Hi thanks for you help
Here is FRST.log scan and the addition.txt is in the next reply
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-09-2013
Ran by Del (administrator) on DEL-PC on 19-09-2013 15:41:07
Running from C:\Users\Del\Desktop
Microsoft Windows 7 Home Premium (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Sophos Plc) C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
(Sophos Plc) C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
(Sophos Plc) C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
(Anvisoft) C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
(Intuit) c:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Sophos Plc) C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Plc) C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
(Sophos Plc) C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Sophos Plc) C:\Program Files\Sophos\AutoUpdate\ALMon.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Anvisoft) C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe
(BrowserSafeguard) C:\Program Files\Browsersafeguard\BrowserSafeguard.exe
(DigitalAlbum Inc) C:\Program Files\CamToPrint\PassportPhoto\CamToPrintTray.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_174_ActiveX.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [149280 2009-12-21] (Sun Microsystems, Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Sophos AutoUpdate Monitor] - C:\Program Files\Sophos\AutoUpdate\almon.exe [439536 2010-09-21] (Sophos Plc)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-01-12] (Apple Inc.)
HKLM\...\Run: [Anvi Smart Defender] - C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe [1229104 2012-08-23] (Anvisoft)
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
HKCU\...\Run: [BrowserSafeguard] - C:\Program Files\Browsersafeguard\Browsersafeguard.exe [563200 2013-09-04] (BrowserSafeguard)
HKCU\...409d6c4515e9\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
MountPoints2: {b1bfd1a0-db9d-11de-8512-806e6f6e6963} - E:\SmartAccess\bcont.exe
HKU\Yvonne\...\Run: [msnmsgr] - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
Startup: C:\Users\Del\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Passport Photo.lnk
ShortcutTarget: Passport Photo.lnk -> C:\Program Files\CamToPrint\PassportPhoto\CamToPrintTray.exe (DigitalAlbum Inc)
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:49180;https=127.0.0.1:49180;
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/?ocid=iehpHKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.co.uk/HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page =
http://www2.delta-se...913_m1&tsp=5009SearchScopes: HKLM - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL =
http://search.mywebs...r={searchTerms}SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.condui...731329631082750SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://www2.delta-se...913_m1&tsp=5009SearchScopes: HKCU - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL =
http://search.mywebs...r={searchTerms}SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.condui...731329631082750BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
BHO: Protect My Choices (Beta) - {3DFCDCA1-AEAC-4302-A690-BFB683568BAA} - C:\Program Files\DigitalAdvertisingAlliance\Protect My Choices\pmc.dll (Digital Advertising Alliance)
BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {3BBD3C14-4C16-4989-8366-95BC9179779D} - No File
Toolbar: HKCU - No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - No File
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.appl...ex/qtplugin.cabDPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E}
https://internetbank...frontdoorFD.cabDPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E}
https://moneymanager...unttracking.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cabDPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cabHandler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Winsock: Catalog9 01 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 02 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 03 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 04 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 05 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 06 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 07 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 08 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Winsock: Catalog9 27 C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll [42736] (Sophos Plc)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
========================== Services (Whitelisted) =================
R2 asdsrv; C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe [686896 2012-08-23] (Anvisoft)
R2 SAVAdminService; C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [163056 2010-10-08] (Sophos Plc)
R2 SAVService; C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe [97520 2010-06-04] (Sophos Plc)
R2 Sophos AutoUpdate Service; C:\Program Files\Sophos\AutoUpdate\ALsvc.exe [232472 2012-04-11] (Sophos Plc)
R2 Sophos Client Firewall; C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe [32496 2010-04-27] (Sophos Plc)
R2 Sophos Client Firewall Manager; C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe [128240 2010-04-27] (Sophos Plc)
R2 swi_service; C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [1543704 2012-02-21] (Sophos Plc)
==================== Drivers (Whitelisted) ====================
R1 asdrm; C:\Windows\System32\DRIVERS\asdrm.sys [16208 2012-08-20] (Anvisoft)
R2 asdrs; C:\Windows\system32\DRIVERS\asdrs.sys [22864 2012-08-20] (Anvisoft)
R2 asdws; C:\Windows\system32\DRIVERS\asdws.sys [14160 2012-08-20] ()
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 FreshIO; C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys [2410 2004-10-26] ()
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
S3 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2012-05-19] (microOLAP Technologies LTD)
S3 PSSDKLBF; C:\Windows\system32\Drivers\pssdklbf.sys [53312 2012-05-19] (microOLAP Technologies LTD)
S3 RapportIaso; c:\programdata\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys [21520 2012-06-30] (Trusteer Ltd.)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [122360 2010-10-08] (Sophos Plc)
R1 scfdriver; C:\Windows\system32\Drivers\scfdriver.sys [86520 2010-03-31] (Sophos Plc)
R1 scflwf; C:\Windows\System32\DRIVERS\scflwf.sys [40440 2010-03-31] (Sophos Plc)
S3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [47176 2010-07-28] (Silicon Laboratories)
S3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [58112 2010-07-28] (Silicon Laboratories)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [22536 2009-02-09] (Sophos Plc)
R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-19 15:40 - 2013-09-19 15:40 - 00000000 ____D C:\FRST
2013-09-19 15:39 - 2013-09-19 15:39 - 01083535 _____ (Farbar) C:\Users\Del\Desktop\FRST.exe
2013-09-18 19:44 - 2013-09-18 19:44 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-18 19:44 - 2013-09-18 19:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-18 19:33 - 2013-09-18 19:33 - 00001991 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-09-18 19:33 - 2013-09-18 19:33 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-09-18 19:32 - 2013-09-18 19:32 - 52677528 _____ (Adobe Systems Incorporated) C:\Users\Del\Desktop\AdbeRdr1011_en_US.exe
2013-09-18 16:41 - 2013-09-18 16:41 - 00256733 _____ C:\Users\Del\Desktop\CatchOutput.txt
2013-09-18 16:15 - 2013-09-18 16:15 - 00000000 _____ C:\Users\Del\Desktop\VEW.txt.txt
2013-09-18 15:58 - 2013-09-18 15:58 - 00005559 _____ C:\Users\Del\Desktop\FSS.txt
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\SpeedAnalysis3
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\Mozilla
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\File Scout
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\7go
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\ProgramData\IBUpdaterService
2013-09-18 15:43 - 2013-09-18 15:43 - 00000000 ____D C:\Program Files\Browsersafeguard
2013-09-18 15:42 - 2013-09-18 15:42 - 00000072 _____ C:\Windows\wininit.ini
2013-09-18 15:42 - 2013-09-18 15:42 - 00000000 ____D C:\ProgramData\BitGuard
2013-09-18 15:41 - 2013-09-18 15:41 - 00000000 ____D C:\ProgramData\DSearchLink
2013-09-18 15:41 - 2013-09-18 15:41 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-18 15:27 - 2013-09-18 15:27 - 00061440 _____ ( ) C:\Users\Del\Desktop\VEW.exe
2013-09-17 20:13 - 2013-09-17 20:13 - 00000971 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-17 20:13 - 2013-09-17 20:13 - 00000000 ____D C:\Program Files\CCleaner
2013-09-17 20:09 - 2013-09-17 20:09 - 00000166 _____ C:\Users\Del\Desktop\RegistryFix.reg
2013-09-17 17:14 - 2013-09-17 17:14 - 00000168 _____ C:\Users\Del\Documents\RegistryFix.reg
2013-09-17 15:56 - 2013-09-17 15:56 - 00013164 _____ C:\Users\Yvonne\Desktop\please help me - letter to MP.eml
2013-09-14 13:53 - 2013-09-14 13:53 - 00000000 ____D C:\Users\Yvonne\AppData\Local\Sophos
2013-09-03 11:24 - 2013-09-03 11:24 - 00000169 _____ C:\Users\Yvonne\Documents\bens list.txt
==================== One Month Modified Files and Folders =======
2013-09-19 15:40 - 2013-09-19 15:40 - 00000000 ____D C:\FRST
2013-09-19 15:39 - 2013-09-19 15:39 - 01083535 _____ (Farbar) C:\Users\Del\Desktop\FRST.exe
2013-09-19 15:37 - 2009-07-14 05:34 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-19 15:37 - 2009-07-14 05:34 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-19 15:33 - 2009-11-27 22:44 - 01481531 _____ C:\Windows\WindowsUpdate.log
2013-09-19 15:32 - 2011-06-20 19:29 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-19 15:32 - 2011-06-20 19:29 - 00000876 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-19 12:38 - 2009-11-27 15:20 - 00000490 _____ C:\Windows\ODBC.INI
2013-09-19 12:38 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-19 12:37 - 2009-07-14 05:39 - 00255939 _____ C:\Windows\setupact.log
2013-09-18 19:44 - 2013-09-18 19:44 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-18 19:44 - 2013-09-18 19:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-18 19:44 - 2009-12-02 12:42 - 00000000 ____D C:\Users\Del\AppData\Local\Adobe
2013-09-18 19:33 - 2013-09-18 19:33 - 00001991 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-09-18 19:33 - 2013-09-18 19:33 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-09-18 19:33 - 2011-02-23 11:16 - 00000000 ____D C:\Program Files\Adobe
2013-09-18 19:33 - 2009-12-02 12:43 - 00000000 ____D C:\ProgramData\Adobe
2013-09-18 19:32 - 2013-09-18 19:32 - 52677528 _____ (Adobe Systems Incorporated) C:\Users\Del\Desktop\AdbeRdr1011_en_US.exe
2013-09-18 19:17 - 2010-01-20 10:37 - 00102682 _____ C:\Windows\PFRO.log
2013-09-18 16:41 - 2013-09-18 16:41 - 00256733 _____ C:\Users\Del\Desktop\CatchOutput.txt
2013-09-18 16:15 - 2013-09-18 16:15 - 00000000 _____ C:\Users\Del\Desktop\VEW.txt.txt
2013-09-18 15:58 - 2013-09-18 15:58 - 00005559 _____ C:\Users\Del\Desktop\FSS.txt
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\SpeedAnalysis3
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\Mozilla
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\File Scout
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\Users\Del\AppData\Roaming\7go
2013-09-18 15:47 - 2013-09-18 15:47 - 00000000 ____D C:\ProgramData\IBUpdaterService
2013-09-18 15:43 - 2013-09-18 15:43 - 00000000 ____D C:\Program Files\Browsersafeguard
2013-09-18 15:42 - 2013-09-18 15:42 - 00000072 _____ C:\Windows\wininit.ini
2013-09-18 15:42 - 2013-09-18 15:42 - 00000000 ____D C:\ProgramData\BitGuard
2013-09-18 15:41 - 2013-09-18 15:41 - 00000000 ____D C:\ProgramData\DSearchLink
2013-09-18 15:41 - 2013-09-18 15:41 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-18 15:28 - 2009-11-27 14:56 - 00000000 ____D C:\Users\Del\AppData\Local\VirtualStore
2013-09-18 15:27 - 2013-09-18 15:27 - 00061440 _____ ( ) C:\Users\Del\Desktop\VEW.exe
2013-09-17 20:13 - 2013-09-17 20:13 - 00000971 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-17 20:13 - 2013-09-17 20:13 - 00000000 ____D C:\Program Files\CCleaner
2013-09-17 20:09 - 2013-09-17 20:09 - 00000166 _____ C:\Users\Del\Desktop\RegistryFix.reg
2013-09-17 17:14 - 2013-09-17 17:14 - 00000168 _____ C:\Users\Del\Documents\RegistryFix.reg
2013-09-17 15:56 - 2013-09-17 15:56 - 00013164 _____ C:\Users\Yvonne\Desktop\please help me - letter to MP.eml
2013-09-15 11:40 - 2013-07-16 13:30 - 00000000 ____D C:\Windows\system32\MRT
2013-09-14 14:37 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\Msdtc
2013-09-14 14:28 - 2011-10-17 19:20 - 00000971 _____ C:\Users\Yvonnewinxp\Desktop\SpeedFan.lnk
2013-09-14 14:28 - 2011-10-17 19:20 - 00000971 _____ C:\Users\Yvonne\Desktop\SpeedFan.lnk
2013-09-14 14:28 - 2011-10-17 19:20 - 00000971 _____ C:\Users\delwinxp\Desktop\SpeedFan.lnk
2013-09-14 14:28 - 2011-10-17 19:20 - 00000971 _____ C:\Users\Del\Desktop\SpeedFan.lnk
2013-09-14 14:28 - 2011-10-17 19:20 - 00000045 _____ C:\Windows\system32\initdebug.nfo
2013-09-14 14:28 - 2011-10-17 19:20 - 00000000 ____D C:\Program Files\SpeedFan
2013-09-14 13:53 - 2013-09-14 13:53 - 00000000 ____D C:\Users\Yvonne\AppData\Local\Sophos
2013-09-13 19:18 - 2009-11-27 14:56 - 00000000 ____D C:\Users\Del
2013-09-13 19:16 - 2012-05-03 19:48 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-09-13 19:16 - 2012-05-03 19:48 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-09-13 19:16 - 2012-05-03 19:48 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2013-09-13 19:16 - 2011-02-15 17:50 - 00000000 ____D C:\ProgramData\Sophos Web Intelligence
2013-09-13 19:16 - 2010-08-15 20:02 - 00000000 ____D C:\Program Files\RC Plane Master
2013-09-13 19:16 - 2009-12-08 21:32 - 00000000 ____D C:\Users\Yvonnewinxp
2013-09-13 19:16 - 2009-12-08 21:31 - 00000000 ___RD C:\Users\delwinxp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-09-13 19:16 - 2009-12-08 21:31 - 00000000 ___RD C:\Users\delwinxp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-09-13 19:16 - 2009-12-08 21:31 - 00000000 ____D C:\Users\delwinxp
2013-09-13 19:16 - 2009-12-02 11:04 - 00000000 ____D C:\Windows\system32\Macromed
2013-09-13 19:16 - 2009-11-30 15:01 - 00000000 ____D C:\Users\Yvonne
2013-09-13 19:16 - 2008-04-29 20:44 - 00000000 ____D C:\Users\delwinxp\Documents\My Albums
2013-09-13 19:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\registration
2013-09-13 19:11 - 2011-06-20 19:29 - 00000000 ____D C:\Program Files\Google
2013-09-03 11:24 - 2013-09-03 11:24 - 00000169 _____ C:\Users\Yvonne\Documents\bens list.txt
2013-09-01 16:57 - 2009-12-01 22:05 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$9c0c89676f848c827691b37f700443a0
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$9c0c89676f848c827691b37f700443a0
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2568410734-3031030142-1223416489-1001\$9c0c89676f848c827691b37f700443a0
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$9c0c89676f848c827691b37f700443a0
Files to move or delete:
====================
C:\ProgramData\dsgsdgdsgdsgw.pad
Some content of TEMP:
====================
C:\Users\Del\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\Del\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2013-09-14 13:53
==================== End Of Log ============================