Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Removing help of virus "gesellschaft zur verfügung von urheberrechtsverletzungen"
Message
<blockquote data-quote="ashash" data-source="post: 116973" data-attributes="member: 7542"><p>Hi,</p><p></p><p>Thanks a lot for reply ... Below is the content of FRST.txt file. Please help me to remove virus.</p><p></p><p>FRST.txt</p><p>---------</p><p>Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-04-2013 (ATTENTION: FRST version is 6 days old)</p><p>Ran by Sanchit at 17-04-2013 13:41:23</p><p>Running from E:\</p><p> Service Pack 1 (X64) OS Language: English(US) </p><p>Attention: Could not load system hive.</p><p>ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.</p><p></p><p></p><p>==================== One Month Created Files and Folders ========</p><p></p><p>2013-04-17 13:41 - 2013-04-17 13:41 - 00000000 ____D C:\FRST</p><p>2013-04-10 14:01 - 2013-04-10 14:01 - 00000000 ____D C:\Windows\pss</p><p>2013-04-09 21:50 - 2013-04-14 10:33 - 00001823 ____A C:\Users\Public\Desktop\HitmanPro.lnk</p><p>2013-04-09 21:50 - 2013-04-09 21:50 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys</p><p>2013-04-09 21:50 - 2013-04-09 21:50 - 00000000 ____D C:\Program Files\HitmanPro</p><p>2013-04-09 21:49 - 2013-04-09 21:49 - 00000000 ____D C:\ProgramData\HitmanPro</p><p>2013-04-09 21:11 - 2013-04-09 21:11 - 00000000 __SHD C:\found.001</p><p>2013-04-09 20:41 - 2013-04-09 20:42 - 09741664 ____A (SurfRight B.V.) C:\Users\Sanchit\Downloads\HitmanPro_x64.exe</p><p>2013-04-09 10:40 - 2013-04-09 10:40 - 00006768 ____N C:\bootsqm.dat</p><p>2013-04-09 10:37 - 2013-04-09 10:37 - 00000000 __SHD C:\found.000</p><p>2013-04-09 08:03 - 2013-04-09 08:03 - 00000000 ____D C:\ProgramData\ltmrj</p><p>2013-04-09 00:45 - 2013-04-09 00:45 - 00141080 ____A (Hilgraeve, Inc.) C:\Users\Sanchit\Desktop\jfgb.tmp</p><p>2013-04-03 19:16 - 2013-04-08 09:29 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Riom</p><p>2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Saqivu</p><p>2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Essybe</p><p>2013-04-03 14:19 - 2013-04-03 14:19 - 00012737 ____A C:\Users\Sanchit\Desktop\hs_err_pid12100.log</p><p>2013-03-31 10:33 - 2013-03-31 10:33 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{56247787-5527-4C84-AFF1-526BFB67A65B}</p><p>2013-03-30 15:57 - 2013-03-30 15:57 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{FD858EF5-6B23-403E-A310-157FA49C236D}</p><p>2013-03-29 11:47 - 2013-03-30 02:10 - 00000000 ____D C:\Users\Sanchit\.android</p><p>2013-03-26 22:24 - 2013-03-26 22:24 - 00000000 ____D C:\Users\Public\Juniper Networks</p><p>2013-03-26 22:24 - 2012-05-05 03:17 - 00590472 ____A (Juniper Networks) C:\Windows\System32\dsNcSmartCardProv.dll</p><p>2013-03-26 22:24 - 2012-05-05 03:17 - 00422024 ____A (Juniper Networks) C:\Windows\System32\dsNcCredProv.dll</p><p>2013-03-26 21:29 - 2013-03-26 21:29 - 00262144 ____A C:\Windows\Minidump\032613-30997-01.dmp</p><p>2013-03-26 21:25 - 2013-03-26 21:25 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit (1).rar</p><p>2013-03-26 21:25 - 2013-03-26 19:11 - 00205247 ____A C:\Users\Sanchit\Downloads\Sanchit.apk</p><p>2013-03-26 21:23 - 2013-03-26 21:23 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit.rar</p><p>2013-03-26 01:09 - 2013-03-26 01:09 - 00000018 ____A C:\pending.un</p><p>2013-03-26 01:09 - 2012-05-05 03:27 - 00099152 ____A (Juniper Networks) C:\Windows\System32\Drivers\NEOFLTR_719_20893.SYS</p><p>2013-03-23 00:27 - 2013-03-23 00:27 - 01633280 ____A C:\Users\Sanchit\Downloads\NGIN SNEC40 Multidomain ATP for TDE(For TMS import)V0.3.xls</p><p>2013-03-20 22:48 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys</p><p>2013-03-20 22:28 - 2013-03-20 22:28 - 00000096 ____A C:\Users\Sanchit\Downloads\Menu.txt</p><p>2013-03-20 13:08 - 2013-03-20 13:08 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Google</p><p>2013-03-19 18:42 - 2013-03-19 18:42 - 00262144 ____A C:\Windows\Minidump\031913-30123-01.dmp</p><p>2013-03-19 18:41 - 2013-03-26 21:29 - 572101397 ____A C:\Windows\MEMORY.DMP</p><p>2013-03-19 00:07 - 2013-03-19 00:07 - 08151705 ____A C:\Users\Sanchit\Downloads\com.goldron.bbfree-1.0.apk</p><p></p><p>==================== One Month Modified Files and Folders =======</p><p></p><p>2013-04-17 10:32 - 2011-06-12 13:52 - 00000000 ____D C:\ProgramData\Sonic</p><p>2013-04-14 10:34 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0</p><p>2013-04-14 10:34 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0</p><p>2013-04-14 10:33 - 2013-04-09 21:50 - 00001823 ____A C:\Users\Public\Desktop\HitmanPro.lnk</p><p>2013-04-14 10:22 - 2013-04-10 14:01 - 00000000 ____D C:\Windows\pss</p><p>2013-04-10 14:57 - 2012-08-24 23:48 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job</p><p>2013-04-10 14:57 - 2011-06-17 21:15 - 00000000 ____D C:\Program Files (x86)\Giraffic</p><p>2013-04-10 14:57 - 2011-06-12 14:02 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup</p><p>2013-04-10 14:56 - 2013-01-19 15:43 - 00007284 ____A C:\Windows\setupact.log</p><p>2013-04-10 14:56 - 2011-06-18 13:48 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job</p><p>2013-04-10 14:56 - 2011-06-12 14:13 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks</p><p>2013-04-10 14:56 - 2011-06-12 14:13 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks</p><p>2013-04-10 14:56 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT</p><p>2013-04-10 14:51 - 2011-06-12 13:27 - 01171389 ____A C:\Windows\WindowsUpdate.log</p><p>2013-04-10 14:19 - 2009-07-14 07:13 - 00006732 ____A C:\Windows\System32\PerfStringBackup.INI</p><p>2013-04-09 21:50 - 2013-04-09 21:50 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys</p><p>2013-04-09 21:50 - 2013-04-09 21:50 - 00000000 ____D C:\Program Files\HitmanPro</p><p>2013-04-09 21:49 - 2013-04-09 21:49 - 00000000 ____D C:\ProgramData\HitmanPro</p><p>2013-04-09 21:11 - 2013-04-09 21:11 - 00000000 __SHD C:\found.001</p><p>2013-04-09 20:42 - 2013-04-09 20:41 - 09741664 ____A (SurfRight B.V.) C:\Users\Sanchit\Downloads\HitmanPro_x64.exe</p><p>2013-04-09 19:28 - 2011-11-19 20:25 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000UA.job</p><p>2013-04-09 19:28 - 2011-06-18 13:48 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job</p><p>2013-04-09 19:28 - 2011-06-15 20:07 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000UA.job</p><p>2013-04-09 10:40 - 2013-04-09 10:40 - 00006768 ____N C:\bootsqm.dat</p><p>2013-04-09 10:37 - 2013-04-09 10:37 - 00000000 __SHD C:\found.000</p><p>2013-04-09 08:08 - 2011-11-19 20:25 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000Core.job</p><p>2013-04-09 08:03 - 2013-04-09 08:03 - 00000000 ____D C:\ProgramData\ltmrj</p><p>2013-04-09 08:01 - 2011-06-18 13:47 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Skype</p><p>2013-04-09 00:45 - 2013-04-09 00:45 - 00141080 ____A (Hilgraeve, Inc.) C:\Users\Sanchit\Desktop\jfgb.tmp</p><p>2013-04-09 00:45 - 2011-06-15 13:01 - 00000000 ____D C:\users\Sanchit</p><p>2013-04-08 23:31 - 2011-06-15 20:07 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000Core.job</p><p>2013-04-08 17:32 - 2011-06-15 14:17 - 00022016 ____A C:\Users\Sanchit\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini</p><p>2013-04-08 09:29 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Riom</p><p>2013-04-07 08:22 - 2012-07-10 22:54 - 00000000 ___RD C:\Program Files (x86)\Skype</p><p>2013-04-07 08:22 - 2011-06-12 13:57 - 00000000 ____D C:\ProgramData\Skype</p><p>2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Saqivu</p><p>2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Essybe</p><p>2013-04-03 14:19 - 2013-04-03 14:19 - 00012737 ____A C:\Users\Sanchit\Desktop\hs_err_pid12100.log</p><p>2013-04-02 23:21 - 2011-08-05 19:39 - 00000000 ____D C:\Sandeep</p><p>2013-04-02 14:31 - 2011-06-15 19:25 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Mozilla</p><p>2013-03-31 15:32 - 2011-11-06 18:34 - 00002384 ____A C:\Users\Sanchit\Desktop\Google Chrome.lnk</p><p>2013-03-31 10:33 - 2013-03-31 10:33 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{56247787-5527-4C84-AFF1-526BFB67A65B}</p><p>2013-03-30 15:57 - 2013-03-30 15:57 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{FD858EF5-6B23-403E-A310-157FA49C236D}</p><p>2013-03-30 02:10 - 2013-03-29 11:47 - 00000000 ____D C:\Users\Sanchit\.android</p><p>2013-03-30 01:14 - 2011-11-17 01:20 - 00000000 ____D C:\Users\Sanchit\workspace</p><p>2013-03-29 01:07 - 2012-08-24 23:23 - 00000000 ____D C:\Users\Sanchit\Documents\Software</p><p>2013-03-28 17:25 - 2011-10-26 23:00 - 00000000 ____D C:\Users\Sanchit\AppData\Local\Windows Live</p><p>2013-03-26 22:24 - 2013-03-26 22:24 - 00000000 ____D C:\Users\Public\Juniper Networks</p><p>2013-03-26 22:24 - 2011-11-20 14:22 - 00000000 ____D C:\Program Files (x86)\Juniper Networks</p><p>2013-03-26 22:24 - 2011-11-20 14:21 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Juniper Networks</p><p>2013-03-26 21:29 - 2013-03-26 21:29 - 00262144 ____A C:\Windows\Minidump\032613-30997-01.dmp</p><p>2013-03-26 21:29 - 2013-03-19 18:41 - 572101397 ____A C:\Windows\MEMORY.DMP</p><p>2013-03-26 21:29 - 2011-09-15 02:41 - 00000000 ____D C:\Windows\Minidump</p><p>2013-03-26 21:25 - 2013-03-26 21:25 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit (1).rar</p><p>2013-03-26 21:23 - 2013-03-26 21:23 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit.rar</p><p>2013-03-26 19:11 - 2013-03-26 21:25 - 00205247 ____A C:\Users\Sanchit\Downloads\Sanchit.apk</p><p>2013-03-26 01:09 - 2013-03-26 01:09 - 00000018 ____A C:\pending.un</p><p>2013-03-23 00:27 - 2013-03-23 00:27 - 01633280 ____A C:\Users\Sanchit\Downloads\NGIN SNEC40 Multidomain ATP for TDE(For TMS import)V0.3.xls</p><p>2013-03-20 22:28 - 2013-03-20 22:28 - 00000096 ____A C:\Users\Sanchit\Downloads\Menu.txt</p><p>2013-03-20 13:08 - 2013-03-20 13:08 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Google</p><p>2013-03-20 13:08 - 2011-06-15 20:07 - 00000000 ____D C:\Users\Sanchit\AppData\Local\Google</p><p>2013-03-20 00:59 - 2011-11-21 22:21 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\vlc</p><p>2013-03-19 18:42 - 2013-03-19 18:42 - 00262144 ____A C:\Windows\Minidump\031913-30123-01.dmp</p><p>2013-03-19 00:07 - 2013-03-19 00:07 - 08151705 ____A C:\Users\Sanchit\Downloads\com.goldron.bbfree-1.0.apk</p><p></p><p></p><p>ZeroAccess:</p><p>C:\$Recycle.Bin\S-1-5-21-2092152589-3654524724-1465183675-1000\$3b99f81f31d5dbab1bcf87d0107a285a</p><p></p><p>ZeroAccess:</p><p>C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a</p><p></p><p>==================== Bamital & volsnap Check =================</p><p></p><p>C:\Windows\System32\winlogon.exe => MD5 is legit</p><p>C:\Windows\System32\wininit.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\wininit.exe => MD5 is legit</p><p>C:\Windows\explorer.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\explorer.exe => MD5 is legit</p><p>C:\Windows\System32\svchost.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\svchost.exe => MD5 is legit</p><p>C:\Windows\System32\services.exe => MD5 is legit</p><p>C:\Windows\System32\User32.dll => MD5 is legit</p><p>C:\Windows\SysWOW64\User32.dll => MD5 is legit</p><p>C:\Windows\System32\userinit.exe => MD5 is legit</p><p>C:\Windows\SysWOW64\userinit.exe => MD5 is legit</p><p>C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit</p><p></p><p>==================== Restore Points =========================</p><p></p><p></p><p>==================== Memory info =========================== </p><p></p><p>Percentage of memory in use: 11%</p><p>Total physical RAM: 4003.18 MB</p><p>Available physical RAM: 3535.78 MB</p><p>Total Pagefile: 8004.54 MB</p><p>Available Pagefile: 7546.76 MB</p><p>Total Virtual: 8192 MB</p><p>Available Virtual: 8191.88 MB</p><p></p><p>==================== Partitions =============================</p><p></p><p>1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:45.04 GB) NTFS</p><p>3 Drive e: () (Removable) (Total:29.8 GB) (Free:12.95 GB) FAT32</p><p></p><p>See the System Event Log for more information.</p><p></p><p>============================== MBR Partition Table ==================</p><p></p><p></p><p>Last Boot: 2013-04-04 08:46</p><p></p><p>==================== End Of Log =============================</p></blockquote><p></p>
[QUOTE="ashash, post: 116973, member: 7542"] Hi, Thanks a lot for reply ... Below is the content of FRST.txt file. Please help me to remove virus. FRST.txt --------- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-04-2013 (ATTENTION: FRST version is 6 days old) Ran by Sanchit at 17-04-2013 13:41:23 Running from E:\ Service Pack 1 (X64) OS Language: English(US) Attention: Could not load system hive. ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY. ==================== One Month Created Files and Folders ======== 2013-04-17 13:41 - 2013-04-17 13:41 - 00000000 ____D C:\FRST 2013-04-10 14:01 - 2013-04-10 14:01 - 00000000 ____D C:\Windows\pss 2013-04-09 21:50 - 2013-04-14 10:33 - 00001823 ____A C:\Users\Public\Desktop\HitmanPro.lnk 2013-04-09 21:50 - 2013-04-09 21:50 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys 2013-04-09 21:50 - 2013-04-09 21:50 - 00000000 ____D C:\Program Files\HitmanPro 2013-04-09 21:49 - 2013-04-09 21:49 - 00000000 ____D C:\ProgramData\HitmanPro 2013-04-09 21:11 - 2013-04-09 21:11 - 00000000 __SHD C:\found.001 2013-04-09 20:41 - 2013-04-09 20:42 - 09741664 ____A (SurfRight B.V.) C:\Users\Sanchit\Downloads\HitmanPro_x64.exe 2013-04-09 10:40 - 2013-04-09 10:40 - 00006768 ____N C:\bootsqm.dat 2013-04-09 10:37 - 2013-04-09 10:37 - 00000000 __SHD C:\found.000 2013-04-09 08:03 - 2013-04-09 08:03 - 00000000 ____D C:\ProgramData\ltmrj 2013-04-09 00:45 - 2013-04-09 00:45 - 00141080 ____A (Hilgraeve, Inc.) C:\Users\Sanchit\Desktop\jfgb.tmp 2013-04-03 19:16 - 2013-04-08 09:29 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Riom 2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Saqivu 2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Essybe 2013-04-03 14:19 - 2013-04-03 14:19 - 00012737 ____A C:\Users\Sanchit\Desktop\hs_err_pid12100.log 2013-03-31 10:33 - 2013-03-31 10:33 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{56247787-5527-4C84-AFF1-526BFB67A65B} 2013-03-30 15:57 - 2013-03-30 15:57 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{FD858EF5-6B23-403E-A310-157FA49C236D} 2013-03-29 11:47 - 2013-03-30 02:10 - 00000000 ____D C:\Users\Sanchit\.android 2013-03-26 22:24 - 2013-03-26 22:24 - 00000000 ____D C:\Users\Public\Juniper Networks 2013-03-26 22:24 - 2012-05-05 03:17 - 00590472 ____A (Juniper Networks) C:\Windows\System32\dsNcSmartCardProv.dll 2013-03-26 22:24 - 2012-05-05 03:17 - 00422024 ____A (Juniper Networks) C:\Windows\System32\dsNcCredProv.dll 2013-03-26 21:29 - 2013-03-26 21:29 - 00262144 ____A C:\Windows\Minidump\032613-30997-01.dmp 2013-03-26 21:25 - 2013-03-26 21:25 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit (1).rar 2013-03-26 21:25 - 2013-03-26 19:11 - 00205247 ____A C:\Users\Sanchit\Downloads\Sanchit.apk 2013-03-26 21:23 - 2013-03-26 21:23 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit.rar 2013-03-26 01:09 - 2013-03-26 01:09 - 00000018 ____A C:\pending.un 2013-03-26 01:09 - 2012-05-05 03:27 - 00099152 ____A (Juniper Networks) C:\Windows\System32\Drivers\NEOFLTR_719_20893.SYS 2013-03-23 00:27 - 2013-03-23 00:27 - 01633280 ____A C:\Users\Sanchit\Downloads\NGIN SNEC40 Multidomain ATP for TDE(For TMS import)V0.3.xls 2013-03-20 22:48 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys 2013-03-20 22:28 - 2013-03-20 22:28 - 00000096 ____A C:\Users\Sanchit\Downloads\Menu.txt 2013-03-20 13:08 - 2013-03-20 13:08 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Google 2013-03-19 18:42 - 2013-03-19 18:42 - 00262144 ____A C:\Windows\Minidump\031913-30123-01.dmp 2013-03-19 18:41 - 2013-03-26 21:29 - 572101397 ____A C:\Windows\MEMORY.DMP 2013-03-19 00:07 - 2013-03-19 00:07 - 08151705 ____A C:\Users\Sanchit\Downloads\com.goldron.bbfree-1.0.apk ==================== One Month Modified Files and Folders ======= 2013-04-17 10:32 - 2011-06-12 13:52 - 00000000 ____D C:\ProgramData\Sonic 2013-04-14 10:34 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-14 10:34 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-14 10:33 - 2013-04-09 21:50 - 00001823 ____A C:\Users\Public\Desktop\HitmanPro.lnk 2013-04-14 10:22 - 2013-04-10 14:01 - 00000000 ____D C:\Windows\pss 2013-04-10 14:57 - 2012-08-24 23:48 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-04-10 14:57 - 2011-06-17 21:15 - 00000000 ____D C:\Program Files (x86)\Giraffic 2013-04-10 14:57 - 2011-06-12 14:02 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2013-04-10 14:56 - 2013-01-19 15:43 - 00007284 ____A C:\Windows\setupact.log 2013-04-10 14:56 - 2011-06-18 13:48 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-04-10 14:56 - 2011-06-12 14:13 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks 2013-04-10 14:56 - 2011-06-12 14:13 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks 2013-04-10 14:56 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-10 14:51 - 2011-06-12 13:27 - 01171389 ____A C:\Windows\WindowsUpdate.log 2013-04-10 14:19 - 2009-07-14 07:13 - 00006732 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-09 21:50 - 2013-04-09 21:50 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys 2013-04-09 21:50 - 2013-04-09 21:50 - 00000000 ____D C:\Program Files\HitmanPro 2013-04-09 21:49 - 2013-04-09 21:49 - 00000000 ____D C:\ProgramData\HitmanPro 2013-04-09 21:11 - 2013-04-09 21:11 - 00000000 __SHD C:\found.001 2013-04-09 20:42 - 2013-04-09 20:41 - 09741664 ____A (SurfRight B.V.) C:\Users\Sanchit\Downloads\HitmanPro_x64.exe 2013-04-09 19:28 - 2011-11-19 20:25 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000UA.job 2013-04-09 19:28 - 2011-06-18 13:48 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-04-09 19:28 - 2011-06-15 20:07 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000UA.job 2013-04-09 10:40 - 2013-04-09 10:40 - 00006768 ____N C:\bootsqm.dat 2013-04-09 10:37 - 2013-04-09 10:37 - 00000000 __SHD C:\found.000 2013-04-09 08:08 - 2011-11-19 20:25 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000Core.job 2013-04-09 08:03 - 2013-04-09 08:03 - 00000000 ____D C:\ProgramData\ltmrj 2013-04-09 08:01 - 2011-06-18 13:47 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Skype 2013-04-09 00:45 - 2013-04-09 00:45 - 00141080 ____A (Hilgraeve, Inc.) C:\Users\Sanchit\Desktop\jfgb.tmp 2013-04-09 00:45 - 2011-06-15 13:01 - 00000000 ____D C:\users\Sanchit 2013-04-08 23:31 - 2011-06-15 20:07 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000Core.job 2013-04-08 17:32 - 2011-06-15 14:17 - 00022016 ____A C:\Users\Sanchit\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-04-08 09:29 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Riom 2013-04-07 08:22 - 2012-07-10 22:54 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-04-07 08:22 - 2011-06-12 13:57 - 00000000 ____D C:\ProgramData\Skype 2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Saqivu 2013-04-03 19:16 - 2013-04-03 19:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Essybe 2013-04-03 14:19 - 2013-04-03 14:19 - 00012737 ____A C:\Users\Sanchit\Desktop\hs_err_pid12100.log 2013-04-02 23:21 - 2011-08-05 19:39 - 00000000 ____D C:\Sandeep 2013-04-02 14:31 - 2011-06-15 19:25 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Mozilla 2013-03-31 15:32 - 2011-11-06 18:34 - 00002384 ____A C:\Users\Sanchit\Desktop\Google Chrome.lnk 2013-03-31 10:33 - 2013-03-31 10:33 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{56247787-5527-4C84-AFF1-526BFB67A65B} 2013-03-30 15:57 - 2013-03-30 15:57 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{FD858EF5-6B23-403E-A310-157FA49C236D} 2013-03-30 02:10 - 2013-03-29 11:47 - 00000000 ____D C:\Users\Sanchit\.android 2013-03-30 01:14 - 2011-11-17 01:20 - 00000000 ____D C:\Users\Sanchit\workspace 2013-03-29 01:07 - 2012-08-24 23:23 - 00000000 ____D C:\Users\Sanchit\Documents\Software 2013-03-28 17:25 - 2011-10-26 23:00 - 00000000 ____D C:\Users\Sanchit\AppData\Local\Windows Live 2013-03-26 22:24 - 2013-03-26 22:24 - 00000000 ____D C:\Users\Public\Juniper Networks 2013-03-26 22:24 - 2011-11-20 14:22 - 00000000 ____D C:\Program Files (x86)\Juniper Networks 2013-03-26 22:24 - 2011-11-20 14:21 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Juniper Networks 2013-03-26 21:29 - 2013-03-26 21:29 - 00262144 ____A C:\Windows\Minidump\032613-30997-01.dmp 2013-03-26 21:29 - 2013-03-19 18:41 - 572101397 ____A C:\Windows\MEMORY.DMP 2013-03-26 21:29 - 2011-09-15 02:41 - 00000000 ____D C:\Windows\Minidump 2013-03-26 21:25 - 2013-03-26 21:25 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit (1).rar 2013-03-26 21:23 - 2013-03-26 21:23 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit.rar 2013-03-26 19:11 - 2013-03-26 21:25 - 00205247 ____A C:\Users\Sanchit\Downloads\Sanchit.apk 2013-03-26 01:09 - 2013-03-26 01:09 - 00000018 ____A C:\pending.un 2013-03-23 00:27 - 2013-03-23 00:27 - 01633280 ____A C:\Users\Sanchit\Downloads\NGIN SNEC40 Multidomain ATP for TDE(For TMS import)V0.3.xls 2013-03-20 22:28 - 2013-03-20 22:28 - 00000096 ____A C:\Users\Sanchit\Downloads\Menu.txt 2013-03-20 13:08 - 2013-03-20 13:08 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Google 2013-03-20 13:08 - 2011-06-15 20:07 - 00000000 ____D C:\Users\Sanchit\AppData\Local\Google 2013-03-20 00:59 - 2011-11-21 22:21 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\vlc 2013-03-19 18:42 - 2013-03-19 18:42 - 00262144 ____A C:\Windows\Minidump\031913-30123-01.dmp 2013-03-19 00:07 - 2013-03-19 00:07 - 08151705 ____A C:\Users\Sanchit\Downloads\com.goldron.bbfree-1.0.apk ZeroAccess: C:\$Recycle.Bin\S-1-5-21-2092152589-3654524724-1465183675-1000\$3b99f81f31d5dbab1bcf87d0107a285a ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 4003.18 MB Available physical RAM: 3535.78 MB Total Pagefile: 8004.54 MB Available Pagefile: 7546.76 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:45.04 GB) NTFS 3 Drive e: () (Removable) (Total:29.8 GB) (Free:12.95 GB) FAT32 See the System Event Log for more information. ============================== MBR Partition Table ================== Last Boot: 2013-04-04 08:46 ==================== End Of Log ============================= [/QUOTE]
Insert quotes…
Verification
Post reply
Top