Okay, here is the result of the scan for you kuttus.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-03-2013 01
Ran by SYSTEM at 05-03-2013 18:47:22
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] "C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe" [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2327952 2010-07-21] (Microsoft Corporation)
HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k [258304 2010-06-28] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-03-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] "C:\Program Files (x86)\Launch Manager\LManager.exe" [1300560 2010-03-03] (Dritek System Inc.)
HKLM-x32\...\Run: [WebrootTrayApp] "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe" [1286960 2010-10-01] (Webroot Software, Inc. )
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Gateway\Screensaver\run_Gateway.exe /default [154144 2010-01-14] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Gateway\Screensaver\run_Gateway.exe /default [154144 2010-01-14] ()
HKU\User\...\Run: [EasyTether] "C:\Program Files (x86)\Mobile Stream\EasyTether\easytthr.exe" [48648 2011-05-22] (Mobile Stream)
HKU\User\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-07-22] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
ShortcutTarget: runctf.lnk -> C:\Users\User\127072486.exe ()
==================== Services (Whitelisted) ===================
2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [202048 2010-09-07] ()
2 WebrootSpySweeperService; "C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe" [3872776 2010-09-22] (Webroot Software, Inc. (www.webroot.com))
2 WRConsumerService; "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe" [3066528 2010-10-01] (Webroot Software, Inc. )
4 vToolbarUpdater14.0.1; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [x]
==================== Drivers (Whitelisted) =====================
3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-28] (Atheros Communications, Inc.)
1 avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [37720 2013-01-30] (AVG Technologies)
3 easytether; C:\Windows\System32\DRIVERS\easytthr.sys [20752 2011-05-22] (Mobile Stream)
3 hitmanpro37; C:\Windows\System32\Drivers\hitmanpro37.sys [32152 2013-02-21] ()
2 ssfmonm; C:\Windows\System32\Drivers\ssfmonm.sys [55360 2010-06-17] (Webroot Software, Inc. (www.webroot.com))
0 ssidrv; C:\Windows\System32\Drivers\ssidrv.sys [136224 2010-06-17] (Webroot Software, Inc. (www.webroot.com))
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-02-26 21:22 - 2013-02-26 21:23 - 95023320 ___AT C:\ProgramData\684270721.pad
2013-02-26 21:22 - 2013-02-26 21:22 - 00095232 ____A C:\Users\User\127072486.exe
2013-02-26 21:22 - 2013-02-26 21:22 - 00002756 ____A C:\ProgramData\684270721.js
2013-02-26 21:22 - 2013-02-26 21:22 - 00000155 ____A C:\ProgramData\684270721.reg
2013-02-26 21:22 - 2013-02-26 21:22 - 00000061 ____A C:\ProgramData\684270721.bat
2013-02-22 18:56 - 2013-01-03 21:41 - 01893224 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-02-22 18:56 - 2013-01-03 21:40 - 00287576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2013-02-22 18:56 - 2013-01-03 21:37 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2013-02-22 18:56 - 2013-01-03 21:37 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-02-22 18:56 - 2013-01-03 21:37 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2013-02-22 18:56 - 2013-01-03 21:36 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-02-22 18:56 - 2013-01-03 21:33 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2013-02-22 18:56 - 2013-01-03 21:30 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-02-22 18:56 - 2013-01-03 21:30 - 00424960 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:51 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-02-22 18:56 - 2013-01-03 20:51 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-02-22 18:56 - 2013-01-03 20:51 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 19:19 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-02-22 18:56 - 2013-01-03 18:48 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-02-22 18:56 - 2013-01-03 18:48 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-02-22 18:56 - 2013-01-03 18:48 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-02-22 18:56 - 2013-01-03 18:48 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-02-22 18:56 - 2013-01-03 18:43 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 18:43 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 18:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 18:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-02-22 18:54 - 2013-01-04 21:57 - 05500776 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-02-22 18:54 - 2013-01-04 21:02 - 03957608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-02-22 18:54 - 2013-01-04 21:02 - 03902312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-02-22 18:53 - 2013-01-03 19:22 - 03150848 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-02-21 17:52 - 2013-02-21 17:53 - 00005334 ____A C:\AdwCleaner[S1].txt
2013-02-21 17:48 - 2013-02-21 17:48 - 00004192 ____A C:\Users\User\Desktop\JRT.txt
2013-02-21 17:36 - 2013-02-21 17:36 - 00547439 ____A (Oleg N. Scherbakov) C:\Users\User\Desktop\JRT.exe
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\Windows\ERUNT
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\JRT
2013-02-21 16:59 - 2013-02-21 16:59 - 00006516 ____A C:\Windows\System32\.crusader
2013-02-21 16:44 - 2013-02-21 17:01 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-02-21 16:17 - 2013-02-21 16:17 - 00000963 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-21 16:17 - 2012-12-14 13:49 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-02-21 16:14 - 2013-02-21 16:14 - 01440846 ____A C:\Users\User\Downloads\mbam-chameleon-1.62.1.1000.zip
2013-02-21 11:31 - 2013-02-21 16:44 - 00001904 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2013-02-21 10:58 - 2013-02-21 11:06 - 00000000 ____D C:\Windows\pss
2013-02-21 10:37 - 2013-02-21 10:37 - 00003368 ____N C:\bootsqm.dat
2013-02-21 10:36 - 2013-02-21 10:36 - 00000000 __SHD C:\found.000
2013-02-14 11:28 - 2013-02-21 11:31 - 00000000 ____D C:\Program Files\HitmanPro
2013-02-14 10:55 - 2013-02-21 17:00 - 00000000 ____D C:\ProgramData\HitmanPro
2013-02-04 09:49 - 2013-02-04 09:49 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
==================== One Month Modified Files and Folders =======
2013-03-05 18:47 - 2013-03-05 18:47 - 00000000 ____D C:\FRST
2013-02-26 21:23 - 2013-02-26 21:22 - 95023320 ___AT C:\ProgramData\684270721.pad
2013-02-26 21:22 - 2013-02-26 21:22 - 00095232 ____A C:\Users\User\127072486.exe
2013-02-26 21:22 - 2013-02-26 21:22 - 00002756 ____A C:\ProgramData\684270721.js
2013-02-26 21:22 - 2013-02-26 21:22 - 00000155 ____A C:\ProgramData\684270721.reg
2013-02-26 21:22 - 2013-02-26 21:22 - 00000061 ____A C:\ProgramData\684270721.bat
2013-02-26 21:18 - 2010-09-14 14:35 - 01388670 ____A C:\Windows\WindowsUpdate.log
2013-02-26 21:17 - 2012-04-14 09:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-02-26 21:17 - 2010-12-28 22:16 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-02-26 16:34 - 2010-12-28 22:16 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-02-25 10:13 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-02-25 10:13 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-02-25 10:08 - 2013-01-30 10:07 - 00000354 ____A C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job
2013-02-25 10:06 - 2012-02-15 07:33 - 00000434 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2013-02-25 10:06 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-02-25 10:06 - 2009-07-13 20:51 - 00074221 ____A C:\Windows\setupact.log
2013-02-25 10:06 - 2009-07-13 20:45 - 00282320 ____A C:\Windows\System32\FNTCACHE.DAT
2013-02-22 21:13 - 2010-11-14 11:20 - 70004024 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-02-22 21:11 - 2009-07-13 21:13 - 00741680 ____A C:\Windows\System32\PerfStringBackup.INI
2013-02-21 18:14 - 2010-07-22 02:44 - 00936312 ____A C:\Windows\PFRO.log
2013-02-21 17:53 - 2013-02-21 17:52 - 00005334 ____A C:\AdwCleaner[S1].txt
2013-02-21 17:48 - 2013-02-21 17:48 - 00004192 ____A C:\Users\User\Desktop\JRT.txt
2013-02-21 17:36 - 2013-02-21 17:36 - 00547439 ____A (Oleg N. Scherbakov) C:\Users\User\Desktop\JRT.exe
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\Windows\ERUNT
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\JRT
2013-02-21 17:10 - 2012-04-14 09:20 - 00697712 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-02-21 17:10 - 2012-04-14 09:20 - 00074096 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-02-21 17:01 - 2013-02-21 16:44 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-02-21 17:01 - 2009-07-13 21:08 - 00032626 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-02-21 17:00 - 2013-02-14 10:55 - 00000000 ____D C:\ProgramData\HitmanPro
2013-02-21 16:59 - 2013-02-21 16:59 - 00006516 ____A C:\Windows\System32\.crusader
2013-02-21 16:44 - 2013-02-21 11:31 - 00001904 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2013-02-21 16:17 - 2013-02-21 16:17 - 00000963 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-21 16:14 - 2013-02-21 16:14 - 01440846 ____A C:\Users\User\Downloads\mbam-chameleon-1.62.1.1000.zip
2013-02-21 11:31 - 2013-02-14 11:28 - 00000000 ____D C:\Program Files\HitmanPro
2013-02-21 11:06 - 2013-02-21 10:58 - 00000000 ____D C:\Windows\pss
2013-02-21 10:37 - 2013-02-21 10:37 - 00003368 ____N C:\bootsqm.dat
2013-02-21 10:36 - 2013-02-21 10:36 - 00000000 __SHD C:\found.000
2013-02-05 08:59 - 2012-11-26 08:24 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2013-02-04 09:49 - 2013-02-04 09:49 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-01-01 21:12:07
Restore point made on: 2013-01-07 05:51:32
Restore point made on: 2013-01-10 10:39:12
Restore point made on: 2013-01-13 20:40:10
Restore point made on: 2013-01-20 20:30:26
Restore point made on: 2013-01-26 22:36:25
Restore point made on: 2013-02-03 21:14:50
Restore point made on: 2013-02-22 18:56:46
Restore point made on: 2013-02-22 21:07:36
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 3834.9 MB
Available physical RAM: 3143.06 MB
Total Pagefile: 3833.05 MB
Available Pagefile: 3125.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (Gateway) (Fixed) (Total:452.66 GB) (Free:370.31 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:13 GB) (Free:3.54 GB) NTFS
4 Drive g: (HITMANPRO) (Removable) (Total:14.88 GB) (Free:14.88 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Disk ID: 5F03A502
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 452 GB 13 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 13 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Gateway NTFS Partition 452 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Disk ID: 2F124634
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G HITMANPRO FAT32 Removable 14 GB Healthy
=========================================================
Last Boot: 2013-02-04 11:02
==================== End Of Log =============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-03-2013 01
Ran by SYSTEM at 05-03-2013 18:47:22
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] "C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe" [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2327952 2010-07-21] (Microsoft Corporation)
HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k [258304 2010-06-28] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-03-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] "C:\Program Files (x86)\Launch Manager\LManager.exe" [1300560 2010-03-03] (Dritek System Inc.)
HKLM-x32\...\Run: [WebrootTrayApp] "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe" [1286960 2010-10-01] (Webroot Software, Inc. )
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Gateway\Screensaver\run_Gateway.exe /default [154144 2010-01-14] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Gateway\Screensaver\run_Gateway.exe /default [154144 2010-01-14] ()
HKU\User\...\Run: [EasyTether] "C:\Program Files (x86)\Mobile Stream\EasyTether\easytthr.exe" [48648 2011-05-22] (Mobile Stream)
HKU\User\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-07-22] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
ShortcutTarget: runctf.lnk -> C:\Users\User\127072486.exe ()
==================== Services (Whitelisted) ===================
2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [202048 2010-09-07] ()
2 WebrootSpySweeperService; "C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe" [3872776 2010-09-22] (Webroot Software, Inc. (www.webroot.com))
2 WRConsumerService; "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe" [3066528 2010-10-01] (Webroot Software, Inc. )
4 vToolbarUpdater14.0.1; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [x]
==================== Drivers (Whitelisted) =====================
3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-28] (Atheros Communications, Inc.)
1 avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [37720 2013-01-30] (AVG Technologies)
3 easytether; C:\Windows\System32\DRIVERS\easytthr.sys [20752 2011-05-22] (Mobile Stream)
3 hitmanpro37; C:\Windows\System32\Drivers\hitmanpro37.sys [32152 2013-02-21] ()
2 ssfmonm; C:\Windows\System32\Drivers\ssfmonm.sys [55360 2010-06-17] (Webroot Software, Inc. (www.webroot.com))
0 ssidrv; C:\Windows\System32\Drivers\ssidrv.sys [136224 2010-06-17] (Webroot Software, Inc. (www.webroot.com))
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-02-26 21:22 - 2013-02-26 21:23 - 95023320 ___AT C:\ProgramData\684270721.pad
2013-02-26 21:22 - 2013-02-26 21:22 - 00095232 ____A C:\Users\User\127072486.exe
2013-02-26 21:22 - 2013-02-26 21:22 - 00002756 ____A C:\ProgramData\684270721.js
2013-02-26 21:22 - 2013-02-26 21:22 - 00000155 ____A C:\ProgramData\684270721.reg
2013-02-26 21:22 - 2013-02-26 21:22 - 00000061 ____A C:\ProgramData\684270721.bat
2013-02-22 18:56 - 2013-01-03 21:41 - 01893224 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-02-22 18:56 - 2013-01-03 21:40 - 00287576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2013-02-22 18:56 - 2013-01-03 21:37 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2013-02-22 18:56 - 2013-01-03 21:37 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-02-22 18:56 - 2013-01-03 21:37 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2013-02-22 18:56 - 2013-01-03 21:36 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-02-22 18:56 - 2013-01-03 21:33 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2013-02-22 18:56 - 2013-01-03 21:30 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-02-22 18:56 - 2013-01-03 21:30 - 00424960 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:27 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 21:26 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:51 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-02-22 18:56 - 2013-01-03 20:51 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-02-22 18:56 - 2013-01-03 20:51 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 20:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 19:19 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-02-22 18:56 - 2013-01-03 18:48 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-02-22 18:56 - 2013-01-03 18:48 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-02-22 18:56 - 2013-01-03 18:48 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-02-22 18:56 - 2013-01-03 18:48 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-02-22 18:56 - 2013-01-03 18:43 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 18:43 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 18:43 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-02-22 18:56 - 2013-01-03 18:43 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-02-22 18:54 - 2013-01-04 21:57 - 05500776 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-02-22 18:54 - 2013-01-04 21:02 - 03957608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-02-22 18:54 - 2013-01-04 21:02 - 03902312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-02-22 18:53 - 2013-01-03 19:22 - 03150848 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-02-21 17:52 - 2013-02-21 17:53 - 00005334 ____A C:\AdwCleaner[S1].txt
2013-02-21 17:48 - 2013-02-21 17:48 - 00004192 ____A C:\Users\User\Desktop\JRT.txt
2013-02-21 17:36 - 2013-02-21 17:36 - 00547439 ____A (Oleg N. Scherbakov) C:\Users\User\Desktop\JRT.exe
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\Windows\ERUNT
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\JRT
2013-02-21 16:59 - 2013-02-21 16:59 - 00006516 ____A C:\Windows\System32\.crusader
2013-02-21 16:44 - 2013-02-21 17:01 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-02-21 16:17 - 2013-02-21 16:17 - 00000963 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-21 16:17 - 2012-12-14 13:49 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-02-21 16:14 - 2013-02-21 16:14 - 01440846 ____A C:\Users\User\Downloads\mbam-chameleon-1.62.1.1000.zip
2013-02-21 11:31 - 2013-02-21 16:44 - 00001904 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2013-02-21 10:58 - 2013-02-21 11:06 - 00000000 ____D C:\Windows\pss
2013-02-21 10:37 - 2013-02-21 10:37 - 00003368 ____N C:\bootsqm.dat
2013-02-21 10:36 - 2013-02-21 10:36 - 00000000 __SHD C:\found.000
2013-02-14 11:28 - 2013-02-21 11:31 - 00000000 ____D C:\Program Files\HitmanPro
2013-02-14 10:55 - 2013-02-21 17:00 - 00000000 ____D C:\ProgramData\HitmanPro
2013-02-04 09:49 - 2013-02-04 09:49 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
==================== One Month Modified Files and Folders =======
2013-03-05 18:47 - 2013-03-05 18:47 - 00000000 ____D C:\FRST
2013-02-26 21:23 - 2013-02-26 21:22 - 95023320 ___AT C:\ProgramData\684270721.pad
2013-02-26 21:22 - 2013-02-26 21:22 - 00095232 ____A C:\Users\User\127072486.exe
2013-02-26 21:22 - 2013-02-26 21:22 - 00002756 ____A C:\ProgramData\684270721.js
2013-02-26 21:22 - 2013-02-26 21:22 - 00000155 ____A C:\ProgramData\684270721.reg
2013-02-26 21:22 - 2013-02-26 21:22 - 00000061 ____A C:\ProgramData\684270721.bat
2013-02-26 21:18 - 2010-09-14 14:35 - 01388670 ____A C:\Windows\WindowsUpdate.log
2013-02-26 21:17 - 2012-04-14 09:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-02-26 21:17 - 2010-12-28 22:16 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-02-26 16:34 - 2010-12-28 22:16 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-02-25 10:13 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-02-25 10:13 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-02-25 10:08 - 2013-01-30 10:07 - 00000354 ____A C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job
2013-02-25 10:06 - 2012-02-15 07:33 - 00000434 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2013-02-25 10:06 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-02-25 10:06 - 2009-07-13 20:51 - 00074221 ____A C:\Windows\setupact.log
2013-02-25 10:06 - 2009-07-13 20:45 - 00282320 ____A C:\Windows\System32\FNTCACHE.DAT
2013-02-22 21:13 - 2010-11-14 11:20 - 70004024 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-02-22 21:11 - 2009-07-13 21:13 - 00741680 ____A C:\Windows\System32\PerfStringBackup.INI
2013-02-21 18:14 - 2010-07-22 02:44 - 00936312 ____A C:\Windows\PFRO.log
2013-02-21 17:53 - 2013-02-21 17:52 - 00005334 ____A C:\AdwCleaner[S1].txt
2013-02-21 17:48 - 2013-02-21 17:48 - 00004192 ____A C:\Users\User\Desktop\JRT.txt
2013-02-21 17:36 - 2013-02-21 17:36 - 00547439 ____A (Oleg N. Scherbakov) C:\Users\User\Desktop\JRT.exe
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\Windows\ERUNT
2013-02-21 17:36 - 2013-02-21 17:36 - 00000000 ____D C:\JRT
2013-02-21 17:10 - 2012-04-14 09:20 - 00697712 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-02-21 17:10 - 2012-04-14 09:20 - 00074096 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-02-21 17:01 - 2013-02-21 16:44 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-02-21 17:01 - 2009-07-13 21:08 - 00032626 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-02-21 17:00 - 2013-02-14 10:55 - 00000000 ____D C:\ProgramData\HitmanPro
2013-02-21 16:59 - 2013-02-21 16:59 - 00006516 ____A C:\Windows\System32\.crusader
2013-02-21 16:44 - 2013-02-21 11:31 - 00001904 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2013-02-21 16:17 - 2013-02-21 16:17 - 00000963 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-02-21 16:17 - 2013-02-21 16:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-21 16:14 - 2013-02-21 16:14 - 01440846 ____A C:\Users\User\Downloads\mbam-chameleon-1.62.1.1000.zip
2013-02-21 11:31 - 2013-02-14 11:28 - 00000000 ____D C:\Program Files\HitmanPro
2013-02-21 11:06 - 2013-02-21 10:58 - 00000000 ____D C:\Windows\pss
2013-02-21 10:37 - 2013-02-21 10:37 - 00003368 ____N C:\bootsqm.dat
2013-02-21 10:36 - 2013-02-21 10:36 - 00000000 __SHD C:\found.000
2013-02-05 08:59 - 2012-11-26 08:24 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2013-02-04 09:49 - 2013-02-04 09:49 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-01-01 21:12:07
Restore point made on: 2013-01-07 05:51:32
Restore point made on: 2013-01-10 10:39:12
Restore point made on: 2013-01-13 20:40:10
Restore point made on: 2013-01-20 20:30:26
Restore point made on: 2013-01-26 22:36:25
Restore point made on: 2013-02-03 21:14:50
Restore point made on: 2013-02-22 18:56:46
Restore point made on: 2013-02-22 21:07:36
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 3834.9 MB
Available physical RAM: 3143.06 MB
Total Pagefile: 3833.05 MB
Available Pagefile: 3125.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (Gateway) (Fixed) (Total:452.66 GB) (Free:370.31 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:13 GB) (Free:3.54 GB) NTFS
4 Drive g: (HITMANPRO) (Removable) (Total:14.88 GB) (Free:14.88 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Disk ID: 5F03A502
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 452 GB 13 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 13 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Gateway NTFS Partition 452 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Disk ID: 2F124634
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G HITMANPRO FAT32 Removable 14 GB Healthy
=========================================================
Last Boot: 2013-02-04 11:02
==================== End Of Log =============================