Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Zeroaccess rootkit removed, need to fix remaining damage


  • This topic is locked This topic is locked
116 replies to this topic

#1 Alonshow

Alonshow

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 23 October 2013 - 09:36 PM

Hi, I recently got infected with a Zeroaccess rootkit and several virus that came with it. I think that I have managed to remove the all the infections, but some of the problems that they caused still persist. I'm requesting help to fix those problems.

 

The origin of the infection might have been a program downloaded from P2P that I tried to run or a malicious website that I visited. I don’t know which one because both things happened almost at the same time.

 

The problems that I am currently experiencing are these:

  • When I run sfc /scannow, it returns an error message:
    Windows Resource Protection found corrupt files but was unable to fix some of them.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log.
    This suggests that there might still be some undetected problems in my system.
     
  • I use a program called WakeUpOnStandBy as an alarm clock. This program does what its name suggests (it wakes up my computer when it is in standby, i. e., sleep or hibernation). Since I got the infection, it can’t wake up my PC from hibernation.

NOTE: I haven't been able to upload the file attach.txt. It's very big (1.3 MB), so the uploader doesn't accept it. It doesn't accept a RAR archive either. I'd like to get feedback on what to do about this.

 

I have written down the process that I have followed to get rid of the infection:

The problem

I got infected with a lot of viruses, including a ZeroAccess rootkit. The origin of the infection might have been a program downloaded from P2P that I tried to run or a malicious website that I visited. I don’t know which one because both things happened almost at the same time.

There were a multitude of symptoms:

  • AVG was detecting viruses constantly, and in some cases it couldn’t remove them.
  • The Windows Security Center is disabled and there is no way to start it. This includes the firewall not working.
  • The computer is very slow.
  • Several system and software crashes.
Actions taken
  • Installed Comodo Firewall as a temporary solution for the lack of firewall.
  • Performed several system scans with AVG. It detected and removed some threats, but it failed to remove others (GAC_32 and GAC_64).
  • Installed Avast antivirus. It detected and reportedly removed what AVG hadn’t, and also some other threats that AVG hadn’t detected.
  • Scanned with MBAM. Detected several threats of minor importance (Potentially Unwanted Programs). It removed them, but it doesn’t look like that was a significant issue.
  • Uninstalled AVG after I learned that two antivirus in the same system is a bad idea. This seemed to improve a bit the speed of the computer, but it still seems too slow.
  • Backup of the system to run MB anti rootkit.
  • Scanned with MB anti rootkit. Detected several threats that had been undetected before and removed all of them.
Problems solved

The security center works again, including the Firewall. Therefore, I uninstalled Comodo Firewall.

Problems persisting
  • The computer is slow.
  • Outlook doesn’t retrieve new messages.
Actions taken
  • Confirmed that Windows Update works (by updating Windows).
  • Checked if sfc /scannow works. It does now (rather than getting stuck at 60%, as it used to), but it returns an error message:
    Windows Resource Protection found corrupt files but was unable to fix some of them.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log.
  • Uninstalled several programs with Revo:
    • GameSpy Comrade: Avast found a virus when trying to uninstall it.
    • HomeRAE. This one seemed to be malware since I downloaded it from the RAE website, so I didn’t even finish the installation. When I tried to uninstall it, I received an error message saying it wasn’t installed, so I just removed it from the installed programs list.
    • Programs that I don’t recall having installed: Apple Application Support, Apple mobile device support, Apple Software Update, Bonjour.
    • Programs that reinstalled automatically: AAC ACM codec, Windows Live Mesh ActiveX Controls.
    • Other programs: DivX setup, DivX H.264 decoder, DTS+AC3 filter, Xfire, Awesome Duplicate Photo Finder, iTunes, MPEG2 Codec, Quicktime, Quicktime Alternative, ffdshow 1.1, VisiPics, SMPlayer, x264vfw, Xvid MPEG-4 Video Codec, Oxford Advanced Learner’s Dictionary, Solid Converter PDF, Nokia Connectivity Cable Driver, PC connectivity Solution, Windows Driver Package – Nokia Modem, Windows Driver Package – pccsmcfd.
  • Repaired the installation of Office. The problem with Outlook persists.
Pending actions
  • Ask for help in bleepingcomputer.com.
18 October Problems solved
  • Outlook is retrieving messages again for no aparent reason. I’m not aware of having done anything to fix it.
Problems pending
  • The computer crashes now and then. Yesterday I got a BSD while using Skype. Two days ago Windows Explorer ceased to work when I tried to access an unresponsive external HD.
  • sfc /scannow returns an error message:
    Windows Resource Protection found corrupt files but was unable to fix some of them.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log.
Actions pending
  • Perform a full antivirus scan.
  • Ask for help in bleepingcomputer.com.
19 October Actions taken
  • Performed full antivirus scan. Result: 2 virus found, but they were in temporary directories, so it is unlikely that they were causing problems.
  • Scheduled boot time antivirus scan.
20 October Problems solved
  • The boot time antivirus didn’t find any virus.
26 October Problems solved
  • The computer hasn’t crashed anymore.
Problems pending
  • sfc /scannow returns an error message:
    Windows Resource Protection found corrupt files but was unable to fix some of them.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log.
  • WakeUpOnStandBy can’t wake up the PC from hibernation.
  • I found out that the firewall was disabled again. This time, however, enabling it was straightforward.
Actions pending
  • Ask for help in bleepingcomputer.com.

 

Thank you,

 

Alonso

Attached Files

  • Attached File  DDS.txt   27.4KB   5 downloads


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,740 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:16 AM

Posted 28 October 2013 - 09:40 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/511691 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 29 October 2013 - 10:17 AM

I haven't performed any additional steps to fix the issues described. However, since I posted my original message I have noticed two other minor issues:

  • Sometimes the system tray doesn’t show the icons for uTorrent or eMule. Therefore, it is impossible to access these programs.
  • The events of the event viewer get deleted automatically, only the last few days are kept.
  • Notepad++ takes an unusually long time to open. This has been happening for some time, I'm not sure if it was happening already before my PC got infected.

I don't have a Windows DVD available (this is an OEM installation).

Attached Files



#4 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:06:16 AM

Posted 29 October 2013 - 07:20 PM

Hello Alonshow, and  :welcome: to the Virus/Trojan/Spyware/Malware Removal forum.

I am oneof4, and I am here to help you!

  • I ask that you refrain from running tools other than those I suggest to you while I am cleaning up your computer. The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received and do not proceed if you need clarification.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please do not re-run any programs I suggest. If you encounter problems please stop and tell me about it. When your computer is clean I will alert you of such. I will also provide you with detailed suggestions for prevention.
  • At the top right-center of the topic you will see a button called Follow this topic. If you click on this, another page will open. Please choose Instantly for notification and then clicking on Follow this topic you will be advised when we respond to your topic and facilitate the cleaning of your machine.
  • If after 5 days you have not replied to this topic, I will assume it has been abandoned, and I will close it.
  • I would also like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. :heart: Please be courteous and appreciative for the assistance provided!
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. Your computer fix will be based on the current condition of your computer! Any changes might delay my ability to help you.

==========

We need to see some information about what is happening in your machine.  Please perform the following scans:

Download Security Check by screen317 from http://screen317.spywareinfoforum.org/SecurityCheck.exe or http://screen317.changelog.fr/SecurityCheck.exe
.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

==========
 
Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

Best Regards,
oneof4.


#5 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 30 October 2013 - 06:51 PM

Here are the logs requested:

 

SecurityCheck

 

 Results of screen317's Security Check version 0.99.75  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 Secunia PSI (3.0.0.7009)   
 Malwarebytes Anti-Malware version 1.75.0.1300  
 Duplicate Cleaner 2.1b   
 JavaFX 2.1.1    
 Java 7 Update 25  
 Java version out of Date!
 Adobe Flash Player 11.9.900.117  
 Adobe Reader 10.1.8 Adobe Reader out of Date!  
 Mozilla Firefox (25.0)
 Google Chrome 30.0.1599.101  
 Google Chrome 30.0.1599.69  
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````

 

 

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-10-2013
Ran by Alonso (administrator) on ALONSO-PC on 31-10-2013 00:39:16
Running from C:\Users\Alonso\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Broadcom Corporation.) C:\windows\system32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\windows\SysWOW64\svchost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Nalpeiron Ltd.) C:\windows\SysWOW64\NLSSRV32.EXE
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Scendix Software-Vertriebsges. mbH) C:\Program Files (x86)\Pamela\Pamela.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(www.dennisbabkin.com) C:\Programs\Utilities\WakeupOnStandBy\wosb.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Google) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(mozilla.org) C:\Program Files (x86)\Cambridge\CALD3\cald3.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Dropbox, Inc.) C:\Users\Alonso\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe [521272 2010-03-22] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-06-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [976672 2013-03-24] (NVIDIA Corporation)
HKLM\...\Run: [OnekeyStudio] - C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [776608 2009-12-19] (Lenovo)
HKLM\...\Policies\Explorer: [3212083974] 0x504B0304C239B7F8068374BFB511000000400000E269F63D73594F6202C9694280CC96A28BBD63516FE3C2D5F7A2FF87AC3A990C3EC3B2ED7B07716237A0DFB1DFB651F67E31CB2E7649F98D5E55E9B25B1A579794989B176C357BDCC11226BD6ECB7DE8A63EA2165F6B31EAD6B0A2A96A6E9D04B9B39F194EF52D48B088D4B6597F685A70FF6912914F86D8235681747DA26CFD83223D3D248872C51095484634EBF976E4595F734BD35CAF42B38DCF9E878AF0BE0A5E84B22940F721E8BBCDCBAA3E53607359252DB16C0D6C38A142261BB4896D12A48C006CC3C21FDF717C155B2AF0375D2545EE286C2AECB2955206EF25C82DC686F7EB83BB3072E94E1E59254B11A2E3628E1D98E177375B54E682A1C77F986E1907FFCB784ACCACB124189751D7EBBAFC91D3A127F134A85E27F8C201D9082F621F5FFFAC09D2AAB94A62F90BD74D6C96A8DB6D42E4E98316449D202A4E24857673E2A50B7DFD9D5AF72A21A19A922ACC9675BA933A1C6AD4E0A11470FBB82EED7A79C5CA2DBB0BEC5B2B43BAA37373D3EF494726D7CF4A4AA8A3D6A5C206CED49148C0100BFA96B707BE91B855151D8DA8E0723DD1303325011B3951C9DF7B10E9B153BCED98376C4D7517F2E0E23A986914B2B0F978454441C47B5797D924CE9CD186D74D308099EE52F226E92DE6B50E4A0691F75CFA9CE733494B8CAFAEB4BE4C65F6C9DFFA34A3C2ED9D14F5844164BE79B7A90495290350177B03AEFA777FF519B624E3C75C219260AC447BBA9A6DB56F34B340A5F75837FAB3C33831A3BC39C2914AEB87A39545BD7ED52450EB7E94D5380E2BABCE3F8EE6E3CDC9D4ED54D9889D9DBD0DC879CAA2B121048A308A7F873252DAD24EA8F8911EA0A3B202DE930A9FC882CF1349FFE229016B2EBFD7821B8986D31DECCBC296BA54FD6D864C915F1D77AC0734D96FE0BA43A669FAB128026C7F90E9E1E0A7047F5A2378E4DE0966EB6C217B3483194B2B21A3FA8A1CBEF1D66A3FC8A5C863BCEA6157981A11449BAE3357F3287501CB9C24E0AFB156F5DDFD6855CD8B7B43FEABD9412C1C208B5DE2330C469A59DE5B490CC06BFD5A4900CB121EB967BC7185A9F00112A5B1E8D8028CA02B0F2B194AF03CC1E172B70C9B88643E3C064B5406CF184AD9EBA26736EF6FEB30DAC8BA400933A32A3C03230BD732FCBE16C4B3BDCC0B501616CE956D968B8DA68B4A9A64238601E81E78095961580431361A4DD9FE963D3CEBA5C21BBA416C1CC9D94BB842C25B2FD12C8BF42C35948272965A3FECF6E9B92D32D7E84A402A0B6214A412A23427E4852CE607FD9F7FF8559BBB96A9AE577DF0C19D108587D372470BE0D3E27ED61FEB442C2D65E55BAC81C2786CF6B837EEBC1B5AF35634B29FD5D96347B5F9C747C8A9A83E7CB3C188D9042F08FBD4EDEEBD65DE7C04B275B7FD74067A0AE3033752AA55A45A05355811416EA4A5101511E99305B700BD44742CBD6A9272B5CF4001505C4057866B57E4DE5EF0EE9F88B41986A80119C962594972011FC0C39B4A74B74747F5116D896A0EBCBB4387685672899AF54B80AE07008971EA1C997A898E33AAB769E4E52FBBEC97EBF199CE76454BADBD4EAB272F1D1CAABB3B49B3AAFC1E67D09EE8FEB0580E414EB45F3F0C25FE88872312FEC2341E7A6100B2E04ED25FCE13A146098DCE98446B2F3875ECB269A886795698619D337DA612F19BF8D4FE3028E79A26548128D1595AF0BF98FF320DC73D873F05EBD07C87CAE28DF067C00DE3E53CC77E801E1304192CA7BF78AB28DB40564328A108F9F0DDD8E1B0BAECCF16BF1DEB3CC5C4B5F5140F6B8A256E9128C203418AA3D93E3F08078977667DC02D830BB6869DE92F29A65AC6D2689D0A5A90887A8643119DC9A68B5B00BD59D45DA9D7ED5DAE6EE6DA6119243F77F51B263200F90ABBB61CCE9A951781EA2012A2C8D7200906439B08E7E76CF9C9536B2E6B560AFD7CBAA5044791EE17DED45ADFD9D359DAC0A9F4ED15BF2CB2EA9B12B7CB11B597CF2E6E750A6C636FE2C4B144F6FF43CCFFDDAE787BE160B0A8B4282B35A6AEECE165814E95CE7ADBE416EF4E51860CB4F5D50AF2A86AA4EE602A30AA54850E0CB4A38DC3A1C711B5D03B6A53EE102AC68E553D11E5FB3D0A8E0EF34266263CA4A3E0B76C55A92F75F921CD61A5363E5DB7737874D57C653D63457260B67B1DF330827B2921C29FDA0045BBE7404E40985039F7DB153F52B2C941A56E922DCFB60B89DBEE327ED6F5C1E438270F766A6ED1730FC581A4AEBCFE3B7726B27D6B092CF5A0B6954196CB4CC2788B8722338EE189D9E22692595F0D5B333B0F715CB8D94A08AFB631DBB1BE79A773E8F1A4EAF7220C24222DDA431B91D9175DFA0C6AE81E8C4C879D64446CF56FAEFE1487CA6739A776AEE42EF8BE40A612F95CDE3B1FEEAC1E1E41A24C92ED8B0152E247239E5A8BC903679CA8C7B94659AD5B1D10551F460D924FB60882FC90508C3723420F86F4CF100387E808133CC429883C0E3ACE91651C075CD19D106E0B437B0363048CA1FEAAF929B87AED90AFDE281EDCA0FA0CC7B5A7F03807FA5AC41B1ED73130EAC1117C631C1818142F24D420F6776CB53D4D0326B9FC3008C3CA03FC649D87D37FA617B74F2865C75298BED54B7D8DC676E2210374D8BF194AE2FEDA62B4798933C764CCDDF845330721FC21E68C0695CA73285103E22AE68DA440326DFEF9A80D17D0A7C3F920E7B0AA806EE9B7549ED9878B6CFB505AC69E8E8D3CFA718675764CFB03861D32AFAAE1D918BE87F6A9AC0D815C57AD3E167D642F5FCDDC25D4BA3AC3E67C26A4DEAA17797B3C0654F271EAAA442A71CBE19372ADCBDE3DF8B3FE491E5A76A79D1291A0DE317FFBF927F42782FA48270F2C969563B183A4B0112F3497DD3C2A423EC83498BDBAAC928910A9FB7FE5788E454C027A28F4A91AF2BF09E261F85B0EEE4F7929E63C4062496CB09534BB6D03FF69ED2915D0EA215B4FB3D1044E86EB87DFB4898BCBD50E5C4DDFBDB83B9410E1ADF91446C43C959E0E341D67A5A7EF8712586DE3B8B9C5B6F80F42F235BF68900EBFE6304BB0D9F67408B76201EC26180B4BD76500DE4F0DF86DF4A063AECECCA69DDF8A162B67A4B9800FA7570D5B551AC2703ADC0FFCED00650A96CD81EC4187B90C6B2140CE99C1937C40587EA72899897E628115BCAB73B3D9F425860B109A67347B8A121F65D0968D56A3DDE6B8171CEA61B08AE568B9D03C398977CE86F75055230EF370CABF67C9CF97C3223719555403F3E0BD2AF0E1E8742DECB05FADB0227F15D40EE2D6DC5A49FE1E6BC9E6CEDDE74294C3BB6FD5C5FEDFAD672DF1DFFD219BD8BC1EC39158EAB507998755F553441D01CD26A5501F6FB2DB4F3597510F85B93A542514C8013EEDBBFC913DCCE8B20A5759665BDFD9919EB22A89163D8656386D857C5BFC7C241C1D726CD94AB0F92D5B0FEFCF1D4ABDD26FBC6C17A4CCACF2D31E5E713059DE93C59D3B8D3E8D03B5D663F9DFADB03E093CB84FCF500A1F0E2E5BA1C9D81DB12CC799C6539AF0CC35682D95CB789C745A452BD8B38E6CF08E0579DA1AB43AD0858D0305F961B15A79C1090F4867040EA2BD36CF6512AAB44CE5A1098EFE039134F23BF057777FEF3E68E45827B0487924CAD4E5F0B1C3B4F5A0E3853B39640EB0782D78888FE92C3B68624E84FF6A5EDED87BE62D34CE858F34E5FFFBBA75F014DF0F648988B51A72DE1FF54D5C7A4B8ECB10C5E9EF51DE98C01EF8C406F9824A0C15A29E16B5A53E3643B0065A4263ECAE50D2CB976D3D2EA6255A65F1C6CC86167F1784A27B832037DB4CE1E262475334F3B2430F86C7A24456EEA82AB678ABA91BB4C0CC82C877B80B6D3574007257272C3E126C17A8B36AA8AA9431FF01BF658F82D8153EDDEA6804CDC564A3F5E9967B08FEEB823D3DB9356A4ACDD80E883CA58A1C661D01D145F80A3AB67E8036C0BAE1BB7BC43204EB0CF38214BC74A9AEF036A31D5A9C552D93A25C0E84057BCE5437B1634680D04A77472D631432D2BAA7A3ACD64220EFCF9E7848F8FD9801BEF7561A470A1822032160EB59EDC0F977882DCE4FB2872D89D27FF076DBA74A9672F86909956579C28853FA8DE7002CC8458D09256D42A39F1A4BDB6B56D36D51488E7368686E54C1BBBFFF48884E0D536BE362E59BD7F18329A4B82AED396E4F92865F594D0DA38F7CACE7A4603AF60C1A53BDFD19476094AAC6E4A8F31FC1257D48D03BB0EF515D8460B9441532C8B5043D0531D5881ADB6D997BB184FD8CAF4D8E6C759C3F7143B9E32BC7A0EC6234B68ADF4111CA1D136721438E5E6D7125D480CE982D84AEA7703B4010CD27867D6DDC5E0C970385196F020E48EDDB24C56972F9E61E6CC29C1712551583828F899534AACFFFC66F99999EA2BA2731D52A7FD2FA262A22B075DA52A5AA58F5B41AA9CDC9181406717F3F75E7C475090121966838125236E4DC6291AE3874968E8208B983AADB03CA60ACD935E6DA1B829407F70A77340E4439F22FDC2FC4218DE0F25D2F886C0AAEB693C2B23DB0EAB9953BF806C2173E0BC9D0D7EF0E763775BC1432FF48D6035B1214294C81B71CD98C42831014090CD99CB74929AE853F88132E559104D4FEA98AD40F17DA4100A909A6981BAD9EFB240A79520927AA12232A56F4D8893BFF92BFC2BD42CF3DC09BDC484DFDBA3A10C609186104CE33E3024F44000BE34814FF5DC9872D44B4157FB3A6655B985F6CC5EF4586F2ABFEE12DCBDB90181B396F95FE3213F094D1F3DD3D7FED800F4ED21290F613B62048E0FC1F1328D9F87A5653B489D36F727BE9D755523DEF0472F1C1D5AC90EE665379FF39D06E863C244890F5333A0B89B92022C1A8198029FE5F8C203B3DD211D4398958EE190108DD50B7850E20D8ABE2B927D53D28F3B8CA26BE81BC6B83C0E2B3B1DDA28066C63860CEA89DF82708EF21D4D36B84663E87B4385A3E37BD3FF1EB2BF64184C44723490669AF4DA092D45BA21A569A352E513D9A9B43E9CD4B812055822626EFC55F950009232B8B3BB2D63D44A8B0BD9BD4E84C5A724496A2326F63C97DBCB235366EC0CF6096B5F4988D073C34BD3A084130CEA8D6EE22E542B411C1E18599667B3FD6DDE0669AD82C85A1C10CA5862213CB1BB277E6C4F6564F20A9BCEA1B48170504C47235D78ED0A0441987C8C17D90D7B56CF487C46733BA4A6848FEC42B97CE4048F3C6D9C493322F052EF93F02F142B3940A10921BD15C911E7A97AA4A20DC383C62CD288D252BA937B3F60761E6653568A01241BB573664DE04811CF3F59B4C2D7E8A6C55DA16F468383456AA751697697397C2A5E5ABFA0F1099D80447D49DA509AA1347F3943EE9BAA1FDAD2A0E69410B34253AD4991282D0E952260F52AB9F02A3D00B37098CF60354424F862066E45E92AC475C99A00E7380766E589ABF66271619142795CF7A7FBD138A6CC5BD7E135122341D1F06EB5B436C59BE0ADEDC71BC03D7C63C16751AD56C69E36DECFE9E8214C719FCDF2E9FE2DC971F03C1C2AD6B6D368FE8B11D0389650C73D1C7E73708145FA05992A150E6A909656EA786E244BDF1CD71F4B0FD05B1335D703182FFA9D96C99108297B1FE327A83BF4F69D2A9C3D1EB73A9DD8CEE2B3220904AC31011FD6407A5BA427FACB46227FDEDB13D1CA6443DED3DC3B6CF06A59DC9B9226FBF357334ABF58412605FD206E7B6125FA19E5D68F75783FA08205B05C0A12D1830068317F6105958C4EB37BCB1BEAE6A401C267641AA58274A410D76B4D2A03E418020869B6886BB81964761B3FCD8EA68050AD6CFF99649CDE8FA53F04B0C96E271C0B092E24D81EA2D723775799E713EA9DA6967EF57AAAFE1C6732F2F047556027F021C65FC20C1C3BCB392ACF8FF7A9E14D9728A5AAACD255FC3866B041E9C96DCF592083D78C9E405DDD7991D2E2536D2EB1BA0F0ECE3DFB6A34C2665CFAC2D1850FD478F617FDD4E9DD4492C553BD375CFD33F4744D642006F3A5216A1FF7D73643ED751CAECDFDCB56247AA2F66FBCB8315DAAA86006A99E0350A72D5D5260D6BB77AC53CDD7ABACB859586C279B7FACDF076C922AC27F3E907FB3B4EC977CA634A28DF064162165222DCCE674DAB60A4E9D48E7FCEA267ABB1F8E0A2012AA6DB532A4CE74FBAF583E2C292FA1B56BE585D14EE073CDAFE3FC0C19050E698EC41B9D27F5DB41A779208118A5D3F8F74333B2AD2FE3CEE273BBFEA485EAD817EFFEDF1260C1A125070589B6F0F31984ED498CBD273E84A718F54C82CBC2747E678F8437DDE23C9EA3C877823034B7C70731C2D01CC09D11D3364E7945B6480B9B416ACB54CD1194B46C6D2E147619AC1C1FA915AF80A5098647247EBCF0449634F69C96AFC740BCE61993228183D98D0F85406D8FFD934
HKCU\...\Run: [] - [x]
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKCU\...\Run: [Pamela.exe] - C:\Program Files (x86)\Pamela\Pamela.exe [12120064 2012-06-14] (Scendix Software-Vertriebsges. mbH)
HKCU\...\Run: [uTorrent] - C:\Program Files (x86)\uTorrent\uTorrent.exe [399736 2013-04-27] (BitTorrent, Inc.)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Run: [WOSB] - C:\Users\Alonso\Music\Playlists\Confident day.wpl [1742 2013-09-04] ()
HKCU\...\Run: [eMuleAutoStart] - C:\Program Files (x86)\eMule\emule.exe [5758976 2010-04-07] (http://www.emule-project.net)
MountPoints2: {63f25427-4351-11e0-a651-889ffad855cf} - G:\MENU.EXE
MountPoints2: {ea277ca5-635e-11e2-bc13-889ffad855cf} - E:\setup_vmc_lite.exe /checkApplicationPresence
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [UnlockerAssistant] - C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe [17408 2010-07-04] ()
HKLM-x32\...\Run: [Google Desktop Search] - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2013-05-27] (Google)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software)
AppInit_DLLs-x32: C:\PROGRA~2\GOOGLE\GOOGLE~2\GO36F4~1.DLL [123392 2013-05-27] (Google)
Startup: C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Cambridge Advanced Learner's Dictionary - 3rd Edition.lnk
ShortcutTarget: Cambridge Advanced Learner's Dictionary - 3rd Edition.lnk -> C:\Program Files (x86)\Cambridge\CALD3\cald3.exe (mozilla.org)
Startup: C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Daily Activity.xlsx.lnk
ShortcutTarget: Daily Activity.xlsx.lnk -> C:\Users\Alonso\Dropbox\Mis Documentos\Personal development\Records\Daily Activity.xlsx ()
Startup: C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Alonso\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Outlook 2007.lnk
ShortcutTarget: Microsoft Office Outlook 2007.lnk -> C:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe ()
Startup: C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk
ShortcutTarget: Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.es/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKCU - {00000000-0000-0000-0000-000000000001} URL = http://buscador-internet.com/r/search?q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=14335&babsrc=SP_ss&mntrId=5e25a3af0000000000001a659dd32694
SearchScopes: HKCU - {3686A260-184E-4E05-B178-6099FC528884} URL = http://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://safesearchr.lavasoft.com/?source=3336ca5f&tbp=rbox&toolbarid=adawaretb&u=17F0DC2EFDE0DA4B67737E50E1F01194&q={searchTerms}
SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = http://127.0.0.1:4664/search&s=dpcMDE7qp_BcV-pvmDu8sVmbOP8?q={searchTerms}
SearchScopes: HKCU - {AB79D3B4-AEDB-428a-B504-BAC00521A1C7} URL = http://www.smartwebsearch.net/index.php?from=4&q={searchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files (x86)\Common Files\Simple Adblock\SimpleAdblockx64.dll (Simple Adblock)
BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll (IDM)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files (x86)\Common Files\Simple Adblock\SimpleAdblock.dll (Simple Adblock)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 06 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 06 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.2 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{BF179810-CFDA-4DCC-AA49-A26AEAEA4BA4}: [NameServer]192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584
FF Homepage: hxxp://www.aemet.es/es/eltiempo/prediccion/municipios/madrid-id28079#reducida
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Alonso\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazon-en-GB.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\chambers-en-GB.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-en-GB.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-en-GB.xml
FF Extension: All-in-One Gestures - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
FF Extension: anticontainer - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\anticontainer@downthemall.net.xpi
FF Extension: elemhidehelper - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\elemhidehelper@adblockplus.org.xpi
FF Extension: gesture-translate - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\gesture-translate@pablocantero.com.xpi
FF Extension: linky - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\linky@gemal.dk.xpi
FF Extension: Adblock Plus - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: dta - C:\Users\Alonso\AppData\Roaming\Mozilla\Firefox\Profiles\utullvus.default-1379126482584\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM-x32\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\
FF HKLM-x32\...\Firefox\Extensions: [fe_9.0@nokia.com] - C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0
FF Extension: Firefox Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Thunderbird\Extensions: [te_9.0@nokia.com] - C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0
FF Extension: Thunderbird Address Book Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Comrade Plugin) - C:\Program Files (x86)\GameSpy\Comrade\npcomrade.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Alonso\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1
CHR Extension: (Google Drive) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1
CHR Extension: (YouTube) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1
CHR Extension: (Google Search) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1
CHR Extension: (Skype Click to Call) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.13.0.13771_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1
CHR Extension: (Gmail) - C:\Users\Alonso\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_3
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-09] (Broadcom Corporation.)
R2 BcmBtRSupport; C:\Windows\SysWow64\BtwRSupportService.exe [0 2013-09-15] ()
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 GoogleDesktopManager-051210-111108; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2013-05-27] (Google)
R3 HPSLPSVC; C:\Users\Alonso\AppData\Local\Temp\7zS0040\hpslpsvc64.dll [1039360 2013-02-06] (Hewlett-Packard Co.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
S3 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230920 2012-09-18] (Nitro PDF Software)
R2 nvsvc; C:\windows\SysWow64\nvvsvc.exe [0 2013-09-15] ()
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1444120 2013-10-17] (Trusteer Ltd.)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia)
S4 tor; C:\Program Files (x86)\Tor\tor.exe [2897422 2012-06-09] ()
S3 VSS; C:\Windows\SysWow64\vssvc.exe [0 2013-09-15] ()
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{79d9f0c7-5719-d496-ed4a-aedbeefdc39f}\   \...\???\{79d9f0c7-5719-d496-ed4a-aedbeefdc39f}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [170712 2013-08-09] (Broadcom Corporation.)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-26] (DT Soft Ltd)
S3 HP8207_8307; C:\Windows\System32\DRIVERS\HP8207_8307.sys [15360 2010-02-05] (Windows ® Win 7 DDK provider)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-04-18] (Secunia)
R1 RapportCerberus_59849; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [606672 2013-10-26] ()
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [284176 2013-10-17] (Trusteer Ltd.)
S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [317808 2013-10-17] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [399312 2013-10-17] (Trusteer Ltd.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [215168 2010-03-18] (Vimicro Corporation)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
U3 BcmSqlStartupSvc;
U2 IviRegMgr;
U2 RichVideo;
S3 rm; \??\C:\windows\system32\drivers\rm.sys [x]
S1 SBRE; \??\C:\windows\system32\drivers\SBREdrv.sys [x]
U3 SQLWriter;
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-31 00:38 - 2013-10-31 00:38 - 00000000 ____D C:\FRST
2013-10-31 00:37 - 2013-10-31 00:37 - 01956614 _____ (Farbar) C:\Users\Alonso\Desktop\FRST64.exe
2013-10-31 00:27 - 2013-10-31 00:27 - 00891172 _____ C:\Users\Alonso\Desktop\SecurityCheck.exe
2013-10-30 01:40 - 2013-10-30 01:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-24 03:04 - 2013-10-29 15:59 - 02108201 _____ C:\Users\Alonso\Desktop\attach.txt
2013-10-24 03:04 - 2013-10-29 15:50 - 00026186 _____ C:\Users\Alonso\Desktop\dds.txt
2013-10-20 00:05 - 2013-10-20 23:55 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Mp3tag
2013-10-19 17:49 - 2013-10-19 17:49 - 00000979 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-10-19 17:49 - 2013-10-19 17:49 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-10-16 17:56 - 2013-10-16 17:56 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WMV9 VCM
2013-10-16 17:56 - 2013-10-16 17:56 - 00000000 ____D C:\Program Files\WMV9_VCM
2013-10-16 17:49 - 2013-10-16 17:49 - 00000000 ____D C:\Program Files\ffdshow
2013-10-16 17:49 - 2013-06-12 21:01 - 00127488 _____ C:\windows\system32\ff_vfw.dll
2013-10-16 17:41 - 2013-10-16 17:41 - 00000000 ____D C:\Program Files (x86)\ffdshow
2013-10-16 17:41 - 2013-06-12 21:00 - 00112640 _____ C:\windows\SysWOW64\ff_vfw.dll
2013-10-04 01:22 - 2013-10-04 01:22 - 00001941 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2013-10-03 16:07 - 2013-10-03 16:07 - 00000000 ____D C:\Users\Alonso\Desktop\Trusteer
2013-10-02 21:06 - 2013-07-31 14:29 - 02312704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-10-02 21:06 - 2013-07-31 14:20 - 01346560 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-10-02 21:06 - 2013-07-31 14:19 - 01392128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-10-02 21:06 - 2013-07-31 14:18 - 01494528 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-10-02 21:06 - 2013-07-31 14:17 - 00237056 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2013-10-02 21:06 - 2013-07-31 14:16 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-10-02 21:06 - 2013-07-31 14:14 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-10-02 21:06 - 2013-07-31 14:13 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-10-02 21:06 - 2013-07-31 14:13 - 00599040 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2013-10-02 21:06 - 2013-07-31 14:11 - 02147840 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-10-02 21:06 - 2013-07-31 14:11 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-10-02 21:06 - 2013-07-31 14:09 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2013-10-02 21:06 - 2013-07-31 14:08 - 02382848 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-10-02 21:06 - 2013-07-31 14:05 - 00248320 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-10-02 21:06 - 2013-07-31 11:00 - 01800704 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-10-02 21:06 - 2013-07-31 10:53 - 01104896 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-10-02 21:06 - 2013-07-31 10:52 - 01427968 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-10-02 21:06 - 2013-07-31 10:52 - 01129472 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-10-02 21:06 - 2013-07-31 10:51 - 00231936 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2013-10-02 21:06 - 2013-07-31 10:49 - 00065024 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-10-02 21:06 - 2013-07-31 10:48 - 00717824 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-10-02 21:06 - 2013-07-31 10:48 - 00420864 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2013-10-02 21:06 - 2013-07-31 10:48 - 00142848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2013-10-02 21:06 - 2013-07-31 10:47 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-10-02 21:06 - 2013-07-31 10:46 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-10-02 21:06 - 2013-07-31 10:45 - 02382848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-10-02 21:06 - 2013-07-31 10:45 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2013-10-02 21:06 - 2013-07-31 10:42 - 00176640 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-10-02 21:05 - 2013-07-31 15:17 - 17833472 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-10-02 21:05 - 2013-07-31 14:42 - 10926080 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-10-02 21:05 - 2013-07-31 11:30 - 12335104 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-10-02 21:05 - 2013-07-31 11:05 - 09738752 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-10-02 20:51 - 2013-08-02 03:23 - 05550528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-10-02 20:51 - 2013-08-02 03:15 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-10-02 20:51 - 2013-08-02 03:15 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2013-10-02 20:51 - 2013-08-02 03:15 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-10-02 20:51 - 2013-08-02 03:15 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2013-10-02 20:51 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2013-10-02 20:51 - 2013-08-02 03:14 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2013-10-02 20:51 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2013-10-02 20:51 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:59 - 03968960 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-10-02 20:51 - 2013-08-02 02:59 - 03913664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-10-02 20:51 - 2013-08-02 02:51 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-10-02 20:51 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2013-10-02 20:51 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2013-10-02 20:51 - 2013-08-02 02:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2013-10-02 20:51 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2013-10-02 20:51 - 2013-08-02 01:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-10-02 20:51 - 2013-08-02 01:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-10-02 20:51 - 2013-08-02 01:45 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-10-02 20:51 - 2013-08-02 01:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-10-02 20:51 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-10-02 20:51 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-10-02 20:50 - 2013-08-08 02:20 - 03155456 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-10-02 20:50 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2013-10-02 20:50 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2013-10-02 20:50 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2013-10-02 20:50 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2013-10-02 20:50 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2013-10-02 09:18 - 2013-10-02 10:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)

==================== One Month Modified Files and Folders =======

2013-10-31 00:38 - 2013-10-31 00:38 - 00000000 ____D C:\FRST
2013-10-31 00:37 - 2013-10-31 00:37 - 01956614 _____ (Farbar) C:\Users\Alonso\Desktop\FRST64.exe
2013-10-31 00:37 - 2011-05-27 12:51 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Skype
2013-10-31 00:36 - 2012-03-30 14:19 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-10-31 00:27 - 2013-10-31 00:27 - 00891172 _____ C:\Users\Alonso\Desktop\SecurityCheck.exe
2013-10-31 00:27 - 2011-02-24 01:20 - 00003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{08C5E391-1C1C-4087-A30E-F5E5A1BAE117}
2013-10-31 00:22 - 2013-07-18 09:12 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\vlc
2013-10-31 00:17 - 2010-12-23 12:10 - 01272923 _____ C:\windows\WindowsUpdate.log
2013-10-31 00:16 - 2011-02-24 03:03 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\uTorrent
2013-10-31 00:03 - 2011-02-26 14:22 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-30 23:49 - 2013-05-15 17:39 - 00000000 ____D C:\Users\Alonso\AppData\Local\Axialis
2013-10-30 22:32 - 2012-07-22 19:27 - 00000932 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-798888835-4293828314-1819521154-1001UA.job
2013-10-30 22:31 - 2013-08-07 17:49 - 00994040 _____ C:\windows\setupact.log
2013-10-30 19:32 - 2012-07-22 19:27 - 00000910 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-798888835-4293828314-1819521154-1001Core.job
2013-10-30 19:03 - 2011-02-26 14:22 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-30 15:45 - 2009-07-14 05:45 - 00022464 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-30 15:45 - 2009-07-14 05:45 - 00022464 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-30 15:39 - 2012-04-25 19:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-30 15:39 - 2009-07-14 06:13 - 00805540 _____ C:\windows\system32\PerfStringBackup.INI
2013-10-30 15:38 - 2012-06-22 16:40 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Dropbox
2013-10-30 15:37 - 2012-06-22 19:52 - 00000000 ___RD C:\Users\Alonso\Dropbox
2013-10-30 15:33 - 2010-12-23 12:31 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-30 15:33 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-10-30 01:40 - 2013-10-30 01:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-29 16:10 - 2012-03-10 04:34 - 00020480 ___SH C:\Users\Alonso\Thumbs.db
2013-10-29 15:59 - 2013-10-24 03:04 - 02108201 _____ C:\Users\Alonso\Desktop\attach.txt
2013-10-29 15:50 - 2013-10-24 03:04 - 00026186 _____ C:\Users\Alonso\Desktop\dds.txt
2013-10-29 01:27 - 2011-03-12 01:46 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Nokia
2013-10-28 15:49 - 2013-05-25 14:00 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\MediaMonkey
2013-10-27 01:59 - 2012-12-19 07:35 - 00000000 ____D C:\Users\Alonso\Downloads\Completed eMule
2013-10-26 20:02 - 2011-08-04 00:14 - 00000000 ____D C:\Program Files\MyDefrag v4.3.1
2013-10-25 18:34 - 2013-04-28 20:08 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Nitro
2013-10-23 01:41 - 2011-02-28 01:51 - 00000000 ____D C:\X
2013-10-20 23:55 - 2013-10-20 00:05 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Mp3tag
2013-10-20 09:16 - 2013-09-19 04:32 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-10-20 09:13 - 2012-12-31 18:38 - 00033424 _____ C:\windows\PFRO.log
2013-10-19 17:49 - 2013-10-19 17:49 - 00000979 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2013-10-19 17:49 - 2013-10-19 17:49 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-10-19 14:48 - 2013-05-25 14:00 - 00001043 _____ C:\Users\Public\Desktop\MediaMonkey.lnk
2013-10-19 14:48 - 2013-05-25 14:00 - 00000000 ____D C:\Program Files (x86)\MediaMonkey
2013-10-19 14:48 - 2011-09-28 16:18 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media
2013-10-18 03:05 - 2013-05-17 16:30 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-17 14:05 - 2011-03-11 23:31 - 00317808 _____ (Trusteer Ltd.) C:\windows\system32\Drivers\RapportKE64.sys
2013-10-16 18:45 - 2011-04-24 20:48 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\avidemux
2013-10-16 17:56 - 2013-10-16 17:56 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WMV9 VCM
2013-10-16 17:56 - 2013-10-16 17:56 - 00000000 ____D C:\Program Files\WMV9_VCM
2013-10-16 17:49 - 2013-10-16 17:49 - 00000000 ____D C:\Program Files\ffdshow
2013-10-16 17:41 - 2013-10-16 17:41 - 00000000 ____D C:\Program Files (x86)\ffdshow
2013-10-15 07:02 - 2011-05-27 12:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-15 07:02 - 2011-02-26 14:22 - 00000000 ____D C:\ProgramData\Skype
2013-10-10 20:45 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF
2013-10-09 12:36 - 2012-03-30 14:19 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 12:36 - 2012-03-30 14:19 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 12:36 - 2011-05-21 12:57 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-07 06:57 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2013-10-06 01:27 - 2013-08-12 05:54 - 00000000 ____D C:\Users\Alonso\AppData\Roaming\Awesome Duplicate Photo Finder
2013-10-05 17:58 - 2011-02-26 14:22 - 00003894 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-05 17:58 - 2011-02-26 14:22 - 00003642 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-04 01:22 - 2013-10-04 01:22 - 00001941 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2013-10-04 01:22 - 2012-02-11 19:44 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
2013-10-04 00:51 - 2011-02-24 01:15 - 00092312 _____ C:\Users\Alonso\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-04 00:48 - 2009-07-14 05:45 - 00375320 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-04 00:03 - 2011-02-28 01:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-04 00:00 - 2012-06-01 02:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2013-10-03 23:53 - 2009-07-29 08:23 - 00000000 ____D C:\windows\ShellNew
2013-10-03 23:52 - 2009-07-14 03:34 - 00000478 _____ C:\windows\win.ini
2013-10-03 16:07 - 2013-10-03 16:07 - 00000000 ____D C:\Users\Alonso\Desktop\Trusteer
2013-10-03 13:07 - 2010-12-23 12:48 - 00000000 ____D C:\Program Files\DIFX
2013-10-03 13:05 - 2013-03-19 03:37 - 00026136 _____ C:\windows\DPINST.LOG
2013-10-03 13:00 - 2011-02-28 00:54 - 00000000 ____D C:\Program Files (x86)\Nokia
2013-10-03 12:44 - 2011-11-13 14:28 - 00000000 ____D C:\Program Files (x86)\Oxford
2013-10-03 11:59 - 2011-04-26 23:29 - 00000000 ____D C:\Users\Alonso\Documents\iZotope RX 2 Presets
2013-10-03 11:59 - 2011-04-23 02:16 - 00000000 ____D C:\Program Files (x86)\iZotope
2013-10-03 11:35 - 2011-03-29 03:18 - 00000000 ____D C:\Program Files (x86)\GNU
2013-10-03 11:32 - 2013-09-21 20:59 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-03 10:44 - 2011-03-01 14:26 - 00000000 ____D C:\Users\Alonso\AppData\Local\GameSpy
2013-10-02 23:31 - 2011-08-04 23:07 - 00000000 ____D C:\ProgramData\DivX
2013-10-02 23:25 - 2011-04-21 22:48 - 00000000 ____D C:\Program Files (x86)\eMule
2013-10-02 21:50 - 2011-02-24 01:14 - 00000000 ___RD C:\Users\Alonso\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-02 21:25 - 2013-09-03 06:51 - 00000000 ____D C:\windows\system32\MRT
2013-10-02 21:11 - 2011-02-24 20:47 - 79143768 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-10-02 10:27 - 2013-10-02 09:18 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-10-02 09:08 - 2013-09-15 23:55 - 00000000 ____D C:\ProgramData\COMODO
2013-10-02 08:49 - 2009-07-14 04:20 - 00000000 ____D C:\windows\L2Schemas
2013-10-01 23:35 - 2012-12-15 18:00 - 00000000 ____D C:\ProgramData\AVG2013
2013-10-01 23:35 - 2012-12-15 17:56 - 00000000 ____D C:\Users\Alonso\AppData\Local\Avg2013
2013-10-01 23:35 - 2012-06-10 00:33 - 00000000 ___HD C:\$AVG
2013-10-01 23:35 - 2012-06-10 00:19 - 00000000 ____D C:\ProgramData\MFAData
2013-10-01 05:20 - 2013-01-02 07:29 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-01 05:20 - 2013-01-02 07:29 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

Files to move or delete:
====================
ZeroAccess:
C:\Users\Alonso\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install


Some content of TEMP:
====================
C:\Users\Alonso\AppData\Local\Temp\CheckLockedWsFiles.exe
C:\Users\Alonso\AppData\Local\Temp\msvcp80.dll
C:\Users\Alonso\AppData\Local\Temp\msvcr80.dll
C:\Users\Alonso\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Alonso\AppData\Local\Temp\setup.exe
C:\Users\Alonso\AppData\Local\Temp\uninstall.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-21 19:07

==================== End Of Log ============================

 

 

Addition

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-10-2013
Ran by Alonso at 2013-10-31 00:40:46
Running from C:\Users\Alonso\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

 Update for Microsoft Office 2007 (KB2508958) (x32)
µTorrent (x32 Version: 2.2.1)
64 Bit HP CIO Components Installer (Version: 6.2.1)
AAC ACM Codec x64 1.8 (Version: 1.8)
ACDSee Photo Manager 12 (x32 Version: 12.0.344)
Adobe AIR (x32 Version: 3.7.0.2090)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader X (10.1.8) (x32 Version: 10.1.8)
Audacity 2.0.3 (x32 Version: 2.0.3)
avast! Free Antivirus (x32 Version: 8.0.1497.0)
Avidemux 2.6 (32-bit) (x32 Version: 2.6.4.8696)
Avidemux 2.6 (x32 Version: 2.6.0.8164)
BPDSoftware (x32 Version: 82.0.173.000)
BPDSoftware_Ini_CCR_Vista (x32 Version: 1.00.0000)
BUG Mod 4.4 (x32)
Cambridge Advanced Learner's Dictionary - 3rd Edition (x32)
CCleaner (Version: 4.05)
CDBurnerXP (x32 Version: 4.5.2.4291)
Conan 1.1.1 (x32 Version: 1.1.1)
Conexant HD Audio (Version: 4.111.0.62)
D3DX10 (x32 Version: 15.4.2368.0902)
DAEMON Tools Lite (x32 Version: 4.47.1.0333)
Dropbox (HKCU Version: 2.0.22)
Duplicate Cleaner 2.1b (x32 Version: 2.1b)
eMule (x32)
Energy Management (x32 Version: 5.4.1.9)
ETDWare PS/2-x64 7.0.4.18_WHQL (Version: 7.0.4.18)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
ffdshow v1.3.4515 [2013-06-12] (x32 Version: 1.3.4515.0)
ffdshow x64 v1.3.4515 [2013-06-12] (Version: 1.3.4515.0)
FFmpeg for Audacity on Windows (x32)
Fraps (x32)
Free YouTube Downloader 3.5.134 (x32)
GOM Player (x32 Version: 2.2.53.5169)
Google Chrome (x32 Version: 30.0.1599.101)
Google Desktop (x32 Version: 5.9.1005.12335)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
HP Officejet Pro K5400/K5300 Series Toolbox (Version: 13.0)
Intel® Control Center (x32 Version: 1.2.1.1007)
Intel® Management Engine Components (x32 Version: 6.0.0.1179)
Intel® Rapid Storage Technology (x32 Version: 9.6.0.1014)
Intel® Turbo Boost Technology Driver (x32 Version: 01.02.00.1002)
Java 7 Update 25 (64-bit) (Version: 7.0.250)
Java 7 Update 25 (x32 Version: 7.0.250)
Java SE Development Kit 7 Update 25 (64-bit) (Version: 1.7.0.250)
JavaFX 2.1.1 (x32 Version: 2.1.1)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
LAME v3.98.3 for Audacity (x32)
Lenovo Bluetooth with Enhanced Data Rate Software (Version: 6.2.1.100)
Lenovo EasyCamera (x32 Version: 1.10.0415.1)
Lenovo OneKey Recovery (Version: 7.0.1230)
Lenovo OneKey Recovery (x32 Version: 7.0.1230)
Lenovo ReadyComm 5 (x32 Version: 5.1.1.20)
Lenovo ReadyComm 5.0 Service (x32 Version: 5.0.0.1)
Lenovo_Wireless_Driver (x32 Version: 1.02.01)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300)
MediaMonkey 4.0 (x32 Version: 4.0)
Mesh Runtime (x32 Version: 15.4.5722.2)
MetFileRegenerator v3.0.16 (x32 Version: 3.0.16)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook Connector (x32 Version: 14.0.6123.5001)
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Windows Media Video 9 VCM (x32)
Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1)
Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1)
Mozilla Firefox 25.0 (x86 en-GB) (x32 Version: 25.0)
Mozilla Maintenance Service (x32 Version: 25.0)
Mp3tag v2.58 (x32 Version: v2.58)
MSVC80_x64_v2 (Version: 1.0.3.0)
MSVC80_x86_v2 (x32 Version: 1.0.3.0)
MSVC90_x64 (Version: 1.0.1.2)
MSVC90_x86 (x32 Version: 1.0.1.2)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
MyDefrag v4.3.1 (Version: 4.0.0.0)
Nitro Pro 8 (Version: 8.0.2.4)
Nokia Connectivity Cable Driver (Version: 7.1.32.69)
Nokia PC Suite (x32 Version: 7.1.60.0)
Nokia Suite (x32 Version: 3.3.89.0)
Notepad++ (x32 Version: 5.9)
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19)
NVIDIA 3D Vision Controller Driver 314.22 (Version: 314.22)
NVIDIA 3D Vision Driver 314.22 (Version: 314.22)
NVIDIA Control Panel 314.22 (Version: 314.22)
NVIDIA GeForce Experience 1.1 (Version: 1.1)
NVIDIA Graphics Driver 314.22 (Version: 314.22)
NVIDIA HD Audio Driver 1.3.23.1 (Version: 1.3.23.1)
NVIDIA Install Application (Version: 2.1002.115.744)
NVIDIA PhysX (x32 Version: 9.12.1031)
NVIDIA PhysX System Software 9.12.1031 (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1422)
NVIDIA Update 3.10.8 (Version: 3.10.8)
NVIDIA Update Components (Version: 3.10.8)
Oblivion - Knights of the Nine (x32 Version: 1.00.0000)
Oblivion - Spell Tomes (x32 Version: 1.00.0000)
Oblivion mod manager 1.1.12 (x32)
Onekey Theater (x32 Version: 2.0.1.8)
OpenSubtitlesPlayer V4.X (x32)
Pamela Pro 4.8 (x32 Version: 4.8)
PC Connectivity Solution (x32 Version: 11.5.29.0)
ProductContext (x32 Version: 130.0.000.000)
QUICKfind server v1.1 (x32)
Rapport (Version: 3.5.1205.20)
Rapport (x32 Version: 3.5.1304.13)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.18.322.2010)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30116)
Secunia PSI (3.0.0.7009) (x32 Version: 3.0.0.7009)
Sid Meier's Civilization 4 - Beyond the Sword (x32 Version: 3.19)
Sid Meier's Civilization 4 - Warlords (x32 Version: 2.13)
Sid Meier's Civilization 4 (x32 Version: 1.00.0000)
Sid Meier's Civilization 4 (x32 Version: 1.74)
Simple Adblock (x32 Version: 1.1.5)
Skype Click to Call (x32 Version: 6.13.13771)
Skype™ 6.9 (x32 Version: 6.9.106)
SpeedFan (remove only) (x32)
Subtitle Edit v3.1 (x32 Version: 3.1)
Susan Jeffers Affirmations Screensaver (x32)
TMPGEnc 4.0 XPress (x32 Version: 4.2.3.193)
Toolbox (x32 Version: 130.0.648.000)
Trusteer Endpoint Protection (x32 Version: 3.5.1304.13)
Ultimate Reference Suite (x32 Version: 2011.0.0.0)
Unlocker 1.9.1-x64 (Version: 1.9.1)
Unofficial Oblivion Patch v3.2.0 (x32 Version: 3.2.0)
Unofficial Shivering Isles Patch v1.5.0 (x32 Version: 1.5.0)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Access 2007 Help (KB963663) (x32)
Update for Microsoft Office Excel 2007 Help (KB963678) (x32)
Update for Microsoft Office Infopath 2007 Help (KB963662) (x32)
Update for Microsoft Office OneNote 2007 Help (KB963670) (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825641) 32-Bit Edition (x32)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update for Microsoft Office Publisher 2007 Help (KB963667) (x32)
Update for Microsoft Office Script Editor Help (KB963671) (x32)
Update for Microsoft Office Word 2007 Help (KB963665) (x32)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Visual C++ 2008 x86 Runtime - (v9.0.30729) (x32 Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (x32 Version: 9.0.30729.01)
Visual Similarity Duplicate Image Finder Corporate 4.2.0.1 (x32 Version: 4.2.0.1)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
VLC media player 2.0.8 (x32 Version: 2.0.8)
WhiteSmoke (x32 Version: 1.00.6023)
Winamp (x32 Version: 5.63 )
WinDirStat 1.1.2 (HKCU)
Windows Driver Package - Broadcom Bluetooth  (06/15/2009 6.2.0.9000) (Version: 06/15/2009 6.2.0.9000)
Windows Driver Package - Broadcom Bluetooth  (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800)
Windows Driver Package - Lenovo (ACPIVPC) System  (10/19/2009 5.4.0.1) (Version: 10/19/2009 5.4.0.1)
Windows Driver Package - Nokia Modem  (10/07/2010 4.6) (Version: 10/07/2010 4.6)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
WinMerge 2.12.4 (x32 Version: 2.12.4)
WinRAR archiver
YTD Video Downloader 4.3 (x32 Version: 4.3)

==================== Restore Points  =========================

27-10-2013 17:20:02 Scheduled Checkpoint

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {080CFD1B-1D42-4AD1-9C02-39A5F23CC75E} - System32\Tasks\{056B2056-B4CD-46D0-9FA6-3FAE5A4B6B12} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {0C11F8EE-DF04-4D63-A15A-D3F48518496D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-26] (Google Inc.)
Task: {1117F3DA-40F6-469F-B907-4FA7769E3283} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {163C8C5A-F3BF-430E-81DE-A1E41BADEC98} - System32\Tasks\{A572B833-B960-4D79-BAEF-B702BBFBB066} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {2717A768-2D9C-4393-AE68-5D9470D69A20} - System32\Tasks\{80577AD7-7743-4856-8D39-545C87FE6F9E} => C:\Program Files (x86)\NCH Software\Scribe\scribe.exe
Task: {3233F746-E153-435C-8BE0-C866011343E8} - System32\Tasks\Alarm => C:\Users\Alonso\Music\Budista\Chanting Of Gayatri Mantra.mp3
Task: {41684244-B5EE-443F-942D-513D3426F137} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {4FED4EB0-FD39-49E5-89D6-B53AE3D350EE} - System32\Tasks\{9119DB28-C4C9-4795-A349-66C388D0E93E} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {53761AF8-268E-47E3-8F6A-A79203EA3E4B} - System32\Tasks\{081CB4AB-9BAD-4E34-A333-4F484C693E06} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {53B0F216-B184-4A27-BEC5-06BE58401FB4} - System32\Tasks\uTorrent => C:\Program Files (x86)\uTorrent\uTorrent.exe [2013-04-27] (BitTorrent, Inc.)
Task: {5681F00E-9524-4937-9AAA-0DA7ECCA3F4F} - System32\Tasks\{DEFD2FAD-6FC3-46DA-9820-7B717BA8D6C7} => F:\cda\CDARGUI.EXE
Task: {5BE20E2D-3B89-4DAB-A039-8E9884170812} - System32\Tasks\{681B5057-C76D-490C-9DBA-BAFC44EBEEEA} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.105/en/abandoninstall?source=lightinstaller&amp;page=tsMain
Task: {6514F645-FA4E-4026-9476-86F0799867AF} - System32\Tasks\{675EE961-4327-4B8C-8B46-3C39D6CED0CB} => F:\cda\CDARGUI.EXE
Task: {69018B25-8803-41F8-9812-F903518B2CD7} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {725AF9BD-D18E-491C-B765-9B55F7DEF899} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {747C6F9E-A869-4FF8-AD30-2D2EA741A7D1} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {793270F4-DF2C-4C6B-A41D-516CD1F0F6BC} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
Task: {7AD83815-C1E4-41BB-9DF0-0584011E5DF9} - System32\Tasks\{DEE2453F-9B96-4F53-B611-B92913A422C0} => C:\Program Files (x86)\NCH Software\Scribe\scribe.exe
Task: {82D62938-E728-4241-974D-456CF89BEC13} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {9D346C50-4D7A-4578-93FA-813BA398D97E} - System32\Tasks\{396C4D5E-5A26-4F33-A312-7F5DE7496F95} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {9FDDB9BE-2561-48AF-AB03-376A8976D5DA} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-798888835-4293828314-1819521154-1001UA => C:\Users\Alonso\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-22] (Facebook Inc.)
Task: {A257351F-F4E8-47E6-9B71-79C190E08E43} - System32\Tasks\Cell phone backup => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-02-01] (Nokia)
Task: {A25D72C3-548A-44BF-8102-FB07E11706B6} - System32\Tasks\{983E8E56-9C72-46F7-BEFA-EE6191CC2D41} => C:\Program Files (x86)\Microsoft Games\Age of Empires III\age3.exe
Task: {A2C4B680-005C-4EB6-BC42-DF15EF915692} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
Task: {AD68E83B-E132-441C-BCFF-76249D940166} - System32\Tasks\{FB733FFA-E83E-47E1-95A4-A00F143B4763} => C:\Programs\Video\Tools\Mpg2Cut2_B418\Mpg2Cut2.exe
Task: {B5B2F86B-21C0-43CF-8BC2-E88094D4E728} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-26] (Google Inc.)
Task: {B88CAACD-694B-4E67-93DD-C48E5D3333A9} - System32\Tasks\{52F635DC-B325-48F0-A6C4-AFA855EAD626} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {C4DA9F47-1A3D-4B82-8B22-6659279B7F18} - System32\Tasks\{96A229B4-3B49-4FBB-A75D-11EDF8B6791B} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-10-02] (Skype Technologies S.A.)
Task: {C575BEC8-909E-43C9-A3EF-47FA2D99BF0A} - System32\Tasks\{C289C6CB-327F-4B28-B807-6BA4BC797BB5} => C:\Program Files (x86)\Microsoft Games\Age of Empires III\age3.exe
Task: {D3D145B1-AF43-493A-B026-B66494C0DEE4} - System32\Tasks\{D70D785F-8924-4084-8BAE-5B867984D219} => C:\Program Files (x86)\Europress\Musicolour\MusiColour.exe
Task: {E9031C26-51FB-4C5D-AC7E-D1B83A1D53F8} - System32\Tasks\{D2F4A4C4-83C7-4D1A-8D66-BEDAE1B89ADD} => C:\Programs\Video\Tools\Mpg2Cut2_B418\Mpg2Cut2.exe
Task: {ED1ABB02-CEF4-4EF9-B29E-590BD0EE3295} - System32\Tasks\{5E62BF6E-10A0-4DE2-B478-5EE364CD6281} => C:\Program Files (x86)\Microsoft Games\Age of Empires III\age3.exe
Task: {F7568E94-6E91-4581-B4B5-1B29F5921B52} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {F8E5D60D-4DC7-4690-97B0-64DEF1C5850E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-798888835-4293828314-1819521154-1001Core => C:\Users\Alonso\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-22] (Facebook Inc.)
Task: {FE5C1756-1A60-4FBB-ADF7-BA4F78B89124} - System32\Tasks\Disk Cleanup => C:\Windows\System32\cleanmgr.exe [2009-07-14] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-798888835-4293828314-1819521154-1001Core.job => C:\Users\Alonso\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-798888835-4293828314-1819521154-1001UA.job => C:\Users\Alonso\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-07-19 01:54 - 2009-12-19 01:52 - 00201120 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect64.dll
2013-07-19 01:54 - 2009-12-19 01:53 - 00156576 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll64.dll
2009-08-11 15:59 - 2009-08-11 15:59 - 00173344 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll
2010-07-15 05:44 - 2010-07-15 05:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2011-02-24 06:47 - 2010-03-15 12:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2011-02-09 01:56 - 2011-02-09 01:56 - 00301568 _____ () C:\Program Files (x86)\Notepad++\NppShell_04.dll
2010-12-23 13:11 - 2009-07-15 16:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2010-12-23 13:11 - 2009-07-15 16:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2012-03-11 13:53 - 2013-10-26 09:53 - 01127152 _____ () C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportMS.dll
2013-10-30 19:35 - 2013-10-30 15:43 - 02107392 _____ () C:\Program Files\AVAST Software\Avast\defs\13103000\algo.dll
2012-06-27 14:09 - 2012-06-27 14:09 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
2013-07-19 01:54 - 2009-12-19 01:50 - 00161696 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll
2013-07-19 01:54 - 2009-12-19 01:51 - 00133024 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll
2010-07-04 22:32 - 2010-07-04 22:32 - 00004608 _____ () C:\Program Files (x86)\Unlocker\UnlockerHook.dll
2012-11-09 17:04 - 2012-11-09 17:04 - 00053760 _____ () C:\Program Files (x86)\Pamela\zlib.dll
2013-05-27 04:56 - 2013-05-27 04:57 - 00034816 _____ () C:\Program Files (x86)\Google\Google Desktop Search\gzlib.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00147456 _____ () C:\Program Files (x86)\Cambridge\CALD3\components\gkwidget.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00512120 _____ () C:\Program Files (x86)\Cambridge\CALD3\smpeg.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00229376 _____ () C:\Program Files (x86)\Cambridge\CALD3\SDL.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00061440 _____ () C:\Program Files (x86)\Cambridge\CALD3\skcore.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00061440 _____ () C:\Program Files (x86)\Cambridge\CALD3\skcomponents\skfindbecursor.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00094208 _____ () C:\Program Files (x86)\Cambridge\CALD3\skfind.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00110592 _____ () C:\Program Files (x86)\Cambridge\CALD3\skcomponents\skfindbenative.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00053248 _____ () C:\Program Files (x86)\Cambridge\CALD3\skcomponents\unicodesimplifier.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00081920 _____ () C:\Program Files (x86)\Cambridge\CALD3\skfindfefs.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00020480 _____ () C:\Program Files (x86)\Cambridge\CALD3\skspell.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00700416 _____ () C:\Program Files (x86)\Cambridge\CALD3\ASpell6Dynamic.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00061440 _____ () C:\Program Files (x86)\Cambridge\CALD3\skfindhiliter.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00094208 _____ () C:\Program Files (x86)\Cambridge\CALD3\skfindfeindex.dll
2008-09-25 08:18 - 2008-09-25 08:18 - 00118784 _____ () C:\Program Files (x86)\Cambridge\CALD3\skfindfewordlist.dll
2013-09-04 02:59 - 2013-09-04 02:59 - 00170496 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\44bfa824a3b8a6f789fda79a2e01a8db\IsdiInterop.ni.dll
2010-12-23 12:22 - 2010-03-03 21:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Alonso\AppData\Roaming\Dropbox\bin\libcef.dll
2013-07-10 17:07 - 2013-07-10 17:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
2013-10-30 01:40 - 2013-10-30 01:40 - 03368048 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\Users\Alonso\AppData\Roaming\Comma Separated Values (Windows).EML:OECustomProperty
AlternateDataStreams: C:\Users\Alonso\AppData\Roaming\Microsoft Excel 97-2003.EML:OECustomProperty
AlternateDataStreams: C:\Users\Alonso\AppData\Roaming\Tab Separated Values (Windows).EML:OECustomProperty

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============

Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/30/2013 11:54:02 PM) (Source: Windows Search Service) (User: )
Description: The index cannot be initialized.


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:02 PM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:02 PM) (Source: Windows Search Service) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:02 PM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:01 PM) (Source: Windows Search Service) (User: )
Description: The index cannot be initialized.


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:01 PM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:01 PM) (Source: Windows Search Service) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:01 PM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:01 PM) (Source: Windows Search Service) (User: )
Description: The index cannot be initialized.


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)

Error: (10/30/2013 11:54:01 PM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
    The system cannot find the file specified.  (HRESULT : 0x80070002) (0x80070002)


System errors:
=============
Error: (10/31/2013 00:41:35 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 6294 time(s).

Error: (10/31/2013 00:41:35 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with the following error:
%%2

Error: (10/31/2013 00:41:34 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 6293 time(s).

Error: (10/31/2013 00:41:34 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with the following error:
%%2

Error: (10/31/2013 00:41:33 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 6292 time(s).

Error: (10/31/2013 00:41:33 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with the following error:
%%2

Error: (10/31/2013 00:41:32 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 6291 time(s).

Error: (10/31/2013 00:41:32 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with the following error:
%%2

Error: (10/31/2013 00:41:01 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 6290 time(s).

Error: (10/31/2013 00:41:01 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with the following error:
%%2


Microsoft Office Sessions:
=========================
Error: (01/01/2013 08:58:57 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 171 seconds with 120 seconds of active time.  This session ended with a crash.

Error: (12/06/2012 09:17:26 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 152 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (11/03/2012 10:12:08 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 147 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (08/08/2012 02:14:44 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 27280 seconds with 2220 seconds of active time.  This session ended with a crash.

Error: (03/06/2012 07:36:15 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 24 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (08/16/2011 11:00:39 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 17580 seconds with 5820 seconds of active time.  This session ended with a crash.

Error: (05/25/2011 05:19:22 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 25086 seconds with 1260 seconds of active time.  This session ended with a crash.

Error: (05/09/2011 11:06:11 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7087 seconds with 7020 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2012-12-17 04:07:37.064
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:07:37.034
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:07:36.994
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:07:36.964
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:04:00.180
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:04:00.150
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:04:00.120
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2012-12-17 04:04:00.090
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Unlocker\UnlockerDriver5.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Percentage of memory in use: 69%
Total physical RAM: 3958.85 MB
Available physical RAM: 1224.18 MB
Total Pagefile: 7915.89 MB
Available Pagefile: 4760.77 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:421.81 GB) (Free:15.31 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:18.09 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: B5BF3EAE)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=422 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=15 GB) - (Type=12)

==================== End Of Log ============================



#6 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:06:16 AM

Posted 01 November 2013 - 05:17 AM

Hey Alonshow, :)

 

Please go to logo.gif
Browse to the following file paths in the "Suspicious files to scan" field on the top of the page:

C:\windows\SysWow64\nvvsvc.exe
C:\Windows\SysWow64\vssvc.exe


Click on the Upload button
If a pop-up appears saying the file has been scanned already, please select the ReScan button.
Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
Paste the contents of the Clipboard in your next reply.


Best Regards,
oneof4.


#7 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 01 November 2013 - 05:20 PM

Hi, oneof4, thank you for your support. I tried to follow your directions, but when I select the file and clic "Upload", I receive an error message: "ERROR: Can't find upload file!". This happens for both files. I have tried using Firefox, Chrome and IE, and received the same error in all cases.



#8 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:06:16 AM

Posted 01 November 2013 - 07:33 PM

Hi :)

 

Not to worry, it's not surprising that they didn't show up, so let's move forward:

 

Download attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

Also, update me on how your system is performing after running the fix.

Attached Files


Best Regards,
oneof4.


#9 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 02 November 2013 - 02:07 AM

I have run FRST and checked again the problems reported.

 

I have noticed improvement when using Notepad++. Now it starts quickly.

 

The following problems persist: sfc /scannow returns an error message. WakeUpOnStandBy can’t wake up the PC from hibernation.

 

It will take some more time to determine if the problems with the event viewer and the system tray persist.

 

Also, I have just noticed another problem: The Outlook search doesn’t work.

 

These are the contents of fixlog.txt:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-10-2013
Ran by Alonso at 2013-11-02 03:16:00 Run:1
Running from C:\Users\Alonso\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKLM\...\Policies\Explorer: [3212083974]
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
MountPoints2: {63f25427-4351-11e0-a651-889ffad855cf} - G:\MENU.EXE
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKCU - {00000000-0000-0000-0000-000000000001} URL = http://buscador-internet.com/r/search?q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=14335&babsrc=SP_ss&mntrId=5e25a3af0000000000001a659dd32694
SearchScopes: HKCU - {70D46D94-BF1E-45ED-B567-48701376298E} URL = http://127.0.0.1:4664/search&s=dpcMDE7qp_BcV-pvmDu8sVmbOP8?q={searchTerms}
SearchScopes: HKCU - {AB79D3B4-AEDB-428a-B504-BAC00521A1C7} URL = http://www.smartwebsearch.net/index.php?from=4&q={searchTerms}
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
SearchScopes: HKCU - {AB79D3B4-AEDB-428a-B504-BAC00521A1C7} URL = http://www.smartwebsearch.net/index.php?from=4&q={searchTerms}
BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 06 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 06 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
R2 nvsvc; C:\windows\SysWow64\nvvsvc.exe [0 2013-09-15] ()
S3 VSS; C:\Windows\SysWow64\vssvc.exe [0 2013-09-15] ()
U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{79d9f0c7-5719-d496-ed4a-aedbeefdc39f}\   \...\???\{79d9f0c7-5719-d496-ed4a-aedbeefdc39f}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
2013-10-23 01:41 - 2011-02-28 01:51 - 00000000 ____D C:\X
ZeroAccess:
C:\Users\Alonso\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install
C:\Users\Alonso\AppData\Local\Temp\CheckLockedWsFiles.exe
C:\Users\Alonso\AppData\Local\Temp\msvcp80.dll
C:\Users\Alonso\AppData\Local\Temp\msvcr80.dll
C:\Users\Alonso\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Alonso\AppData\Local\Temp\setup.exe
C:\Users\Alonso\AppData\Local\Temp\uninstall.exe
Task: {5681F00E-9524-4937-9AAA-0DA7ECCA3F4F} - System32\Tasks\{DEFD2FAD-6FC3-46DA-9820-7B717BA8D6C7} => F:\cda\CDARGUI.EXE
Task: {6514F645-FA4E-4026-9476-86F0799867AF} - System32\Tasks\{675EE961-4327-4B8C-8B46-3C39D6CED0CB} => F:\cda\CDARGUI.EXE
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\Users\Alonso\AppData\Roaming\Comma Separated Values (Windows).EML:OECustomProperty
AlternateDataStreams: C:\Users\Alonso\AppData\Roaming\Microsoft Excel 97-2003.EML:OECustomProperty
AlternateDataStreams: C:\Users\Alonso\AppData\Roaming\Tab Separated Values (Windows).EML:OECustomProperty
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\3212083974 => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update* => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{63f25427-4351-11e0-a651-889ffad855cf} => Key deleted successfully.
HKCR\CLSID\{63f25427-4351-11e0-a651-889ffad855cf} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{00000000-0000-0000-0000-000000000001} => Key deleted successfully.
HKCR\CLSID\{00000000-0000-0000-0000-000000000001} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully.
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} => Key deleted successfully.
HKCR\CLSID\{70D46D94-BF1E-45ED-B567-48701376298E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7} => Key deleted successfully.
HKCR\CLSID\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7} => Key not found.
HKCR\PROTOCOLS\Handler\linkscanner => Key deleted successfully.
HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7} => Key not found.
HKCR\CLSID\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} => Key deleted successfully.
HKCR\PROTOCOLS\Handler\linkscanner => Key not found.
HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\linkscanner => Key not found.
HKCR\Wow6432Node\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key not found.
Winsock: Catalog5 entry 000000000001\\LibraryPath  was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5 entry 000000000006\\LibraryPath  was set successfully to %SystemRoot%\System32\mswsock.dll
Winsock: Catalog5-x64 entry 000000000001\\LibraryPath  was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5-x64 entry 000000000006\\LibraryPath  was set successfully to %SystemRoot%\System32\mswsock.dll
nvsvc => Service deleted successfully.
VSS => Service deleted successfully.
*etadpug => Service deleted successfully.
C:\X => Moved successfully.
C:\Users\Alonso\AppData\Local\Google\Desktop\Install => Moved successfully.
C:\Program Files (x86)\Google\Desktop\Install => Moved successfully.
C:\Users\Alonso\AppData\Local\Temp\CheckLockedWsFiles.exe => Moved successfully.
C:\Users\Alonso\AppData\Local\Temp\msvcp80.dll => Moved successfully.
C:\Users\Alonso\AppData\Local\Temp\msvcr80.dll => Moved successfully.
C:\Users\Alonso\AppData\Local\Temp\NOSEventMessages.dll => Moved successfully.
C:\Users\Alonso\AppData\Local\Temp\setup.exe => Moved successfully.
C:\Users\Alonso\AppData\Local\Temp\uninstall.exe => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5681F00E-9524-4937-9AAA-0DA7ECCA3F4F} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5681F00E-9524-4937-9AAA-0DA7ECCA3F4F} => Key deleted successfully.
C:\Windows\System32\Tasks\{DEFD2FAD-6FC3-46DA-9820-7B717BA8D6C7} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DEFD2FAD-6FC3-46DA-9820-7B717BA8D6C7} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6514F645-FA4E-4026-9476-86F0799867AF} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6514F645-FA4E-4026-9476-86F0799867AF} => Key deleted successfully.
C:\Windows\System32\Tasks\{675EE961-4327-4B8C-8B46-3C39D6CED0CB} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{675EE961-4327-4B8C-8B46-3C39D6CED0CB} => Key deleted successfully.
C:\Windows => ":nlsPreferences" ADS removed successfully.
C:\ProgramData\Temp => ":D1B5B4F1" ADS removed successfully.
C:\Users\Alonso\AppData\Roaming\Comma Separated Values (Windows).EML => ":OECustomProperty" ADS removed successfully.
C:\Users\Alonso\AppData\Roaming\Microsoft Excel 97-2003.EML => ":OECustomProperty" ADS removed successfully.
C:\Users\Alonso\AppData\Roaming\Tab Separated Values (Windows).EML => ":OECustomProperty" ADS removed successfully.


The system needs a manual reboot.

==== End of Fixlog ====



#10 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 02 November 2013 - 02:14 AM

One more thing: FRST has had an undesired side effect. It has quarantined the folder C:\X. This is a legitimate folder, I created it.



#11 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 02 November 2013 - 10:16 AM

I just found out that WakeUpOnStandby is properly waking the system from hibernation. Last night I hadn't tested it properly. Therefore, the current summary of the situation is:

  • Problems solved:
    • Notepad++ starts slowly.
    • WakeUpOnStandBy doesn’t wake the PC from hibernation.
  • Problems not solved:
    • sfc /scannow returns an error message.
    • The Outlook search doesn’t work.
  • Problems that need more time to determine if they are solved:
    • The event viewer only shows the more recent events.
    • Sometimes the system tray doesn't show the icons of eMule and uTorrent.

Overall, things looking better now.



#12 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:06:16 AM

Posted 02 November 2013 - 01:08 PM

Good Deal! :thumbsup:  We are making progress...
 
Please perform the following:
 

===================================================

Running TDSSKiller with Changed Parameters

--------------------

  • Please download TDSSKiller from here and save it to your Desktop
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters

tds2.jpg

  • Check Loaded Modules, Verify Driver Digital Signature, and Detect TDLFS file system
  • If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now

2012081514h0118.png

  • Click Start Scan and allow the scan process to run

tds4-1.jpg

  • If threats are detected select Skip for all of them unless I instruct you otherwise
  • Click Continue

tds6.jpg

  • Click Reboot computer
  • Please zip and attach in your reply the TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)

Best Regards,
oneof4.


#13 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 03 November 2013 - 12:06 PM

TDSSKiller has generated two logs rather than one. Probably the reason is that I was asked to reboot the computer when I checked the option "Loaded modules". I guess that the relevant log is the second one, but I attach both in the zip file just in case.

 

No threats were detected.

Attached Files



#14 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:06:16 AM

Posted 03 November 2013 - 10:25 PM

Please download and Run ComboFix. To do so, please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.


Best Regards,
oneof4.


#15 Alonshow

Alonshow
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Madrid, Spain
  • Local time:11:16 AM

Posted 06 November 2013 - 07:36 PM

Hi, I ran ComboFix, but while it was running I was watching the log screen and saw that it was deleting the contents of my C:\X folder, so I stopped it. Eventually I discovered that it had quarantined the contents of the folder, but I was worried until then.

 

Anyway, now I don't know if I should just run the program again. It has ran halfway, it has made some changes to the system, but it hasn't created a log.


Edited by Alonshow, 06 November 2013 - 07:36 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users