Hello everybody,
I tried all the Sunday to remove Sirefef but I stay unsuccessful.
I read a lot of post and I've done the same thing as in the other ones, here are the two log files from FRST:
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 05-08-2012
Ran by SYSTEM at 05-08-2012 18:11:02
Running from G:\sirefef removal
Windows Vista (TM) Home Premium (X86) OS Language: German Standard
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2007-08-28] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [154136 2007-08-28] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [137752 2007-08-28] (Intel Corporation)
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [159744 2007-06-30] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" [181544 2007-09-30] (CyberLink Corp.)
HKLM\...\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [202032 2007-09-27] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0" [222504 2007-09-13] (CyberLink Corp.)
HKLM\...\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [x]
HKLM\...\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [40048 2007-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM\...\Run: [] [x]
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-10-09] (Apple Inc.)
HKLM\...\Run: [crrss] C:\Windows\system32\crrss.exe [44544 2010-02-03] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Beatrice\...\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background [5674352 2007-01-19] (Microsoft Corporation)
HKU\Beatrice\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\Beatrice\...\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" [247728 2012-01-23] (TomTom)
HKU\Beatrice\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [201728 2006-11-02] (Microsoft Corporation)
HKU\Beatrice\...\Run: [wevtutil] C:\Users\Beatrice\AppData\Local\Microsoft\Windows\4933\wevtutil.exe [53760 2012-08-02] ()
HKU\Beatrice\...\Run: [rdrlunas] rundll32 "C:\Users\Beatrice\AppData\Local\Temp\dvduhost.dll",CreateProcessNotify [x]
HKU\Beatrice\...\Run: [winlogon] C:\Users\Beatrice\winlogon.exe [44544 2010-02-03] ()
HKU\Beatrice\...\Winlogon: [Shell] explorer.exe "C:\Users\Beatrice\winlogon.exe" [44544 2010-02-03] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Windows\system32\crrss.exe [44544 2010-02-03] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
================================ Services (Whitelisted) ==================
3 Com4Qlb; "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe" [110592 2007-03-05] (Hewlett-Packard Development Company, L.P.)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [22016 2006-11-02] (Microsoft Corporation)
2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.)
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [272024 2007-01-09] ()
3 usnjsvc; "C:\Program Files\MSN Messenger\usnsvc.exe" [97136 2007-01-19] (Microsoft Corporation)
2 HP Health Check Service; "c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe" [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
========================== Drivers (Whitelisted) =============
3 HBtnKey; C:\Windows\System32\DRIVERS\cpqbttn.sys [9472 2006-06-28] (Hewlett-Packard Development Company, L.P.)
3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [176640 2007-10-11] (Conexant Systems Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
1 nwjvqslu; \??\C:\Windows\system32\drivers\nwjvqslu.sys [42960 2012-08-05] (Microsoft Corporation)
3 RTL8023xp; C:\Windows\System32\DRIVERS\Rtnicxp.sys [50176 2007-04-23] (Realtek Semiconductor Corporation )
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
1 eabfiltr; [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 SymIM; C:\Windows\System32\DRIVERS\SymIM.sys [x]
3 SymIMMP; C:\Windows\System32\DRIVERS\SymIM.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-05 18:10 - 2012-08-05 18:10 - 00000000 ____D C:\FRST
2012-08-05 17:05 - 2012-08-05 17:05 - 00042960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nwjvqslu.sys
2012-08-05 14:12 - 2012-08-05 14:12 - 00000000 ____D C:\Program Files\SpeedyPC Software
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\Application Data\SpeedyPC Software
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\Application Data\DriverCure
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\AppData\Roaming\SpeedyPC Software
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\AppData\Roaming\DriverCure
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-08-05 11:14 - 2012-08-05 11:08 - 04986272 ____A (SpeedyPC Software) C:\Users\Beatrice\Desktop\2-SpeedyPC Pro Installer.exe
2012-08-05 11:14 - 2012-08-05 11:08 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Beatrice\Desktop\3-SpyHunter-Installer.exe
2012-08-05 11:14 - 2012-08-05 11:07 - 00001205 ____A C:\Users\Beatrice\Desktop\FixNCR.reg
2012-08-05 11:14 - 2012-08-05 10:51 - 00064009 ____A C:\Users\Beatrice\Desktop\562354_2.zip
2012-08-04 19:47 - 2012-08-04 19:52 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-08-04 19:47 - 2012-08-04 19:47 - 00001061 ____A C:\Users\Beatrice\Desktop\Spybot - Search & Destroy.lnk
2012-08-04 19:47 - 2012-08-04 19:47 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2012-08-04 19:36 - 2012-08-04 19:36 - 00000000 ____D C:\Users\Beatrice\Local Settings\Macromedia
2012-08-04 19:36 - 2012-08-04 19:36 - 00000000 ____D C:\Users\Beatrice\Local Settings\Application Data\Macromedia
2012-08-04 19:36 - 2012-08-04 19:36 - 00000000 ____D C:\Users\Beatrice\AppData\Local\Macromedia
2012-08-04 19:23 - 2012-08-05 13:39 - 00001002 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-04 19:23 - 2012-08-04 19:23 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-04 19:23 - 2012-08-04 19:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 12:51 - 2012-08-02 12:51 - 00000002 ____A C:\Users\Beatrice\uz.dat
============ 3 Months Modified Files ========================
2012-08-05 17:05 - 2012-08-05 17:05 - 00042960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nwjvqslu.sys
2012-08-05 17:04 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-05 17:04 - 2006-11-02 13:47 - 00003072 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-05 17:04 - 2006-11-02 13:47 - 00003072 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-05 17:02 - 2006-11-02 09:35 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-05 13:41 - 2008-04-03 13:11 - 00000165 ____A C:\Users\Public\Documents\hpqp.ini
2012-08-05 13:39 - 2012-08-04 19:23 - 00001002 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-05 11:08 - 2012-08-05 11:14 - 04986272 ____A (SpeedyPC Software) C:\Users\Beatrice\Desktop\2-SpeedyPC Pro Installer.exe
2012-08-05 11:08 - 2012-08-05 11:14 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Beatrice\Desktop\3-SpyHunter-Installer.exe
2012-08-05 11:07 - 2012-08-05 11:14 - 00001205 ____A C:\Users\Beatrice\Desktop\FixNCR.reg
2012-08-05 10:51 - 2012-08-05 11:14 - 00064009 ____A C:\Users\Beatrice\Desktop\562354_2.zip
2012-08-04 19:47 - 2012-08-04 19:47 - 00001061 ____A C:\Users\Beatrice\Desktop\Spybot - Search & Destroy.lnk
2012-08-04 19:45 - 2012-01-03 18:01 - 00001912 ____A C:\Windows\epplauncher.mif
2012-08-04 19:45 - 2008-04-03 12:43 - 01648267 ____A C:\Windows\WindowsUpdate.log
2012-08-04 19:37 - 2006-11-02 14:01 - 00032552 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-04 19:23 - 2012-08-04 19:23 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-04 19:23 - 2012-08-04 19:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 12:51 - 2012-08-02 12:51 - 00000002 ____A C:\Users\Beatrice\uz.dat
2012-07-26 13:40 - 2006-11-02 11:33 - 01512256 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-25 18:18 - 2006-11-02 11:23 - 00000219 ____A C:\Windows\win.ini
2012-07-25 18:15 - 2006-11-02 11:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-05-31 11:25 - 2010-01-16 16:14 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-15 13:55 - 2011-12-30 17:01 - 00010971 ____A C:\Users\Beatrice\Desktop\Budget 2011.xlsx
ZeroAccess:
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\n
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L\00000004.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000004.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000008.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\000000cb.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\80000032.@
ZeroAccess:
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\n
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L\00000004.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000004.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000008.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\000000cb.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\80000032.@
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2006-11-02 09:35] - [2012-08-05 17:02] - 0279552 ____A (Microsoft Corporation) A246A7052A70C2E1BE4F7E54DF31E4DF
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 3061.4 MB
Available physical RAM: 2517.38 MB
Total Pagefile: 2775.97 MB
Available Pagefile: 2598.99 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.55 MB
======================= Partitions =========================
1 Drive c: (System) (Fixed) (Total:73.25 GB) (Free:31.21 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Data) (Fixed) (Total:29.3 GB) (Free:29.2 GB) NTFS
3 Drive e: (HP_RECOVERY) (Fixed) (Total:9.24 GB) (Free:2.87 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive g: (PRIVATE PMO) (Removable) (Total:7.45 GB) (Free:2.89 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 112 GB 2552 KB
Disk 1 Online 7648 MB 0 B
==========================================================
Last Boot: 2012-08-04 19:49
======================= End Of Log ==========================
Search.txt
Farbar Recovery Scan Tool Version: 05-08-2012
Ran by SYSTEM at 2012-08-05 18:12:26
Running from G:\sirefef removal
================== Search: "services.exe" ===================
C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 09:35] - [2006-11-02 10:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\WINDOWS\System32\services.exe
[2006-11-02 09:35] - [2012-08-05 17:02] - 0279552 ____A (Microsoft Corporation) A246A7052A70C2E1BE4F7E54DF31E4DF
C:\WINDOWS\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2010-02-13 17:28] - [2008-01-19 08:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
=== End Of Search ===
Thanks for your help
I tried all the Sunday to remove Sirefef but I stay unsuccessful.
I read a lot of post and I've done the same thing as in the other ones, here are the two log files from FRST:
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 05-08-2012
Ran by SYSTEM at 05-08-2012 18:11:02
Running from G:\sirefef removal
Windows Vista (TM) Home Premium (X86) OS Language: German Standard
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2007-08-28] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [154136 2007-08-28] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [137752 2007-08-28] (Intel Corporation)
HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [159744 2007-06-30] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" [181544 2007-09-30] (CyberLink Corp.)
HKLM\...\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [202032 2007-09-27] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0" [222504 2007-09-13] (CyberLink Corp.)
HKLM\...\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [x]
HKLM\...\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [40048 2007-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM\...\Run: [] [x]
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-10-09] (Apple Inc.)
HKLM\...\Run: [crrss] C:\Windows\system32\crrss.exe [44544 2010-02-03] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Beatrice\...\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background [5674352 2007-01-19] (Microsoft Corporation)
HKU\Beatrice\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\Beatrice\...\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" [247728 2012-01-23] (TomTom)
HKU\Beatrice\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [201728 2006-11-02] (Microsoft Corporation)
HKU\Beatrice\...\Run: [wevtutil] C:\Users\Beatrice\AppData\Local\Microsoft\Windows\4933\wevtutil.exe [53760 2012-08-02] ()
HKU\Beatrice\...\Run: [rdrlunas] rundll32 "C:\Users\Beatrice\AppData\Local\Temp\dvduhost.dll",CreateProcessNotify [x]
HKU\Beatrice\...\Run: [winlogon] C:\Users\Beatrice\winlogon.exe [44544 2010-02-03] ()
HKU\Beatrice\...\Winlogon: [Shell] explorer.exe "C:\Users\Beatrice\winlogon.exe" [44544 2010-02-03] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Windows\system32\crrss.exe [44544 2010-02-03] ()
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
================================ Services (Whitelisted) ==================
3 Com4Qlb; "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe" [110592 2007-03-05] (Hewlett-Packard Development Company, L.P.)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [22016 2006-11-02] (Microsoft Corporation)
2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.)
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [272024 2007-01-09] ()
3 usnjsvc; "C:\Program Files\MSN Messenger\usnsvc.exe" [97136 2007-01-19] (Microsoft Corporation)
2 HP Health Check Service; "c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe" [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
========================== Drivers (Whitelisted) =============
3 HBtnKey; C:\Windows\System32\DRIVERS\cpqbttn.sys [9472 2006-06-28] (Hewlett-Packard Development Company, L.P.)
3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [176640 2007-10-11] (Conexant Systems Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
1 nwjvqslu; \??\C:\Windows\system32\drivers\nwjvqslu.sys [42960 2012-08-05] (Microsoft Corporation)
3 RTL8023xp; C:\Windows\System32\DRIVERS\Rtnicxp.sys [50176 2007-04-23] (Realtek Semiconductor Corporation )
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
1 eabfiltr; [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 SymIM; C:\Windows\System32\DRIVERS\SymIM.sys [x]
3 SymIMMP; C:\Windows\System32\DRIVERS\SymIM.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-05 18:10 - 2012-08-05 18:10 - 00000000 ____D C:\FRST
2012-08-05 17:05 - 2012-08-05 17:05 - 00042960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nwjvqslu.sys
2012-08-05 14:12 - 2012-08-05 14:12 - 00000000 ____D C:\Program Files\SpeedyPC Software
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\Application Data\SpeedyPC Software
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\Application Data\DriverCure
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\AppData\Roaming\SpeedyPC Software
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\Beatrice\AppData\Roaming\DriverCure
2012-08-05 13:16 - 2012-08-05 13:16 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-08-05 11:14 - 2012-08-05 11:08 - 04986272 ____A (SpeedyPC Software) C:\Users\Beatrice\Desktop\2-SpeedyPC Pro Installer.exe
2012-08-05 11:14 - 2012-08-05 11:08 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Beatrice\Desktop\3-SpyHunter-Installer.exe
2012-08-05 11:14 - 2012-08-05 11:07 - 00001205 ____A C:\Users\Beatrice\Desktop\FixNCR.reg
2012-08-05 11:14 - 2012-08-05 10:51 - 00064009 ____A C:\Users\Beatrice\Desktop\562354_2.zip
2012-08-04 19:47 - 2012-08-04 19:52 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-08-04 19:47 - 2012-08-04 19:47 - 00001061 ____A C:\Users\Beatrice\Desktop\Spybot - Search & Destroy.lnk
2012-08-04 19:47 - 2012-08-04 19:47 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2012-08-04 19:36 - 2012-08-04 19:36 - 00000000 ____D C:\Users\Beatrice\Local Settings\Macromedia
2012-08-04 19:36 - 2012-08-04 19:36 - 00000000 ____D C:\Users\Beatrice\Local Settings\Application Data\Macromedia
2012-08-04 19:36 - 2012-08-04 19:36 - 00000000 ____D C:\Users\Beatrice\AppData\Local\Macromedia
2012-08-04 19:23 - 2012-08-05 13:39 - 00001002 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-04 19:23 - 2012-08-04 19:23 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-04 19:23 - 2012-08-04 19:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 12:51 - 2012-08-02 12:51 - 00000002 ____A C:\Users\Beatrice\uz.dat
============ 3 Months Modified Files ========================
2012-08-05 17:05 - 2012-08-05 17:05 - 00042960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nwjvqslu.sys
2012-08-05 17:04 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-05 17:04 - 2006-11-02 13:47 - 00003072 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-05 17:04 - 2006-11-02 13:47 - 00003072 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-05 17:02 - 2006-11-02 09:35 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-05 13:41 - 2008-04-03 13:11 - 00000165 ____A C:\Users\Public\Documents\hpqp.ini
2012-08-05 13:39 - 2012-08-04 19:23 - 00001002 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-05 11:08 - 2012-08-05 11:14 - 04986272 ____A (SpeedyPC Software) C:\Users\Beatrice\Desktop\2-SpeedyPC Pro Installer.exe
2012-08-05 11:08 - 2012-08-05 11:14 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Beatrice\Desktop\3-SpyHunter-Installer.exe
2012-08-05 11:07 - 2012-08-05 11:14 - 00001205 ____A C:\Users\Beatrice\Desktop\FixNCR.reg
2012-08-05 10:51 - 2012-08-05 11:14 - 00064009 ____A C:\Users\Beatrice\Desktop\562354_2.zip
2012-08-04 19:47 - 2012-08-04 19:47 - 00001061 ____A C:\Users\Beatrice\Desktop\Spybot - Search & Destroy.lnk
2012-08-04 19:45 - 2012-01-03 18:01 - 00001912 ____A C:\Windows\epplauncher.mif
2012-08-04 19:45 - 2008-04-03 12:43 - 01648267 ____A C:\Windows\WindowsUpdate.log
2012-08-04 19:37 - 2006-11-02 14:01 - 00032552 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-04 19:23 - 2012-08-04 19:23 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-04 19:23 - 2012-08-04 19:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 12:51 - 2012-08-02 12:51 - 00000002 ____A C:\Users\Beatrice\uz.dat
2012-07-26 13:40 - 2006-11-02 11:33 - 01512256 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-25 18:18 - 2006-11-02 11:23 - 00000219 ____A C:\Windows\win.ini
2012-07-25 18:15 - 2006-11-02 11:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-05-31 11:25 - 2010-01-16 16:14 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-15 13:55 - 2011-12-30 17:01 - 00010971 ____A C:\Users\Beatrice\Desktop\Budget 2011.xlsx
ZeroAccess:
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\n
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L\00000004.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000004.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000008.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\000000cb.@
C:\Windows\Installer\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\80000032.@
ZeroAccess:
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\n
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\L\00000004.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000004.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\00000008.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\000000cb.@
C:\Users\Beatrice\AppData\Local\{8f454403-c5a8-ac9e-3379-c0f77e5e9928}\U\80000032.@
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2006-11-02 09:35] - [2012-08-05 17:02] - 0279552 ____A (Microsoft Corporation) A246A7052A70C2E1BE4F7E54DF31E4DF
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 17%
Total physical RAM: 3061.4 MB
Available physical RAM: 2517.38 MB
Total Pagefile: 2775.97 MB
Available Pagefile: 2598.99 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.55 MB
======================= Partitions =========================
1 Drive c: (System) (Fixed) (Total:73.25 GB) (Free:31.21 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Data) (Fixed) (Total:29.3 GB) (Free:29.2 GB) NTFS
3 Drive e: (HP_RECOVERY) (Fixed) (Total:9.24 GB) (Free:2.87 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive g: (PRIVATE PMO) (Removable) (Total:7.45 GB) (Free:2.89 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 112 GB 2552 KB
Disk 1 Online 7648 MB 0 B
==========================================================
Last Boot: 2012-08-04 19:49
======================= End Of Log ==========================
Search.txt
Farbar Recovery Scan Tool Version: 05-08-2012
Ran by SYSTEM at 2012-08-05 18:12:26
Running from G:\sirefef removal
================== Search: "services.exe" ===================
C:\WINDOWS\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 09:35] - [2006-11-02 10:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\WINDOWS\System32\services.exe
[2006-11-02 09:35] - [2012-08-05 17:02] - 0279552 ____A (Microsoft Corporation) A246A7052A70C2E1BE4F7E54DF31E4DF
C:\WINDOWS\SoftwareDistribution\Download\c91af43e301542f65a88d59517636d32\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2010-02-13 17:28] - [2008-01-19 08:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
=== End Of Search ===
Thanks for your help