Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by Stefan (administrator) on STEFAN-PC on 08-10-2013 06:50:22 Running from C:\Users\Stefan\Downloads Microsoft Windows 7 Ultimate (X86) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe () C:\Users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Eastman Kodak Company) C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE (VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [33648 2007-08-24] (Microsoft Corporation) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Conime] - %windir%\system32\conime.exe HKLM\...\Run: [EKAiO2StatusMonitor] - C:\Windows\system32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe [2421760 2011-03-01] (Eastman Kodak Company) HKLM\...\Run: [MobileBroadband] - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [408576 2011-04-19] (Vodafone) HKLM\...\Run: [Microsoft Windows Hosting Service] - C:\Users\Stefan\AppData\Local\Temp\csrss.exe [239616 2013-09-19] (NoVirusThanks Company Srl) <===== ATTENTION HKLM\...\Policies\Explorer\Run: [44992] - c:\progra~2\dxrrblix.exe [357888 2009-07-14] ( ()) HKLM\...\Policies\Explorer: [3212083974] 0x504B0304C239B7F8068374BFB511000000400000E269F63D73594F6202C9694280CC96A28BBD63516FE3C2D5F7A2FF87AC3A990C3EC3B2ED7B07716237A0DFB1DFB651F67E31CB2E7649F98D5E55E9B25B1A579794989B176C357BDCC11226BD6ECB7DE8A63EA2165F6B31EAD6B0A2A96A6E9D04B9B39F194EF52D48B088D4B6597F685A70FF6912914F86D8235681747DA26CFD83223D3D248872C51095484634EBF976E4595F734BD35CAF42B38DCF9E878AF0BE0A5E84B22940F721E8BBCDCBAA3E53607359252DB16C0D6C38A142261BB4896D12A48C006CC3C21FDF717C155B2AF0375D2545EE286C2AECB2955206EF25C82DC686F7EB83BB3072E94E1E59254B11A2E3628E1D98E177375B54E682A1C77F986E1907FFCB784ACCACB124189751D7EBBAFC91D3A127F134A85E27F8C201D9082F621F5FFFAC09D2AAB94A62F90BD74D6C96A8DB6D42E4E98316449D202A4E24857673E2A50B7DFD9D5AF72A21A19A922ACC9675BA933A1C6AD4E0A11470FBB82EED7A79C5CA2DBB0BEC5B2B43BAA37373D3EF494726D7CF4A4AA8A3D6A5C206CED49148C0100BFA96B707BE91B855151D8DA8E0723DD1303325011B3951C9DF7B10E9B153BCED98376C4D7517F2E0E23A986914B2B0F978454441C47B5797D924CE9CD186D74D308099EE52F226E92DE6B50E4A0691F75CFA9CE733494B8CAFAEB4BE4C65F6C9DFFA34A3C2ED9D14F5844164BE79B7A90495290350177B03AEFA777FF519B624E3C75C219260AC447BBA9A6DB56F34B340A5F75837FAB3C33831A3BC39C2914AEB87A39545BD7ED52450EB7E94D5380E2BABCE3F8EE6E3CDC9D4ED54D9889D9DBD0DC879CAA2B121048A308A7F873252DAD24EA8F8911EA0A3B202DE930A9FC882CF1349FFE229016B2EBFD7821B8986D31DECCBC296BA54FD6D864C915F1D77AC0734D96FE0BA43A669FAB128026C7F90E9E1E0A7047F5A2378E4DE0966EB6C217B3483194B2B21A3FA8A1CBEF1D66A3FC8A5C863BCEA6157981A11449BAE3357F3287501CB9C24E0AFB156F5DDFD6855CD8B7B43FEABD9412C1C208B5DE2330C469A59DE5B490CC06BFD5A4900CB121EB967BC7185A9F00112A5B1E8D8028CA02B0F2B194AF03CC1E172B70C9B88643E3C064B5406CF184AD9EBA26736EF6FEB30DAC8BA400933A32A3C03230BD732FCBE16C4B3BDCC0B501616CE956D968B8DA68B4A9A64238601E81E78095961580431361A4DD9FE963D3CEBA5C21BBA416C1CC9D94BB842C25B2FD12C8BF42C35948272965A3FECF6E9B92D32D7E84A402A0B6214A412A23427E4852CE607FD9F7FF8559BBB96A9AE577DF0C19D108587D372470BE0D3E27ED61FEB442C2D65E55BAC81C2786CF6B837EEBC1B5AF35634B29FD5D96347B5F9C747C8A9A83E7CB3C188D9042F08FBD4EDEEBD65DE7C04B275B7FD74067A0AE3033752AA55A45A05355811416EA4A5101511E99305B700BD44742CBD6A9272B5CF4001505C4057866B57E4DE5EF0EE9F88B41986A80119C962594972011FC0C39B4A74B74747F5116D896A0EBCBB4387685672899AF54B80AE07008971EA1C997A898E33AAB769E4E52FBBEC97EBF199CE76454BADBD4EAB272F1D1CAABB3B49B3AAFC1E67D09EE8FEB0580E414EB45F3F0C25FE88872312FEC2341E7A6100B2E04ED25FCE13A146098DCE98446B2F3875ECB269A886795698619D337DA612F19BF8D4FE3028E79A26548128D1595AF0BF98FF320DC73D873F05EBD07C87CAE28DF067C00DE3E53CC77E801E1304192CA7BF78AB28DB40564328A108F9F0DDD8E1B0BAECCF16BF1DEB3CC5C4B5F5140F6B8A256E9128C203418AA3D93E3F08078977667DC02D830BB6869DE92F29A65AC6D2689D0A5A90887A8643119DC9A68B5B00BD59D45DA9D7ED5DAE6EE6DA6119243F77F51B263200F90ABBB61CCE9A951781EA2012A2C8D7200906439B08E7E76CF9C9536B2E6B560AFD7CBAA5044791EE17DED45ADFD9D359DAC0A9F4ED15BF2CB2EA9B12B7CB11B597CF2E6E750A6C636FE2C4B144F6FF43CCFFDDAE787BE160B0A8B4282B35A6AEECE165814E95CE7ADBE416EF4E51860CB4F5D50AF2A86AA4EE602A30AA54850E0CB4A38DC3A1C711B5D03B6A53EE102AC68E553D11E5FB3D0A8E0EF34266263CA4A3E0B76C55A92F75F921CD61A5363E5DB7737874D57C653D63457260B67B1DF330827B2921C29FDA0045BBE7404E40985039F7DB153F52B2C941A56E922DCFB60B89DBEE327ED6F5C1E438270F766A6ED1730FC581A4AEBCFE3B7726B27D6B092CF5A0B6954196CB4CC2788B8722338EE189D9E22692595F0D5B333B0F715CB8D94A08AFB631DBB1BE79A773E8F1A4EAF7220C24222DDA431B91D9175DFA0C6AE81E8C4C879D64446CF56FAEFE1487CA6739A776AEE42EF8BE40A612F95CDE3B1FEEAC1E1E41A24C92ED8B0152E247239E5A8BC903679CA8C7B94659AD5B1D10551F460D924FB60882FC90508C3723420F86F4CF100387E808133CC429883C0E3ACE91651C075CD19D106E0B437B0363048CA1FEAAF929B87AED90AFDE281EDCA0FA0CC7B5A7F03807FA5AC41B1ED73130EAC1117C631C1818142F24D420F6776CB53D4D0326B9FC3008C3CA03FC649D87D37FA617B74F2865C75298BED54B7D8DC676E2210374D8BF194AE2FEDA62B4798933C764CCDDF845330721FC21E68C0695CA73285103E22AE68DA440326DFEF9A80D17D0A7C3F920E7B0AA806EE9B7549ED9878B6CFB505AC69E8E8D3CFA718675764CFB03861D32AFAAE1D918BE87F6A9AC0D815C57AD3E167D642F5FCDDC25D4BA3AC3E67C26A4DEAA17797B3C0654F271EAAA442A71CBE19372ADCBDE3DF8B3FE491E5A76A79D1291A0DE317FFBF927F42782FA48270F2C969563B183A4B0112F3497DD3C2A423EC83498BDBAAC928910A9FB7FE5788E454C027A28F4A91AF2BF09E261F85B0EEE4F7929E63C4062496CB09534BB6D03FF69ED2915D0EA215B4FB3D1044E86EB87DFB4898BCBD50E5C4DDFBDB83B9410E1ADF91446C43C959E0E341D67A5A7EF8712586DE3B8B9C5B6F80F42F235BF68900EBFE6304BB0D9F67408B76201EC26180B4BD76500DE4F0DF86DF4A063AECECCA69DDF8A162B67A4B9800FA7570D5B551AC2703ADC0FFCED00650A96CD81EC4187B90C6B2140CE99C1937C40587EA72899897E628115BCAB73B3D9F425860B109A67347B8A121F65D0968D56A3DDE6B8171CEA61B08AE568B9D03C398977CE86F75055230EF370CABF67C9CF97C3223719555403F3E0BD2AF0E1E8742DECB05FADB0227F15D40EE2D6DC5A49FE1E6BC9E6CEDDE74294C3BB6FD5C5FEDFAD672DF1DFFD219BD8BC1EC39158EAB507998755F553441D01CD26A5501F6FB2DB4F3597510F85B93A542514C8013EEDBBFC913DCCE8B20A5759665BDFD9919EB22A89163D8656386D857C5BFC7C241C1D726CD94AB0F92D5B0FEFCF1D4ABDD26FBC6C17A4CCACF2D31E5E713059DE93C59D3B8D3E8D03B5D663F9DFADB03E093CB84FCF500A1F0E2E5BA1C9D81DB12CC799C6539AF0CC35682D95CB789C745A452BD8B38E6CF08E0579DA1AB43AD0858D0305F961B15A79C1090F4867040EA2BD36CF6512AAB44CE5A1098EFE039134F23BF057777FEF3E68E45827B0487924CAD4E5F0B1C3B4F5A0E3853B39640EB0782D78888FE92C3B68624E84FF6A5EDED87BE62D34CE858F34E5FFFBBA75F014DF0F648988B51A72DE1FF54D5C7A4B8ECB10C5E9EF51DE98C01EF8C406F9824A0C15A29E16B5A53E3643B0065A4263ECAE50D2CB976D3D2EA6255A65F1C6CC86167F1784A27B832037DB4CE1E262475334F3B2430F86C7A24456EEA82AB678ABA91BB4C0CC82C877B80B6D3574007257272C3E126C17A8B36AA8AA9431FF01BF658F82D8153EDDEA6804CDC564A3F5E9967B08FEEB823D3DB9356A4ACDD80E883CA58A1C661D01D145F80A3AB67E8036C0BAE1BB7BC43204EB0CF38214BC74A9AEF036A31D5A9C552D93A25C0E84057BCE5437B1634680D04A77472D631432D2BAA7A3ACD64220EFCF9E7848F8FD9801BEF7561A470A1822032160EB59EDC0F977882DCE4FB2872D89D27FF076DBA74A9672F86909956579C28853FA8DE7002CC8458D09256D42A39F1A4BDB6B56D36D51488E7368686E54C1BBBFFF48884E0D536BE362E59BD7F18329A4B82AED396E4F92865F594D0DA38F7CACE7A4603AF60C1A53BDFD19476094AAC6E4A8F31FC1257D48D03BB0EF515D8460B9441532C8B5043D0531D5881ADB6D997BB184FD8CAF4D8E6C759C3F7143B9E32BC7A0EC6234B68ADF4111CA1D136721438E5E6D7125D480CE982D84AEA7703B4010CD27867D6DDC5E0C970385196F020E48EDDB24C56972F9E61E6CC29C1712551583828F899534AACFFFC66F99999EA2BA2731D52A7FD2FA262A22B075DA52A5AA58F5B41AA9CDC9181406717F3F75E7C475090121966838125236E4DC6291AE3874968E8208B983AADB03CA60ACD935E6DA1B829407F70A77340E4439F22FDC2FC4218DE0F25D2F886C0AAEB693C2B23DB0EAB9953BF806C2173E0BC9D0D7EF0E763775BC1432FF48D6035B1214294C81B71CD98C42831014090CD99CB74929AE853F88132E559104D4FEA98AD40F17DA4100A909A6981BAD9EFB240A79520927AA12232A56F4D8893BFF92BFC2BD42CF3DC09BDC484DFDBA3A10C609186104CE33E3024F44000BE34814FF5DC9872D44B4157FB3A6655B985F6CC5EF4586F2ABFEE12DCBDB90181B396F95FE3213F094D1F3DD3D7FED800F4ED21290F613B62048E0FC1F1328D9F87A5653B489D36F727BE9D755523DEF0472F1C1D5AC90EE665379FF39D06E863C244890F5333A0B89B92022C1A8198029FE5F8C203B3DD211D4398958EE190108DD50B7850E20D8ABE2B927D53D28F3B8CA26BE81BC6B83C0E2B3B1DDA28066C63860CEA89DF82708EF21D4D36B84663E87B4385A3E37BD3FF1EB2BF64184C44723490669AF4DA092D45BA21A569A352E513D9A9B43E9CD4B812055822626EFC55F950009232B8B3BB2D63D44A8B0BD9BD4E84C5A724496A2326F63C97DBCB235366EC0CF6096B5F4988D073C34BD3A084130CEA8D6EE22E542B411C1E18599667B3FD6DDE0669AD82C85A1C10CA5862213CB1BB277E6C4F6564F20A9BCEA1B48170504C47235D78ED0A0441987C8C17D90D7B56CF487C46733BA4A6848FEC42B97CE4048F3C6D9C493322F052EF93F02F142B3940A10921BD15C911E7A97AA4A20DC383C62CD288D252BA937B3F60761E6653568A01241BB573664DE04811CF3F59B4C2D7E8A6C55DA16F468383456AA751697697397C2A5E5ABFA0F1099D80447D49DA509AA1347F3943EE9BAA1FDAD2A0E69410B34253AD4991282D0E952260F52AB9F02A3D00B37098CF60354424F862066E45E92AC475C99A00E7380766E589ABF66271619142795CF7A7FBD138A6CC5BD7E135122341D1F06EB5B436C59BE0ADEDC71BC03D7C63C16751AD56C69E36DECFE9E8214C719FCDF2E9FE2DC971F03C1C2AD6B6D368FE8B11D0389650C73D1C7E73708145FA05992A150E6A909656EA786E244BDF1CD71F4B0FD05B1335D703182FFA9D96C99108297B1FE327A83BF4F69D2A9C3D1EB73A9DD8CEE2B3220904AC31011FD6407A5BA427FACB46227FDEDB13D1CA6443DED3DC3B6CF06A59DC9B9226FBF357334ABF58412605FD206E7B6125FA19E5D68F75783FA08205B05C0A12D1830068317F6105958C4EB37BCB1BEAE6A401C267641AA58274A410D76B4D2A03E418020869B6886BB81964761B3FCD8EA68050AD6CFF99649CDE8FA53F04B0C96E271C0B092E24D81EA2D723775799E713EA9DA6967EF57AAAFE1C6732F2F047556027F021C65FC20C1C3BCB392ACF8FF7A9E14D9728A5AAACD255FC3866B041E9C96DCF592083D78C9E405DDD7991D2E2536D2EB1BA0F0ECE3DFB6A34C2665CFAC2D1850FD478F617FDD4E9DD4492C553BD375CFD33F4744D642006F3A5216A1FF7D73643ED751CAECDFDCB56247AA2F66FBCB8315DAAA86006A99E0350A72D5D5260D6BB77AC53CDD7ABACB859586C279B7FACDF076C922AC27F3E907FB3B4EC977CA634A28DF064162165222DCCE674DAB60A4E9D48E7FCEA267ABB1F8E0A2012AA6DB532A4CE74FBAF583E2C292FA1B56BE585D14EE073CDAFE3FC0C19050E698EC41B9D27F5DB41A779208118A5D3F8F74333B2AD2FE3CEE273BBFEA485EAD817EFFEDF1260C1A125070589B6F0F31984ED498CBD273E84A718F54C82CBC2747E678F8437DDE23C9EA3C877823034B7C70731C2D01CC09D11D3364E7945B6480B9B416ACB54CD1194B46C6D2E147619AC1C1FA915AF80A5098647247EBCF0449634F69C96AFC740BCE61993228183D98D0F85406D8FFD934 HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path) HKCU\...\Run: [Microsoft Windows Hosting Service] - C:\Users\Stefan\AppData\Local\Temp\csrss.exe [239616 2013-09-19] (NoVirusThanks Company Srl) <===== ATTENTION HKCU\...\CurrentVersion\Windows: [Load] c:\users\stefan\dxmwpq.exe <===== ATTENTION MountPoints2: I - I:\_AUTORUN\AUTORUN.EXE MountPoints2: {031d204d-7e61-11e2-85f8-02c0ee6543d1} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {031d210d-7e61-11e2-85f8-02c0ee6543d1} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {031d2165-7e61-11e2-85f8-02c0ee6543d1} - I:\autorun.exe MountPoints2: {16f87916-03ea-11e3-abb3-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {16fba005-1aa2-11e3-a79d-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {3a9f90e5-86e5-11e2-b64c-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {65538eaf-8c71-11e2-a1e4-02c0ee6562cf} - F:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {65538eb4-8c71-11e2-a1e4-02c0ee6562cf} - F:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {7127b1f2-1af4-11e3-ac9b-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {7127b204-1af4-11e3-ac9b-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {8f396b0a-ebb6-11e2-a859-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {ca4bcc16-1c3b-11e3-9400-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {f06774a7-b30b-11e2-8f64-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence MountPoints2: {f70ec47d-b898-11e2-a843-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence AppInit_DLLs: [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.search.us.com/v/2/?guid={5CD6CB79-8ADD-4852-82CF-00ED47F6214E}&serpv=5 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.youwillfind.info/?pid=658&r=2013/05/02&hid=763785938&lg=EN&cc=ZA SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.youwillfind.info/?l=1&q={searchTerms}&pid=658&r=2013/05/02&hid=763785938&lg=EN&cc=ZA SearchScopes: HKCU - {5C49C060-6DEE-4BE9-8C91-B03DBFF55B81} URL = http://search.us.com/serp?guid={5CD6CB79-8ADD-4852-82CF-00ED47F6214E}&action=default_search&serpv=5&k={searchTerms} SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.youwillfind.info/?l=1&q={searchTerms}&pid=658&r=2013/05/02&hid=763785938&lg=EN&cc=ZA SearchScopes: HKCU - {D735BCC8-CE8F-4074-A6F9-39F6424517E8} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10547 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: DefaultTab Browser Helper - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 02 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog9 01 mswsock.dll File Not found () Winsock: Catalog9 02 mswsock.dll File Not found () Winsock: Catalog9 03 mswsock.dll File Not found () Winsock: Catalog9 04 mswsock.dll File Not found () Winsock: Catalog9 05 mswsock.dll File Not found () Winsock: Catalog9 06 mswsock.dll File Not found () Winsock: Catalog9 07 mswsock.dll File Not found () Winsock: Catalog9 08 mswsock.dll File Not found () Winsock: Catalog9 09 mswsock.dll File Not found () Winsock: Catalog9 10 mswsock.dll File Not found () Winsock: Catalog9 11 mswsock.dll File Not found () Winsock: Catalog9 12 mswsock.dll File Not found () Winsock: Catalog9 13 mswsock.dll File Not found () Winsock: Catalog9 14 mswsock.dll File Not found () Winsock: Catalog9 15 mswsock.dll File Not found () Winsock: Catalog9 16 mswsock.dll File Not found () Winsock: Catalog9 17 mswsock.dll File Not found () Winsock: Catalog9 18 mswsock.dll File Not found () Winsock: Catalog9 19 mswsock.dll File Not found () Winsock: Catalog9 20 mswsock.dll File Not found () Winsock: Catalog9 21 mswsock.dll File Not found () Winsock: Catalog9 22 mswsock.dll File Not found () Winsock: Catalog9 23 mswsock.dll File Not found () Winsock: Catalog9 24 mswsock.dll File Not found () Winsock: Catalog9 25 mswsock.dll File Not found () Winsock: Catalog9 26 mswsock.dll File Not found () Winsock: Catalog9 27 mswsock.dll File Not found () Winsock: Catalog9 28 mswsock.dll File Not found () Winsock: Catalog9 29 mswsock.dll File Not found () Winsock: Catalog9 30 mswsock.dll File Not found () Winsock: Catalog9 31 mswsock.dll File Not found () Winsock: Catalog9 32 mswsock.dll File Not found () Winsock: Catalog9 33 mswsock.dll File Not found () Winsock: Catalog9 34 mswsock.dll File Not found () Winsock: Catalog9 35 mswsock.dll File Not found () Winsock: Catalog9 36 mswsock.dll File Not found () Winsock: Catalog9 37 mswsock.dll File Not found () Winsock: Catalog9 38 mswsock.dll File Not found () Winsock: Catalog9 39 mswsock.dll File Not found () Winsock: Catalog9 40 mswsock.dll File Not found () Winsock: Catalog9 41 mswsock.dll File Not found () Winsock: Catalog9 42 mswsock.dll File Not found () Winsock: Catalog9 43 mswsock.dll File Not found () Winsock: Catalog9 44 mswsock.dll File Not found () Winsock: Catalog9 45 mswsock.dll File Not found () Winsock: Catalog9 46 mswsock.dll File Not found () Winsock: Catalog9 47 mswsock.dll File Not found () Winsock: Catalog9 48 mswsock.dll File Not found () Winsock: Catalog9 49 mswsock.dll File Not found () Winsock: Catalog9 50 mswsock.dll File Not found () Winsock: Catalog9 51 mswsock.dll File Not found () Winsock: Catalog9 52 mswsock.dll File Not found () Winsock: Catalog9 53 mswsock.dll File Not found () Winsock: Catalog9 54 mswsock.dll File Not found () Winsock: Catalog9 55 mswsock.dll File Not found () Winsock: Catalog9 56 mswsock.dll File Not found () Winsock: Catalog9 57 mswsock.dll File Not found () Winsock: Catalog9 58 mswsock.dll File Not found () Winsock: Catalog9 59 mswsock.dll File Not found () Winsock: Catalog9 60 mswsock.dll File Not found () Winsock: Catalog9 61 mswsock.dll File Not found () Winsock: Catalog9 62 mswsock.dll File Not found () Winsock: Catalog9 63 mswsock.dll File Not found () Winsock: Catalog9 64 mswsock.dll File Not found () Winsock: Catalog9 65 mswsock.dll File Not found () Winsock: Catalog9 66 mswsock.dll File Not found () Winsock: Catalog9 67 mswsock.dll File Not found () Winsock: Catalog9 68 mswsock.dll File Not found () Tcpip\Parameters: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{131B5047-1B2C-449F-9AAC-DC252D82C1E1}: [NameServer]196.207.36.251 196.207.36.254 Tcpip\..\Interfaces\{17F7B7DA-3406-4F8D-9541-EA905EED8D4A}: [NameServer]196.207.36.251 196.207.36.254 Tcpip\..\Interfaces\{C775872A-FCC3-42EA-AAFA-AD8B5396A367}: [NameServer]196.207.36.251 196.207.36.254 Tcpip\..\Interfaces\{CB318F49-15F3-407F-9EBE-BBA23BBCC213}: [NameServer]196.207.36.251 196.207.36.254 FireFox: ======== FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default FF Homepage: hxxp://start.search.us.com/v/2/?guid={5CD6CB79-8ADD-4852-82CF-00ED47F6214E}&serpv=5 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tightropeinteractive.com/Plugin - C:\Users\Stefan\AppData\Local\TNT2\2.0.0.1599\npTNT2.dll (Search.Us.com) FF Plugin HKCU: @tnt2ghost.com/Plugin - C:\Users\Stefan\AppData\Local\TNT2\2.0.0.1599\npTNT2ghost.dll (Search.Us.com) ========================== Services (Whitelisted) ================= S3 CoordinatorServiceHost; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [87336 2010-10-05] (Dassault Systèmes SolidWorks Corp.) S2 DefaultTabSearch; C:\Program Files\DefaultTab\DefaultTabSearch.exe [573952 2013-09-16] () R2 DefaultTabUpdate; C:\Users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [107520 2013-08-23] () S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2013-07-18] (Flexera Software, Inc.) R2 Kodak AiO Network Discovery Service; C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe [366000 2011-03-09] (Eastman Kodak Company) S4 msvsmon80; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2799808 2006-10-26] (Microsoft Corporation) S3 SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-07-18] (SolidWorks) S2 VmbService; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2011-04-19] (Vodafone) S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x] U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{2e754a38-a09f-89b0-736a-408075ef620d}\ \...\???\{2e754a38-a09f-89b0-736a-408075ef620d}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess) ==================== Drivers (Whitelisted) ==================== R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-02-24] (DT Soft Ltd) S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [85760 2011-04-18] (Huawei Technologies Co., Ltd.) S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26496 2011-04-18] (Huawei Technologies Co., Ltd.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [168448 2011-04-18] (Huawei Technologies Co., Ltd.) S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2011-01-04] (CACE Technologies) R3 RTL85n86; C:\Windows\System32\DRIVERS\RTL85n86.sys [311808 2009-07-14] (Realtek) S3 iBurstu; system32\DRIVERS\iBurstu.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-08 06:50 - 2013-10-08 06:50 - 00000000 ____D C:\FRST 2013-10-08 06:47 - 2013-10-08 06:47 - 01087213 _____ (Farbar) C:\Users\Stefan\Downloads\FRST.exe 2013-10-07 16:22 - 2013-10-07 16:23 - 00000000 ____D C:\ProgramData\MFAData 2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\MFAData 2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\Avg2014 2013-10-07 16:11 - 2013-10-07 16:12 - 04433128 _____ (AVG Technologies) C:\Users\Stefan\Downloads\avg_isct_stb_all_2014_4142_free.exe 2013-10-07 14:55 - 2013-10-07 14:54 - 00006396 _____ C:\Users\Stefan\Downloads\0677.mpssvc.reg 2013-10-07 14:54 - 2013-10-07 14:54 - 00229548 _____ C:\Users\Stefan\Downloads\1055.BFE.reg 2013-10-07 14:42 - 2013-10-07 14:47 - 00007619 _____ C:\Users\Stefan\AppData\Local\Resmon.ResmonCfg 2013-10-07 14:29 - 2013-10-08 06:50 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\NetSpeedMonitor 2013-10-07 14:29 - 2013-10-07 14:29 - 00000000 ____D C:\Program Files\NetSpeedMonitor 2013-10-04 04:26 - 2013-10-04 04:26 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-01 17:08 - 2013-10-01 17:08 - 00002153 _____ C:\Users\Public\Desktop\Sid Meier's Pirates!.lnk 2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\Documents\My Games 2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firaxis Games 2013-10-01 17:07 - 2013-10-01 17:07 - 00000000 ____D C:\Program Files\Firaxis Games 2013-09-13 13:04 - 2013-09-13 13:05 - 00160272 _____ C:\Windows\Minidump\091313-22432-01.dmp 2013-09-13 13:04 - 2013-09-13 13:04 - 356384572 _____ C:\Windows\MEMORY.DMP 2013-09-13 07:17 - 2013-09-13 07:17 - 00000000 ____D C:\Program Files\ESET 2013-09-12 16:59 - 2013-09-13 13:04 - 00000000 ____D C:\Windows\Minidump 2013-09-12 16:59 - 2013-09-12 16:59 - 00661376 _____ C:\Windows\Minidump\091213-18486-01.dmp 2013-09-12 14:53 - 2013-09-12 14:53 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Mozilla 2013-09-12 14:52 - 2013-10-07 13:31 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-12 14:52 - 2013-09-12 14:52 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-11 14:59 - 2013-09-11 15:42 - 00000000 ___HD C:\Users\Stefan\Desktop\leeupoort 2013-09-11 07:43 - 2013-09-11 07:43 - 00002735 _____ C:\Users\Public\Desktop\SMS.lnk 2013-09-11 07:43 - 2013-09-11 07:43 - 00002166 _____ C:\Users\Public\Desktop\Vodafone Mobile Broadband.lnk 2013-09-11 07:43 - 2013-09-11 07:43 - 00000000 ____D C:\Program Files\Vodafone 2013-09-09 09:39 - 2013-09-09 09:39 - 00000000 ____D C:\Sports Mogul 2013-09-09 09:09 - 2013-09-09 09:09 - 00000000 __SHD C:\Windows\system32\%APPDATA% 2013-09-09 09:02 - 2013-09-09 09:02 - 00002220 _____ C:\Users\Public\Desktop\OOTP Baseball 13.lnk 2013-09-09 09:02 - 2013-09-09 09:02 - 00000000 ____D C:\Users\Stefan\Documents\Out of the Park Developments 2013-09-09 09:02 - 2013-09-09 09:02 - 00000000 ____D C:\ProgramData\eSellerate 2013-09-09 09:02 - 2013-09-09 09:02 - 00000000 ____D C:\Program Files\Common Files\eSellerate 2013-09-09 09:01 - 2013-09-09 09:01 - 00000000 ____D C:\Windows\Out of the Park Baseball 13 2013-09-09 09:01 - 2013-09-09 09:01 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Out of the Park Developments 2013-09-09 09:01 - 2013-09-09 09:01 - 00000000 ____D C:\Program Files\Out of the Park Developments 2013-09-08 18:49 - 2013-09-10 18:42 - 00000049 _____ C:\Windows\NeroDigital.ini ==================== One Month Modified Files and Folders ======= 2013-10-08 06:50 - 2013-10-08 06:50 - 00000000 ____D C:\FRST 2013-10-08 06:50 - 2013-10-07 14:29 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\NetSpeedMonitor 2013-10-08 06:47 - 2013-10-08 06:47 - 01087213 _____ (Farbar) C:\Users\Stefan\Downloads\FRST.exe 2013-10-08 06:40 - 2013-02-24 10:59 - 00795074 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-08 06:36 - 2013-03-08 03:05 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\vlc 2013-10-08 06:15 - 2013-05-18 14:17 - 00000000 ____D C:\ProgramData\Kodak 2013-10-08 06:15 - 2013-02-25 18:47 - 00012764 _____ C:\Windows\PFRO.log 2013-10-08 06:15 - 2013-02-24 13:13 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-08 06:15 - 2013-02-24 10:55 - 00000000 ____D C:\Users\Stefan 2013-10-08 06:15 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-08 06:15 - 2009-07-14 06:39 - 00152768 _____ C:\Windows\setupact.log 2013-10-07 17:14 - 2013-07-03 17:21 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\BitTorrent 2013-10-07 16:59 - 2013-03-01 08:23 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-07 16:23 - 2013-10-07 16:22 - 00000000 ____D C:\ProgramData\MFAData 2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\MFAData 2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\Avg2014 2013-10-07 16:12 - 2013-10-07 16:11 - 04433128 _____ (AVG Technologies) C:\Users\Stefan\Downloads\avg_isct_stb_all_2014_4142_free.exe 2013-10-07 16:09 - 2013-03-10 18:56 - 00000000 ____D C:\Users\Stefan\Desktop\Torrents 2013-10-07 15:26 - 2013-02-24 11:55 - 00000000 ____D C:\Users\Stefan\Desktop\Start-up CD 2013-10-07 14:54 - 2013-10-07 14:55 - 00006396 _____ C:\Users\Stefan\Downloads\0677.mpssvc.reg 2013-10-07 14:54 - 2013-10-07 14:54 - 00229548 _____ C:\Users\Stefan\Downloads\1055.BFE.reg 2013-10-07 14:47 - 2013-10-07 14:42 - 00007619 _____ C:\Users\Stefan\AppData\Local\Resmon.ResmonCfg 2013-10-07 14:29 - 2013-10-07 14:29 - 00000000 ____D C:\Program Files\NetSpeedMonitor 2013-10-07 13:31 - 2013-09-12 14:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-04 09:20 - 2013-02-24 12:10 - 00000000 ____D C:\Users\Stefan\AppData\Local\Mozilla 2013-10-04 04:26 - 2013-10-04 04:26 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-01 17:09 - 2013-03-11 06:33 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-01 17:09 - 2013-02-24 11:02 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-01 17:08 - 2013-10-01 17:08 - 00002153 _____ C:\Users\Public\Desktop\Sid Meier's Pirates!.lnk 2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\Documents\My Games 2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firaxis Games 2013-10-01 17:07 - 2013-10-01 17:07 - 00000000 ____D C:\Program Files\Firaxis Games 2013-10-01 17:06 - 2013-03-11 06:30 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2013-09-29 17:16 - 2013-08-23 11:17 - 00000000 ____D C:\Program Files\DefaultTab 2013-09-29 11:30 - 2013-08-31 15:27 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\dvdcss 2013-09-27 22:00 - 2013-02-24 12:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-27 22:00 - 2013-02-24 12:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-16 07:50 - 2013-02-24 10:55 - 00000000 ____D C:\Users\Stefan\AppData\Local\VirtualStore 2013-09-16 07:46 - 2013-05-01 14:21 - 00000000 ___HD C:\Users\Stefan\Desktop\Application 2013-09-15 21:28 - 2013-08-31 15:29 - 00000000 ____D C:\Users\Stefan\.dvdcss 2013-09-14 18:57 - 2013-08-23 11:17 - 00000884 __RSH C:\Users\Stefan\ntuser.pol 2013-09-13 13:05 - 2013-09-13 13:04 - 00160272 _____ C:\Windows\Minidump\091313-22432-01.dmp 2013-09-13 13:04 - 2013-09-13 13:04 - 356384572 _____ C:\Windows\MEMORY.DMP 2013-09-13 13:04 - 2013-09-12 16:59 - 00000000 ____D C:\Windows\Minidump 2013-09-13 07:17 - 2013-09-13 07:17 - 00000000 ____D C:\Program Files\ESET 2013-09-12 16:59 - 2013-09-12 16:59 - 00661376 _____ C:\Windows\Minidump\091213-18486-01.dmp 2013-09-12 14:53 - 2013-09-12 14:53 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Mozilla 2013-09-12 14:52 - 2013-09-12 14:52 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-12 14:51 - 2013-08-08 18:03 - 00000000 ____D C:\Program Files\Google 2013-09-12 14:51 - 2013-05-02 19:48 - 00000000 ____D C:\Users\Stefan\AppData\Local\Google 2013-09-11 18:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-09-11 17:11 - 2009-07-14 06:33 - 00428040 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-11 17:09 - 2013-02-24 10:56 - 00830016 _____ C:\Windows\WindowsUpdate.log 2013-09-11 15:42 - 2013-09-11 14:59 - 00000000 ___HD C:\Users\Stefan\Desktop\leeupoort 2013-09-11 07:44 - 2013-02-24 11:04 - 00122560 _____ C:\Users\Stefan\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-11 07:43 - 2013-09-11 07:43 - 00002735 _____ C:\Users\Public\Desktop\SMS.lnk 2013-09-11 07:43 - 2013-09-11 07:43 - 00002166 _____ C:\Users\Public\Desktop\Vodafone Mobile Broadband.lnk 2013-09-11 07:43 - 2013-09-11 07:43 - 00000000 ____D C:\Program Files\Vodafone 2013-09-10 18:42 - 2013-09-08 18:49 - 00000049 _____ C:\Windows\NeroDigital.ini 2013-09-09 09:39 - 2013-09-09 09:39 - 00000000 ____D C:\Sports Mogul 2013-09-09 09:09 - 2013-09-09 09:09 - 00000000 __SHD C:\Windows\system32\%APPDATA% 2013-09-09 09:02 - 2013-09-09 09:02 - 00002220 _____ C:\Users\Public\Desktop\OOTP Baseball 13.lnk 2013-09-09 09:02 - 2013-09-09 09:02 - 00000000 ____D C:\Users\Stefan\Documents\Out of the Park Developments 2013-09-09 09:02 - 2013-09-09 09:02 - 00000000 ____D C:\ProgramData\eSellerate 2013-09-09 09:02 - 2013-09-09 09:02 - 00000000 ____D C:\Program Files\Common Files\eSellerate 2013-09-09 09:02 - 2013-03-20 19:05 - 00000439 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-09 09:01 - 2013-09-09 09:01 - 00000000 ____D C:\Windows\Out of the Park Baseball 13 2013-09-09 09:01 - 2013-09-09 09:01 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Out of the Park Developments 2013-09-09 09:01 - 2013-09-09 09:01 - 00000000 ____D C:\Program Files\Out of the Park Developments ZeroAccess: C:\Windows\assembly\GAC\Desktop.ini Files to move or delete: ==================== C:\Users\Stefan\AppData\Local\Temp\csrss.exe ZeroAccess: C:\Users\Stefan\AppData\Local\Google\Desktop\Install ZeroAccess: C:\Program Files\Google\Desktop\Install C:\ProgramData\dxrrblix.exe C:\Users\Stefan\dxakokxu.exe C:\Users\Stefan\dxavzr.exe C:\Users\Stefan\dxbesgdoq.exe C:\Users\Stefan\dxcadh.exe C:\Users\Stefan\dxcbaathv.exe C:\Users\Stefan\dxddoi.exe C:\Users\Stefan\dxdjbu.exe C:\Users\Stefan\dxehlohv.exe C:\Users\Stefan\dxgcftur.exe C:\Users\Stefan\dxhuamnw.exe C:\Users\Stefan\dxhvrn.exe C:\Users\Stefan\dxiewkke.exe C:\Users\Stefan\dxifgxuu.exe C:\Users\Stefan\dxiynj.exe C:\Users\Stefan\dxizkvbep.exe C:\Users\Stefan\dxkdufa.exe C:\Users\Stefan\dxlabpuqo.exe C:\Users\Stefan\dxlmhx.exe C:\Users\Stefan\dxmwpq.exe C:\Users\Stefan\dxojim.exe C:\Users\Stefan\dxoyiv.exe C:\Users\Stefan\dxqafz.exe C:\Users\Stefan\dxriojni.exe C:\Users\Stefan\dxrjiy.exe C:\Users\Stefan\dxsezfjt.exe C:\Users\Stefan\dxtjrk.exe C:\Users\Stefan\dxtseu.exe C:\Users\Stefan\dxudeh.exe C:\Users\Stefan\dxvyvlii.exe C:\Users\Stefan\dxxikia.exe C:\Users\Stefan\dxxtwdeuo.exe C:\Users\Stefan\dxyrsiu.exe C:\Users\Stefan\dxzkhbwa.exe Some content of TEMP: ==================== C:\Users\Stefan\AppData\Local\Temp\1345545343.exe C:\Users\Stefan\AppData\Local\Temp\1345550028.exe C:\Users\Stefan\AppData\Local\Temp\1347056850.exe C:\Users\Stefan\AppData\Local\Temp\1348369731.exe C:\Users\Stefan\AppData\Local\Temp\1348385342.exe C:\Users\Stefan\AppData\Local\Temp\1348385637.exe C:\Users\Stefan\AppData\Local\Temp\1364500553.exe C:\Users\Stefan\AppData\Local\Temp\1364503380.exe C:\Users\Stefan\AppData\Local\Temp\1373093828.exe C:\Users\Stefan\AppData\Local\Temp\1373099186.exe C:\Users\Stefan\AppData\Local\Temp\1373307441.exe C:\Users\Stefan\AppData\Local\Temp\1390877027.exe C:\Users\Stefan\AppData\Local\Temp\1423717569.exe C:\Users\Stefan\AppData\Local\Temp\77Zip973867.exe C:\Users\Stefan\AppData\Local\Temp\AutoRun.exe C:\Users\Stefan\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Stefan\AppData\Local\Temp\BackupSetup.exe C:\Users\Stefan\AppData\Local\Temp\CmdLineExt03.dll C:\Users\Stefan\AppData\Local\Temp\csrss.exe C:\Users\Stefan\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Stefan\AppData\Local\Temp\EBU1489.EXE C:\Users\Stefan\AppData\Local\Temp\EBU14F6.DLL C:\Users\Stefan\AppData\Local\Temp\EBU34D5.EXE C:\Users\Stefan\AppData\Local\Temp\EBU35EE.DLL C:\Users\Stefan\AppData\Local\Temp\EBU7B27.EXE C:\Users\Stefan\AppData\Local\Temp\EBU7BA4.DLL C:\Users\Stefan\AppData\Local\Temp\mgsqlite3.dll C:\Users\Stefan\AppData\Local\Temp\msdt.exe C:\Users\Stefan\AppData\Local\Temp\ootp13setup.exe C:\Users\Stefan\AppData\Local\Temp\ose00000.exe C:\Users\Stefan\AppData\Local\Temp\SIntf16.dll C:\Users\Stefan\AppData\Local\Temp\SIntf32.dll C:\Users\Stefan\AppData\Local\Temp\SIntfNT.dll C:\Users\Stefan\AppData\Local\Temp\SweetIMSetup.exe C:\Users\Stefan\AppData\Local\Temp\ubiC524.tmp.exe C:\Users\Stefan\AppData\Local\Temp\uninstaller.exe C:\Users\Stefan\AppData\Local\Temp\utt5FE5.tmp.exe C:\Users\Stefan\AppData\Local\Temp\WAKUNX.exe C:\Users\Stefan\AppData\Local\Temp\_isFD26.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender LastRegBack: 2013-10-03 02:14 ==================== End Of Log ============================