:25 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 08:25 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 08:25 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 08:25 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 08:25 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 08:25 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 08:25 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 08:25 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 08:25 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 08:25 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 08:25 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 08:25 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 08:25 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 08:25 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 08:25 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 08:25 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 08:25 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 08:25 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 08:25 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 08:25 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 08:25 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 08:25 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 08:25 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 08:25 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 06:41 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 06:41 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 06:41 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 06:41 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 06:41 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 06:41 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 06:41 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 06:41 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 06:41 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 06:41 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 06:41 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 06:41 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 06:41 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 06:41 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 06:41 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 06:41 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 06:41 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
============ 3 Months Modified Files ========================
2012-06-30 22:21 - 2012-06-30 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.26551EFC42F92159
2012-06-30 22:21 - 2012-06-30 22:21 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ztgdaepm.sys
2012-06-30 22:19 - 2009-07-13 21:13 - 00783224 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-30 22:18 - 2012-06-30 22:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B2FCBDAC23F3B4E
2012-06-30 22:15 - 2012-06-30 22:13 - 00000494 ____A C:\Windows\Tasks\SpeedyPC Registration3.job
2012-06-30 22:15 - 2012-04-25 11:39 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-30 22:15 - 2011-11-11 12:40 - 00043664 ____A C:\Windows\setupact.log
2012-06-30 22:15 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-30 22:14 - 2012-06-30 22:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5700CA9E4736953
2012-06-30 22:12 - 2012-06-30 22:12 - 00001166 ____A C:\Users\Robert\Desktop\SpeedyPC Pro.lnk
2012-06-30 22:11 - 2012-06-30 22:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5F905C98B4F5313
2012-06-30 22:08 - 2012-06-30 22:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E7AA26374AABF56B
2012-06-30 22:05 - 2012-06-30 22:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B4F9720926DF0A61
2012-06-30 22:04 - 2011-11-21 10:41 - 01219548 ____A C:\Windows\WindowsUpdate.log
2012-06-30 21:59 - 2012-06-30 21:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9716C049E27862B6
2012-06-30 21:53 - 2012-06-30 21:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129217ABB62BD4E1
2012-06-30 21:52 - 2011-12-25 11:21 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1617886939-4081324411-3031297083-1000UA.job
2012-06-30 21:50 - 2011-11-09 13:59 - 00797374 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-30 21:50 - 2011-11-09 13:59 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-30 21:44 - 2012-04-25 11:39 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-30 12:54 - 2011-12-25 11:23 - 00002375 ____A C:\Users\Robert\Desktop\Google Chrome.lnk
2012-06-30 09:01 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-30 09:01 - 2009-07-13 20:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-30 07:52 - 2011-12-25 11:21 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1617886939-4081324411-3031297083-1000Core.job
2012-06-23 14:00 - 2012-06-23 14:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2012-06-23 13:52 - 2011-12-26 07:57 - 00139583 ____A C:\Windows\DirectX.log
2012-06-14 08:50 - 2009-07-13 20:45 - 04996032 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 08:30 - 2011-11-09 17:18 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-02 14:19 - 2012-06-21 08:47 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 08:47 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 08:47 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 08:47 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 08:47 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 08:47 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 10:42 - 2011-12-25 14:23 - 00001024 ____A C:\Users\Robert\Desktop\Dropbox.lnk
2012-05-29 19:42 - 2012-05-29 19:42 - 00007605 ____A C:\Users\Robert\AppData\Local\Resmon.ResmonCfg
2012-05-21 21:49 - 2012-05-21 21:49 - 00262144 ____A C:\Windows\Minidump\052112-14835-01.dmp
2012-05-19 13:08 - 2011-12-25 14:13 - 00000914 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-17 18:47 - 2012-06-14 08:25 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-14 08:25 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-14 08:25 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-14 08:25 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-14 08:25 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-14 08:25 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-14 08:25 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-14 08:25 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-14 08:25 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-14 08:25 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-14 08:25 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-14 08:25 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-14 08:25 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-14 08:25 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-14 08:25 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-14 08:25 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-14 08:25 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-14 08:25 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-14 08:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 08:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-14 08:25 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-14 08:25 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 08:25 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-14 08:25 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 08:25 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-14 08:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 08:25 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 08:25 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 06:41 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-07 17:59 - 2011-12-25 15:13 - 00007124 ____A C:\Windows\PFRO.log
2012-05-05 06:53 - 2012-04-25 12:30 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-05 06:53 - 2012-04-25 11:41 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-05 06:53 - 2011-11-09 18:39 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-04 03:06 - 2012-06-13 06:41 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 06:41 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 06:41 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-02 15:42 - 2012-05-02 15:42 - 04960718 ____A C:\Users\Robert\Downloads\Pazera_Free_MKV_to_AVI_Converter.zip
2012-04-30 21:40 - 2012-06-13 06:41 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 14:13 - 2012-04-30 14:12 - 00013821 ____A C:\Users\Robert\Documents\Install STAR WARS The Old Republic.log
2012-04-29 22:50 - 2012-04-29 22:50 - 00525792 ____A (Microsoft Corporation) C:\Windows\DIFxAPI.dll
2012-04-29 22:50 - 2012-04-29 22:49 - 00002338 ____A C:\RHDSetup.log
2012-04-29 22:50 - 2012-04-29 22:49 - 00000206 ____A C:\setup.log
2012-04-29 19:11 - 2012-04-29 19:11 - 00021712 ____A (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
2012-04-27 19:55 - 2012-06-13 06:41 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 22:50 - 2012-04-25 22:50 - 00000637 ____A C:\Users\Robert\Desktop\Games.lnk
2012-04-25 22:35 - 2012-04-25 22:35 - 00178800 ____A (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2012-04-25 21:41 - 2012-06-13 06:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 06:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 06:41 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-25 11:39 - 2012-04-25 11:39 - 00740104 ____A (Google Inc.) C:\Users\Robert\Downloads\googledrivesync.exe
2012-04-23 21:37 - 2012-06-13 06:41 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 06:41 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 06:41 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 06:41 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 06:41 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 06:41 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 16:17 - 2012-04-03 13:16 - 00000971 ____A C:\Users\Public\Desktop\MATLAB R2011a.lnk
2012-04-18 18:43 - 2012-04-18 18:43 - 05933164 ____A (Jacek Pazera ) C:\Users\Robert\Downloads\Pazera_Free_MP4_to_AVI_Converter.exe
2012-04-07 04:31 - 2012-06-13 06:41 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 06:41 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-04-05 21:34 - 2012-04-05 21:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 00054784 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 00050176 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-04-04 21:54 - 2012-04-04 21:54 - 00001750 ____A C:\Users\Public\Desktop\iTunes.lnk
ZeroAccess:
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\L
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\L\00000004.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\L\55490ac4
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\00000008.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\80000000.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\80000032.@
C:\Windows\Installer\{5bcd3c61-957e-6ba1-4eba-d62c31cda963}\U\80000064.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe
[2011-10-16 22:08] - [2011-03-01 00:07] - 0027648 ____A (Microsoft Corporation) 6F68F63794097E54F36474ED4384B759
C:\Windows\SysWOW64\svchost.exe
[2011-10-16 22:08] - [2011-03-01 00:05] - 0021504 ____A (Microsoft Corporation) ECDB182F885292145826C58252B53000
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2011-10-16 22:08] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8105.55 MB
Available physical RAM: 7283.71 MB
Total Pagefile: 8103.75 MB
Available Pagefile: 7277.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Windows) (Fixed) (Total:50 GB) (Free:8.41 GB) NTFS
2 Drive e: (TEMP_PART01) (Fixed) (Total:625.94 GB) (Free:432.39 GB) NTFS
3 Drive f: (SAMSUNG_REC) (Fixed) (Total:22.59 GB) (Free:2.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: (USB20FD) (Removable) (Total:3.77 GB) (Free:3.76 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 7641 MB 0 B
Disk 1 Online 698 GB 0 B
Disk 2 Online 3864 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7639 MB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 73
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 50 GB 101 MB
Partition 3 Primary 625 GB 50 GB
Partition 4 Recovery 22 GB 676 GB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Windows NTFS Partition 50 GB Healthy
==================================================================================
Disk: 1
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E TEMP_PART01 NTFS Partition 625 GB Healthy
==================================================================================
Disk: 1
Partition 4
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F SAMSUNG_REC NTFS Partition 22 GB Healthy Hidden
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3863 MB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H USB20FD FAT32 Removable 3863 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 11:55
======================= End Of Log ==========================