Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02
Ran by Cosmin U (administrator) on COSMINU-PC on 18-11-2013 19:01:32
Running from I:\
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apache Software Foundation) D:\Programe\XAMPP\apache\bin\httpd.exe
() D:\Programe\XAMPP\mysql\bin\mysqld.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\system32\PnkBstrA.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Apache Software Foundation) D:\Programe\XAMPP\apache\bin\httpd.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe
(Google Inc.) C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SwitchBoard] - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10967656 2012-03-27] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1387288 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AMD AVT] - "Cmd.exe" /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdcBase.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] ()
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKCU\...\Run: [Dropbox] - C:\Users\Cosmin U\AppData\Roaming\46E48F\46E48F.exe [32592 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Cosmin U\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-12-01] (Google Inc.)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
MountPoints2: G - G:\Installer.exe
MountPoints2: I - I:\setup.exe
MountPoints2: {4f52e964-bfe2-11e2-88f0-6cf04919e65a} - G:\.\Setup.exe AUTORUN=1
MountPoints2: {e62a4bc5-f0b3-11df-8d85-806e6f6e6963} - G:\setup.exe
AppInit_DLLs: C:\Windows\System32\ [ ] ()
IMEO\htcsyncmanager.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
BootExecute: autocheck autochk * SmartDefragBootTime.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEF5BAC502E7FCB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ie
URLSearchHook: HKCU - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File
SearchScopes: HKLM - {D0295D2A-D6BC-40B1-9F18-D33EAA24B55D} URL =
http://startsear.ch/...q={searchTerms}
SearchScopes: HKCU - {043C5167-00BB-4324-AF7E-62013FAEDACF} URL =
http://vshare.toolba...Terms}&srch=dsp
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?q={sear
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
http://isearch.avg.c...q={searchTerms}
SearchScopes: HKCU - {9751D8DA-6E55-408F-B468-0A900F34E5C1} URL =
http://websearch.ask...2C-5E516015EB5A
SearchScopes: HKCU - {D0295D2A-D6BC-40B1-9F18-D33EAA24B55D} URL =
http://startsear.ch/...q={searchTerms}
BHO: vShare Toolbar - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - vShare Toolbar - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - vShare Toolbar - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
Toolbar: HKCU - No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset...lineScanner.cab
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 mswsock.dll File Not found ()
Winsock: Catalog9 02 mswsock.dll File Not found ()
Winsock: Catalog9 03 mswsock.dll File Not found ()
Winsock: Catalog9 04 mswsock.dll File Not found ()
Winsock: Catalog9 05 mswsock.dll File Not found ()
Winsock: Catalog9 06 mswsock.dll File Not found ()
Winsock: Catalog9 07 mswsock.dll File Not found ()
Winsock: Catalog9 08 mswsock.dll File Not found ()
Winsock: Catalog9 09 mswsock.dll File Not found ()
Winsock: Catalog9 10 mswsock.dll File Not found ()
Winsock: Catalog9 11 mswsock.dll File Not found ()
Winsock: Catalog9 12 mswsock.dll File Not found ()
Winsock: Catalog9 13 mswsock.dll File Not found ()
Winsock: Catalog9 14 mswsock.dll File Not found ()
Winsock: Catalog9 15 mswsock.dll File Not found ()
Winsock: Catalog9 16 mswsock.dll File Not found ()
Winsock: Catalog9 17 mswsock.dll File Not found ()
Winsock: Catalog9 18 mswsock.dll File Not found ()
Winsock: Catalog9 19 mswsock.dll File Not found ()
Winsock: Catalog9 20 mswsock.dll File Not found ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 193.231.252.1 213.154.124.1
Chrome:
=======
CHR RestoreOnStartup: ""
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\29.0.1547.76\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\29.0.1547.76\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (vShare.tv plug-in) - C:\Users\Cosmin U\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_1\chvsharetvplg.dll No File
CHR Plugin: (vShare.tv plug-in) - C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll (vShare.tv )
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Windows Genuine Advantage) - C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Veetle TV Player) - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Cosmin U\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Extension: (Dr.Web Anti-Virus Link Checker) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleggpabliehgbeagmfhnodcijcmbonb\3.4_0
CHR Extension: (Rumola - bypass CAPTCHA) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjjgbdlbgjeoankjijbmheneoekbghcg\1.0.4_0
CHR Extension: (YouTube) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Firebug Lite for Google Chrome\u2122) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench\1.4.0.11967_0
CHR Extension: (Subway Surfers for PC) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpncgglkpfjldmpgfomdggpppnbkgoo\1.0_0
CHR Extension: (VshareComplete plugin for chrome) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_0
CHR Extension: (Pixlr-o-matic) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj\1.2_0
CHR Extension: (AdBlock) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.11_0
CHR Extension: (Cut the Rope) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\16_0
CHR Extension: (Pictico \u2014 Coloring for Kids) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndkeamlgkegbmmoheplcndpopglacgf\3.0.1_0
CHR Extension: (SearchPreview) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcjdanpjacpeeppdjkppebobilhaglfo\3.2_0
CHR Extension: (IE Tab) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\5.8.13.1_0
CHR Extension: (Image Properties Context Menu) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon\0.7.6_0
CHR Extension: (Picozu) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lajpehananomepaahgohcnmgkgmkhogf\1.1_0
CHR Extension: (Awesome New Tab Page\u2122) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg\2013.446.11_0
CHR Extension: (Google Wallet) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Fangos) - C:\Users\COSMIN~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pedijpnaiabopojfjbjbmmfoggenjegg\3.2.3_0
CHR HKLM\...\Chrome\Extension: [aaaaojmikegpiepcfdkkjaplodkpfmlo] - C:\Users\Cosmin U\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx
CHR HKLM\...\Chrome\Extension: [dlfienamagdnkekbbbocojppncdambda] - C:\Program Files\VshareComplete\chrome\VshareCompleteChrome.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Cosmin U\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 Apache2.4; D:\Programe\XAMPP\apache\bin\httpd.exe [22016 2012-06-06] (Apache Software Foundation)
S3 FileZillaServer; D:\Programe\XAMPP\FileZillaFTP\FileZillaServer.exe [632320 2012-05-11] (FileZilla Project)
S4 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-01-29] (Nero AG)
S2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] ()
R2 mysql; D:\Programe\XAMPP\mysql\bin\my.ini [5819 2012-08-26] ()
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] ()
R2 NitroDriverReadSpool8; C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe [197128 2012-10-01] (Nitro PDF Software)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2012-11-25] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1699168 2012-09-19] (TuneUp Software)
U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{bdb5ce38-1571-11e0-06d9-6eaf5d8425a7}\ \...\???\{bdb5ce38-1571-11e0-06d9-6eaf5d8425a7}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
==================== Drivers (Whitelisted) ====================
S3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [30360 2011-09-02] (Logitech, Inc.)
R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [199528 2011-12-02] (Realtek Semiconductor Corp.)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [15672 2010-11-26] ()
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-18] (TuneUp Software)
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x32.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [x]
S0 sptd; System32\Drivers\sptd.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-18 19:01 - 2013-11-18 19:01 - 00000000 ____D C:\FRST
2013-11-18 18:59 - 2013-11-18 18:59 - 00000000 ____D C:\ProgramData\Panda Security
2013-11-18 18:59 - 2013-11-18 18:59 - 00000000 ____D C:\Program Files\Panda USB Vaccine
2013-11-18 18:57 - 2013-11-18 18:54 - 00848856 _____ (Panda Security ) C:\Users\Cosmin U\Desktop\USBVaccineSetup.exe
2013-11-18 18:56 - 2013-11-18 18:56 - 00094906 _____ C:\Users\Cosmin U\Desktop\OTL.Txt
2013-10-19 13:39 - 2013-10-19 13:42 - 00001908 _____ C:\Windows\diagwrn.xml
2013-10-19 13:39 - 2013-10-19 13:42 - 00001908 _____ C:\Windows\diagerr.xml
2013-10-19 12:58 - 2013-10-18 08:41 - 11265368 _____ (Microsoft Corporation) C:\Users\Cosmin U\Desktop\mseinstall.exe
2013-10-19 12:54 - 2013-10-19 12:55 - 00000000 ____D C:\WINSSLog
==================== One Month Modified Files and Folders =======
2013-11-18 19:02 - 2011-12-01 22:12 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2140763589-1229600939-2173147066-1000UA.job
2013-11-18 19:02 - 2011-12-01 22:12 - 00000868 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2140763589-1229600939-2173147066-1000Core.job
2013-11-18 19:01 - 2013-11-18 19:01 - 00000000 ____D C:\FRST
2013-11-18 18:59 - 2013-11-18 18:59 - 00000000 ____D C:\ProgramData\Panda Security
2013-11-18 18:59 - 2013-11-18 18:59 - 00000000 ____D C:\Program Files\Panda USB Vaccine
2013-11-18 18:56 - 2013-11-18 18:56 - 00094906 _____ C:\Users\Cosmin U\Desktop\OTL.Txt
2013-11-18 18:54 - 2013-11-18 18:57 - 00848856 _____ (Panda Security ) C:\Users\Cosmin U\Desktop\USBVaccineSetup.exe
2013-11-18 18:52 - 2010-11-08 22:08 - 00778498 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-18 18:47 - 2009-07-14 06:34 - 00018224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-18 18:47 - 2009-07-14 06:34 - 00018224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-18 18:40 - 2013-09-25 12:41 - 00003676 _____ C:\Windows\setupact.log
2013-11-18 18:40 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-17 11:02 - 2010-11-08 15:06 - 00000000 ____D C:\Users\Cosmin U\AppData\Roaming\vlc
2013-11-17 10:38 - 2012-07-16 21:42 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-17 09:23 - 2010-11-08 16:17 - 00000000 ____D C:\Users\Cosmin U\AppData\Roaming\dvdcss
2013-11-05 18:13 - 2010-11-08 13:02 - 00000000 ____D C:\Users\Cosmin U\AppData\Roaming\uTorrent
2013-10-21 17:16 - 2010-11-08 22:07 - 01375361 _____ C:\Windows\WindowsUpdate.log
2013-10-21 17:09 - 2013-09-27 13:46 - 00009920 _____ C:\Windows\PFRO.log
2013-10-19 13:46 - 2011-03-16 09:55 - 00002121 _____ C:\Windows\epplauncher.mif
2013-10-19 13:46 - 2011-03-16 09:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-10-19 13:42 - 2013-10-19 13:39 - 00001908 _____ C:\Windows\diagwrn.xml
2013-10-19 13:42 - 2013-10-19 13:39 - 00001908 _____ C:\Windows\diagerr.xml
2013-10-19 13:39 - 2013-09-25 12:41 - 00000000 _____ C:\Windows\setuperr.log
2013-10-19 12:55 - 2013-10-19 12:54 - 00000000 ____D C:\WINSSLog
ZeroAccess:
C:\Users\Cosmin U\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
Files to move or delete:
====================
C:\Users\Cosmin U\AppData\Roaming\RegFree.ini
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Microsoft Security Client
LastRegBack: 2013-11-17 09:22
==================== End Of Log ============================