Rearranged
Posts: 12 +0
Evening 
We have unfortunately come across this nasty little virus tonight, probably between 16:00 and 19:00 local time (from logging below). After scouring Google for an hour have seen lots of helpful replies from this forum and so come begging for help
Below are the two logs from FRST. If anyone can help me successfully remove this I will gladly send a donation your way for your time and effort. Many thanks in advance
Logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-01-2013 02
Ran by SYSTEM at 30-01-2013 19:25:07
Running from F:\
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-28] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-27] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-16] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152544 2012-12-11] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [3147384 2012-12-10] (AVG Technologies CZ, s.r.o.)
HKU\Ann\...\Run: [Google Update] "C:\Users\Ann\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-09-16] (Google Inc.)
HKU\Ann\...\Run: [Mezzmo] C:\Program Files (x86)\Conceiva\Mezzmo\Mezzmo.exe [10608496 2012-09-26] (Conceiva Pty. Ltd.)
HKU\Ann\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-22] (Apple Inc.)
HKU\Ann\...\Run: [Facebook Update] "C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-08-22] (Facebook Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Ann\Start Menu\Programs\Startup\Facebook Messenger.lnk
ShortcutTarget: Facebook Messenger.lnk -> (No File)
Startup: C:\Users\Ann\Start Menu\Programs\Startup\Mezzmo.lnk
ShortcutTarget: Mezzmo.lnk -> C:\Program Files (x86)\Conceiva\Mezzmo\Mezzmo.exe (Conceiva Pty. Ltd.)
Startup: C:\Users\Ann\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Ann\Start Menu\Programs\Startup\PeerBlock.lnk
ShortcutTarget: PeerBlock.lnk -> C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
==================== Services (Whitelisted) ===================
2 avgfws; "C:\Program Files (x86)\AVG\AVG2013\avgfws.exe" [1342024 2012-12-09] (AVG Technologies CZ, s.r.o.)
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe" [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe" [196664 2012-10-21] (AVG Technologies CZ, s.r.o.)
2 Mezzmo; C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe [3119472 2012-09-26] (Conceiva Pty. Ltd.)
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
==================== Drivers (Whitelisted) =====================
1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [50296 2012-09-03] (AVG Technologies CZ, s.r.o.)
1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [154464 2012-10-21] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [63328 2012-10-14] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [185696 2012-10-01] (AVG Technologies CZ, s.r.o.)
0 Avgloga; C:\Windows\System32\Drivers\Avgloga.sys [225120 2012-09-20] (AVG Technologies CZ, s.r.o.)
0 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [40800 2012-09-13] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [200032 2012-09-20] (AVG Technologies CZ, s.r.o.)
3 pbfilter; \??\C:\Program Files\PeerBlock\pbfilter.sys [24176 2010-11-06] ()
3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-01-29 21:27 - 2013-01-29 21:40 - 00008257 ____A C:\Windows\System32\avgrep.txt
2013-01-29 20:52 - 2013-01-29 20:52 - 00000000 ____D C:\Users\Ann\AppData\Roaming\AVG2013
2013-01-29 20:48 - 2013-01-29 20:49 - 00000000 ____D C:\Users\All Users\AVG2013
2013-01-29 20:48 - 2013-01-29 20:48 - 00000972 ____A C:\Users\Public\Desktop\AVG 2013.lnk
2013-01-29 20:48 - 2013-01-29 20:48 - 00000000 ____D C:\Users\Ann\AppData\Roaming\TuneUp Software
2013-01-29 20:45 - 2013-01-29 21:27 - 00000000 ____D C:\Users\Ann\AppData\Local\Avg2013
2013-01-29 20:45 - 2013-01-29 20:45 - 04411440 ____A (AVG Technologies) C:\Users\Ann\Downloads\avg_isct_stb_all_2013_2667_evol1.exe
2013-01-29 20:45 - 2013-01-29 20:45 - 00000000 ____D C:\Users\Ann\AppData\Local\MFAData
2013-01-29 20:20 - 2013-01-29 20:20 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Roaming\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Local\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\All Users\Babylon
2013-01-28 22:26 - 2013-01-28 19:18 - 57489900 ____N C:\Users\Ann\Desktop\IMG_0713.MOV
2013-01-19 13:21 - 2013-01-19 15:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-01-14 00:35 - 2013-01-14 00:35 - 00000444 ____A C:\Users\Ann\Downloads\google.csv
2013-01-08 16:10 - 2012-12-07 05:20 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-08 16:10 - 2012-12-07 05:15 - 02746368 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-08 16:10 - 2012-12-07 04:26 - 00308736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-01-08 16:10 - 2012-12-07 04:20 - 02576384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-01-08 16:10 - 2012-12-07 03:20 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00055296 ____A (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00051712 ____A (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00046592 ____A (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00045568 ____A (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00044544 ____A (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00043520 ____A (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00040960 ____A (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00030720 ____A (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00023552 ____A (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00021504 ____A (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00015360 ____A (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-01-08 16:10 - 2012-11-21 21:44 - 00800768 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-08 16:10 - 2012-11-21 20:45 - 00626688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-01-08 16:10 - 2012-11-19 21:48 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-01-08 16:10 - 2012-11-19 20:51 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-01-08 16:10 - 2012-11-08 21:45 - 00750592 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-08 16:10 - 2012-11-08 20:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-01-08 16:10 - 2012-10-31 21:43 - 02002432 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-08 16:10 - 2012-10-31 21:43 - 01882624 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2013-01-08 16:10 - 2012-10-31 20:47 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2013-01-08 16:10 - 2012-10-31 20:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2013-01-08 16:09 - 2012-11-29 21:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2013-01-08 16:09 - 2012-11-29 21:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-08 16:09 - 2012-11-29 21:41 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:54 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-01-08 16:09 - 2012-11-29 20:53 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-01-08 16:09 - 2012-11-29 20:53 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 19:23 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-08 16:09 - 2012-11-29 18:44 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-01-08 16:09 - 2012-11-29 18:44 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-01-08 16:09 - 2012-11-29 18:44 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-01-08 16:09 - 2012-11-29 18:44 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-01-08 16:09 - 2012-11-29 18:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 18:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 18:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 18:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 15:17 - 00420064 ____A C:\Windows\SysWOW64\locale.nls
2013-01-08 16:09 - 2012-11-29 15:15 - 00420064 ____A C:\Windows\System32\locale.nls
2013-01-08 16:09 - 2012-11-22 19:26 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-08 16:09 - 2012-11-22 19:13 - 00068608 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
==================== One Month Modified Files and Folders =======
2013-01-30 19:24 - 2013-01-30 19:24 - 00000000 ____D C:\FRST
2013-01-29 22:17 - 2011-09-16 14:47 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000UA.job
2013-01-29 22:00 - 2012-04-08 14:51 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-01-29 21:54 - 2011-11-09 17:03 - 00000000 ____D C:\Program Files\PeerBlock
2013-01-29 21:53 - 2009-07-13 20:45 - 00022400 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-29 21:53 - 2009-07-13 20:45 - 00022400 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-29 21:50 - 2009-07-13 21:13 - 00726270 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-29 21:46 - 2012-09-02 19:36 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-29 21:46 - 2012-08-22 16:28 - 00035853 ____A C:\Windows\SysWOW64\debug.log
2013-01-29 21:46 - 2012-06-01 18:58 - 00009540 ____A C:\Windows\setupact.log
2013-01-29 21:46 - 2011-09-16 00:39 - 00000043 ____A C:\Windows\MezzmoMediaServer.INI
2013-01-29 21:46 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-29 21:40 - 2013-01-29 21:27 - 00008257 ____A C:\Windows\System32\avgrep.txt
2013-01-29 21:27 - 2013-01-29 20:45 - 00000000 ____D C:\Users\Ann\AppData\Local\Avg2013
2013-01-29 21:00 - 2011-11-01 22:37 - 00000000 ____D C:\Users\All Users\MFAData
2013-01-29 20:52 - 2013-01-29 20:52 - 00000000 ____D C:\Users\Ann\AppData\Roaming\AVG2013
2013-01-29 20:51 - 2010-11-20 19:47 - 00028918 ____A C:\Windows\PFRO.log
2013-01-29 20:49 - 2013-01-29 20:48 - 00000000 ____D C:\Users\All Users\AVG2013
2013-01-29 20:49 - 2012-07-17 00:34 - 00000000 ___HD C:\$AVG
2013-01-29 20:48 - 2013-01-29 20:48 - 00000972 ____A C:\Users\Public\Desktop\AVG 2013.lnk
2013-01-29 20:48 - 2013-01-29 20:48 - 00000000 ____D C:\Users\Ann\AppData\Roaming\TuneUp Software
2013-01-29 20:47 - 2012-07-17 00:33 - 00000000 ____D C:\Program Files (x86)\AVG
2013-01-29 20:46 - 2012-09-02 19:36 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-29 20:45 - 2013-01-29 20:45 - 04411440 ____A (AVG Technologies) C:\Users\Ann\Downloads\avg_isct_stb_all_2013_2667_evol1.exe
2013-01-29 20:45 - 2013-01-29 20:45 - 00000000 ____D C:\Users\Ann\AppData\Local\MFAData
2013-01-29 20:42 - 2012-04-25 11:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-01-29 20:40 - 2011-09-05 23:26 - 00000000 ____D C:\Users\Ann\AppData\Roaming\uTorrent
2013-01-29 20:20 - 2013-01-29 20:20 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-01-29 19:57 - 2011-09-03 22:11 - 01283296 ____A C:\Windows\WindowsUpdate.log
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Roaming\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Local\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\All Users\Babylon
2013-01-29 18:32 - 2012-08-22 16:27 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000UA.job
2013-01-29 15:32 - 2012-08-22 16:27 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000Core.job
2013-01-29 09:17 - 2011-09-16 14:47 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000Core.job
2013-01-28 22:26 - 2011-09-04 01:20 - 00000000 ____D C:\Users\Ann\AppData\Roaming\vlc
2013-01-28 21:52 - 2011-09-10 22:40 - 00000000 ____D C:\Program Files\GOTSent
2013-01-28 19:18 - 2013-01-28 22:26 - 57489900 ____N C:\Users\Ann\Desktop\IMG_0713.MOV
2013-01-19 15:18 - 2013-01-19 13:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-01-14 00:35 - 2013-01-14 00:35 - 00000444 ____A C:\Users\Ann\Downloads\google.csv
2013-01-09 07:00 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-01-09 06:21 - 2009-07-13 20:45 - 00297064 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-09 06:01 - 2011-09-09 12:45 - 67599240 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-01-08 18:00 - 2012-04-08 14:51 - 00697864 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-01-08 18:00 - 2011-09-17 15:05 - 00074248 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-01-03 12:03 - 2011-09-03 22:15 - 00000000 ____D C:\users\Ann
2013-01-03 11:50 - 2012-01-24 16:02 - 00123388 ___AH C:\Windows\SysWOW64\mlfcache.dat
ZeroAccess:
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L\00000004.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L\201d3dde
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L\76603ac3
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\00000004.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\00000008.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\000000cb.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\80000000.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\80000032.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-01-16 03:00:06
Restore point made on: 2013-01-23 03:00:10
Restore point made on: 2013-01-29 20:47:50
Restore point made on: 2013-01-29 20:48:09
==================== Memory info ===========================
Percentage of memory in use: 9%
Total physical RAM: 8174.7 MB
Available physical RAM: 7431.99 MB
Total Pagefile: 8172.9 MB
Available Pagefile: 7423.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Partitions =============================
1 Drive c: (Windows) (Fixed) (Total:116.96 GB) (Free:22.53 GB) NTFS
2 Drive d: (Apps) (Fixed) (Total:814.33 GB) (Free:128.92 GB) NTFS
3 Drive e: (Jan 16 2013) (CDROM) (Total:0.07 GB) (Free:0 GB) UDF
4 Drive f: () (Removable) (Total:7.64 GB) (Free:7.64 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B *
Disk 1 Online 7840 MB 0 B
Partitions of Disk 0:
===============
Disk ID: {CB6476DE-BD40-454D-ADF9-7804C41AB71B}
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 System (partition with boot components) 100 MB 1024 KB
Partition 2 Reserved 128 MB 101 MB
Partition 3 Primary 116 GB 229 MB
Partition 4 Primary 814 GB 117 GB
==================================================================================
Disk: 0
Partition 1
Type : c12a7328-f81f-11d2-ba4b-00a0c93ec93b
Hidden : Yes
Required: No
Attrib : 0X8000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 FAT32 Partition 100 MB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : e3c9e316-0b5c-4db8-817d-f92df00215ae
Hidden : Yes
Required: No
Attrib : 0X8000000000000000
There is no volume associated with this partition.
=========================================================
Disk: 0
Partition 3
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Windows NTFS Partition 116 GB Healthy
=========================================================
Disk: 0
Partition 4
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Apps NTFS Partition 814 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Disk ID: 91F72D24
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7839 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F FAT32 Removable 7839 MB Healthy
=========================================================
Last Boot: 2013-01-23 03:38
==================== End Of Log =============================
We have unfortunately come across this nasty little virus tonight, probably between 16:00 and 19:00 local time (from logging below). After scouring Google for an hour have seen lots of helpful replies from this forum and so come begging for help
Below are the two logs from FRST. If anyone can help me successfully remove this I will gladly send a donation your way for your time and effort. Many thanks in advance
Logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-01-2013 02
Ran by SYSTEM at 30-01-2013 19:25:07
Running from F:\
Windows 7 Enterprise Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-28] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-27] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-16] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152544 2012-12-11] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [3147384 2012-12-10] (AVG Technologies CZ, s.r.o.)
HKU\Ann\...\Run: [Google Update] "C:\Users\Ann\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-09-16] (Google Inc.)
HKU\Ann\...\Run: [Mezzmo] C:\Program Files (x86)\Conceiva\Mezzmo\Mezzmo.exe [10608496 2012-09-26] (Conceiva Pty. Ltd.)
HKU\Ann\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-22] (Apple Inc.)
HKU\Ann\...\Run: [Facebook Update] "C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-08-22] (Facebook Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Ann\Start Menu\Programs\Startup\Facebook Messenger.lnk
ShortcutTarget: Facebook Messenger.lnk -> (No File)
Startup: C:\Users\Ann\Start Menu\Programs\Startup\Mezzmo.lnk
ShortcutTarget: Mezzmo.lnk -> C:\Program Files (x86)\Conceiva\Mezzmo\Mezzmo.exe (Conceiva Pty. Ltd.)
Startup: C:\Users\Ann\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Ann\Start Menu\Programs\Startup\PeerBlock.lnk
ShortcutTarget: PeerBlock.lnk -> C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
==================== Services (Whitelisted) ===================
2 avgfws; "C:\Program Files (x86)\AVG\AVG2013\avgfws.exe" [1342024 2012-12-09] (AVG Technologies CZ, s.r.o.)
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe" [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe" [196664 2012-10-21] (AVG Technologies CZ, s.r.o.)
2 Mezzmo; C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe [3119472 2012-09-26] (Conceiva Pty. Ltd.)
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
==================== Drivers (Whitelisted) =====================
1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [50296 2012-09-03] (AVG Technologies CZ, s.r.o.)
1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [154464 2012-10-21] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [63328 2012-10-14] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [185696 2012-10-01] (AVG Technologies CZ, s.r.o.)
0 Avgloga; C:\Windows\System32\Drivers\Avgloga.sys [225120 2012-09-20] (AVG Technologies CZ, s.r.o.)
0 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [40800 2012-09-13] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [200032 2012-09-20] (AVG Technologies CZ, s.r.o.)
3 pbfilter; \??\C:\Program Files\PeerBlock\pbfilter.sys [24176 2010-11-06] ()
3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-01-29 21:27 - 2013-01-29 21:40 - 00008257 ____A C:\Windows\System32\avgrep.txt
2013-01-29 20:52 - 2013-01-29 20:52 - 00000000 ____D C:\Users\Ann\AppData\Roaming\AVG2013
2013-01-29 20:48 - 2013-01-29 20:49 - 00000000 ____D C:\Users\All Users\AVG2013
2013-01-29 20:48 - 2013-01-29 20:48 - 00000972 ____A C:\Users\Public\Desktop\AVG 2013.lnk
2013-01-29 20:48 - 2013-01-29 20:48 - 00000000 ____D C:\Users\Ann\AppData\Roaming\TuneUp Software
2013-01-29 20:45 - 2013-01-29 21:27 - 00000000 ____D C:\Users\Ann\AppData\Local\Avg2013
2013-01-29 20:45 - 2013-01-29 20:45 - 04411440 ____A (AVG Technologies) C:\Users\Ann\Downloads\avg_isct_stb_all_2013_2667_evol1.exe
2013-01-29 20:45 - 2013-01-29 20:45 - 00000000 ____D C:\Users\Ann\AppData\Local\MFAData
2013-01-29 20:20 - 2013-01-29 20:20 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Roaming\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Local\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\All Users\Babylon
2013-01-28 22:26 - 2013-01-28 19:18 - 57489900 ____N C:\Users\Ann\Desktop\IMG_0713.MOV
2013-01-19 13:21 - 2013-01-19 15:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-01-14 00:35 - 2013-01-14 00:35 - 00000444 ____A C:\Users\Ann\Downloads\google.csv
2013-01-08 16:10 - 2012-12-07 05:20 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-08 16:10 - 2012-12-07 05:15 - 02746368 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-08 16:10 - 2012-12-07 04:26 - 00308736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-01-08 16:10 - 2012-12-07 04:20 - 02576384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-01-08 16:10 - 2012-12-07 03:20 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-08 16:10 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-08 16:10 - 2012-12-07 03:19 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00055296 ____A (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00051712 ____A (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00046592 ____A (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00045568 ____A (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00044544 ____A (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00043520 ____A (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00040960 ____A (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00030720 ____A (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00023552 ____A (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00021504 ____A (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-01-08 16:10 - 2012-12-07 02:46 - 00015360 ____A (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-01-08 16:10 - 2012-11-21 21:44 - 00800768 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-08 16:10 - 2012-11-21 20:45 - 00626688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-01-08 16:10 - 2012-11-19 21:48 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-01-08 16:10 - 2012-11-19 20:51 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-01-08 16:10 - 2012-11-08 21:45 - 00750592 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-08 16:10 - 2012-11-08 20:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-01-08 16:10 - 2012-10-31 21:43 - 02002432 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-08 16:10 - 2012-10-31 21:43 - 01882624 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2013-01-08 16:10 - 2012-10-31 20:47 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2013-01-08 16:10 - 2012-10-31 20:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-08 16:09 - 2012-11-29 21:45 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2013-01-08 16:09 - 2012-11-29 21:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2013-01-08 16:09 - 2012-11-29 21:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-08 16:09 - 2012-11-29 21:41 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:54 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-01-08 16:09 - 2012-11-29 20:53 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-01-08 16:09 - 2012-11-29 20:53 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 19:23 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-08 16:09 - 2012-11-29 18:44 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-01-08 16:09 - 2012-11-29 18:44 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-01-08 16:09 - 2012-11-29 18:44 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-01-08 16:09 - 2012-11-29 18:44 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-01-08 16:09 - 2012-11-29 18:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 18:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 18:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 18:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-08 16:09 - 2012-11-29 15:17 - 00420064 ____A C:\Windows\SysWOW64\locale.nls
2013-01-08 16:09 - 2012-11-29 15:15 - 00420064 ____A C:\Windows\System32\locale.nls
2013-01-08 16:09 - 2012-11-22 19:26 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-08 16:09 - 2012-11-22 19:13 - 00068608 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
==================== One Month Modified Files and Folders =======
2013-01-30 19:24 - 2013-01-30 19:24 - 00000000 ____D C:\FRST
2013-01-29 22:17 - 2011-09-16 14:47 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000UA.job
2013-01-29 22:00 - 2012-04-08 14:51 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-01-29 21:54 - 2011-11-09 17:03 - 00000000 ____D C:\Program Files\PeerBlock
2013-01-29 21:53 - 2009-07-13 20:45 - 00022400 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-29 21:53 - 2009-07-13 20:45 - 00022400 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-29 21:50 - 2009-07-13 21:13 - 00726270 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-29 21:46 - 2012-09-02 19:36 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-29 21:46 - 2012-08-22 16:28 - 00035853 ____A C:\Windows\SysWOW64\debug.log
2013-01-29 21:46 - 2012-06-01 18:58 - 00009540 ____A C:\Windows\setupact.log
2013-01-29 21:46 - 2011-09-16 00:39 - 00000043 ____A C:\Windows\MezzmoMediaServer.INI
2013-01-29 21:46 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-29 21:40 - 2013-01-29 21:27 - 00008257 ____A C:\Windows\System32\avgrep.txt
2013-01-29 21:27 - 2013-01-29 20:45 - 00000000 ____D C:\Users\Ann\AppData\Local\Avg2013
2013-01-29 21:00 - 2011-11-01 22:37 - 00000000 ____D C:\Users\All Users\MFAData
2013-01-29 20:52 - 2013-01-29 20:52 - 00000000 ____D C:\Users\Ann\AppData\Roaming\AVG2013
2013-01-29 20:51 - 2010-11-20 19:47 - 00028918 ____A C:\Windows\PFRO.log
2013-01-29 20:49 - 2013-01-29 20:48 - 00000000 ____D C:\Users\All Users\AVG2013
2013-01-29 20:49 - 2012-07-17 00:34 - 00000000 ___HD C:\$AVG
2013-01-29 20:48 - 2013-01-29 20:48 - 00000972 ____A C:\Users\Public\Desktop\AVG 2013.lnk
2013-01-29 20:48 - 2013-01-29 20:48 - 00000000 ____D C:\Users\Ann\AppData\Roaming\TuneUp Software
2013-01-29 20:47 - 2012-07-17 00:33 - 00000000 ____D C:\Program Files (x86)\AVG
2013-01-29 20:46 - 2012-09-02 19:36 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-29 20:45 - 2013-01-29 20:45 - 04411440 ____A (AVG Technologies) C:\Users\Ann\Downloads\avg_isct_stb_all_2013_2667_evol1.exe
2013-01-29 20:45 - 2013-01-29 20:45 - 00000000 ____D C:\Users\Ann\AppData\Local\MFAData
2013-01-29 20:42 - 2012-04-25 11:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-01-29 20:40 - 2011-09-05 23:26 - 00000000 ____D C:\Users\Ann\AppData\Roaming\uTorrent
2013-01-29 20:20 - 2013-01-29 20:20 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-01-29 19:57 - 2011-09-03 22:11 - 01283296 ____A C:\Windows\WindowsUpdate.log
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Roaming\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\Ann\AppData\Local\Babylon
2013-01-29 19:54 - 2013-01-29 19:54 - 00000000 ____D C:\Users\All Users\Babylon
2013-01-29 18:32 - 2012-08-22 16:27 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000UA.job
2013-01-29 15:32 - 2012-08-22 16:27 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000Core.job
2013-01-29 09:17 - 2011-09-16 14:47 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3317690383-389001063-789236981-1000Core.job
2013-01-28 22:26 - 2011-09-04 01:20 - 00000000 ____D C:\Users\Ann\AppData\Roaming\vlc
2013-01-28 21:52 - 2011-09-10 22:40 - 00000000 ____D C:\Program Files\GOTSent
2013-01-28 19:18 - 2013-01-28 22:26 - 57489900 ____N C:\Users\Ann\Desktop\IMG_0713.MOV
2013-01-19 15:18 - 2013-01-19 13:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-01-14 00:35 - 2013-01-14 00:35 - 00000444 ____A C:\Users\Ann\Downloads\google.csv
2013-01-09 07:00 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-01-09 06:21 - 2009-07-13 20:45 - 00297064 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-09 06:01 - 2011-09-09 12:45 - 67599240 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-01-08 18:00 - 2012-04-08 14:51 - 00697864 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-01-08 18:00 - 2011-09-17 15:05 - 00074248 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-01-03 12:03 - 2011-09-03 22:15 - 00000000 ____D C:\users\Ann
2013-01-03 11:50 - 2012-01-24 16:02 - 00123388 ___AH C:\Windows\SysWOW64\mlfcache.dat
ZeroAccess:
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L\00000004.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L\201d3dde
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\L\76603ac3
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\00000004.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\00000008.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\000000cb.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\80000000.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\80000032.@
C:\Windows\Installer\{c812ecc5-ea15-6f7e-0181-0717ab8c5026}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-01-16 03:00:06
Restore point made on: 2013-01-23 03:00:10
Restore point made on: 2013-01-29 20:47:50
Restore point made on: 2013-01-29 20:48:09
==================== Memory info ===========================
Percentage of memory in use: 9%
Total physical RAM: 8174.7 MB
Available physical RAM: 7431.99 MB
Total Pagefile: 8172.9 MB
Available Pagefile: 7423.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Partitions =============================
1 Drive c: (Windows) (Fixed) (Total:116.96 GB) (Free:22.53 GB) NTFS
2 Drive d: (Apps) (Fixed) (Total:814.33 GB) (Free:128.92 GB) NTFS
3 Drive e: (Jan 16 2013) (CDROM) (Total:0.07 GB) (Free:0 GB) UDF
4 Drive f: () (Removable) (Total:7.64 GB) (Free:7.64 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B *
Disk 1 Online 7840 MB 0 B
Partitions of Disk 0:
===============
Disk ID: {CB6476DE-BD40-454D-ADF9-7804C41AB71B}
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 System (partition with boot components) 100 MB 1024 KB
Partition 2 Reserved 128 MB 101 MB
Partition 3 Primary 116 GB 229 MB
Partition 4 Primary 814 GB 117 GB
==================================================================================
Disk: 0
Partition 1
Type : c12a7328-f81f-11d2-ba4b-00a0c93ec93b
Hidden : Yes
Required: No
Attrib : 0X8000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 FAT32 Partition 100 MB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : e3c9e316-0b5c-4db8-817d-f92df00215ae
Hidden : Yes
Required: No
Attrib : 0X8000000000000000
There is no volume associated with this partition.
=========================================================
Disk: 0
Partition 3
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Windows NTFS Partition 116 GB Healthy
=========================================================
Disk: 0
Partition 4
Type : ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
Hidden : No
Required: No
Attrib : 0000000000000000
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Apps NTFS Partition 814 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Disk ID: 91F72D24
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7839 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F FAT32 Removable 7839 MB Healthy
=========================================================
Last Boot: 2013-01-23 03:38
==================== End Of Log =============================