Scan result of Farbar Recovery Scan Tool Version: 08-07-2012
Ran by SYSTEM at 08-07-2012 23:06:37
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [206208 2010-08-29] ()
HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-04-12] (ELAN Microelectronic Corp.)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-05] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2012-01-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392984 2012-01-10] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417560 2012-01-10] (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM-x32\...\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [1484856 2010-11-22] (McAfee, Inc.)
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-05-26] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [407920 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k [265984 2010-06-28] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [968272 2010-06-21] (Dritek System Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-26] (Apple Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Dan\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-07-13] (Google Inc.)
HKU\Dan\...\Run: [Switcher] "C:\Users\Dan\Documents\Switcher\Switcher.exe" /quiet [425984 2007-10-28] (Bao_Nguyen)
HKU\Dan\...\Run: [Ditto] C:\Users\Dan\Documents\DittoPortable_3_17_0_17\Ditto\Ditto.exe [831488 2011-06-23] ()
HKU\Dan\...\Run: [Facebook Update] "C:\Users\Dan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [137536 2011-09-02] (Facebook Inc.)
HKU\Dan\...\Run: [colodiag] rundll32 "C:\Windows\calcperf.dll",CreateProcessNotify [x]
HKU\Dan\...\Run: [dvdugMgr] rundll32 "C:\Windows\system32\calcperf64.dll",CreateProcessNotify [62976 2012-06-10] (ESET)
HKU\Dan\...\Run: [hinsp] "C:\Windows\System32\rundll32.exe" "C:\Users\Dan\AppData\Roaming\hinsp.dll",SaveMeshToXW [345088 2012-06-10] (Andrea Electronics Corporation)
HKU\Dan\...\CurrentVersion\Windows: [Load] C:\Users\Dan\AppData\Local\Temp\{44097~1.EXE
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\Dan\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 CronService; "C:\Prey\platform\windows\cronsvc.exe" [19968 2011-02-15] (Fork Ltd.)
2 DsiWMIService; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [321104 2010-06-21] (Dritek System Inc.)
2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated)
2 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 McMPFSvc; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 mcmscsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 McNaiAnn; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 McNASvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
3 McODS; "C:\Program Files\mcafee\VirusScan\mcods.exe" [509416 2010-10-07] (McAfee, Inc.)
4 McOobeSv; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 McProxy; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 McShield; "C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe" [200056 2010-10-13] (McAfee, Inc.)
2 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [245352 2010-10-13] (McAfee, Inc.)
2 mfevtp; "C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe" [149032 2010-10-13] (McAfee, Inc.)
2 MSK80Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [355440 2010-03-10] (McAfee, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.)
2 UNS; "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe" [2320920 2010-03-17] (Intel Corporation)
========================== Drivers (Whitelisted) =============
3 cfwids; C:\Windows\System32\Drivers\cfwids.sys [62800 2010-10-13] (McAfee, Inc.)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 mfeapfk; C:\Windows\System32\Drivers\mfeapfk.sys [121248 2010-10-13] (McAfee, Inc.)
3 mfeavfk; C:\Windows\System32\Drivers\mfeavfk.sys [190136 2010-10-13] (McAfee, Inc.)
3 mfefirek; C:\Windows\System32\Drivers\mfefirek.sys [441328 2010-10-13] (McAfee, Inc.)
0 mfehidk; C:\Windows\System32\Drivers\mfehidk.sys [529128 2010-10-13] (McAfee, Inc.)
1 mfenlfk; C:\Windows\System32\Drivers\mfenlfk.sys [75032 2010-10-13] (McAfee, Inc.)
3 mferkdet; C:\Windows\System32\Drivers\mferkdet.sys [94864 2010-10-13] (McAfee, Inc.)
0 mfewfpk; C:\Windows\System32\Drivers\mfewfpk.sys [283360 2010-10-13] (McAfee, Inc.)
3 NTIDrvr; C:\Windows\System32\Drivers\NTIDrvr.sys [18432 2010-04-19] (NTI Corporation)
2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [13784 2009-11-02] ()
3 UBHelper; C:\Windows\System32\Drivers\UBHelper.sys [17408 2010-07-08] (NTI Corporation)
2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [x]
3 mfeavfk01; [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-08 23:06 - 2012-07-08 23:06 - 00000000 ____D C:\FRST
2012-07-06 11:12 - 2012-07-06 11:12 - 00262144 ____A C:\Windows\Minidump\070612-20904-01.dmp
2012-07-06 10:02 - 2012-07-06 10:03 - 00607260 ____R (Swearware) C:\Users\Dan\Desktop\dds.com
2012-07-06 09:54 - 2012-07-06 09:54 - 00001640 ____A C:\Users\Dan\Desktop\aswmbr0.txt
2012-07-06 08:03 - 2012-07-06 08:03 - 00001640 ____A C:\Users\Dan\Desktop\aswMBR2.txt
2012-07-06 07:55 - 2012-07-06 07:55 - 00001640 ____A C:\Users\Dan\Desktop\awsmbr2.txt
2012-07-06 07:48 - 2012-07-06 07:48 - 00001640 ____A C:\Users\Dan\Desktop\aswMBR1.txt
2012-07-06 06:54 - 2012-07-06 06:54 - 00262144 ____A C:\Windows\Minidump\070612-17862-01.dmp
2012-07-06 06:49 - 2012-07-06 06:49 - 00001694 ____A C:\Users\Dan\Desktop\aswMBR.txt
2012-07-06 06:37 - 2012-07-06 11:11 - 422173733 ____A C:\Windows\MEMORY.DMP
2012-07-06 06:37 - 2012-07-06 06:37 - 00262144 ____A C:\Windows\Minidump\070612-20716-01.dmp
2012-07-06 06:27 - 2012-07-06 06:27 - 04731392 ____A (AVAST Software) C:\Users\Dan\Desktop\aswMBR.exe
2012-07-06 06:25 - 2012-07-06 06:25 - 00000000 ____A C:\Users\Dan\Desktop\aswMBR.exe.wb21glj.partial
2012-07-06 06:16 - 2012-07-06 06:16 - 00066206 ____A C:\Users\Dan\Desktop\ktsdsd.txt
2012-07-06 06:10 - 2012-07-06 06:10 - 02116179 ____A C:\Users\Dan\Downloads\tdsskiller.zip
2012-07-06 06:10 - 2012-07-06 06:10 - 00000000 ____D C:\Users\Dan\Downloads\tdsskiller
2012-07-06 05:56 - 2012-07-06 05:56 - 00137096 ____A (ESET) C:\Users\Dan\Desktop\ESETSirefefRemover.exe
2012-07-05 04:58 - 2012-07-05 04:58 - 00000036 ____A C:\Users\Dan\AppData\Local\housecall.guid.cache
2012-07-05 04:57 - 2012-07-05 04:58 - 02406064 ____A (Trend Micro Inc.) C:\Users\Dan\Desktop\HousecallLauncher64.exe
2012-06-13 04:50 - 2012-07-08 13:58 - 00002856 ____A C:\Windows\setupact.log
2012-06-13 04:50 - 2012-06-13 04:50 - 00000000 ____A C:\Windows\setuperr.log
2012-06-13 04:32 - 2012-06-13 04:32 - 00000082 ____A C:\Users\Dan\Desktop\cc_20120613_133231.reg
2012-06-13 04:21 - 2012-06-13 04:21 - 00001117 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-13 04:21 - 2012-06-13 04:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-13 04:21 - 2012-04-04 06:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-10 10:21 - 2012-06-10 10:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-10 04:02 - 2012-06-10 04:02 - 00022660 ___RA C:\Users\Dan\Documents\Party Plan.docxENX
2012-06-10 04:00 - 2012-06-10 04:00 - 00002117 ____A C:\Users\Public\Desktop\PC Tools AntiVirus Free.lnk
2012-06-10 04:00 - 2012-05-11 02:14 - 00092896 ____A (PC Tools) C:\Windows\System32\Drivers\pctplsg64.sys
2012-06-10 04:00 - 2012-05-11 02:13 - 00014776 ____A (PC Tools) C:\Windows\System32\Drivers\pctBTFix64.sys
2012-06-10 04:00 - 2012-05-11 02:09 - 00145432 ____A (PC Tools) C:\Windows\System32\Drivers\pctwfpfilter64.sys
2012-06-10 04:00 - 2012-05-11 02:08 - 00341168 ____A (PC Tools) C:\Windows\System32\Drivers\pctgntdi64.sys
2012-06-10 04:00 - 2012-02-28 02:43 - 01096176 ____A (PC Tools) C:\Windows\System32\Drivers\pctEFA64.sys
2012-06-10 04:00 - 2012-02-28 02:43 - 00453896 ____A (PC Tools) C:\Windows\System32\Drivers\pctDS64.sys
2012-06-10 03:54 - 2012-04-23 03:36 - 00426616 ____A (PC Tools) C:\Windows\System32\Drivers\PCTCore64.sys
2012-06-10 03:51 - 2012-06-10 03:51 - 04183000 ____A (PC Tools) C:\Users\Dan\Downloads\pctoolsspywaredoctor.exe
2012-06-10 03:40 - 2012-06-10 03:40 - 00000000 ____D C:\Users\Dan\AppData\Roaming\Malwarebytes
2012-06-10 03:40 - 2012-06-10 03:40 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-10 03:16 - 2012-05-08 09:21 - 02267064 ____A (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll0645.old
2012-06-10 03:16 - 2012-05-08 09:21 - 02267064 ____A (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll
2012-06-10 03:16 - 2012-05-08 09:21 - 01681336 ____A (Threat Expert Ltd.) C:\Windows\PCTBDRes.dll
2012-06-10 03:16 - 2012-05-08 09:21 - 00767928 ____A C:\Windows\BDTSupport.dll0645.old
2012-06-10 03:16 - 2012-05-08 09:21 - 00767928 ____A C:\Windows\BDTSupport.dll
2012-06-10 03:16 - 2012-05-08 09:21 - 00149432 ____A (PC Tools) C:\Windows\SGDetectionTool.dll0645.old
2012-06-10 03:16 - 2012-05-08 09:21 - 00149432 ____A (PC Tools) C:\Windows\SGDetectionTool.dll
2012-06-10 03:16 - 2012-05-08 09:21 - 00085192 ____A (PC Tools) C:\Windows\System32\Drivers\PCTBD64.sys
2012-06-10 03:16 - 2012-05-08 08:47 - 00003488 ____A C:\Windows\UDB.zip
2012-06-10 03:16 - 2012-05-08 08:47 - 00000882 ____A C:\Windows\RegSDImport.xml
2012-06-10 03:16 - 2012-05-08 08:47 - 00000879 ____A C:\Windows\RegISSImport.xml
2012-06-10 03:16 - 2012-05-08 08:47 - 00000131 ____A C:\Windows\IDB.zip
2012-06-10 03:15 - 2012-06-10 03:54 - 00000000 ____D C:\Program Files (x86)\PC Tools
2012-06-10 03:14 - 2012-05-11 02:14 - 00251528 ____A (PC Tools) C:\Windows\System32\Drivers\PCTSD64.sys
2012-06-10 03:13 - 2012-06-13 04:21 - 00000000 ____D C:\Users\Dan\Documents\virus thing
2012-06-10 03:13 - 2012-06-10 04:00 - 00000000 ____D C:\Users\All Users\PC Tools
2012-06-10 03:13 - 2012-06-10 03:13 - 00000000 ____D C:\Users\Dan\AppData\Roaming\TestApp
2012-06-10 02:52 - 2012-06-10 02:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-10 02:49 - 2012-06-10 02:49 - 00345088 ____A (Andrea Electronics Corporation) C:\Users\Dan\AppData\Roaming\hinsp.dll
2012-06-10 02:49 - 2012-06-10 02:49 - 00062976 ___AH (ESET) C:\Windows\System32\calcperf64.dll
2012-06-10 02:48 - 2012-06-10 06:52 - 00000000 ____D C:\Users\All Users\B7E858860000239D0001205DB4EB2367
============ 3 Months Modified Files ========================
2012-07-08 13:58 - 2012-06-13 04:50 - 00002856 ____A C:\Windows\setupact.log
2012-07-08 13:58 - 2011-08-18 09:50 - 00000029 ____A C:\Windows\SysWOW64\TempWmicBatchFile.bat
2012-07-08 13:58 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-06 11:20 - 2011-05-27 04:35 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-06 11:16 - 2011-05-27 04:35 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-06 11:12 - 2012-07-06 11:12 - 00262144 ____A C:\Windows\Minidump\070612-20904-01.dmp
2012-07-06 11:11 - 2012-07-06 06:37 - 422173733 ____A C:\Windows\MEMORY.DMP
2012-07-06 11:04 - 2009-07-13 21:13 - 00738798 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-06 10:03 - 2012-07-06 10:02 - 00607260 ____R (Swearware) C:\Users\Dan\Desktop\dds.com
2012-07-06 09:54 - 2012-07-06 09:54 - 00001640 ____A C:\Users\Dan\Desktop\aswmbr0.txt
2012-07-06 08:03 - 2012-07-06 08:03 - 00001640 ____A C:\Users\Dan\Desktop\aswMBR2.txt
2012-07-06 07:55 - 2012-07-06 07:55 - 00001640 ____A C:\Users\Dan\Desktop\awsmbr2.txt
2012-07-06 07:48 - 2012-07-06 07:48 - 00001640 ____A C:\Users\Dan\Desktop\aswMBR1.txt
2012-07-06 06:54 - 2012-07-06 06:54 - 00262144 ____A C:\Windows\Minidump\070612-17862-01.dmp
2012-07-06 06:49 - 2012-07-06 06:49 - 00001694 ____A C:\Users\Dan\Desktop\aswMBR.txt
2012-07-06 06:37 - 2012-07-06 06:37 - 00262144 ____A C:\Windows\Minidump\070612-20716-01.dmp
2012-07-06 06:27 - 2012-07-06 06:27 - 04731392 ____A (AVAST Software) C:\Users\Dan\Desktop\aswMBR.exe
2012-07-06 06:25 - 2012-07-06 06:25 - 00000000 ____A C:\Users\Dan\Desktop\aswMBR.exe.wb21glj.partial
2012-07-06 06:16 - 2012-07-06 06:16 - 00066206 ____A C:\Users\Dan\Desktop\ktsdsd.txt
2012-07-06 06:10 - 2012-07-06 06:10 - 02116179 ____A C:\Users\Dan\Downloads\tdsskiller.zip
2012-07-06 05:56 - 2012-07-06 05:56 - 00137096 ____A (ESET) C:\Users\Dan\Desktop\ESETSirefefRemover.exe
2012-07-06 05:55 - 2011-09-02 14:50 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1478088397-1558616173-1976592655-1001UA.job
2012-07-05 05:08 - 2010-08-29 09:10 - 01519280 ____A C:\Windows\WindowsUpdate.log
2012-07-05 04:58 - 2012-07-05 04:58 - 00000036 ____A C:\Users\Dan\AppData\Local\housecall.guid.cache
2012-07-05 04:58 - 2012-07-05 04:57 - 02406064 ____A (Trend Micro Inc.) C:\Users\Dan\Desktop\HousecallLauncher64.exe
2012-07-05 04:22 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-05 04:22 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-13 04:50 - 2012-06-13 04:50 - 00000000 ____A C:\Windows\setuperr.log
2012-06-13 04:32 - 2012-06-13 04:32 - 00000082 ____A C:\Users\Dan\Desktop\cc_20120613_133231.reg
2012-06-13 04:21 - 2012-06-13 04:21 - 00001117 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-12 08:36 - 2009-07-13 21:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-10 10:22 - 2010-12-25 03:43 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-10 10:21 - 2010-12-25 03:43 - 00735726 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-10 04:02 - 2012-06-10 04:02 - 00022660 ___RA C:\Users\Dan\Documents\Party Plan.docxENX
2012-06-10 04:00 - 2012-06-10 04:00 - 00002117 ____A C:\Users\Public\Desktop\PC Tools AntiVirus Free.lnk
2012-06-10 03:51 - 2012-06-10 03:51 - 04183000 ____A (PC Tools) C:\Users\Dan\Downloads\pctoolsspywaredoctor.exe
2012-06-10 02:50 - 2012-04-02 03:44 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-10 02:50 - 2011-06-13 08:13 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-10 02:49 - 2012-06-10 02:49 - 00345088 ____A (Andrea Electronics Corporation) C:\Users\Dan\AppData\Roaming\hinsp.dll
2012-06-10 02:49 - 2012-06-10 02:49 - 00062976 ___AH (ESET) C:\Windows\System32\calcperf64.dll
2012-06-09 14:55 - 2011-09-02 14:50 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1478088397-1558616173-1976592655-1001Core.job
2012-06-07 16:17 - 2012-06-07 16:17 - 00000120 ____A C:\Windows\wininit.ini
2012-06-07 16:16 - 2012-04-16 12:36 - 00001013 ____A C:\Users\Dan\Desktop\Dropbox.lnk
2012-05-31 11:05 - 2012-05-31 11:05 - 00002018 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-05-14 15:06 - 2012-05-14 15:06 - 00001462 ____A C:\Users\Dan\Desktop\Windows Live Mail.lnk
2012-05-11 08:20 - 2009-07-13 20:45 - 04863560 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-11 07:54 - 2010-12-25 02:51 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-11 02:14 - 2012-06-10 04:00 - 00092896 ____A (PC Tools) C:\Windows\System32\Drivers\pctplsg64.sys
2012-05-11 02:14 - 2012-06-10 03:14 - 00251528 ____A (PC Tools) C:\Windows\System32\Drivers\PCTSD64.sys
2012-05-11 02:13 - 2012-06-10 04:00 - 00014776 ____A (PC Tools) C:\Windows\System32\Drivers\pctBTFix64.sys
2012-05-11 02:09 - 2012-06-10 04:00 - 00145432 ____A (PC Tools) C:\Windows\System32\Drivers\pctwfpfilter64.sys
2012-05-11 02:08 - 2012-06-10 04:00 - 00341168 ____A (PC Tools) C:\Windows\System32\Drivers\pctgntdi64.sys
2012-05-08 13:24 - 2011-08-03 08:33 - 00001247 ____A C:\Users\Dan\Desktop\DVDVideoSoft Free Studio.lnk
2012-05-08 09:21 - 2012-06-10 03:16 - 02267064 ____A (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll0645.old
2012-05-08 09:21 - 2012-06-10 03:16 - 02267064 ____A (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll
2012-05-08 09:21 - 2012-06-10 03:16 - 01681336 ____A (Threat Expert Ltd.) C:\Windows\PCTBDRes.dll
2012-05-08 09:21 - 2012-06-10 03:16 - 00767928 ____A C:\Windows\BDTSupport.dll0645.old
2012-05-08 09:21 - 2012-06-10 03:16 - 00767928 ____A C:\Windows\BDTSupport.dll
2012-05-08 09:21 - 2012-06-10 03:16 - 00149432 ____A (PC Tools) C:\Windows\SGDetectionTool.dll0645.old
2012-05-08 09:21 - 2012-06-10 03:16 - 00149432 ____A (PC Tools) C:\Windows\SGDetectionTool.dll
2012-05-08 09:21 - 2012-06-10 03:16 - 00085192 ____A (PC Tools) C:\Windows\System32\Drivers\PCTBD64.sys
2012-05-08 08:47 - 2012-06-10 03:16 - 00003488 ____A C:\Windows\UDB.zip
2012-05-08 08:47 - 2012-06-10 03:16 - 00000882 ____A C:\Windows\RegSDImport.xml
2012-05-08 08:47 - 2012-06-10 03:16 - 00000879 ____A C:\Windows\RegISSImport.xml
2012-05-08 08:47 - 2012-06-10 03:16 - 00000131 ____A C:\Windows\IDB.zip
2012-04-29 13:20 - 2012-04-29 13:20 - 00001374 ____A C:\Windows\SysWOW64\bash.exe.stackdump
2012-04-23 03:36 - 2012-06-10 03:54 - 00426616 ____A (PC Tools) C:\Windows\System32\Drivers\PCTCore64.sys
2012-04-18 04:49 - 2012-05-08 13:24 - 00405176 ____A (Newtonsoft) C:\Windows\SysWOW64\Newtonsoft.Json.Net20.dll
ZeroAccess:
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\@
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\L
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\U
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\U\00000001.@
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\U\80000000.$
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\U\80000000.@
C:\Windows\Installer\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\U\800000cb.@
ZeroAccess:
C:\Users\Dan\AppData\Local\{08a08fd3-50d2-9b4f-403f-603a6455c6de}
C:\Users\Dan\AppData\Local\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\@
C:\Users\Dan\AppData\Local\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\L
C:\Users\Dan\AppData\Local\{08a08fd3-50d2-9b4f-403f-603a6455c6de}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 3766.71 MB
Available physical RAM: 3057.84 MB
Total Pagefile: 3764.86 MB
Available Pagefile: 3049.18 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Acer) (Fixed) (Total:452.66 GB) (Free:323.04 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:13 GB) (Free:1.46 GB) NTFS
5 Drive h: (DAN SIMOU) (Removable) (Total:0.48 GB) (Free:0.48 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 Online 489 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 452 GB 13 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 13 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Acer NTFS Partition 452 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 488 MB 16 KB
==================================================================================
Disk: 2
Partition 1
Type : 0E
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H DAN SIMOU FAT Removable 488 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-12 18:33
======================= End Of Log ==========================