Here are the results from Farbar
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2013
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Pokki) C:\Users\dendi\AppData\Local\Pokki\Engine\pokki.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SoftEther Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Dropbox, Inc.) C:\Users\dendi\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Visagesoft) C:\Program Files (x86)\Avanquest\Expert PDF 8 Professional\vspdfprsrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Zemana Ltd.) C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe
(Pokki) C:\Users\dendi\AppData\Local\Pokki\Engine\pokki.exe
(Pokki) C:\Users\dendi\AppData\Local\Pokki\Engine\pokki.exe
(Pokki) C:\Users\dendi\AppData\Local\Pokki\Engine\pokki.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.)
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe" [627360 2011-05-20] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe" [379552 2011-05-20] (Atheros Commnucations)
HKLM\...\Run: [SoftEther VPN Client UI Helper] "C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe" /uihelp [4267064 2013-04-27] (SoftEther Project at University
of Tsukuba, Japan.)
HKLM-x32\...\Runonce: [WD Smartware Upgrader - Uninstall] cmd /c MsiExec.exe /X{3890215D-D18A-43EF-AE0C-0C6B084F652D} /qn [x]
HKCU\...\Run: [Facebook Update] "C:\Users\dendi\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2013-02-15] (Facebook Inc.)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18678376 2013-04-19] (Skype Technologies S.A.)
HKCU\...\Run: [openvpntray.EXE] C:\Users\dendi\AppData\Roaming\Hotspot Shield\bin\openvpntray.EXE -nonadmin [x]
HKCU\...\Run: [Mobile Partner] C:\Program Files (x86)\Qtel Mobile Broadband\Qtel Mobile Broadband.exe [515072 2013-04-15] ()
HKCU\...\Run: [Pokki] C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\LaunchDeskband.dll",RunLaunchDeskband [x]
HKCU\...\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-03-28] (Samsung)
MountPoints2: F - "F:\WD Drive Unlock.exe" autoplay=true
MountPoints2: G - "G:\WD Drive Unlock.exe" autoplay=true
MountPoints2: H - H:\AutoRun.exe
MountPoints2: {0da1c840-a657-11e2-8218-ca5426c6984a} - I:\AutoRun.exe /s
MountPoints2: {8f088e77-a8d9-11e2-8603-c7e321c0e347} - F:\AutoRun.exe
MountPoints2: {9381be26-abd7-11e2-987f-efe378551f59} - F:\AutoRun.exe
MountPoints2: {93c3d6b6-a1a5-11e2-a75c-00ac778b001b} - F:\AutoRun.exe /s
MountPoints2: {93c3d6cd-a1a5-11e2-a75c-00ac778b001b} - F:\AutoRun.exe /s
MountPoints2: {93d8decf-a4c2-11e2-83d0-00ac778b001b} - F:\AutoRun.exe
MountPoints2: {93d8dee5-a4c2-11e2-83d0-00ac778b001b} - F:\AutoRun.exe
MountPoints2: {93d8df06-a4c2-11e2-83d0-00ac778b001b} - F:\AutoRun.exe
MountPoints2: {9aac018e-86e9-11e2-870c-e42f57de7c53} - F:\AutoRun.exe
MountPoints2: {9aac01d8-86e9-11e2-870c-e42f57de7c53} - F:\AutoRun.exe
MountPoints2: {9aac081a-86e9-11e2-870c-e42f57de7c53} - F:\AutoRun.exe
MountPoints2: {cdf5a621-7342-11e2-ae63-00ac778b001b} - G:\LaunchU3.exe -a
MountPoints2: {e82726c8-5a1c-11e2-a341-7845c4a33b5a} - "F:\WD Drive Unlock.exe" autoplay=true
HKLM-x32\...\Run: [Communicator] "C:\Program Files (x86)\Microsoft Office Communicator\communicator.exe" /fromrunkey [5164624 2012-11-30] (Microsoft Corporation)
HKLM-x32\...\Run: [vspdfprsrv.exe] C:\Program Files (x86)\Avanquest\Expert PDF 8 Professional\vspdfprsrv.exe --background [6078464 2012-04-23] (Visagesoft)
HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5237256 2012-12-20] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310640 2013-03-28] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe [601928 2013-05-13] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [ZALFree] "C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe" /MINIMIZED [12995376 2013-05-24] (Zemana Ltd.)
AppInit_DLLs: C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL [89936 2013-05-24] (Zemana Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL [82696 2013-05-24] (Zemana Ltd.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\vpngui.exe.lnk
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe (No File)
Startup: C:\Users\dendi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\dendi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
ProxyServer: nhq-proxy:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uae.msn.com/?rd=1&ucc=QA&dcc=QA&opt=1&ocid=iehp&tc=0
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 06 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 mswsock.dll File Not found ()
Winsock: Catalog9 02 mswsock.dll File Not found ()
Winsock: Catalog9 03 mswsock.dll File Not found ()
Winsock: Catalog9 04 mswsock.dll File Not found ()
Winsock: Catalog9 05 mswsock.dll File Not found ()
Winsock: Catalog9 06 mswsock.dll File Not found ()
Winsock: Catalog9 07 mswsock.dll File Not found ()
Winsock: Catalog9 08 mswsock.dll File Not found ()
Winsock: Catalog9 09 mswsock.dll File Not found ()
Winsock: Catalog9 10 mswsock.dll File Not found ()
Winsock: Catalog9 11 mswsock.dll File Not found ()
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 06 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9-x64 01 mswsock.dll File Not found ()
Winsock: Catalog9-x64 02 mswsock.dll File Not found ()
Winsock: Catalog9-x64 03 mswsock.dll File Not found ()
Winsock: Catalog9-x64 04 mswsock.dll File Not found ()
Winsock: Catalog9-x64 05 mswsock.dll File Not found ()
Winsock: Catalog9-x64 06 mswsock.dll File Not found ()
Winsock: Catalog9-x64 07 mswsock.dll File Not found ()
Winsock: Catalog9-x64 08 mswsock.dll File Not found ()
Winsock: Catalog9-x64 09 mswsock.dll File Not found ()
Winsock: Catalog9-x64 10 mswsock.dll File Not found ()
Winsock: Catalog9-x64 11 mswsock.dll File Not found ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3B634AEE-6BB1-478B-9E4E-35FBEC5D2DD2}: [NameServer]212.77.192.59 212.77.192.60
Tcpip\..\Interfaces\{A4E60143-839F-4212-8694-2C4921D717CC}: [NameServer]212.77.192.59 212.77.192.60
FireFox:
========
FF ProfilePath: C:\Users\dendi\AppData\Roaming\Mozilla\Firefox\Profiles\rlolupo8.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32:
google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: ???????? HTTP ?????????? - C:\Users\dendi\AppData\Roaming\Mozilla\Firefox\Profiles\rlolupo8.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
Chrome:
=======
CHR HomePage: hxxp://
www.google.com/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google

riginalQueryForSuggestion}{google:assistedQueryStats}
{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey=
{google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\dendi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.110.22) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Bejeweled) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0
CHR Extension: (Google Docs) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.65_0
CHR Extension: (Cut the Rope) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\15_0
CHR Extension: (Expenses.co.in) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gplpdfhoildmmfmchmhhfgigfhehjdbn\1.0.0.0_0
CHR Extension: (CouponsHelper) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpeepoceboiddajjkgdccddjkmmiigdh\1.3_0
CHR Extension: (Poppit) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0
CHR Extension: (Google Mail Checker) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0
CHR Extension: (Booking.com) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pficdecjkdlnacnnbkociacmdbpmhdoc\1.0.0.6_0
CHR Extension: (Gmail) - C:\Users\dendi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-05-20] (Atheros)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-05-13] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-05-13] (BlueStack Systems, Inc.)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S2 Qtel Mobile Broadband. RunOuc; C:\Program Files (x86)\Qtel Mobile Broadband\UpdateDog\ouc.exe [655712 2012-06-14] ()
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [4267064 2013-04-27] (SoftEther Project at University of Tsukuba, Japan.)
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15680000 2012-08-15] ()
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1155088 2012-12-20] (Western Digital )
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [248840 2012-12-20] (Western Digital)
R2 WDRulesService; C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [1178128 2012-12-20] (Western Digital )
==================== Drivers (Whitelisted) ====================
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-05-13] (BlueStack Systems)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-05-13] (BlueStack Systems)
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
R3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [26080 2013-05-24] (Zemana Ltd.)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0118.sys [29312 2013-01-26] (SoftEther Corporation)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.)
S3 massfilter_lte; \??\C:\Windows\system32\drivers\massfilter_lte.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
S3 zgdcat; system32\DRIVERS\zgdcat.sys [x]
S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [x]
S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [x]
S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [x]
S3 zgdcnmea; system32\DRIVERS\zgdcnmea.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-22 16:30 - 2013-06-22 16:30 - 00000000 ____D C:\FRST
2013-06-22 16:17 - 2013-06-22 16:17 - 02347384 ____A (ESET) C:\Users\dendi\Downloads\esetsmartinstaller_enu.exe
2013-06-22 16:17 - 2013-06-22 16:17 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-22 16:16 - 2013-06-22 16:16 - 01931364 ____A (Farbar) C:\Users\dendi\Downloads\FRST64.exe
2013-06-20 22:45 - 2013-06-20 22:45 - 00000000 ____D C:\Program Files (x86)\Twitter
2013-06-20 22:43 - 2013-06-20 22:44 - 14643200 ____A C:\Users\dendi\Downloads\TweetDeck.msi
2013-06-20 22:16 - 2013-06-22 15:44 - 00000000 ____D C:\Users\dendi\AppData\Local\AntiLogger Free
2013-06-20 22:07 - 2013-06-20 22:07 - 00000000 ____D C:\Program Files (x86)\Zemana AntiLogger Free
2013-06-20 22:07 - 2013-06-20 22:07 - 00000000 ____D C:\Program Files (x86)\KeyCryptSDK
2013-06-20 22:07 - 2013-05-24 17:08 - 00026080 ____A (Zemana Ltd.) C:\Windows\System32\Drivers\KeyCrypt64.sys
2013-06-20 22:06 - 2013-06-20 22:06 - 04316560 ____A (Zemana Ltd. ) C:\Users\dendi\Downloads
\AntiLoggerFree_Setup_1.6.2.226.exe
2013-06-19 10:53 - 2013-06-19 10:53 - 26981471 ____A C:\Users\dendi\Downloads\homepage_personal_20130619.psd
2013-06-19 10:44 - 2013-06-19 10:44 - 26981471 ____A C:\Users\dendi\Downloads\homepage_personal.psd
2013-06-19 10:21 - 2013-06-19 10:22 - 99012171 ____A C:\Users\dendi\Downloads\Ramadan Charity.rar
2013-06-18 12:11 - 2013-06-18 12:11 - 00020941 ____A C:\Users\dendi\Desktop\Copy of QODP DB Credentials Cross env's v1 2 (6).xlsx
2013-06-16 08:48 - 2013-06-16 15:49 - 00009477 ____A C:\Users\dendi\Desktop\Hours - June QTL10.xlsx
2013-06-13 14:15 - 2013-06-13 14:15 - 01418352 ____A (Juniper Networks, Inc.) C:\Users\dendi\Downloads\JuniperSetupClientInstaller.exe
2013-06-13 12:48 - 2013-06-13 12:48 - 03502400 ____A (RealVNC Ltd) C:\Users\dendi\Downloads\VNC-Viewer-5.0.5-Windows-64bit.exe
2013-06-08 23:06 - 2013-06-09 15:07 - 00000141 ____A C:\Users\dendi\Desktop\Numbers.txt
2013-06-02 16:02 - 2013-06-02 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-31 23:55 - 2013-05-31 23:55 - 00272531 ____A C:\Users\dendi\Downloads\contacts.csv
2013-05-31 22:43 - 2013-05-31 22:43 - 00851007 ____A C:\Users\dendi\Downloads\00001.vcf
2013-05-28 23:46 - 2013-05-29 00:08 - 00000000 ____D C:\Program Files (x86)\SmartBear
2013-05-28 23:46 - 2013-05-28 23:46 - 00002273 ____A C:\Users\Public\Desktop\soapUI 4.5.2.lnk
2013-05-28 23:26 - 2013-05-28 23:44 - 143916176 ____A (SmartBear Software) C:\Users\dendi\Downloads\soapUI-x32-4.5.2.exe
2013-05-23 10:54 - 2013-05-23 10:54 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2013-05-23 10:53 - 2013-05-23 10:58 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2013-05-23 10:53 - 2013-05-23 10:54 - 00000000 ____D C:\ProgramData\BlueStacks
2013-05-23 10:53 - 2013-05-23 10:53 - 11995256 ____A (BlueStack Systems Inc.) C:\Users\dendi\Downloads\BlueStacks-SplitInstaller_native.exe
==================== One Month Modified Files and Folders =======
2013-06-22 16:30 - 2013-06-22 16:30 - 00000000 ____D C:\FRST
2013-06-22 16:25 - 2013-01-09 09:10 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-22 16:22 - 2013-01-18 03:13 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-22 16:17 - 2013-06-22 16:17 - 02347384 ____A (ESET) C:\Users\dendi\Downloads\esetsmartinstaller_enu.exe
2013-06-22 16:17 - 2013-06-22 16:17 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-22 16:16 - 2013-06-22 16:16 - 01931364 ____A (Farbar) C:\Users\dendi\Downloads\FRST64.exe
2013-06-22 16:15 - 2009-07-14 07:45 - 00015488 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-22 16:15 - 2009-07-14 07:45 - 00015488 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-22 16:11 - 2013-01-09 11:14 - 00000000 ____D C:\Users\dendi\AppData\Roaming\Dropbox
2013-06-22 16:10 - 2013-01-09 08:37 - 00000000 ____D C:\Users\dendi\AppData\Roaming\Skype
2013-06-22 16:08 - 2013-01-09 16:12 - 00000000 ____D C:\Users\dendi\Tracing
2013-06-22 16:06 - 2013-04-06 17:01 - 00000000 ____D C:\Program Files\SoftEther VPN Client
2013-06-22 16:06 - 2013-01-09 09:10 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-22 16:05 - 2013-03-18 00:14 - 00026936 ____A C:\Windows\setupact.log
2013-06-22 16:05 - 2013-03-14 10:34 - 00000000 ____D C:\ProgramData\VMware
2013-06-22 16:05 - 2009-07-14 08:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-22 15:59 - 2013-03-21 23:33 - 00000000 ____D C:\ProgramData\MFAData
2013-06-22 15:51 - 2013-02-15 02:00 - 00000962 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-343818398-725345543-12728Core.job
2013-06-22 15:44 - 2013-06-20 22:16 - 00000000 ____D C:\Users\dendi\AppData\Local\AntiLogger Free
2013-06-22 15:44 - 2013-02-15 02:00 - 00000984 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1085031214-343818398-725345543-12728UA.job
2013-06-22 01:07 - 2013-04-12 15:12 - 00000000 ____D C:\Users\dendi\AppData\Roaming\vlc
2013-06-22 00:45 - 2013-04-04 21:34 - 00000000 ____D C:\Users\dendi\AppData\Roaming\uTorrent
2013-06-21 20:56 - 2013-04-19 21:03 - 00000000 ____D C:\Users\dendi\AppData\Local\Pokki
2013-06-20 22:45 - 2013-06-20 22:45 - 00000000 ____D C:\Program Files (x86)\Twitter
2013-06-20 22:44 - 2013-06-20 22:43 - 14643200 ____A C:\Users\dendi\Downloads\TweetDeck.msi
2013-06-20 22:07 - 2013-06-20 22:07 - 00000000 ____D C:\Program Files (x86)\Zemana AntiLogger Free
2013-06-20 22:07 - 2013-06-20 22:07 - 00000000 ____D C:\Program Files (x86)\KeyCryptSDK
2013-06-20 22:06 - 2013-06-20 22:06 - 04316560 ____A (Zemana Ltd. ) C:\Users\dendi\Downloads
\AntiLoggerFree_Setup_1.6.2.226.exe
2013-06-20 11:10 - 2013-01-23 08:48 - 00000000 ____D C:\Users\dendi\Desktop\Temporary
2013-06-19 14:22 - 2013-01-14 18:53 - 00002188 ___AH C:\Users\dendi\Documents\Default.rdp
2013-06-19 10:53 - 2013-06-19 10:53 - 26981471 ____A C:\Users\dendi\Downloads\homepage_personal_20130619.psd
2013-06-19 10:44 - 2013-06-19 10:44 - 26981471 ____A C:\Users\dendi\Downloads\homepage_personal.psd
2013-06-19 10:22 - 2013-06-19 10:21 - 99012171 ____A C:\Users\dendi\Downloads\Ramadan Charity.rar
2013-06-18 21:40 - 2013-02-12 22:44 - 00000132 ____A C:\Users\dendi\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-06-18 21:39 - 2013-02-09 13:20 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-06-18 21:11 - 2009-07-14 08:13 - 00730528 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-18 12:11 - 2013-06-18 12:11 - 00020941 ____A C:\Users\dendi\Desktop\Copy of QODP DB Credentials Cross env's v1 2 (6).xlsx
2013-06-17 09:10 - 2013-02-05 22:09 - 00000000 ____D C:\Users\dendi\Desktop\Personal
2013-06-16 15:49 - 2013-06-16 08:48 - 00009477 ____A C:\Users\dendi\Desktop\Hours - June QTL10.xlsx
2013-06-13 14:15 - 2013-06-13 14:15 - 01418352 ____A (Juniper Networks, Inc.) C:\Users\dendi\Downloads\JuniperSetupClientInstaller.exe
2013-06-13 12:48 - 2013-06-13 12:48 - 03502400 ____A (RealVNC Ltd) C:\Users\dendi\Downloads\VNC-Viewer-5.0.5-Windows-64bit.exe
2013-06-12 10:22 - 2013-01-18 03:13 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 10:22 - 2013-01-18 03:13 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 08:54 - 2013-01-13 15:45 - 00000000 ____D C:\Users\dendi\Documents\My Received Files
2013-06-09 15:07 - 2013-06-08 23:06 - 00000141 ____A C:\Users\dendi\Desktop\Numbers.txt
2013-06-03 08:00 - 2013-01-08 15:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-02 16:02 - 2013-06-02 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-02 08:04 - 2013-03-21 23:53 - 00042728 ____A C:\Windows\PFRO.log
2013-05-31 23:55 - 2013-05-31 23:55 - 00272531 ____A C:\Users\dendi\Downloads\contacts.csv
2013-05-31 22:43 - 2013-05-31 22:43 - 00851007 ____A C:\Users\dendi\Downloads\00001.vcf
2013-05-29 00:08 - 2013-05-28 23:46 - 00000000 ____D C:\Program Files (x86)\SmartBear
2013-05-29 00:08 - 2013-01-08 11:25 - 00000000 ____D C:\users\iHorizons
2013-05-28 23:46 - 2013-05-28 23:46 - 00002273 ____A C:\Users\Public\Desktop\soapUI 4.5.2.lnk
2013-05-28 23:44 - 2013-05-28 23:26 - 143916176 ____A (SmartBear Software) C:\Users\dendi\Downloads\soapUI-x32-4.5.2.exe
2013-05-26 10:00 - 2013-04-25 13:13 - 00237056 ____A C:\Users\dendi\Desktop\Octopus_Issue_Feedback_Post_Go_Live_v1 0_2013-23-05.xls
2013-05-24 17:08 - 2013-06-20 22:07 - 00026080 ____A (Zemana Ltd.) C:\Windows\System32\Drivers\KeyCrypt64.sys
2013-05-23 10:58 - 2013-05-23 10:53 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2013-05-23 10:54 - 2013-05-23 10:54 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2013-05-23 10:54 - 2013-05-23 10:53 - 00000000 ____D C:\ProgramData\BlueStacks
2013-05-23 10:54 - 2009-07-14 06:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-05-23 10:53 - 2013-05-23 10:53 - 11995256 ____A (BlueStack Systems Inc.) C:\Users\dendi\Downloads\BlueStacks-SplitInstaller_native.exe
ZeroAccess:
C:\Windows\Installer\{b053bc83-39fe-543c-7b96-99a430e0365a}
C:\Windows\Installer\{b053bc83-39fe-543c-7b96-99a430e0365a}\@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
==================== End Of Log ============================