Hi,
My name is Simon and I'm student from Slovenia.
I'm infected with Win64/Patched.A (service.exe) and I need your help ASAP.
After reading few threads I found out that I have to scan my computer with Farbar Recovery Scan Tool. I'm using Win 7 64-bit.
Here is my FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-11-2012
Ran by Simon at 20-11-2012 12:44:44
Running from G:\
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
==================== One Month Created Files and Folders ========
2012-11-20 12:29 - 2012-11-20 12:29 - 00000326 ____A C:\Users\Simon\Downloads\fixlist.txt
2012-11-19 08:34 - 2012-11-20 21:41 - 00000000 ____D C:\Program Files (x86)\Verimatrix
2012-11-19 08:33 - 2012-11-19 08:34 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller (1).msi
2012-11-19 07:40 - 2012-11-19 07:40 - 00003210 ____A C:\Users\Simon\Desktop\RKreport[1]_S_11192012_02d0740.txt
2012-11-19 07:39 - 2012-11-19 07:40 - 00000000 ____D C:\Users\Simon\Desktop\RK_Quarantine
2012-11-19 07:39 - 2012-11-19 07:39 - 00729088 ____A C:\Users\Simon\Downloads\RogueKiller.exe
2012-11-18 21:58 - 2012-11-18 21:58 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-18 21:47 - 2012-11-18 21:47 - 00000000 ____D C:\Windows\System32\appmgmt
2012-11-18 21:24 - 2012-11-18 21:24 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-11-18 21:24 - 2012-11-18 21:24 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-11-18 20:47 - 2012-11-18 20:47 - 00000000 ____D C:\Program Files (x86)\Mega Codec Pack
2012-11-18 20:09 - 2012-11-18 20:41 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 Eng [DVDRip] Dual Audio - DiAMOND
2012-11-18 20:09 - 2012-11-18 20:09 - 00030903 ____A C:\Users\Simon\Downloads\[isoHunt] 4935305.torrent
2012-11-18 20:06 - 2012-11-18 20:07 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775 (1).exe
2012-11-18 20:05 - 2012-11-18 20:05 - 00000000 ____D C:\Program Files (x86)\Xvid
2012-11-18 20:05 - 2011-05-30 14:42 - 00255488 ____A C:\Windows\System32\xvidvfw.dll
2012-11-18 20:05 - 2011-05-30 14:42 - 00240640 ____A C:\Windows\SysWOW64\xvidvfw.dll
2012-11-18 20:05 - 2011-05-23 10:52 - 00153088 ____A C:\Windows\SysWOW64\xvid.ax
2012-11-18 20:05 - 2011-05-23 08:49 - 00173568 ____A C:\Windows\System32\xvid.ax
2012-11-18 20:05 - 2011-05-23 08:46 - 00645632 ____A C:\Windows\SysWOW64\xvidcore.dll
2012-11-18 20:05 - 2011-05-23 08:45 - 00696832 ____A C:\Windows\System32\xvidcore.dll
2012-11-18 20:03 - 2012-11-18 20:04 - 10768856 ____A (Xvid Team) C:\Users\Simon\Downloads\Xvid-1.3.2-20110601.exe
2012-11-18 20:00 - 2012-11-18 20:01 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775.exe
2012-11-18 19:41 - 2012-11-18 20:09 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R
2012-11-18 19:40 - 2012-11-18 19:40 - 00014370 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R.torrent
2012-11-18 17:46 - 2012-11-18 19:40 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect [2012] R5 XViD - RAWNiTRO
2012-11-18 17:45 - 2012-11-18 17:45 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 English HD-quality
2012-11-18 17:44 - 2012-11-18 17:44 - 00008591 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect [2012] R5 XViD - RAWNiTRO.torrent
2012-11-18 17:41 - 2012-11-18 17:42 - 00056893 ____A C:\Users\Simon\Downloads\[isoHunt] download.torrent
2012-11-14 03:05 - 2012-07-26 05:55 - 00785512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2012-11-14 03:05 - 2012-07-26 05:55 - 00054376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2012-11-14 03:05 - 2012-07-26 03:36 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\Wdfres.dll
2012-11-14 03:05 - 2012-06-02 15:35 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2012-11-14 03:01 - 2012-10-08 13:19 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-11-14 03:01 - 2012-10-08 12:42 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-11-14 03:01 - 2012-10-08 12:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-11-14 03:01 - 2012-10-08 12:24 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-11-14 03:01 - 2012-10-08 12:23 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-11-14 03:01 - 2012-10-08 12:22 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-11-14 03:01 - 2012-10-08 12:22 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-11-14 03:01 - 2012-10-08 12:20 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-11-14 03:01 - 2012-10-08 12:18 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-11-14 03:01 - 2012-10-08 12:17 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-11-14 03:01 - 2012-10-08 12:17 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-11-14 03:01 - 2012-10-08 12:15 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-11-14 03:01 - 2012-10-08 12:15 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-11-14 03:01 - 2012-10-08 12:13 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-11-14 03:01 - 2012-10-08 12:13 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-11-14 03:01 - 2012-10-08 12:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-11-14 03:01 - 2012-10-08 09:28 - 12320768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-11-14 03:01 - 2012-10-08 09:02 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-11-14 03:01 - 2012-10-08 08:56 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-11-14 03:01 - 2012-10-08 08:48 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-11-14 03:01 - 2012-10-08 08:48 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-11-14 03:01 - 2012-10-08 08:47 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-11-14 03:01 - 2012-10-08 08:46 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-11-14 03:01 - 2012-10-08 08:45 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-11-14 03:01 - 2012-10-08 08:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-11-14 03:01 - 2012-10-08 08:43 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-11-14 03:01 - 2012-10-08 08:43 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-11-14 03:01 - 2012-10-08 08:42 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-11-14 03:01 - 2012-10-08 08:41 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-11-14 03:01 - 2012-10-08 08:41 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-11-14 03:01 - 2012-10-08 08:40 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-11-14 03:01 - 2012-10-08 08:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00744448 ____A (Microsoft Corporation) C:\Windows\System32\WUDFx.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe
2012-11-14 03:00 - 2012-07-26 04:08 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\WUDFPlatform.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\WUDFSvc.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\WUDFCoinstaller.dll
2012-11-14 03:00 - 2012-07-26 03:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys
2012-11-14 03:00 - 2012-07-26 03:26 - 00087040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys
2012-11-14 03:00 - 2012-06-02 15:57 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2012-11-14 01:04 - 2012-11-14 03:15 - 00000000 ____D C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW
2012-11-14 01:03 - 2012-11-14 01:03 - 00151230 ____A C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW.torrent
2012-11-13 23:05 - 2012-10-18 19:25 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-11-13 23:05 - 2012-10-09 19:17 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2012-11-13 23:05 - 2012-10-09 19:17 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2012-11-13 23:05 - 2012-10-09 18:40 - 00193536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2012-11-13 23:05 - 2012-10-09 18:40 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2012-11-13 23:05 - 2012-10-03 18:56 - 01914248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-11-13 23:05 - 2012-10-03 18:44 - 00303104 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00246272 ____A (Microsoft Corporation) C:\Windows\System32\netcorehc.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00216576 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\netevent.dll
2012-11-13 23:05 - 2012-10-03 18:42 - 00569344 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2012-11-13 23:05 - 2012-10-03 17:42 - 00175104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2012-11-13 23:05 - 2012-10-03 17:42 - 00156672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2012-11-13 23:05 - 2012-10-03 17:42 - 00018944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2012-11-13 23:05 - 2012-10-03 17:07 - 00045568 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2012-11-13 23:05 - 2012-01-13 08:12 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2012-11-13 23:04 - 2012-09-25 23:47 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2012-11-13 23:04 - 2012-09-25 23:46 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\synceng.dll
2012-11-11 20:58 - 2012-11-11 20:58 - 00004376 ____A C:\WirelessDiagLog.csv
2012-11-10 17:08 - 2012-11-10 17:08 - 00027520 ____A C:\Users\Simon\AppData\Local\dt.dat
2012-11-10 16:36 - 2012-11-10 16:56 - 00000000 ____D C:\Program Files\Dell Support Center
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dell
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\All Users\PCDr
2012-11-10 16:32 - 2012-11-10 16:32 - 00038984 ____A (Dell Computer Corporation) C:\Users\Simon\Downloads\DellPCDiagnostics.exe
2012-11-10 16:32 - 2012-11-10 16:32 - 00000000 ____D C:\Users\Simon\AppData\Roaming\PCDr
2012-11-10 16:25 - 2012-11-10 16:26 - 06059000 ____A C:\Users\Simon\Downloads\R295126.exe
2012-11-10 16:24 - 2012-11-10 16:25 - 08276776 ____A C:\Users\Simon\Downloads\USB3_Renesas_W7_A03_Setup-61X2W_ZPE.exe
2012-11-10 16:16 - 2012-11-10 16:18 - 17371337 ____A C:\Users\Simon\Downloads\R317457.zip
2012-11-10 16:12 - 2012-11-10 16:13 - 04300104 ____A C:\Users\Simon\Downloads\CW1394A0.exe
2012-11-10 15:59 - 2012-11-20 21:41 - 00000000 ____D C:\Users\Simon\AppData\Local\Akamai
2012-11-10 15:57 - 2012-11-10 15:58 - 11064264 ____A (Akamai Technologies, Inc.) C:\Users\Simon\Downloads\Dell_Download_Manager_Setup.exe
2012-11-10 15:49 - 2012-11-10 15:49 - 00127480 ____A C:\Users\Simon\Downloads\DELL_S2230MX-MONITOR_A00-00_R303587.exe
2012-11-10 15:48 - 2012-11-10 15:49 - 10797616 ____A C:\Users\Simon\Downloads\R296901.exe
2012-11-10 15:47 - 2012-11-10 15:47 - 00010579 ____A C:\Users\Simon\Downloads\dellsystemdetect.application
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Verimatrix
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\All Users\Verimatrix
2012-11-10 15:39 - 2012-11-10 15:40 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller.msi
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Windows\System32\Macromed
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Users\All Users\ALM
2012-11-04 20:13 - 2012-11-04 20:13 - 00000000 ____D C:\Users\Simon\Adobe Flash Builder 4.6
2012-11-04 20:08 - 2012-11-04 20:08 - 00002026 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2012-11-04 18:53 - 2012-11-04 19:06 - 00000000 ____D C:\Users\Simon\Desktop\Adobe CS6 Master Collection
2012-11-04 17:35 - 2012-11-04 17:35 - 00016981 ____A C:\Users\Simon\Downloads\[isoHunt] Adobe CS6 Master Collection (1).torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000616 ____A C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE.torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000000 ____D C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE
2012-11-04 17:25 - 2012-11-04 17:25 - 00001706 ____A C:\Users\Simon\Downloads\Adobe_CS6_All_Products_Activator__x32___x64___2012_-MPT (1).torrent
2012-11-04 13:55 - 2012-11-09 00:37 - 00000000 ____D C:\Users\Simon\AppData\Roaming\TeamViewer
2012-11-04 13:54 - 2012-11-04 13:54 - 00001166 ____A C:\Users\Public\Desktop\TeamViewer 7.lnk
2012-11-04 13:54 - 2012-11-04 13:54 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2012-11-04 13:52 - 2012-11-04 13:52 - 04939440 ____A (TeamViewer GmbH) C:\Users\Simon\Downloads\TeamViewer_Setup.exe
2012-11-04 13:50 - 2012-11-18 21:45 - 00000000 ____D C:\Program Files (x86)\VaudiX
2012-11-04 13:49 - 2012-11-20 12:43 - 00000370 ___AH C:\Windows\Tasks\VaudiXUpdaterTask{6F5B29B3-E8F2-4AE4-83C7-C188B6020673}.job
2012-11-04 13:49 - 2012-11-04 13:50 - 00000000 ____D C:\Users\All Users\Premium
2012-11-04 13:48 - 2012-11-18 21:45 - 00000000 ____D C:\Users\All Users\InstallMate
2012-11-04 13:48 - 2012-11-04 13:48 - 00300936 ____A (Premium) C:\Users\Simon\Downloads\VaudiX.exe
2012-11-04 13:48 - 2012-11-04 13:48 - 00000000 ____D C:\Users\All Users\Vaudix
2012-11-04 10:03 - 2012-11-04 10:03 - 00015872 ____A C:\Users\Simon\Downloads\seminarji.xls
2012-11-03 22:55 - 2012-11-03 22:55 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Mozilla
2012-10-30 09:41 - 2012-10-30 09:41 - 00482816 ____H C:\Users\Simon\Downloads\~WRL2901.tmp
2012-10-28 17:33 - 2012-10-28 17:33 - 00056823 ____A C:\Users\Simon\Downloads\Ice.Age.4.Continental.Drift.2012.SLOSubs.DVDRip.XviD-DrSi.torrent
2012-10-26 22:13 - 2012-10-27 00:37 - 00000000 ____D C:\CS6
2012-10-26 21:58 - 2012-10-26 22:09 - 00000000 ____D C:\Users\Simon\Downloads\Project.X.2012.EXTENDED.SLOSubs.DVDRip.XviD-DrSi
2012-10-24 21:41 - 2012-10-24 21:41 - 00055176 ____A C:\Users\Simon\Downloads\Adobe.CS6.Master.Collection-milkman (1).torrent
2012-10-24 21:35 - 2012-10-24 21:35 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-10-24 21:35 - 2012-10-24 21:35 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-10-24 21:32 - 2012-10-24 21:34 - 39483256 ____A (Apple Inc.) C:\Users\Simon\Downloads\QuickTimeInstaller.exe
2012-10-23 18:06 - 2012-10-23 18:07 - 16061064 ____A C:\Users\Simon\Downloads\getOrder_promo_mix.mp4
2012-10-22 11:33 - 2012-10-22 11:33 - 00000000 ____D C:\Users\All Users\Hewlett-Packard
2012-10-21 21:20 - 2012-11-20 12:44 - 00000000 ___RD C:\Users\Simon\Dropbox
2012-10-21 21:20 - 2012-10-21 21:20 - 00001043 ____A C:\Users\Simon\Desktop\Dropbox.lnk
2012-10-21 21:18 - 2012-11-20 12:44 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dropbox
2012-10-21 21:18 - 2012-10-21 21:18 - 05694794 ____A C:\Users\Simon\Downloads\template-discsurface.zip
2012-10-21 21:16 - 2012-10-21 21:17 - 17813784 ____A (Dropbox, Inc.) C:\Users\Simon\Downloads\Dropbox 1.4.17.exe
==================== One Month Modified Files and Folders =======
2012-11-20 21:41 - 2012-11-19 08:34 - 00000000 ____D C:\Program Files (x86)\Verimatrix
2012-11-20 21:41 - 2012-11-10 15:59 - 00000000 ____D C:\Users\Simon\AppData\Local\Akamai
2012-11-20 21:41 - 2012-07-15 14:09 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2012-11-20 21:41 - 2012-07-10 14:13 - 00000000 ____D C:\Windows\System32\Drivers\AVG
2012-11-20 21:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2012-11-20 21:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat
2012-11-20 12:44 - 2012-11-20 12:44 - 00000000 ____D C:\FRST
2012-11-20 12:44 - 2012-10-21 21:20 - 00000000 ___RD C:\Users\Simon\Dropbox
2012-11-20 12:44 - 2012-10-21 21:18 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dropbox
2012-11-20 12:43 - 2012-11-04 13:49 - 00000370 ___AH C:\Windows\Tasks\VaudiXUpdaterTask{6F5B29B3-E8F2-4AE4-83C7-C188B6020673}.job
2012-11-20 12:43 - 2012-08-04 22:00 - 00001050 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-11-20 12:43 - 2012-07-10 13:18 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-11-20 12:43 - 2012-07-10 12:52 - 00000000 ____D C:\users\Simon
2012-11-20 12:43 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-11-20 12:43 - 2009-07-14 05:51 - 00038635 ____A C:\Windows\setupact.log
2012-11-20 12:29 - 2012-11-20 12:29 - 00000326 ____A C:\Users\Simon\Downloads\fixlist.txt
2012-11-20 02:00 - 2012-08-22 12:16 - 00000000 ____D C:\Users\Simon\AppData\Local\Adobe
2012-11-19 08:34 - 2012-11-19 08:33 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller (1).msi
2012-11-19 08:10 - 2012-08-04 22:00 - 00001054 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-11-19 07:49 - 2009-07-14 05:45 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-19 07:49 - 2009-07-14 05:45 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-19 07:48 - 2009-07-14 06:13 - 00778660 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-19 07:42 - 2012-07-10 14:13 - 00000000 ____D C:\Users\All Users\AVG2012
2012-11-19 07:42 - 2010-11-21 04:47 - 00010042 ____A C:\Windows\PFRO.log
2012-11-19 07:41 - 2012-07-21 12:40 - 00000000 ____D C:\Users\Simon\AppData\Roaming\uTorrent
2012-11-19 07:40 - 2012-11-19 07:40 - 00003210 ____A C:\Users\Simon\Desktop\RKreport[1]_S_11192012_02d0740.txt
2012-11-19 07:40 - 2012-11-19 07:39 - 00000000 ____D C:\Users\Simon\Desktop\RK_Quarantine
2012-11-19 07:39 - 2012-11-19 07:39 - 00729088 ____A C:\Users\Simon\Downloads\RogueKiller.exe
2012-11-19 07:37 - 2012-07-10 13:54 - 00001066 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4188228576-3451463030-3658580190-1000UA.job
2012-11-19 07:00 - 2012-07-10 14:04 - 00000000 ____D C:\Users\All Users\MFAData
2012-11-18 21:58 - 2012-11-18 21:58 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-18 21:47 - 2012-11-18 21:47 - 00000000 ____D C:\Windows\System32\appmgmt
2012-11-18 21:45 - 2012-11-04 13:50 - 00000000 ____D C:\Program Files (x86)\VaudiX
2012-11-18 21:45 - 2012-11-04 13:48 - 00000000 ____D C:\Users\All Users\InstallMate
2012-11-18 21:27 - 2012-07-15 14:42 - 00000000 ____D C:\Users\Simon\AppData\Roaming\vlc
2012-11-18 21:24 - 2012-11-18 21:24 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-11-18 21:24 - 2012-11-18 21:24 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-11-18 20:47 - 2012-11-18 20:47 - 00000000 ____D C:\Program Files (x86)\Mega Codec Pack
2012-11-18 20:47 - 2012-07-10 12:52 - 01728130 ____A C:\Windows\WindowsUpdate.log
2012-11-18 20:41 - 2012-11-18 20:09 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 Eng [DVDRip] Dual Audio - DiAMOND
2012-11-18 20:09 - 2012-11-18 20:09 - 00030903 ____A C:\Users\Simon\Downloads\[isoHunt] 4935305.torrent
2012-11-18 20:09 - 2012-11-18 19:41 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R
2012-11-18 20:07 - 2012-11-18 20:06 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775 (1).exe
2012-11-18 20:05 - 2012-11-18 20:05 - 00000000 ____D C:\Program Files (x86)\Xvid
2012-11-18 20:04 - 2012-11-18 20:03 - 10768856 ____A (Xvid Team) C:\Users\Simon\Downloads\Xvid-1.3.2-20110601.exe
2012-11-18 20:01 - 2012-11-18 20:00 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775.exe
2012-11-18 19:40 - 2012-11-18 19:40 - 00014370 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R.torrent
2012-11-18 19:40 - 2012-11-18 17:46 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect [2012] R5 XViD - RAWNiTRO
2012-11-18 17:45 - 2012-11-18 17:45 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 English HD-quality
2012-11-18 17:44 - 2012-11-18 17:44 - 00008591 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect [2012] R5 XViD - RAWNiTRO.torrent
2012-11-18 17:42 - 2012-11-18 17:41 - 00056893 ____A C:\Users\Simon\Downloads\[isoHunt] download.torrent
2012-11-18 16:59 - 2012-07-24 14:42 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Skype
2012-11-18 15:55 - 2012-07-10 13:54 - 00001014 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4188228576-3451463030-3658580190-1000Core.job
2012-11-16 15:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
2012-11-15 01:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2012-11-14 03:29 - 2012-07-10 13:51 - 00087984 ____A C:\Users\Simon\AppData\Local\GDIPFONTCACHEV1.DAT
2012-11-14 03:24 - 2009-07-14 05:45 - 04990416 ____A C:\Windows\System32\FNTCACHE.DAT
2012-11-14 03:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-11-14 03:15 - 2012-11-14 01:04 - 00000000 ____D C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW
2012-11-14 01:03 - 2012-11-14 01:03 - 00151230 ____A C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW.torrent
2012-11-11 20:58 - 2012-11-11 20:58 - 00004376 ____A C:\WirelessDiagLog.csv
2012-11-10 17:16 - 2012-07-10 13:54 - 00000000 ____D C:\Users\Simon\AppData\Local\Deployment
2012-11-10 17:08 - 2012-11-10 17:08 - 00027520 ____A C:\Users\Simon\AppData\Local\dt.dat
2012-11-10 16:56 - 2012-11-10 16:36 - 00000000 ____D C:\Program Files\Dell Support Center
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dell
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\All Users\PCDr
2012-11-10 16:36 - 2012-07-10 14:09 - 00000000 ____D C:\Users\All Users\Dell
2012-11-10 16:32 - 2012-11-10 16:32 - 00038984 ____A (Dell Computer Corporation) C:\Users\Simon\Downloads\DellPCDiagnostics.exe
2012-11-10 16:32 - 2012-11-10 16:32 - 00000000 ____D C:\Users\Simon\AppData\Roaming\PCDr
2012-11-10 16:26 - 2012-11-10 16:25 - 06059000 ____A C:\Users\Simon\Downloads\R295126.exe
2012-11-10 16:25 - 2012-11-10 16:24 - 08276776 ____A C:\Users\Simon\Downloads\USB3_Renesas_W7_A03_Setup-61X2W_ZPE.exe
2012-11-10 16:18 - 2012-11-10 16:16 - 17371337 ____A C:\Users\Simon\Downloads\R317457.zip
2012-11-10 16:13 - 2012-11-10 16:12 - 04300104 ____A C:\Users\Simon\Downloads\CW1394A0.exe
2012-11-10 15:58 - 2012-11-10 15:57 - 11064264 ____A (Akamai Technologies, Inc.) C:\Users\Simon\Downloads\Dell_Download_Manager_Setup.exe
2012-11-10 15:51 - 2012-07-10 13:17 - 00000000 ____D C:\Program Files (x86)\Intel
2012-11-10 15:49 - 2012-11-10 15:49 - 00127480 ____A C:\Users\Simon\Downloads\DELL_S2230MX-MONITOR_A00-00_R303587.exe
2012-11-10 15:49 - 2012-11-10 15:48 - 10797616 ____A C:\Users\Simon\Downloads\R296901.exe
2012-11-10 15:47 - 2012-11-10 15:47 - 00010579 ____A C:\Users\Simon\Downloads\dellsystemdetect.application
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Verimatrix
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\All Users\Verimatrix
2012-11-10 15:40 - 2012-11-10 15:39 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller.msi
2012-11-09 00:37 - 2012-11-04 13:55 - 00000000 ____D C:\Users\Simon\AppData\Roaming\TeamViewer
2012-11-09 00:36 - 2012-07-22 21:53 - 00001998 ___AH C:\Users\Simon\Documents\Default.rdp
2012-11-08 23:56 - 2012-07-10 14:14 - 00000000 ____D C:\Users\All Users\AVG Secure Search
2012-11-08 23:56 - 2012-07-10 14:14 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search
2012-11-08 23:55 - 2012-08-27 08:43 - 00030568 ____A (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys
2012-11-05 00:11 - 2012-09-02 10:30 - 00000021 ____A C:\Windows\SurCode.INI
2012-11-05 00:11 - 2012-09-02 10:30 - 00000000 ____D C:\Users\Simon\Documents\Adobe
2012-11-04 20:29 - 2012-08-22 13:54 - 00000000 ____D C:\Users\All Users\Adobe
2012-11-04 20:27 - 2012-09-30 20:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Windows\System32\Macromed
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Users\All Users\ALM
2012-11-04 20:19 - 2012-07-10 13:57 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Adobe
2012-11-04 20:17 - 2012-08-22 14:01 - 00000000 ____D C:\Program Files (x86)\Adobe
2012-11-04 20:13 - 2012-11-04 20:13 - 00000000 ____D C:\Users\Simon\Adobe Flash Builder 4.6
2012-11-04 20:08 - 2012-11-04 20:08 - 00002026 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2012-11-04 19:56 - 2012-08-22 14:00 - 00000000 ____D C:\Program Files\Adobe
2012-11-04 19:06 - 2012-11-04 18:53 - 00000000 ____D C:\Users\Simon\Desktop\Adobe CS6 Master Collection
2012-11-04 17:58 - 2012-08-20 12:37 - 00000000 ____D C:\Users\Simon\Downloads\Adobe CS6 Master Collection
2012-11-04 17:40 - 2012-09-30 22:22 - 00000000 ____D C:\Users\Simon\Downloads\Adobe.Master.Collection.CS6.LS16+Patch [WORKING]
2012-11-04 17:40 - 2012-09-26 12:49 - 00000000 ____D C:\Users\Simon\Downloads\Adobe.CS6.Master.Collection-milkman
2012-11-04 17:40 - 2012-07-23 18:35 - 00000000 ____D C:\Users\Simon\Downloads\Adobe Premiere Pro CS6 (64 Bit) - Cool Release
2012-11-04 17:35 - 2012-11-04 17:35 - 00016981 ____A C:\Users\Simon\Downloads\[isoHunt] Adobe CS6 Master Collection (1).torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000616 ____A C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE.torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000000 ____D C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE
2012-11-04 17:25 - 2012-11-04 17:25 - 00001706 ____A C:\Users\Simon\Downloads\Adobe_CS6_All_Products_Activator__x32___x64___2012_-MPT (1).torrent
2012-11-04 13:54 - 2012-11-04 13:54 - 00001166 ____A C:\Users\Public\Desktop\TeamViewer 7.lnk
2012-11-04 13:54 - 2012-11-04 13:54 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2012-11-04 13:52 - 2012-11-04 13:52 - 04939440 ____A (TeamViewer GmbH) C:\Users\Simon\Downloads\TeamViewer_Setup.exe
2012-11-04 13:50 - 2012-11-04 13:49 - 00000000 ____D C:\Users\All Users\Premium
2012-11-04 13:48 - 2012-11-04 13:48 - 00300936 ____A (Premium) C:\Users\Simon\Downloads\VaudiX.exe
2012-11-04 13:48 - 2012-11-04 13:48 - 00000000 ____D C:\Users\All Users\Vaudix
2012-11-04 11:40 - 2012-07-15 10:46 - 00000000 ____D C:\Users\Simon\AppData\Local\Apple Computer
2012-11-04 10:03 - 2012-11-04 10:03 - 00015872 ____A C:\Users\Simon\Downloads\seminarji.xls
2012-11-03 22:55 - 2012-11-03 22:55 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Mozilla
2012-10-30 09:41 - 2012-10-30 09:41 - 00482816 ____H C:\Users\Simon\Downloads\~WRL2901.tmp
2012-10-28 17:33 - 2012-10-28 17:33 - 00056823 ____A C:\Users\Simon\Downloads\Ice.Age.4.Continental.Drift.2012.SLOSubs.DVDRip.XviD-DrSi.torrent
2012-10-27 00:37 - 2012-10-26 22:13 - 00000000 ____D C:\CS6
2012-10-26 22:09 - 2012-10-26 21:58 - 00000000 ____D C:\Users\Simon\Downloads\Project.X.2012.EXTENDED.SLOSubs.DVDRip.XviD-DrSi
2012-10-24 21:41 - 2012-10-24 21:41 - 00055176 ____A C:\Users\Simon\Downloads\Adobe.CS6.Master.Collection-milkman (1).torrent
2012-10-24 21:35 - 2012-10-24 21:35 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-10-24 21:35 - 2012-10-24 21:35 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-10-24 21:34 - 2012-10-24 21:32 - 39483256 ____A (Apple Inc.) C:\Users\Simon\Downloads\QuickTimeInstaller.exe
2012-10-23 18:07 - 2012-10-23 18:06 - 16061064 ____A C:\Users\Simon\Downloads\getOrder_promo_mix.mp4
2012-10-22 11:33 - 2012-10-22 11:33 - 00000000 ____D C:\Users\All Users\Hewlett-Packard
2012-10-21 21:20 - 2012-10-21 21:20 - 00001043 ____A C:\Users\Simon\Desktop\Dropbox.lnk
2012-10-21 21:18 - 2012-10-21 21:18 - 05694794 ____A C:\Users\Simon\Downloads\template-discsurface.zip
2012-10-21 21:17 - 2012-10-21 21:16 - 17813784 ____A (Dropbox, Inc.) C:\Users\Simon\Downloads\Dropbox 1.4.17.exe
ZeroAccess:
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L\00000004.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L\201d3dde
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L\55490ac4
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\00000004.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\00000008.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\000000cb.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\80000000.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\80000032.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 24%
Total physical RAM: 8086.17 MB
Available physical RAM: 6103.46 MB
Total Pagefile: 16170.53 MB
Available Pagefile: 14007.01 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:390.62 GB) (Free:100.36 GB) NTFS
2 Drive d: () (Fixed) (Total:288.38 GB) (Free:38.71 GB) NTFS
3 Drive e: (GSP1RMCPRXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:7.44 GB) (Free:3.45 GB) FAT32
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 7638 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 19 GB 104 MB
Partition 3 Primary 288 GB 19 GB
Partition 4 Primary 390 GB 308 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
There is no volume associated with this partition.
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 RECOVERY NTFS Partition 19 GB Healthy System (partition with boot components)
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D NTFS Partition 288 GB Healthy
=========================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 C NTFS Partition 390 GB Healthy Boot
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7634 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 G FAT32 Removable 7634 MB Healthy
=========================================================
Last Boot: 2012-11-15 01:23
==================== End Of Log =============================
My name is Simon and I'm student from Slovenia.
I'm infected with Win64/Patched.A (service.exe) and I need your help ASAP.
After reading few threads I found out that I have to scan my computer with Farbar Recovery Scan Tool. I'm using Win 7 64-bit.
Here is my FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-11-2012
Ran by Simon at 20-11-2012 12:44:44
Running from G:\
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
==================== One Month Created Files and Folders ========
2012-11-20 12:29 - 2012-11-20 12:29 - 00000326 ____A C:\Users\Simon\Downloads\fixlist.txt
2012-11-19 08:34 - 2012-11-20 21:41 - 00000000 ____D C:\Program Files (x86)\Verimatrix
2012-11-19 08:33 - 2012-11-19 08:34 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller (1).msi
2012-11-19 07:40 - 2012-11-19 07:40 - 00003210 ____A C:\Users\Simon\Desktop\RKreport[1]_S_11192012_02d0740.txt
2012-11-19 07:39 - 2012-11-19 07:40 - 00000000 ____D C:\Users\Simon\Desktop\RK_Quarantine
2012-11-19 07:39 - 2012-11-19 07:39 - 00729088 ____A C:\Users\Simon\Downloads\RogueKiller.exe
2012-11-18 21:58 - 2012-11-18 21:58 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-18 21:47 - 2012-11-18 21:47 - 00000000 ____D C:\Windows\System32\appmgmt
2012-11-18 21:24 - 2012-11-18 21:24 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-11-18 21:24 - 2012-11-18 21:24 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-11-18 20:47 - 2012-11-18 20:47 - 00000000 ____D C:\Program Files (x86)\Mega Codec Pack
2012-11-18 20:09 - 2012-11-18 20:41 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 Eng [DVDRip] Dual Audio - DiAMOND
2012-11-18 20:09 - 2012-11-18 20:09 - 00030903 ____A C:\Users\Simon\Downloads\[isoHunt] 4935305.torrent
2012-11-18 20:06 - 2012-11-18 20:07 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775 (1).exe
2012-11-18 20:05 - 2012-11-18 20:05 - 00000000 ____D C:\Program Files (x86)\Xvid
2012-11-18 20:05 - 2011-05-30 14:42 - 00255488 ____A C:\Windows\System32\xvidvfw.dll
2012-11-18 20:05 - 2011-05-30 14:42 - 00240640 ____A C:\Windows\SysWOW64\xvidvfw.dll
2012-11-18 20:05 - 2011-05-23 10:52 - 00153088 ____A C:\Windows\SysWOW64\xvid.ax
2012-11-18 20:05 - 2011-05-23 08:49 - 00173568 ____A C:\Windows\System32\xvid.ax
2012-11-18 20:05 - 2011-05-23 08:46 - 00645632 ____A C:\Windows\SysWOW64\xvidcore.dll
2012-11-18 20:05 - 2011-05-23 08:45 - 00696832 ____A C:\Windows\System32\xvidcore.dll
2012-11-18 20:03 - 2012-11-18 20:04 - 10768856 ____A (Xvid Team) C:\Users\Simon\Downloads\Xvid-1.3.2-20110601.exe
2012-11-18 20:00 - 2012-11-18 20:01 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775.exe
2012-11-18 19:41 - 2012-11-18 20:09 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R
2012-11-18 19:40 - 2012-11-18 19:40 - 00014370 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R.torrent
2012-11-18 17:46 - 2012-11-18 19:40 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect [2012] R5 XViD - RAWNiTRO
2012-11-18 17:45 - 2012-11-18 17:45 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 English HD-quality
2012-11-18 17:44 - 2012-11-18 17:44 - 00008591 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect [2012] R5 XViD - RAWNiTRO.torrent
2012-11-18 17:41 - 2012-11-18 17:42 - 00056893 ____A C:\Users\Simon\Downloads\[isoHunt] download.torrent
2012-11-14 03:05 - 2012-07-26 05:55 - 00785512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2012-11-14 03:05 - 2012-07-26 05:55 - 00054376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2012-11-14 03:05 - 2012-07-26 03:36 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\Wdfres.dll
2012-11-14 03:05 - 2012-06-02 15:35 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2012-11-14 03:01 - 2012-10-08 13:19 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-11-14 03:01 - 2012-10-08 12:42 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-11-14 03:01 - 2012-10-08 12:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-11-14 03:01 - 2012-10-08 12:24 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-11-14 03:01 - 2012-10-08 12:23 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-11-14 03:01 - 2012-10-08 12:22 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-11-14 03:01 - 2012-10-08 12:22 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-11-14 03:01 - 2012-10-08 12:20 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-11-14 03:01 - 2012-10-08 12:18 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-11-14 03:01 - 2012-10-08 12:17 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-11-14 03:01 - 2012-10-08 12:17 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-11-14 03:01 - 2012-10-08 12:15 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-11-14 03:01 - 2012-10-08 12:15 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-11-14 03:01 - 2012-10-08 12:13 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-11-14 03:01 - 2012-10-08 12:13 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-11-14 03:01 - 2012-10-08 12:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-11-14 03:01 - 2012-10-08 09:28 - 12320768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-11-14 03:01 - 2012-10-08 09:02 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-11-14 03:01 - 2012-10-08 08:56 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-11-14 03:01 - 2012-10-08 08:48 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-11-14 03:01 - 2012-10-08 08:48 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-11-14 03:01 - 2012-10-08 08:47 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-11-14 03:01 - 2012-10-08 08:46 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-11-14 03:01 - 2012-10-08 08:45 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-11-14 03:01 - 2012-10-08 08:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-11-14 03:01 - 2012-10-08 08:43 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-11-14 03:01 - 2012-10-08 08:43 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-11-14 03:01 - 2012-10-08 08:42 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-11-14 03:01 - 2012-10-08 08:41 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-11-14 03:01 - 2012-10-08 08:41 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-11-14 03:01 - 2012-10-08 08:40 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-11-14 03:01 - 2012-10-08 08:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00744448 ____A (Microsoft Corporation) C:\Windows\System32\WUDFx.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe
2012-11-14 03:00 - 2012-07-26 04:08 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\WUDFPlatform.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\WUDFSvc.dll
2012-11-14 03:00 - 2012-07-26 04:08 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\WUDFCoinstaller.dll
2012-11-14 03:00 - 2012-07-26 03:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys
2012-11-14 03:00 - 2012-07-26 03:26 - 00087040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys
2012-11-14 03:00 - 2012-06-02 15:57 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2012-11-14 01:04 - 2012-11-14 03:15 - 00000000 ____D C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW
2012-11-14 01:03 - 2012-11-14 01:03 - 00151230 ____A C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW.torrent
2012-11-13 23:05 - 2012-10-18 19:25 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-11-13 23:05 - 2012-10-09 19:17 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2012-11-13 23:05 - 2012-10-09 19:17 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2012-11-13 23:05 - 2012-10-09 18:40 - 00193536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2012-11-13 23:05 - 2012-10-09 18:40 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2012-11-13 23:05 - 2012-10-03 18:56 - 01914248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-11-13 23:05 - 2012-10-03 18:44 - 00303104 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00246272 ____A (Microsoft Corporation) C:\Windows\System32\netcorehc.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00216576 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2012-11-13 23:05 - 2012-10-03 18:44 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\netevent.dll
2012-11-13 23:05 - 2012-10-03 18:42 - 00569344 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2012-11-13 23:05 - 2012-10-03 17:42 - 00175104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2012-11-13 23:05 - 2012-10-03 17:42 - 00156672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2012-11-13 23:05 - 2012-10-03 17:42 - 00018944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2012-11-13 23:05 - 2012-10-03 17:07 - 00045568 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2012-11-13 23:05 - 2012-01-13 08:12 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2012-11-13 23:04 - 2012-09-25 23:47 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2012-11-13 23:04 - 2012-09-25 23:46 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\synceng.dll
2012-11-11 20:58 - 2012-11-11 20:58 - 00004376 ____A C:\WirelessDiagLog.csv
2012-11-10 17:08 - 2012-11-10 17:08 - 00027520 ____A C:\Users\Simon\AppData\Local\dt.dat
2012-11-10 16:36 - 2012-11-10 16:56 - 00000000 ____D C:\Program Files\Dell Support Center
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dell
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\All Users\PCDr
2012-11-10 16:32 - 2012-11-10 16:32 - 00038984 ____A (Dell Computer Corporation) C:\Users\Simon\Downloads\DellPCDiagnostics.exe
2012-11-10 16:32 - 2012-11-10 16:32 - 00000000 ____D C:\Users\Simon\AppData\Roaming\PCDr
2012-11-10 16:25 - 2012-11-10 16:26 - 06059000 ____A C:\Users\Simon\Downloads\R295126.exe
2012-11-10 16:24 - 2012-11-10 16:25 - 08276776 ____A C:\Users\Simon\Downloads\USB3_Renesas_W7_A03_Setup-61X2W_ZPE.exe
2012-11-10 16:16 - 2012-11-10 16:18 - 17371337 ____A C:\Users\Simon\Downloads\R317457.zip
2012-11-10 16:12 - 2012-11-10 16:13 - 04300104 ____A C:\Users\Simon\Downloads\CW1394A0.exe
2012-11-10 15:59 - 2012-11-20 21:41 - 00000000 ____D C:\Users\Simon\AppData\Local\Akamai
2012-11-10 15:57 - 2012-11-10 15:58 - 11064264 ____A (Akamai Technologies, Inc.) C:\Users\Simon\Downloads\Dell_Download_Manager_Setup.exe
2012-11-10 15:49 - 2012-11-10 15:49 - 00127480 ____A C:\Users\Simon\Downloads\DELL_S2230MX-MONITOR_A00-00_R303587.exe
2012-11-10 15:48 - 2012-11-10 15:49 - 10797616 ____A C:\Users\Simon\Downloads\R296901.exe
2012-11-10 15:47 - 2012-11-10 15:47 - 00010579 ____A C:\Users\Simon\Downloads\dellsystemdetect.application
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Verimatrix
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\All Users\Verimatrix
2012-11-10 15:39 - 2012-11-10 15:40 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller.msi
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Windows\System32\Macromed
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Users\All Users\ALM
2012-11-04 20:13 - 2012-11-04 20:13 - 00000000 ____D C:\Users\Simon\Adobe Flash Builder 4.6
2012-11-04 20:08 - 2012-11-04 20:08 - 00002026 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2012-11-04 18:53 - 2012-11-04 19:06 - 00000000 ____D C:\Users\Simon\Desktop\Adobe CS6 Master Collection
2012-11-04 17:35 - 2012-11-04 17:35 - 00016981 ____A C:\Users\Simon\Downloads\[isoHunt] Adobe CS6 Master Collection (1).torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000616 ____A C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE.torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000000 ____D C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE
2012-11-04 17:25 - 2012-11-04 17:25 - 00001706 ____A C:\Users\Simon\Downloads\Adobe_CS6_All_Products_Activator__x32___x64___2012_-MPT (1).torrent
2012-11-04 13:55 - 2012-11-09 00:37 - 00000000 ____D C:\Users\Simon\AppData\Roaming\TeamViewer
2012-11-04 13:54 - 2012-11-04 13:54 - 00001166 ____A C:\Users\Public\Desktop\TeamViewer 7.lnk
2012-11-04 13:54 - 2012-11-04 13:54 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2012-11-04 13:52 - 2012-11-04 13:52 - 04939440 ____A (TeamViewer GmbH) C:\Users\Simon\Downloads\TeamViewer_Setup.exe
2012-11-04 13:50 - 2012-11-18 21:45 - 00000000 ____D C:\Program Files (x86)\VaudiX
2012-11-04 13:49 - 2012-11-20 12:43 - 00000370 ___AH C:\Windows\Tasks\VaudiXUpdaterTask{6F5B29B3-E8F2-4AE4-83C7-C188B6020673}.job
2012-11-04 13:49 - 2012-11-04 13:50 - 00000000 ____D C:\Users\All Users\Premium
2012-11-04 13:48 - 2012-11-18 21:45 - 00000000 ____D C:\Users\All Users\InstallMate
2012-11-04 13:48 - 2012-11-04 13:48 - 00300936 ____A (Premium) C:\Users\Simon\Downloads\VaudiX.exe
2012-11-04 13:48 - 2012-11-04 13:48 - 00000000 ____D C:\Users\All Users\Vaudix
2012-11-04 10:03 - 2012-11-04 10:03 - 00015872 ____A C:\Users\Simon\Downloads\seminarji.xls
2012-11-03 22:55 - 2012-11-03 22:55 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Mozilla
2012-10-30 09:41 - 2012-10-30 09:41 - 00482816 ____H C:\Users\Simon\Downloads\~WRL2901.tmp
2012-10-28 17:33 - 2012-10-28 17:33 - 00056823 ____A C:\Users\Simon\Downloads\Ice.Age.4.Continental.Drift.2012.SLOSubs.DVDRip.XviD-DrSi.torrent
2012-10-26 22:13 - 2012-10-27 00:37 - 00000000 ____D C:\CS6
2012-10-26 21:58 - 2012-10-26 22:09 - 00000000 ____D C:\Users\Simon\Downloads\Project.X.2012.EXTENDED.SLOSubs.DVDRip.XviD-DrSi
2012-10-24 21:41 - 2012-10-24 21:41 - 00055176 ____A C:\Users\Simon\Downloads\Adobe.CS6.Master.Collection-milkman (1).torrent
2012-10-24 21:35 - 2012-10-24 21:35 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-10-24 21:35 - 2012-10-24 21:35 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-10-24 21:32 - 2012-10-24 21:34 - 39483256 ____A (Apple Inc.) C:\Users\Simon\Downloads\QuickTimeInstaller.exe
2012-10-23 18:06 - 2012-10-23 18:07 - 16061064 ____A C:\Users\Simon\Downloads\getOrder_promo_mix.mp4
2012-10-22 11:33 - 2012-10-22 11:33 - 00000000 ____D C:\Users\All Users\Hewlett-Packard
2012-10-21 21:20 - 2012-11-20 12:44 - 00000000 ___RD C:\Users\Simon\Dropbox
2012-10-21 21:20 - 2012-10-21 21:20 - 00001043 ____A C:\Users\Simon\Desktop\Dropbox.lnk
2012-10-21 21:18 - 2012-11-20 12:44 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dropbox
2012-10-21 21:18 - 2012-10-21 21:18 - 05694794 ____A C:\Users\Simon\Downloads\template-discsurface.zip
2012-10-21 21:16 - 2012-10-21 21:17 - 17813784 ____A (Dropbox, Inc.) C:\Users\Simon\Downloads\Dropbox 1.4.17.exe
==================== One Month Modified Files and Folders =======
2012-11-20 21:41 - 2012-11-19 08:34 - 00000000 ____D C:\Program Files (x86)\Verimatrix
2012-11-20 21:41 - 2012-11-10 15:59 - 00000000 ____D C:\Users\Simon\AppData\Local\Akamai
2012-11-20 21:41 - 2012-07-15 14:09 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2012-11-20 21:41 - 2012-07-10 14:13 - 00000000 ____D C:\Windows\System32\Drivers\AVG
2012-11-20 21:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2012-11-20 21:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat
2012-11-20 12:44 - 2012-11-20 12:44 - 00000000 ____D C:\FRST
2012-11-20 12:44 - 2012-10-21 21:20 - 00000000 ___RD C:\Users\Simon\Dropbox
2012-11-20 12:44 - 2012-10-21 21:18 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dropbox
2012-11-20 12:43 - 2012-11-04 13:49 - 00000370 ___AH C:\Windows\Tasks\VaudiXUpdaterTask{6F5B29B3-E8F2-4AE4-83C7-C188B6020673}.job
2012-11-20 12:43 - 2012-08-04 22:00 - 00001050 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-11-20 12:43 - 2012-07-10 13:18 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-11-20 12:43 - 2012-07-10 12:52 - 00000000 ____D C:\users\Simon
2012-11-20 12:43 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-11-20 12:43 - 2009-07-14 05:51 - 00038635 ____A C:\Windows\setupact.log
2012-11-20 12:29 - 2012-11-20 12:29 - 00000326 ____A C:\Users\Simon\Downloads\fixlist.txt
2012-11-20 02:00 - 2012-08-22 12:16 - 00000000 ____D C:\Users\Simon\AppData\Local\Adobe
2012-11-19 08:34 - 2012-11-19 08:33 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller (1).msi
2012-11-19 08:10 - 2012-08-04 22:00 - 00001054 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-11-19 07:49 - 2009-07-14 05:45 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-19 07:49 - 2009-07-14 05:45 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-19 07:48 - 2009-07-14 06:13 - 00778660 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-19 07:42 - 2012-07-10 14:13 - 00000000 ____D C:\Users\All Users\AVG2012
2012-11-19 07:42 - 2010-11-21 04:47 - 00010042 ____A C:\Windows\PFRO.log
2012-11-19 07:41 - 2012-07-21 12:40 - 00000000 ____D C:\Users\Simon\AppData\Roaming\uTorrent
2012-11-19 07:40 - 2012-11-19 07:40 - 00003210 ____A C:\Users\Simon\Desktop\RKreport[1]_S_11192012_02d0740.txt
2012-11-19 07:40 - 2012-11-19 07:39 - 00000000 ____D C:\Users\Simon\Desktop\RK_Quarantine
2012-11-19 07:39 - 2012-11-19 07:39 - 00729088 ____A C:\Users\Simon\Downloads\RogueKiller.exe
2012-11-19 07:37 - 2012-07-10 13:54 - 00001066 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4188228576-3451463030-3658580190-1000UA.job
2012-11-19 07:00 - 2012-07-10 14:04 - 00000000 ____D C:\Users\All Users\MFAData
2012-11-18 21:58 - 2012-11-18 21:58 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-18 21:47 - 2012-11-18 21:47 - 00000000 ____D C:\Windows\System32\appmgmt
2012-11-18 21:45 - 2012-11-04 13:50 - 00000000 ____D C:\Program Files (x86)\VaudiX
2012-11-18 21:45 - 2012-11-04 13:48 - 00000000 ____D C:\Users\All Users\InstallMate
2012-11-18 21:27 - 2012-07-15 14:42 - 00000000 ____D C:\Users\Simon\AppData\Roaming\vlc
2012-11-18 21:24 - 2012-11-18 21:24 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-11-18 21:24 - 2012-11-18 21:24 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-11-18 20:47 - 2012-11-18 20:47 - 00000000 ____D C:\Program Files (x86)\Mega Codec Pack
2012-11-18 20:47 - 2012-07-10 12:52 - 01728130 ____A C:\Windows\WindowsUpdate.log
2012-11-18 20:41 - 2012-11-18 20:09 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 Eng [DVDRip] Dual Audio - DiAMOND
2012-11-18 20:09 - 2012-11-18 20:09 - 00030903 ____A C:\Users\Simon\Downloads\[isoHunt] 4935305.torrent
2012-11-18 20:09 - 2012-11-18 19:41 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R
2012-11-18 20:07 - 2012-11-18 20:06 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775 (1).exe
2012-11-18 20:05 - 2012-11-18 20:05 - 00000000 ____D C:\Program Files (x86)\Xvid
2012-11-18 20:04 - 2012-11-18 20:03 - 10768856 ____A (Xvid Team) C:\Users\Simon\Downloads\Xvid-1.3.2-20110601.exe
2012-11-18 20:01 - 2012-11-18 20:00 - 09060224 ____A (Gygan Inc ) C:\Users\Simon\Downloads\gyganinstall_0775.exe
2012-11-18 19:40 - 2012-11-18 19:40 - 00014370 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect 2012 DVDRip XviD-HELLRAZ0R.torrent
2012-11-18 19:40 - 2012-11-18 17:46 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect [2012] R5 XViD - RAWNiTRO
2012-11-18 17:45 - 2012-11-18 17:45 - 00000000 ____D C:\Users\Simon\Downloads\Pitch Perfect 2012 English HD-quality
2012-11-18 17:44 - 2012-11-18 17:44 - 00008591 ____A C:\Users\Simon\Downloads\[isoHunt] Pitch Perfect [2012] R5 XViD - RAWNiTRO.torrent
2012-11-18 17:42 - 2012-11-18 17:41 - 00056893 ____A C:\Users\Simon\Downloads\[isoHunt] download.torrent
2012-11-18 16:59 - 2012-07-24 14:42 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Skype
2012-11-18 15:55 - 2012-07-10 13:54 - 00001014 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4188228576-3451463030-3658580190-1000Core.job
2012-11-16 15:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
2012-11-15 01:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2012-11-14 03:29 - 2012-07-10 13:51 - 00087984 ____A C:\Users\Simon\AppData\Local\GDIPFONTCACHEV1.DAT
2012-11-14 03:24 - 2009-07-14 05:45 - 04990416 ____A C:\Windows\System32\FNTCACHE.DAT
2012-11-14 03:23 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-11-14 03:15 - 2012-11-14 01:04 - 00000000 ____D C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW
2012-11-14 01:03 - 2012-11-14 01:03 - 00151230 ____A C:\Users\Simon\Downloads\Call.of.Duty.Black.Ops.II-SKIDROW.torrent
2012-11-11 20:58 - 2012-11-11 20:58 - 00004376 ____A C:\WirelessDiagLog.csv
2012-11-10 17:16 - 2012-07-10 13:54 - 00000000 ____D C:\Users\Simon\AppData\Local\Deployment
2012-11-10 17:08 - 2012-11-10 17:08 - 00027520 ____A C:\Users\Simon\AppData\Local\dt.dat
2012-11-10 16:56 - 2012-11-10 16:36 - 00000000 ____D C:\Program Files\Dell Support Center
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Dell
2012-11-10 16:36 - 2012-11-10 16:36 - 00000000 ____D C:\Users\All Users\PCDr
2012-11-10 16:36 - 2012-07-10 14:09 - 00000000 ____D C:\Users\All Users\Dell
2012-11-10 16:32 - 2012-11-10 16:32 - 00038984 ____A (Dell Computer Corporation) C:\Users\Simon\Downloads\DellPCDiagnostics.exe
2012-11-10 16:32 - 2012-11-10 16:32 - 00000000 ____D C:\Users\Simon\AppData\Roaming\PCDr
2012-11-10 16:26 - 2012-11-10 16:25 - 06059000 ____A C:\Users\Simon\Downloads\R295126.exe
2012-11-10 16:25 - 2012-11-10 16:24 - 08276776 ____A C:\Users\Simon\Downloads\USB3_Renesas_W7_A03_Setup-61X2W_ZPE.exe
2012-11-10 16:18 - 2012-11-10 16:16 - 17371337 ____A C:\Users\Simon\Downloads\R317457.zip
2012-11-10 16:13 - 2012-11-10 16:12 - 04300104 ____A C:\Users\Simon\Downloads\CW1394A0.exe
2012-11-10 15:58 - 2012-11-10 15:57 - 11064264 ____A (Akamai Technologies, Inc.) C:\Users\Simon\Downloads\Dell_Download_Manager_Setup.exe
2012-11-10 15:51 - 2012-07-10 13:17 - 00000000 ____D C:\Program Files (x86)\Intel
2012-11-10 15:49 - 2012-11-10 15:49 - 00127480 ____A C:\Users\Simon\Downloads\DELL_S2230MX-MONITOR_A00-00_R303587.exe
2012-11-10 15:49 - 2012-11-10 15:48 - 10797616 ____A C:\Users\Simon\Downloads\R296901.exe
2012-11-10 15:47 - 2012-11-10 15:47 - 00010579 ____A C:\Users\Simon\Downloads\dellsystemdetect.application
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Verimatrix
2012-11-10 15:46 - 2012-11-10 15:46 - 00000000 ____D C:\Users\All Users\Verimatrix
2012-11-10 15:40 - 2012-11-10 15:39 - 11154432 ____A C:\Users\Simon\Downloads\ViewRightWebInstaller.msi
2012-11-09 00:37 - 2012-11-04 13:55 - 00000000 ____D C:\Users\Simon\AppData\Roaming\TeamViewer
2012-11-09 00:36 - 2012-07-22 21:53 - 00001998 ___AH C:\Users\Simon\Documents\Default.rdp
2012-11-08 23:56 - 2012-07-10 14:14 - 00000000 ____D C:\Users\All Users\AVG Secure Search
2012-11-08 23:56 - 2012-07-10 14:14 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search
2012-11-08 23:55 - 2012-08-27 08:43 - 00030568 ____A (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys
2012-11-05 00:11 - 2012-09-02 10:30 - 00000021 ____A C:\Windows\SurCode.INI
2012-11-05 00:11 - 2012-09-02 10:30 - 00000000 ____D C:\Users\Simon\Documents\Adobe
2012-11-04 20:29 - 2012-08-22 13:54 - 00000000 ____D C:\Users\All Users\Adobe
2012-11-04 20:27 - 2012-09-30 20:12 - 00000000 ____D C:\Program Files\Common Files\Adobe
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Windows\System32\Macromed
2012-11-04 20:19 - 2012-11-04 20:19 - 00000000 ____D C:\Users\All Users\ALM
2012-11-04 20:19 - 2012-07-10 13:57 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Adobe
2012-11-04 20:17 - 2012-08-22 14:01 - 00000000 ____D C:\Program Files (x86)\Adobe
2012-11-04 20:13 - 2012-11-04 20:13 - 00000000 ____D C:\Users\Simon\Adobe Flash Builder 4.6
2012-11-04 20:08 - 2012-11-04 20:08 - 00002026 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2012-11-04 19:56 - 2012-08-22 14:00 - 00000000 ____D C:\Program Files\Adobe
2012-11-04 19:06 - 2012-11-04 18:53 - 00000000 ____D C:\Users\Simon\Desktop\Adobe CS6 Master Collection
2012-11-04 17:58 - 2012-08-20 12:37 - 00000000 ____D C:\Users\Simon\Downloads\Adobe CS6 Master Collection
2012-11-04 17:40 - 2012-09-30 22:22 - 00000000 ____D C:\Users\Simon\Downloads\Adobe.Master.Collection.CS6.LS16+Patch [WORKING]
2012-11-04 17:40 - 2012-09-26 12:49 - 00000000 ____D C:\Users\Simon\Downloads\Adobe.CS6.Master.Collection-milkman
2012-11-04 17:40 - 2012-07-23 18:35 - 00000000 ____D C:\Users\Simon\Downloads\Adobe Premiere Pro CS6 (64 Bit) - Cool Release
2012-11-04 17:35 - 2012-11-04 17:35 - 00016981 ____A C:\Users\Simon\Downloads\[isoHunt] Adobe CS6 Master Collection (1).torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000616 ____A C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE.torrent
2012-11-04 17:26 - 2012-11-04 17:26 - 00000000 ____D C:\Users\Simon\Downloads\ADOBE_CS6.0_MASTER_COLLECTION_WIN_OSX_KEYGEN-XFORCE
2012-11-04 17:25 - 2012-11-04 17:25 - 00001706 ____A C:\Users\Simon\Downloads\Adobe_CS6_All_Products_Activator__x32___x64___2012_-MPT (1).torrent
2012-11-04 13:54 - 2012-11-04 13:54 - 00001166 ____A C:\Users\Public\Desktop\TeamViewer 7.lnk
2012-11-04 13:54 - 2012-11-04 13:54 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2012-11-04 13:52 - 2012-11-04 13:52 - 04939440 ____A (TeamViewer GmbH) C:\Users\Simon\Downloads\TeamViewer_Setup.exe
2012-11-04 13:50 - 2012-11-04 13:49 - 00000000 ____D C:\Users\All Users\Premium
2012-11-04 13:48 - 2012-11-04 13:48 - 00300936 ____A (Premium) C:\Users\Simon\Downloads\VaudiX.exe
2012-11-04 13:48 - 2012-11-04 13:48 - 00000000 ____D C:\Users\All Users\Vaudix
2012-11-04 11:40 - 2012-07-15 10:46 - 00000000 ____D C:\Users\Simon\AppData\Local\Apple Computer
2012-11-04 10:03 - 2012-11-04 10:03 - 00015872 ____A C:\Users\Simon\Downloads\seminarji.xls
2012-11-03 22:55 - 2012-11-03 22:55 - 00000000 ____D C:\Users\Simon\AppData\Roaming\Mozilla
2012-10-30 09:41 - 2012-10-30 09:41 - 00482816 ____H C:\Users\Simon\Downloads\~WRL2901.tmp
2012-10-28 17:33 - 2012-10-28 17:33 - 00056823 ____A C:\Users\Simon\Downloads\Ice.Age.4.Continental.Drift.2012.SLOSubs.DVDRip.XviD-DrSi.torrent
2012-10-27 00:37 - 2012-10-26 22:13 - 00000000 ____D C:\CS6
2012-10-26 22:09 - 2012-10-26 21:58 - 00000000 ____D C:\Users\Simon\Downloads\Project.X.2012.EXTENDED.SLOSubs.DVDRip.XviD-DrSi
2012-10-24 21:41 - 2012-10-24 21:41 - 00055176 ____A C:\Users\Simon\Downloads\Adobe.CS6.Master.Collection-milkman (1).torrent
2012-10-24 21:35 - 2012-10-24 21:35 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-10-24 21:35 - 2012-10-24 21:35 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-10-24 21:34 - 2012-10-24 21:32 - 39483256 ____A (Apple Inc.) C:\Users\Simon\Downloads\QuickTimeInstaller.exe
2012-10-23 18:07 - 2012-10-23 18:06 - 16061064 ____A C:\Users\Simon\Downloads\getOrder_promo_mix.mp4
2012-10-22 11:33 - 2012-10-22 11:33 - 00000000 ____D C:\Users\All Users\Hewlett-Packard
2012-10-21 21:20 - 2012-10-21 21:20 - 00001043 ____A C:\Users\Simon\Desktop\Dropbox.lnk
2012-10-21 21:18 - 2012-10-21 21:18 - 05694794 ____A C:\Users\Simon\Downloads\template-discsurface.zip
2012-10-21 21:17 - 2012-10-21 21:16 - 17813784 ____A (Dropbox, Inc.) C:\Users\Simon\Downloads\Dropbox 1.4.17.exe
ZeroAccess:
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L\00000004.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L\201d3dde
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\L\55490ac4
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\00000004.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\00000008.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\000000cb.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\80000000.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\80000032.@
C:\Windows\Installer\{4a932166-9e69-a220-2dc9-039feeedcfac}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 24%
Total physical RAM: 8086.17 MB
Available physical RAM: 6103.46 MB
Total Pagefile: 16170.53 MB
Available Pagefile: 14007.01 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:390.62 GB) (Free:100.36 GB) NTFS
2 Drive d: () (Fixed) (Total:288.38 GB) (Free:38.71 GB) NTFS
3 Drive e: (GSP1RMCPRXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
5 Drive g: () (Removable) (Total:7.44 GB) (Free:3.45 GB) FAT32
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 7638 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 19 GB 104 MB
Partition 3 Primary 288 GB 19 GB
Partition 4 Primary 390 GB 308 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
There is no volume associated with this partition.
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 RECOVERY NTFS Partition 19 GB Healthy System (partition with boot components)
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D NTFS Partition 288 GB Healthy
=========================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 C NTFS Partition 390 GB Healthy Boot
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7634 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 G FAT32 Removable 7634 MB Healthy
=========================================================
Last Boot: 2012-11-15 01:23
==================== End Of Log =============================