My wife has managed to get this on her laptop, and it's beyond me to get it removed.
I've read other threads about this virus and done what I could,
The operating system is Windows 7 Home Premium 64
Thanks in advance.
Here is the farbar log
Scan result of Farbar Recovery Scan Tool Version: 20-06-2012 04
Ran by SYSTEM at 20-06-2012 23:14:14
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-23] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [444416 2009-06-28] (IDT, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-16] (Dell Inc.)
HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [3189016 2009-10-01] (Dell Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" [148888 2010-02-08] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.)
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [409744 2009-06-24] (Creative Technology Ltd)
HKLM-x32\...\Run: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [498160 2009-10-15] ()
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKU\Nicola\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3883856 2009-07-26] (Microsoft Corporation)
HKU\Nicola\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\Nicola\...\Run: [Google Update] "C:\Users\Nicola\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-26] (Google Inc.)
HKLM-x32\...\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe [165104 2009-09-17] (Softthinks)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Nicola\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-10-13] (Microsoft Corporation)
3 FLEXnet Licensing Service; "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [654848 2010-05-06] (Macrovision Europe Ltd.)
2 lxdx_device; C:\Windows\system32\lxdxcoms.exe -service [1039872 2009-10-16] ( )
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-28] (IDT, Inc.)
========================== Drivers (Whitelisted) =============
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-20 23:14 - 2012-06-20 23:14 - 00000000 ____D C:\FRST
2012-06-18 16:28 - 2012-06-18 16:58 - 00000000 ____D C:\Windows\pss
2012-06-18 15:48 - 2012-06-18 15:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-18 15:47 - 2012-06-18 15:48 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 15:31 - 2012-06-18 15:39 - 00000000 ____D C:\Users\Nicola\Application Data\Azureus
2012-06-18 15:31 - 2012-06-18 15:39 - 00000000 ____D C:\Users\Nicola\AppData\Roaming\Azureus
2012-06-18 15:31 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\.swt
2012-06-14 06:17 - 2012-05-17 21:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 06:17 - 2012-05-17 21:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 06:17 - 2012-05-17 21:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 06:17 - 2012-05-17 20:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 06:17 - 2012-05-17 20:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 06:17 - 2012-05-17 20:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 06:17 - 2012-05-17 20:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 06:17 - 2012-05-17 20:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 06:17 - 2012-05-17 20:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 06:17 - 2012-05-17 20:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 06:17 - 2012-05-17 20:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 06:17 - 2012-05-17 20:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 06:17 - 2012-05-17 20:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 06:17 - 2012-05-17 20:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 06:17 - 2012-05-17 18:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 06:17 - 2012-05-17 17:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 06:17 - 2012-05-17 17:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 06:17 - 2012-05-17 17:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 06:17 - 2012-05-17 17:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 06:17 - 2012-05-17 17:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 06:17 - 2012-05-17 17:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 06:17 - 2012-05-17 17:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 06:17 - 2012-05-17 17:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 06:17 - 2012-05-17 17:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 06:17 - 2012-05-17 17:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 06:17 - 2012-05-17 17:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 06:17 - 2012-05-17 17:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 06:17 - 2012-05-17 17:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-14 05:29 - 2012-05-14 20:32 - 03144192 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-14 05:29 - 2012-05-04 05:52 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-14 05:29 - 2012-05-04 05:08 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-14 05:29 - 2012-05-04 05:08 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-14 05:29 - 2012-05-02 00:32 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-14 05:29 - 2012-04-27 22:50 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-14 05:29 - 2012-04-26 00:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-14 05:29 - 2012-04-26 00:34 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-14 05:29 - 2012-04-26 00:28 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-14 05:29 - 2012-04-24 00:59 - 01460224 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-14 05:29 - 2012-04-24 00:59 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-14 05:29 - 2012-04-24 00:59 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-14 05:29 - 2012-04-23 23:47 - 01156608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-14 05:29 - 2012-04-23 23:47 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-14 05:29 - 2012-04-23 23:47 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-14 05:29 - 2012-04-07 07:18 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-14 05:29 - 2012-04-07 06:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-07 05:47 - 2012-06-07 05:47 - 00000000 __SHD C:\Windows\System32\%APPDATA%
============ 3 Months Modified Files and Folders =============
2012-06-20 23:14 - 2012-06-20 23:14 - 00000000 ____D C:\FRST
2012-06-20 16:04 - 2010-05-05 15:14 - 00000000 ____D C:\Users\Nicola\Tracing
2012-06-20 16:04 - 2010-05-05 14:49 - 00000000 ____D C:\Users\Nicola\Local Settings\SoftThinks
2012-06-20 16:04 - 2010-05-05 14:49 - 00000000 ____D C:\Users\Nicola\Local Settings\Application Data\SoftThinks
2012-06-20 16:04 - 2010-05-05 14:49 - 00000000 ____D C:\Users\Nicola\AppData\Local\SoftThinks
2012-06-20 16:03 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-20 16:03 - 2009-07-13 23:51 - 00065755 ____A C:\Windows\setupact.log
2012-06-20 16:00 - 2010-02-08 20:42 - 00474078 ____A C:\Windows\PFRO.log
2012-06-18 16:58 - 2012-06-18 16:28 - 00000000 ____D C:\Windows\pss
2012-06-18 16:55 - 2011-03-06 15:07 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-18 16:28 - 2009-07-14 00:10 - 01874521 ____A C:\Windows\WindowsUpdate.log
2012-06-18 16:28 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-18 16:28 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-18 16:21 - 2010-02-08 19:30 - 00000071 ____A C:\Windows\SysWOW64\ToasterLauncherLog.log
2012-06-18 16:09 - 2010-02-08 19:01 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2012-06-18 16:02 - 2012-01-11 14:58 - 00000000 __SHD C:\Users\Nicola\Local Settings\Application Data\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
2012-06-18 16:02 - 2012-01-11 14:58 - 00000000 __SHD C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
2012-06-18 15:59 - 2012-01-11 14:58 - 00000000 __SHD C:\Users\Nicola\Local Settings\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
2012-06-18 15:56 - 2011-03-06 16:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-18 15:48 - 2012-06-18 15:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-18 15:48 - 2012-06-18 15:47 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 15:48 - 2011-03-06 16:40 - 00739730 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-18 15:39 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\Application Data\Azureus
2012-06-18 15:39 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\AppData\Roaming\Azureus
2012-06-18 15:39 - 2012-03-26 14:34 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3205693759-3490152921-415697551-1001UA.job
2012-06-18 15:31 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\.swt
2012-06-18 15:31 - 2010-05-05 14:49 - 00000000 ____D C:\users\Nicola
2012-06-16 14:39 - 2012-03-26 14:34 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3205693759-3490152921-415697551-1001Core.job
2012-06-14 09:45 - 2009-07-13 23:45 - 02351776 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 06:25 - 2010-02-08 19:04 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-14 06:25 - 2010-02-08 19:04 - 00000000 ____D C:\Users\All Users\Application Data\Microsoft Help
2012-06-14 06:24 - 2009-07-14 00:13 - 00739950 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-12 06:40 - 2012-03-26 14:36 - 00002407 ____A C:\Users\Nicola\Desktop\Google Chrome.lnk
2012-06-07 05:47 - 2012-06-07 05:47 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-30 14:04 - 2012-02-20 10:03 - 00000000 ____D C:\Users\Nicola\CV
2012-05-26 15:24 - 2012-04-22 03:34 - 00000050 ____A C:\Windows\bsm.ini
2012-05-26 15:10 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2012-05-17 21:47 - 2012-06-14 06:17 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 21:16 - 2012-06-14 06:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 21:06 - 2012-06-14 06:17 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 20:59 - 2012-06-14 06:17 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 20:59 - 2012-06-14 06:17 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 20:58 - 2012-06-14 06:17 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 20:58 - 2012-06-14 06:17 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 20:56 - 2012-06-14 06:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 20:55 - 2012-06-14 06:17 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 20:55 - 2012-06-14 06:17 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 20:54 - 2012-06-14 06:17 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 20:51 - 2012-06-14 06:17 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 20:51 - 2012-06-14 06:17 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 20:47 - 2012-06-14 06:17 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 18:11 - 2012-06-14 06:17 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 17:48 - 2012-06-14 06:17 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 17:45 - 2012-06-14 06:17 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 17:36 - 2012-06-14 06:17 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 17:35 - 2012-06-14 06:17 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 17:35 - 2012-06-14 06:17 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 17:33 - 2012-06-14 06:17 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 17:31 - 2012-06-14 06:17 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 17:29 - 2012-06-14 06:17 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 17:29 - 2012-06-14 06:17 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 17:27 - 2012-06-14 06:17 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 17:25 - 2012-06-14 06:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 17:24 - 2012-06-14 06:17 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 17:20 - 2012-06-14 06:17 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 20:32 - 2012-06-14 05:29 - 03144192 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 16:03 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-05-11 15:58 - 2012-05-11 15:58 - 00016896 ____A C:\Users\Nicola\My Documents\xanders naming ceremony.wps
2012-05-11 15:58 - 2012-05-11 15:58 - 00016896 ____A C:\Users\Nicola\Documents\xanders naming ceremony.wps
2012-05-11 15:58 - 2012-05-11 15:34 - 00000490 ____A C:\Users\Nicola\Application Data\wklnhst.dat
2012-05-11 15:58 - 2012-05-11 15:34 - 00000490 ____A C:\Users\Nicola\AppData\Roaming\wklnhst.dat
2012-05-11 15:51 - 2012-05-11 15:43 - 00016896 ____A C:\Users\Nicola\My Documents\Sophie naming ceremony.wps
2012-05-11 15:51 - 2012-05-11 15:43 - 00016896 ____A C:\Users\Nicola\Documents\Sophie naming ceremony.wps
2012-05-11 15:34 - 2012-05-11 15:34 - 00000000 ____D C:\Users\Nicola\Application Data\Template
2012-05-11 15:34 - 2012-05-11 15:34 - 00000000 ____D C:\Users\Nicola\AppData\Roaming\Template
2012-05-10 08:41 - 2010-02-08 19:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-10 08:40 - 2009-07-14 02:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-04 05:52 - 2012-06-14 05:29 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 05:08 - 2012-06-14 05:29 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 05:08 - 2012-06-14 05:29 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-02 00:32 - 2012-06-14 05:29 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 22:50 - 2012-06-14 05:29 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 00:34 - 2012-06-14 05:29 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 00:34 - 2012-06-14 05:29 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 00:28 - 2012-06-14 05:29 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 00:59 - 2012-06-14 05:29 - 01460224 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 00:59 - 2012-06-14 05:29 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 00:59 - 2012-06-14 05:29 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 23:47 - 2012-06-14 05:29 - 01156608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 23:47 - 2012-06-14 05:29 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 23:47 - 2012-06-14 05:29 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-22 03:26 - 2012-04-22 03:26 - 00001936 ____A C:\Users\Public\Desktop\Theory Interactive.lnk
2012-04-22 03:26 - 2012-04-22 03:26 - 00001936 ____A C:\Users\All Users\Desktop\Theory Interactive.lnk
2012-04-22 03:26 - 2010-02-08 18:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-04-22 03:22 - 2012-04-22 03:20 - 00000000 ____D C:\Program Files (x86)\Theory Interactive
2012-04-20 08:12 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-16 13:41 - 2009-07-14 00:08 - 00032544 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-04-07 07:18 - 2012-06-14 05:29 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 06:34 - 2012-06-14 05:29 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 09:56 - 2011-03-06 16:16 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-31 14:09 - 2009-07-13 21:34 - 00000478 ____A C:\Windows\win.ini
2012-03-30 06:09 - 2012-05-09 15:08 - 01895280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-26 14:36 - 2012-03-26 14:34 - 00000000 ____D C:\Users\Nicola\Local Settings\Google
2012-03-26 14:36 - 2012-03-26 14:34 - 00000000 ____D C:\Users\Nicola\Local Settings\Application Data\Google
2012-03-26 14:36 - 2012-03-26 14:34 - 00000000 ____D C:\Users\Nicola\AppData\Local\Google
2012-03-26 14:34 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\Local Settings\Deployment
2012-03-26 14:34 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\Local Settings\Application Data\Deployment
2012-03-26 14:34 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\AppData\Local\Deployment
2012-03-26 14:33 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\AppData\Local\Apps\2.0
ZeroAccess:
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\@
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\L
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\n
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\U
ZeroAccess:
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\@
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\L
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3956.54 MB
Available physical RAM: 3363.49 MB
Total Pagefile: 3954.69 MB
Available Pagefile: 3349.12 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
2 Drive c: (OS) (Fixed) (Total:451.07 GB) (Free:398.77 GB) NTFS
4 Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:9.46 GB) NTFS
5 Drive f: (USBDISKPRO) (Removable) (Total:0.12 GB) (Free:0.11 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 122 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 14 GB 39 MB
Partition 3 Primary 451 GB 14 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E RECOVERY NTFS Partition 14 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 122 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F USBDISKPRO FAT32 Removable 122 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-11 07:39
======================= End Of Log ==========================
I've read other threads about this virus and done what I could,
The operating system is Windows 7 Home Premium 64
Thanks in advance.
Here is the farbar log
Scan result of Farbar Recovery Scan Tool Version: 20-06-2012 04
Ran by SYSTEM at 20-06-2012 23:14:14
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-23] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [444416 2009-06-28] (IDT, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-16] (Dell Inc.)
HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [3189016 2009-10-01] (Dell Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" [148888 2010-02-08] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.)
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [409744 2009-06-24] (Creative Technology Ltd)
HKLM-x32\...\Run: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [498160 2009-10-15] ()
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKU\Nicola\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3883856 2009-07-26] (Microsoft Corporation)
HKU\Nicola\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\Nicola\...\Run: [Google Update] "C:\Users\Nicola\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-26] (Google Inc.)
HKLM-x32\...\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe [165104 2009-09-17] (Softthinks)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Nicola\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 BBUpdate; "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" [249648 2011-10-13] (Microsoft Corporation)
3 FLEXnet Licensing Service; "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [654848 2010-05-06] (Macrovision Europe Ltd.)
2 lxdx_device; C:\Windows\system32\lxdxcoms.exe -service [1039872 2009-10-16] ( )
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-28] (IDT, Inc.)
========================== Drivers (Whitelisted) =============
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-20 23:14 - 2012-06-20 23:14 - 00000000 ____D C:\FRST
2012-06-18 16:28 - 2012-06-18 16:58 - 00000000 ____D C:\Windows\pss
2012-06-18 15:48 - 2012-06-18 15:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-18 15:47 - 2012-06-18 15:48 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 15:31 - 2012-06-18 15:39 - 00000000 ____D C:\Users\Nicola\Application Data\Azureus
2012-06-18 15:31 - 2012-06-18 15:39 - 00000000 ____D C:\Users\Nicola\AppData\Roaming\Azureus
2012-06-18 15:31 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\.swt
2012-06-14 06:17 - 2012-05-17 21:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 06:17 - 2012-05-17 21:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 06:17 - 2012-05-17 21:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 06:17 - 2012-05-17 20:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 06:17 - 2012-05-17 20:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 06:17 - 2012-05-17 20:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 06:17 - 2012-05-17 20:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 06:17 - 2012-05-17 20:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 06:17 - 2012-05-17 20:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 06:17 - 2012-05-17 20:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 06:17 - 2012-05-17 20:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 06:17 - 2012-05-17 20:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 06:17 - 2012-05-17 20:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 06:17 - 2012-05-17 20:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-14 06:17 - 2012-05-17 18:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-14 06:17 - 2012-05-17 17:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-14 06:17 - 2012-05-17 17:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-14 06:17 - 2012-05-17 17:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-14 06:17 - 2012-05-17 17:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-14 06:17 - 2012-05-17 17:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-14 06:17 - 2012-05-17 17:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-14 06:17 - 2012-05-17 17:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-14 06:17 - 2012-05-17 17:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-14 06:17 - 2012-05-17 17:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-14 06:17 - 2012-05-17 17:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-14 06:17 - 2012-05-17 17:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-14 06:17 - 2012-05-17 17:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-14 06:17 - 2012-05-17 17:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-14 05:29 - 2012-05-14 20:32 - 03144192 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-14 05:29 - 2012-05-04 05:52 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-14 05:29 - 2012-05-04 05:08 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-14 05:29 - 2012-05-04 05:08 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-14 05:29 - 2012-05-02 00:32 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-14 05:29 - 2012-04-27 22:50 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-14 05:29 - 2012-04-26 00:34 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-14 05:29 - 2012-04-26 00:34 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-14 05:29 - 2012-04-26 00:28 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-14 05:29 - 2012-04-24 00:59 - 01460224 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-14 05:29 - 2012-04-24 00:59 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-14 05:29 - 2012-04-24 00:59 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-14 05:29 - 2012-04-23 23:47 - 01156608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-14 05:29 - 2012-04-23 23:47 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-14 05:29 - 2012-04-23 23:47 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-14 05:29 - 2012-04-07 07:18 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-14 05:29 - 2012-04-07 06:34 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-07 05:47 - 2012-06-07 05:47 - 00000000 __SHD C:\Windows\System32\%APPDATA%
============ 3 Months Modified Files and Folders =============
2012-06-20 23:14 - 2012-06-20 23:14 - 00000000 ____D C:\FRST
2012-06-20 16:04 - 2010-05-05 15:14 - 00000000 ____D C:\Users\Nicola\Tracing
2012-06-20 16:04 - 2010-05-05 14:49 - 00000000 ____D C:\Users\Nicola\Local Settings\SoftThinks
2012-06-20 16:04 - 2010-05-05 14:49 - 00000000 ____D C:\Users\Nicola\Local Settings\Application Data\SoftThinks
2012-06-20 16:04 - 2010-05-05 14:49 - 00000000 ____D C:\Users\Nicola\AppData\Local\SoftThinks
2012-06-20 16:03 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-20 16:03 - 2009-07-13 23:51 - 00065755 ____A C:\Windows\setupact.log
2012-06-20 16:00 - 2010-02-08 20:42 - 00474078 ____A C:\Windows\PFRO.log
2012-06-18 16:58 - 2012-06-18 16:28 - 00000000 ____D C:\Windows\pss
2012-06-18 16:55 - 2011-03-06 15:07 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-18 16:28 - 2009-07-14 00:10 - 01874521 ____A C:\Windows\WindowsUpdate.log
2012-06-18 16:28 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-18 16:28 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-18 16:21 - 2010-02-08 19:30 - 00000071 ____A C:\Windows\SysWOW64\ToasterLauncherLog.log
2012-06-18 16:09 - 2010-02-08 19:01 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2012-06-18 16:02 - 2012-01-11 14:58 - 00000000 __SHD C:\Users\Nicola\Local Settings\Application Data\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
2012-06-18 16:02 - 2012-01-11 14:58 - 00000000 __SHD C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
2012-06-18 15:59 - 2012-01-11 14:58 - 00000000 __SHD C:\Users\Nicola\Local Settings\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
2012-06-18 15:56 - 2011-03-06 16:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-18 15:48 - 2012-06-18 15:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-18 15:48 - 2012-06-18 15:47 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-18 15:48 - 2011-03-06 16:40 - 00739730 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-18 15:39 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\Application Data\Azureus
2012-06-18 15:39 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\AppData\Roaming\Azureus
2012-06-18 15:39 - 2012-03-26 14:34 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3205693759-3490152921-415697551-1001UA.job
2012-06-18 15:31 - 2012-06-18 15:31 - 00000000 ____D C:\Users\Nicola\.swt
2012-06-18 15:31 - 2010-05-05 14:49 - 00000000 ____D C:\users\Nicola
2012-06-16 14:39 - 2012-03-26 14:34 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3205693759-3490152921-415697551-1001Core.job
2012-06-14 09:45 - 2009-07-13 23:45 - 02351776 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 06:25 - 2010-02-08 19:04 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-14 06:25 - 2010-02-08 19:04 - 00000000 ____D C:\Users\All Users\Application Data\Microsoft Help
2012-06-14 06:24 - 2009-07-14 00:13 - 00739950 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-12 06:40 - 2012-03-26 14:36 - 00002407 ____A C:\Users\Nicola\Desktop\Google Chrome.lnk
2012-06-07 05:47 - 2012-06-07 05:47 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-30 14:04 - 2012-02-20 10:03 - 00000000 ____D C:\Users\Nicola\CV
2012-05-26 15:24 - 2012-04-22 03:34 - 00000050 ____A C:\Windows\bsm.ini
2012-05-26 15:10 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2012-05-17 21:47 - 2012-06-14 06:17 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 21:16 - 2012-06-14 06:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 21:06 - 2012-06-14 06:17 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 20:59 - 2012-06-14 06:17 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 20:59 - 2012-06-14 06:17 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 20:58 - 2012-06-14 06:17 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 20:58 - 2012-06-14 06:17 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 20:56 - 2012-06-14 06:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 20:55 - 2012-06-14 06:17 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 20:55 - 2012-06-14 06:17 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 20:54 - 2012-06-14 06:17 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 20:51 - 2012-06-14 06:17 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 20:51 - 2012-06-14 06:17 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 20:47 - 2012-06-14 06:17 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 18:11 - 2012-06-14 06:17 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 17:48 - 2012-06-14 06:17 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 17:45 - 2012-06-14 06:17 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 17:36 - 2012-06-14 06:17 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 17:35 - 2012-06-14 06:17 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 17:35 - 2012-06-14 06:17 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 17:33 - 2012-06-14 06:17 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 17:31 - 2012-06-14 06:17 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 17:29 - 2012-06-14 06:17 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 17:29 - 2012-06-14 06:17 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 17:27 - 2012-06-14 06:17 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 17:25 - 2012-06-14 06:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 17:24 - 2012-06-14 06:17 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 17:20 - 2012-06-14 06:17 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 20:32 - 2012-06-14 05:29 - 03144192 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 16:03 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2012-05-11 15:58 - 2012-05-11 15:58 - 00016896 ____A C:\Users\Nicola\My Documents\xanders naming ceremony.wps
2012-05-11 15:58 - 2012-05-11 15:58 - 00016896 ____A C:\Users\Nicola\Documents\xanders naming ceremony.wps
2012-05-11 15:58 - 2012-05-11 15:34 - 00000490 ____A C:\Users\Nicola\Application Data\wklnhst.dat
2012-05-11 15:58 - 2012-05-11 15:34 - 00000490 ____A C:\Users\Nicola\AppData\Roaming\wklnhst.dat
2012-05-11 15:51 - 2012-05-11 15:43 - 00016896 ____A C:\Users\Nicola\My Documents\Sophie naming ceremony.wps
2012-05-11 15:51 - 2012-05-11 15:43 - 00016896 ____A C:\Users\Nicola\Documents\Sophie naming ceremony.wps
2012-05-11 15:34 - 2012-05-11 15:34 - 00000000 ____D C:\Users\Nicola\Application Data\Template
2012-05-11 15:34 - 2012-05-11 15:34 - 00000000 ____D C:\Users\Nicola\AppData\Roaming\Template
2012-05-10 08:41 - 2010-02-08 19:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-10 08:40 - 2009-07-14 02:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-04 05:52 - 2012-06-14 05:29 - 05505392 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 05:08 - 2012-06-14 05:29 - 03958128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 05:08 - 2012-06-14 05:29 - 03902320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-02 00:32 - 2012-06-14 05:29 - 00208896 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 22:50 - 2012-06-14 05:29 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 00:34 - 2012-06-14 05:29 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 00:34 - 2012-06-14 05:29 - 00076288 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 00:28 - 2012-06-14 05:29 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 00:59 - 2012-06-14 05:29 - 01460224 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 00:59 - 2012-06-14 05:29 - 00182272 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 00:59 - 2012-06-14 05:29 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 23:47 - 2012-06-14 05:29 - 01156608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 23:47 - 2012-06-14 05:29 - 00139264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 23:47 - 2012-06-14 05:29 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-22 03:26 - 2012-04-22 03:26 - 00001936 ____A C:\Users\Public\Desktop\Theory Interactive.lnk
2012-04-22 03:26 - 2012-04-22 03:26 - 00001936 ____A C:\Users\All Users\Desktop\Theory Interactive.lnk
2012-04-22 03:26 - 2010-02-08 18:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-04-22 03:22 - 2012-04-22 03:20 - 00000000 ____D C:\Program Files (x86)\Theory Interactive
2012-04-20 08:12 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-16 13:41 - 2009-07-14 00:08 - 00032544 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-04-07 07:18 - 2012-06-14 05:29 - 03213824 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 06:34 - 2012-06-14 05:29 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-04 09:56 - 2011-03-06 16:16 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-03-31 14:09 - 2009-07-13 21:34 - 00000478 ____A C:\Windows\win.ini
2012-03-30 06:09 - 2012-05-09 15:08 - 01895280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-26 14:36 - 2012-03-26 14:34 - 00000000 ____D C:\Users\Nicola\Local Settings\Google
2012-03-26 14:36 - 2012-03-26 14:34 - 00000000 ____D C:\Users\Nicola\Local Settings\Application Data\Google
2012-03-26 14:36 - 2012-03-26 14:34 - 00000000 ____D C:\Users\Nicola\AppData\Local\Google
2012-03-26 14:34 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\Local Settings\Deployment
2012-03-26 14:34 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\Local Settings\Application Data\Deployment
2012-03-26 14:34 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\AppData\Local\Deployment
2012-03-26 14:33 - 2012-03-26 14:33 - 00000000 ____D C:\Users\Nicola\AppData\Local\Apps\2.0
ZeroAccess:
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\@
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\L
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\n
C:\Windows\Installer\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\U
ZeroAccess:
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\@
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\L
C:\Users\Nicola\AppData\Local\{d3ed6ce9-2bc9-d767-2346-e38c72483d20}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3956.54 MB
Available physical RAM: 3363.49 MB
Total Pagefile: 3954.69 MB
Available Pagefile: 3349.12 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
2 Drive c: (OS) (Fixed) (Total:451.07 GB) (Free:398.77 GB) NTFS
4 Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:9.46 GB) NTFS
5 Drive f: (USBDISKPRO) (Removable) (Total:0.12 GB) (Free:0.11 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 122 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 14 GB 39 MB
Partition 3 Primary 451 GB 14 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E RECOVERY NTFS Partition 14 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 122 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F USBDISKPRO FAT32 Removable 122 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-11 07:39
======================= End Of Log ==========================