Scan result of Farbar Recovery Scan Tool Version: 20-07-2012 Ran by [removed] at 20-07-2012 19:36:40 Running from F:\ Windows 7 Home Premium (X64) OS Language: English(US) The current controlset is ControlSet002 ========================== Registry (Whitelisted) ============= HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-15] () HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167960 2011-02-09] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2011-02-09] (Intel Corporation) HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [418328 2011-02-09] (Intel Corporation) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 [2188904 2011-01-17] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [617120 2011-03-13] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [379552 2011-03-13] (Atheros Commnucations) HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4156 2010-04-16] () HKLM\...\Run: [BDAgent] "C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe" [1067256 2012-03-22] (Bitdefender) HKLM\...\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h [9569096 2012-03-11] (COMODO) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini" [371 2012-07-20] () HKLM-x32\...\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] () HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-18] (ASUS) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup [336952 2012-04-18] (Power Software Ltd) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [213304 2011-11-23] (COMODO) HKLM-x32\...\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [184120 2011-11-23] (COMODO) HKU\Neil\...\Run: [SanDiskSecureAccess_Manager.exe] C:\Users\Neil\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [27311232 2011-06-28] (Gemalto N.V.) HKU\Neil\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17146504 2012-02-15] (Skype Technologies S.A.) HKU\Neil\...\Run: [Mobile Partner] C:\Program Files (x86)\Zain e-GO\Zain e-GO.exe [514048 2012-03-05] () HKU\Neil\...\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler [222496 2009-05-05] (Acresso Corporation) HKU\UpdatusUser\...\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler [222496 2009-05-05] (Acresso Corporation) HKU\UpdatusUser\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-01-12] (Google Inc.) Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll C:\Windows\system32\guard64.dll Tcpip\..\Interfaces\{09458F37-365E-4F58-843D-7DCFE0C4B100}: [NameServer]83.136.58.187 83.136.56.53 Tcpip\..\Interfaces\{4F7687F2-934B-4FE0-B68F-E2AD42FAD8D0}: [NameServer]8.26.56.26,156.154.70.22 Tcpip\..\Interfaces\{80A8F56A-F469-47E5-8294-BE04F73C6CF4}: [NameServer]83.136.58.187 83.136.56.53 Tcpip\..\Interfaces\{8646602E-03A4-4875-B020-DB4813EBEC71}: [NameServer]10.93.56.1 Tcpip\..\Interfaces\{87E2C2A3-91E2-498B-A848-A273AED51E55}: [NameServer]8.26.56.26,156.154.70.22 Tcpip\..\Interfaces\{CB7320FF-8640-4C87-B512-F635F8B01962}: [NameServer]83.136.58.187 83.136.56.53 Startup: C:\Users\All Users\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe () Startup: C:\Users\All Users\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe () ==================== Services (Whitelisted) ====== 2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) 2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros) 2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) 2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-14] (ASUS) 2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [42184 2011-02-23] (AVAST Software) 2 avast! Firewall; "C:\Program Files\AVAST Software\Avast\afwServ.exe" [121000 2011-02-23] (AVAST Software) 2 CLPSLS; C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [1267000 2011-11-23] (COMODO) 2 cmdAgent; "C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe" [2815496 2012-03-11] (COMODO) 2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [542552 2012-04-10] () 3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [77520 2012-04-10] () 2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS [329544 2012-04-02] () 2 HWDeviceService64.exe; "C:\ProgramData\DatacardService\HWDeviceService64.exe" -/service [346976 2011-03-14] () 3 Update Server; C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [466736 2011-10-14] (BitDefender) 2 UPDATESRV; "C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe" /service [66096 2012-03-13] (Bitdefender) 2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe /service [1956616 2012-03-23] (Bitdefender) 2 Zain e-GO. RunOuc; C:\Program Files (x86)\Zain e-GO\UpdateDog\ouc.exe [655712 2012-03-05] () ========================== Drivers (Whitelisted) ============= 2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS) 2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22360 2011-02-23] (AVAST Software) 1 aswFW; C:\Windows\System32\Drivers\aswFW.sys [127320 2011-02-23] (AVAST Software) 2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [64344 2011-02-23] (AVAST Software) 0 aswNdis2; C:\Windows\System32\Drivers\aswNdis2.sys [253784 2011-02-23] (AVAST Software) 1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [31064 2011-02-23] (AVAST Software) 1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [505176 2011-02-23] (AVAST Software) 1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [280408 2011-02-23] (AVAST Software) 1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53592 2011-02-23] (AVAST Software) 3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [36000 2011-03-13] (Atheros) 1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS) 0 avc3; C:\Windows\System32\Drivers\avc3.sys [691896 2012-03-20] (BitDefender) 3 avchv; C:\Windows\System32\Drivers\avchv.sys [258736 2011-11-25] (BitDefender) 3 avckf; C:\Windows\System32\Drivers\avckf.sys [545064 2012-02-17] (BitDefender) 0 bdfsfltr; C:\Windows\System32\Drivers\bdfsfltr.sys [442088 2012-07-08] (BitDefender) 1 bdfwfpf; \??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) 3 bdsandbox; C:\Windows\System32\Drivers\bdsandbox.sys [79952 2011-11-17] (BitDefender SRL) 1 BDVEDISK; C:\Windows\System32\Drivers\BDVEDISK.sys [103944 2010-01-19] (BitDefender) 3 BTATH_A2DP; C:\Windows\System32\Drivers\BTATH_A2DP.sys [298656 2011-03-13] (Atheros) 3 BTATH_BUS; C:\Windows\System32\Drivers\BTATH_BUS.sys [28832 2011-03-13] (Atheros) 3 BTATH_HCRP; C:\Windows\System32\Drivers\BTATH_HCRP.sys [201376 2011-03-13] (Atheros) 3 BTATH_LWFLT; C:\Windows\System32\Drivers\BTATH_LWFLT.sys [55456 2011-03-13] (Atheros) 3 BTATH_RCP; C:\Windows\System32\Drivers\BTATH_RCP.sys [154272 2011-03-13] (Atheros) 3 BtFilter; C:\Windows\System32\Drivers\BtFilter.sys [280224 2011-03-13] (Atheros) 1 cmdGuard; C:\Windows\System32\Drivers\cmdGuard.sys [577824 2012-03-11] (COMODO) 1 cmdHlp; C:\Windows\System32\Drivers\cmdHlp.sys [43248 2012-03-11] (COMODO) 3 ewusbmbb; C:\Windows\System32\DRIVERS\ewusbwwan.sys [417280 2012-03-05] (Huawei Technologies Co., Ltd.) 3 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2012-03-05] (Huawei Technologies Co., Ltd.) 3 huawei_enumerator; C:\Windows\System32\DRIVERS\ew_jubusenum.sys [87040 2012-03-05] (Huawei Technologies Co., Ltd.) 1 inspect; C:\Windows\System32\Drivers\inspect.sys [93200 2012-02-03] (COMODO) 3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( ) 2 trufos; C:\Windows\System32\Drivers\trufos.sys [329800 2012-07-08] (BitDefender S.R.L.) 2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [13832 2010-04-16] () ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-07-20 08:31 - 2012-07-20 08:31 - 02136664 ____N (Kaspersky Lab ZAO) C:\Users\Neil\Desktop\tdsskiller.exe 2012-07-20 07:53 - 2012-07-20 08:22 - 00000112 ____A C:\Windows\setupact.log 2012-07-20 07:53 - 2012-07-20 07:53 - 00000000 ____A C:\Windows\setuperr.log 2012-07-19 00:55 - 2012-07-19 00:55 - 00000000 ____A C:\Users\Neil\Documents\bt.log 2012-07-18 11:46 - 2012-07-20 08:08 - 00000221 ____A C:\Windows\System32\checkdnsid.xml 2012-07-18 00:19 - 2012-07-18 00:20 - 00000048 ____N C:\Users\Neil\Desktop\Papers.txt 2012-07-16 10:55 - 2012-07-16 10:55 - 00607260 ____N (Swearware) C:\Users\Neil\Desktop\dds.scr 2012-07-15 13:27 - 2012-07-15 13:27 - 00000000 ____D C:\Users\Neil\AppData\Roaming\Malwarebytes 2012-07-15 13:26 - 2012-07-15 13:26 - 00001115 ____N C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-15 13:26 - 2012-07-15 13:26 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-07-15 13:26 - 2012-07-15 13:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-07-15 13:26 - 2012-07-03 02:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-15 13:12 - 2012-07-15 13:12 - 10652120 ____N (Malwarebytes Corporation ) C:\Users\Neil\Desktop\mbam-setup-1.62.0.1300.exe 2012-07-14 12:27 - 2012-07-14 12:27 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA% 2012-07-13 08:59 - 2012-07-13 09:20 - 00000000 ____D C:\Users\Neil\Desktop\Jannat 2 - DVDRip - XviD - 1CDRip - [DDR] 2012-07-13 08:57 - 2012-07-13 08:57 - 00016620 ____N C:\Users\Neil\Desktop\D17A77B214382CF9A54B6665F300DDFB1B9F887D.torrent 2012-07-10 13:17 - 2012-07-12 14:46 - 00000000 ____D C:\Users\All Users\CPA_VA 2012-07-10 13:16 - 2012-07-10 13:16 - 00000000 ____D C:\Users\Public\Documents\COMODO 2012-07-10 12:59 - 2012-07-10 13:08 - 00000000 ____D C:\Users\All Users\Comodo 2012-07-10 12:59 - 2012-07-10 12:59 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2012-07-10 12:59 - 2012-07-10 12:59 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2012-07-10 12:59 - 2012-07-10 12:59 - 00001846 ____N C:\Users\Public\Desktop\COMODO Firewall.lnk 2012-07-10 12:59 - 2012-07-10 12:59 - 00001047 ____N C:\Users\Public\Desktop\COMODO GeekBuddy.lnk 2012-07-10 12:59 - 2012-07-10 12:59 - 00000000 ____D C:\Program Files\COMODO 2012-07-10 12:46 - 2012-07-10 12:56 - 62855008 ____N (COMODO) C:\Users\Neil\Desktop\cfw_installer.exe 2012-07-10 12:24 - 2012-07-10 12:24 - 00000281 ____N C:\Users\Neil\Desktop\pinned.lnk 2012-07-09 19:44 - 2012-07-09 19:44 - 00000385 ____A C:\Users\Neil\AppData\Roaminguser_gensett.xml 2012-07-09 11:50 - 2012-07-09 11:50 - 00000000 ____D C:\Program Files (x86)\ESET 2012-07-09 11:29 - 2012-07-09 11:36 - 00000000 ____D C:\Program Files (x86)\Eusing Free Registry Cleaner 2012-07-09 11:29 - 2012-07-09 11:29 - 00977171 ____N C:\Users\Neil\Desktop\EFRCSetup.exe 2012-07-09 11:29 - 2012-07-09 11:29 - 00001059 ____N C:\Users\Neil\Desktop\Eusing Free Registry Cleaner.lnk 2012-07-09 11:29 - 2012-07-09 11:29 - 00001059 ____A C:\Users\UpdatusUser\Desktop\Eusing Free Registry Cleaner.lnk 2012-07-09 01:38 - 2012-07-15 11:54 - 00000430 ____A C:\Windows\Tasks\FrontLine Registry Cleaner Scheduled Scan - Neil.job 2012-07-09 01:38 - 2012-07-09 02:04 - 00000000 ____D C:\Program Files (x86)\Frontline Registry Cleaner 2012-07-09 01:38 - 2012-07-09 01:38 - 00000000 ____D C:\Users\All Users\FrontLine Registry Cleaner 2012-07-09 00:56 - 2012-07-02 16:13 - 57442464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe 2012-07-09 00:47 - 2012-07-09 02:06 - 00000000 ____D C:\Users\All Users\SecTaskMan 2012-07-09 00:47 - 2012-07-09 02:05 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2012-07-09 00:32 - 2011-02-17 22:33 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\prevhost.exe 2012-07-09 00:32 - 2011-02-17 21:33 - 00031232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe 2012-07-08 13:08 - 2012-07-08 13:08 - 00000000 ____D C:\Windows\SysWOW64\My Vaults 2012-07-08 12:57 - 2012-07-08 12:57 - 00001052 ____N C:\Users\Neil\Desktop\478CE86971D6EC4F729B7F8DCD5BDBDC4C927D0E.torrent 2012-07-08 12:30 - 2012-07-08 12:30 - 00329800 ____N (BitDefender S.R.L.) C:\Windows\System32\Drivers\trufos.sys 2012-07-08 12:28 - 2012-07-08 12:28 - 00442088 ____N (BitDefender) C:\Windows\System32\Drivers\bdfsfltr.sys 2012-07-08 12:09 - 2012-07-08 12:09 - 00030856 ____A C:\Users\Neil\Documents\cc_20120708_230852.reg 2012-07-08 11:42 - 2012-07-08 11:42 - 00000000 ____D C:\Users\All Users\bdch 2012-07-08 07:10 - 2012-07-08 07:10 - 00000000 __SHD C:\found.000 2012-07-08 06:33 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-07-08 06:33 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-07-08 06:33 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-07-08 06:33 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-07-08 06:33 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-07-08 06:33 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-07-08 06:33 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-07-08 06:32 - 2012-06-02 04:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-07-08 06:32 - 2012-06-02 04:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-07-08 06:02 - 2012-07-08 06:02 - 00000385 ____A C:\Windows\System32\user_gensett.xml 2012-07-07 21:19 - 2012-07-08 12:11 - 00001276 ____A C:\Users\Neil\Documents\cc_20120708_081945.reg 2012-07-07 21:18 - 2012-07-07 21:18 - 00000824 ____N C:\Users\Public\Desktop\CCleaner.lnk 2012-07-07 21:18 - 2012-07-07 21:18 - 00000000 ____D C:\Program Files\CCleaner 2012-07-07 13:23 - 2012-07-20 08:23 - 00000376 ____A C:\Users\Neil\AppData\Roamingprivacy.xml 2012-07-07 13:20 - 2012-07-07 13:20 - 00398436 ____A C:\Users\All Users\1341694288.bdinstall.bin 2012-07-07 13:19 - 2012-07-07 13:20 - 00004966 ____N C:\Users\Neil\Desktop\New Text Document.txt 2012-07-07 13:19 - 2012-07-07 13:19 - 00002098 ____N C:\Users\Public\Desktop\Bitdefender Antivirus Plus 2012.lnk 2012-07-07 13:19 - 2012-07-07 13:19 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_avchv_01009.Wdf 2012-07-07 13:19 - 2012-07-07 13:19 - 00000000 ____D C:\Users\Neil\AppData\Roaming\Bitdefender 2012-07-07 13:19 - 2012-07-07 13:19 - 00000000 ____D C:\Users\All Users\BDLogging 2012-07-07 13:18 - 2012-07-07 13:19 - 00000000 ____D C:\Users\All Users\Bitdefender 2012-07-07 13:07 - 2012-07-07 13:08 - 04819616 ____N (SpeedyPC Software Inc.) C:\Users\Neil\Desktop\Repair_Tool(1).exe 2012-07-07 12:54 - 2012-07-07 12:54 - 00000000 ____D C:\Users\Neil\AppData\Roaming\QuickScan 2012-07-07 12:53 - 2012-07-07 12:53 - 00000000 ____D C:\Program Files\Bitdefender 2012-07-07 12:51 - 2012-07-07 12:51 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2012-07-07 12:40 - 2012-07-15 11:54 - 00000490 ____A C:\Windows\Tasks\SpeedyPC Registration3.job 2012-07-07 12:40 - 2012-07-07 12:40 - 00000000 ____D C:\Users\Neil\AppData\Roaming\SpeedyPC Software 2012-07-07 12:40 - 2012-07-07 12:40 - 00000000 ____D C:\Users\Neil\AppData\Roaming\DriverCure 2012-07-07 12:39 - 2012-07-15 14:25 - 00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job 2012-07-07 12:39 - 2012-07-15 11:54 - 00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job 2012-07-07 12:39 - 2012-07-07 12:39 - 00001201 ____N C:\Users\Neil\Desktop\SpeedyPC Pro.lnk 2012-07-07 12:39 - 2012-07-07 12:39 - 00000000 ____D C:\Users\All Users\SpeedyPC Software 2012-07-07 12:39 - 2012-07-07 12:39 - 00000000 ____D C:\Program Files (x86)\SpeedyPC Software 2012-07-07 12:31 - 2012-07-07 12:39 - 04819616 ____N (SpeedyPC Software Inc.) C:\Users\Neil\Desktop\Repair_Tool.exe 2012-07-07 12:20 - 2012-07-07 12:41 - 00000000 ____D C:\Users\Neil\Desktop\Bitdefender Antivirus Plus 2012 Build 15.0.27.312 Final [xk3nvel0xTPB] 2012-07-07 12:19 - 2012-07-07 12:19 - 00018266 ____N C:\Users\Neil\Desktop\[kat.ph]bitdefender.antivirus.plus.2012.build.15.0.27.312.final.torrent 2012-07-07 06:21 - 2012-07-07 06:22 - 00000000 ____D C:\Users\Neil\Desktop\Chemistry Notes 2012-07-04 12:59 - 2012-07-04 13:02 - 00001024 ____A C:\Users\All Users\sowdp88.dat 2012-07-04 12:59 - 2012-07-04 12:59 - 00000048 ____A C:\Windows\SysWOW64\pdfutil.ini 2012-07-04 12:56 - 2012-07-04 12:56 - 00000040 ____A C:\Windows\winDecrypt.INI 2012-07-04 12:43 - 2012-07-04 12:43 - 00000000 ____D C:\Users\Neil\Documents\Wondershare PDF Password Remover 2012-07-03 23:04 - 2012-07-03 23:03 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll 2012-07-03 23:04 - 2012-07-03 23:03 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe 2012-07-03 23:04 - 2012-07-03 23:03 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe 2012-07-03 23:04 - 2012-07-03 23:03 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe 2012-07-03 23:03 - 2012-07-03 23:03 - 00000000 ____D C:\Program Files (x86)\Java 2012-06-29 12:12 - 2012-06-29 12:12 - 00028720 ____N C:\Users\Neil\Desktop\428A5014B4CAB78383A06A5BB042AD104C5A9344.torrent 2012-06-26 04:10 - 2012-06-26 04:10 - 00090038 ____N C:\Users\Neil\Desktop\books-i-should-refer-cbse-iit-jee-702648.html 2012-06-26 04:10 - 2012-06-26 04:10 - 00000000 ____D C:\Users\Neil\Desktop\books-i-should-refer-cbse-iit-jee-702648_files ============ 3 Months Modified Files ======================== 2012-07-20 08:32 - 2011-05-16 12:56 - 01815056 ____A C:\Windows\WindowsUpdate.log 2012-07-20 08:31 - 2012-07-20 08:31 - 02136664 ____N (Kaspersky Lab ZAO) C:\Users\Neil\Desktop\tdsskiller.exe 2012-07-20 08:30 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-20 08:30 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-20 08:24 - 2011-01-12 09:19 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-07-20 08:23 - 2012-07-07 13:23 - 00000376 ____A C:\Users\Neil\AppData\Roamingprivacy.xml 2012-07-20 08:23 - 2011-05-16 13:30 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2012-07-20 08:23 - 2011-01-12 09:19 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-07-20 08:22 - 2012-07-20 07:53 - 00000112 ____A C:\Windows\setupact.log 2012-07-20 08:22 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-20 08:14 - 2009-07-13 21:13 - 00813692 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-20 08:08 - 2012-07-18 11:46 - 00000221 ____A C:\Windows\System32\checkdnsid.xml 2012-07-20 07:53 - 2012-07-20 07:53 - 00000000 ____A C:\Windows\setuperr.log 2012-07-19 00:55 - 2012-07-19 00:55 - 00000000 ____A C:\Users\Neil\Documents\bt.log 2012-07-18 00:20 - 2012-07-18 00:19 - 00000048 ____N C:\Users\Neil\Desktop\Papers.txt 2012-07-16 10:55 - 2012-07-16 10:55 - 00607260 ____N (Swearware) C:\Users\Neil\Desktop\dds.scr 2012-07-15 14:25 - 2012-07-07 12:39 - 00000418 ____A C:\Windows\Tasks\SpeedyPC Pro.job 2012-07-15 13:26 - 2012-07-15 13:26 - 00001115 ____N C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-15 13:12 - 2012-07-15 13:12 - 10652120 ____N (Malwarebytes Corporation ) C:\Users\Neil\Desktop\mbam-setup-1.62.0.1300.exe 2012-07-15 11:54 - 2012-07-09 01:38 - 00000430 ____A C:\Windows\Tasks\FrontLine Registry Cleaner Scheduled Scan - Neil.job 2012-07-15 11:54 - 2012-07-07 12:40 - 00000490 ____A C:\Windows\Tasks\SpeedyPC Registration3.job 2012-07-15 11:54 - 2012-07-07 12:39 - 00000462 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job 2012-07-13 08:57 - 2012-07-13 08:57 - 00016620 ____N C:\Users\Neil\Desktop\D17A77B214382CF9A54B6665F300DDFB1B9F887D.torrent 2012-07-10 13:16 - 2011-05-16 13:31 - 00002254 ____A C:\Windows\System32\AutoRunFilter.ini 2012-07-10 13:16 - 2011-05-16 13:31 - 00001429 ____A C:\Windows\System32\ServiceFilter.ini 2012-07-10 13:15 - 2009-07-13 21:08 - 00032602 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-07-10 12:59 - 2012-07-10 12:59 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2012-07-10 12:59 - 2012-07-10 12:59 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2012-07-10 12:59 - 2012-07-10 12:59 - 00001846 ____N C:\Users\Public\Desktop\COMODO Firewall.lnk 2012-07-10 12:59 - 2012-07-10 12:59 - 00001047 ____N C:\Users\Public\Desktop\COMODO GeekBuddy.lnk 2012-07-10 12:56 - 2012-07-10 12:46 - 62855008 ____N (COMODO) C:\Users\Neil\Desktop\cfw_installer.exe 2012-07-10 12:24 - 2012-07-10 12:24 - 00000281 ____N C:\Users\Neil\Desktop\pinned.lnk 2012-07-10 06:41 - 2009-07-13 18:34 - 00000499 ____A C:\Windows\win.ini 2012-07-10 06:35 - 2011-10-08 09:49 - 00799236 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-07-09 19:44 - 2012-07-09 19:44 - 00000385 ____A C:\Users\Neil\AppData\Roaminguser_gensett.xml 2012-07-09 19:31 - 2009-07-13 20:45 - 00413120 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-09 11:29 - 2012-07-09 11:29 - 00977171 ____N C:\Users\Neil\Desktop\EFRCSetup.exe 2012-07-09 11:29 - 2012-07-09 11:29 - 00001059 ____N C:\Users\Neil\Desktop\Eusing Free Registry Cleaner.lnk 2012-07-09 11:29 - 2012-07-09 11:29 - 00001059 ____A C:\Users\UpdatusUser\Desktop\Eusing Free Registry Cleaner.lnk 2012-07-08 13:09 - 2011-10-08 02:19 - 00108728 ____A C:\Users\Neil\AppData\Local\GDIPFONTCACHEV1.DAT 2012-07-08 12:57 - 2012-07-08 12:57 - 00001052 ____N C:\Users\Neil\Desktop\478CE86971D6EC4F729B7F8DCD5BDBDC4C927D0E.torrent 2012-07-08 12:30 - 2012-07-08 12:30 - 00329800 ____N (BitDefender S.R.L.) C:\Windows\System32\Drivers\trufos.sys 2012-07-08 12:28 - 2012-07-08 12:28 - 00442088 ____N (BitDefender) C:\Windows\System32\Drivers\bdfsfltr.sys 2012-07-08 12:11 - 2012-07-07 21:19 - 00001276 ____A C:\Users\Neil\Documents\cc_20120708_081945.reg 2012-07-08 12:09 - 2012-07-08 12:09 - 00030856 ____A C:\Users\Neil\Documents\cc_20120708_230852.reg 2012-07-08 06:02 - 2012-07-08 06:02 - 00000385 ____A C:\Windows\System32\user_gensett.xml 2012-07-07 21:18 - 2012-07-07 21:18 - 00000824 ____N C:\Users\Public\Desktop\CCleaner.lnk 2012-07-07 13:20 - 2012-07-07 13:20 - 00398436 ____A C:\Users\All Users\1341694288.bdinstall.bin 2012-07-07 13:20 - 2012-07-07 13:19 - 00004966 ____N C:\Users\Neil\Desktop\New Text Document.txt 2012-07-07 13:19 - 2012-07-07 13:19 - 00002098 ____N C:\Users\Public\Desktop\Bitdefender Antivirus Plus 2012.lnk 2012-07-07 13:19 - 2012-07-07 13:19 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_avchv_01009.Wdf 2012-07-07 13:08 - 2012-07-07 13:07 - 04819616 ____N (SpeedyPC Software Inc.) C:\Users\Neil\Desktop\Repair_Tool(1).exe 2012-07-07 12:39 - 2012-07-07 12:39 - 00001201 ____N C:\Users\Neil\Desktop\SpeedyPC Pro.lnk 2012-07-07 12:39 - 2012-07-07 12:31 - 04819616 ____N (SpeedyPC Software Inc.) C:\Users\Neil\Desktop\Repair_Tool.exe 2012-07-07 12:19 - 2012-07-07 12:19 - 00018266 ____N C:\Users\Neil\Desktop\[kat.ph]bitdefender.antivirus.plus.2012.build.15.0.27.312.final.torrent 2012-07-07 12:07 - 2012-01-16 01:42 - 00001945 ____A C:\Windows\epplauncher.mif 2012-07-04 13:02 - 2012-07-04 12:59 - 00001024 ____A C:\Users\All Users\sowdp88.dat 2012-07-04 12:59 - 2012-07-04 12:59 - 00000048 ____A C:\Windows\SysWOW64\pdfutil.ini 2012-07-04 12:56 - 2012-07-04 12:56 - 00000040 ____A C:\Windows\winDecrypt.INI 2012-07-03 23:03 - 2012-07-03 23:04 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll 2012-07-03 23:03 - 2012-07-03 23:04 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe 2012-07-03 23:03 - 2012-07-03 23:04 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe 2012-07-03 23:03 - 2012-07-03 23:04 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe 2012-07-03 23:03 - 2012-03-09 06:54 - 00472840 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll 2012-07-03 02:46 - 2012-07-15 13:26 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-02 16:13 - 2012-07-09 00:56 - 57442464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe 2012-06-29 12:12 - 2012-06-29 12:12 - 00028720 ____N C:\Users\Neil\Desktop\428A5014B4CAB78383A06A5BB042AD104C5A9344.torrent 2012-06-26 04:10 - 2012-06-26 04:10 - 00090038 ____N C:\Users\Neil\Desktop\books-i-should-refer-cbse-iit-jee-702648.html 2012-06-07 02:34 - 2012-06-07 02:34 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-06-07 02:34 - 2012-03-12 04:46 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-06-03 12:28 - 2012-03-09 10:04 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-06-02 14:19 - 2012-07-08 06:33 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-07-08 06:33 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-07-08 06:33 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-07-08 06:33 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-07-08 06:33 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:15 - 2012-07-08 06:33 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:15 - 2012-07-08 06:33 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 04:19 - 2012-07-08 06:32 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 04:15 - 2012-07-08 06:32 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-05-12 09:16 - 2012-05-12 09:16 - 00001013 ____N C:\Users\Public\Desktop\PowerISO.lnk 2012-05-12 06:42 - 2012-05-12 02:32 - 00002453 ____N C:\Users\Public\Desktop\SeaTools for Windows.lnk 2012-05-12 02:26 - 2012-05-12 02:26 - 00000000 ____A C:\Windows\SysWOW64\cd.dat 2012-05-11 01:54 - 2012-03-07 04:10 - 01891384 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2012-05-02 03:28 - 2012-05-02 03:28 - 00130820 ____N C:\Users\Neil\Desktop\binkw32.zip 2012-04-28 10:33 - 2012-04-16 03:19 - 00000858 ____N C:\Users\Neil\Desktop\TeraCopy.lnk 2012-04-28 10:33 - 2012-01-16 02:23 - 00001632 ____N C:\Users\Neil\Desktop\Turbo C++.lnk ZeroAccess: C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199} C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\@ C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\L C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\U C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\L\00000004.@ C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\L\1afb2d56 C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\L\201d3dde C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\U\00000004.$ C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\U\000000cb.@ C:\Windows\Installer\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\U\80000000.$ ZeroAccess: C:\Users\Neil\AppData\Local\{c9ca9eb3-6dd8-8597-d375-41171a9dd199} C:\Users\Neil\AppData\Local\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\@ C:\Users\Neil\AppData\Local\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\L C:\Users\Neil\AppData\Local\{c9ca9eb3-6dd8-8597-d375-41171a9dd199}\U ZeroAccess: C:\Windows\assembly\GAC_32\Desktop.ini ZeroAccess: C:\Windows\assembly\GAC_64\Desktop.ini ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!. C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 14% Total physical RAM: 4007.85 MB Available physical RAM: 3423.89 MB Total Pagefile: 4006 MB Available Pagefile: 3416.82 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ======================= Partitions ========================= 1 Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:109.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] 2 Drive d: (DATA) (Fixed) (Total:254.45 GB) (Free:58.49 GB) NTFS 4 Drive f: (NEIL) (Removable) (Total:0.49 GB) (Free:0.46 GB) FAT 5 Drive g: (Zain e-GO) (CDROM) (Total:0.04 GB) (Free:0 GB) CDFS 7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt -------- ------------- ------- ------- --- --- Disk 0 Online 465 GB 1024 KB Disk 1 Online 502 MB 0 B Disk 2 No Media 0 B 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 25 GB 1024 KB Partition 2 Primary 186 GB 25 GB Partition 0 Extended 254 GB 211 GB Partition 3 Logical 254 GB 211 GB ================================================================================== Disk: 0 Partition 1 Type : 1C Hidden: Yes Active: No There is no volume associated with this partition. ================================================================================== Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 C OS NTFS Partition 186 GB Healthy ================================================================================== Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 D DATA NTFS Partition 254 GB Healthy ================================================================================== Partitions of Disk 1: =============== Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 502 MB 16 KB ================================================================================== Disk: 1 Partition 1 Type : 06 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 F NEIL FAT Removable 502 MB Healthy ================================================================================== testsigning: ==> Check for possible unsigned malware driver <===== ATTENTION! ========================================================== Last Boot: 2012-07-17 21:50 ======================= End Of Log ==========================