Joseph Rapley
Posts: 9 +0
Hi
Looks like this is the place to come for help with this annoying problem.
Hadn't used computer for a while and after using it for a few hours noticed that the virus protection (MS Security Essentials) was not functioning well so I tried to reinstall it. After doing so it detected infected services.exe files and tried to clean them but then started rebooting with the 'Windows has encountered problem...' error.
I have downloaded FRST64.EXE and have pasted the FRST.TXT contents below. I'm not able to complete a file search before WIndows restarts.
Help with this problem would be greatly appreciated.
Thank you in advance for any assistance.
Joseph
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-10-2012
Ran by joe at 13-10-2012 18:32:42
Running from C:\Users\joe\Desktop
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
==================== One Month Created Files and Folders ========
2012-10-13 18:33 - 2012-10-13 18:33 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bedjzlli.sys
2012-10-13 18:29 - 2012-10-13 18:32 - 00000000 ____D C:\FRST
2012-10-13 18:29 - 2012-10-13 18:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17627B7B2776FEC4
2012-10-13 18:29 - 2012-10-13 18:29 - 00004096 ___AH C:\Users\joe\Desktop\._FRST64.exe
2012-10-13 18:29 - 2012-10-13 18:28 - 01456821 ____A (Farbar) C:\Users\joe\Desktop\FRST64.exe
2012-10-13 18:26 - 2012-10-13 18:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9341647272B507BE
2012-10-13 18:23 - 2012-10-13 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C37E765747901CC7
2012-10-13 18:19 - 2012-10-13 18:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60A7E533FFC9EA34
2012-10-13 18:18 - 2012-10-13 18:19 - 00000025 ____A C:\Users\joe\Desktop\stop shutdown.bat
2012-10-13 18:16 - 2012-10-13 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D92A35D1EF713FB
2012-10-13 18:13 - 2012-10-13 18:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1898A60DE2614A51
2012-10-13 18:09 - 2012-10-13 18:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.05ECC41AD079FFDD
2012-10-13 18:06 - 2012-10-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E07BD0F351D4B89C
2012-10-13 18:06 - 2012-10-13 18:06 - 00000000 ___SD C:\32788R22FWJFW
2012-10-13 18:06 - 2012-10-13 18:06 - 00000000 ____D C:\Windows\erdnt
2012-10-13 18:05 - 2012-10-13 18:05 - 04771502 ____R (Swearware) C:\Users\joe\Desktop\ComboFix.exe
2012-10-13 18:05 - 2012-10-13 18:05 - 00004096 ___AH C:\Users\joe\Desktop\._ComboFix.exe
2012-10-13 17:54 - 2012-10-13 17:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17D124396AE4C9A4
2012-10-12 21:56 - 2012-10-12 21:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71C7F78B5F41D819
2012-10-12 21:46 - 2012-10-12 21:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.608850FFB1802BB4
2012-10-12 20:03 - 2012-10-12 20:57 - 00000000 ____D C:\Users\joe\Desktop\The.Walking.Dead.Episode.3-RELOADED
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded.torrent
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded (1).torrent
==================== 3 Months Modified Files ==================
2012-10-13 18:34 - 2010-12-05 22:16 - 00000408 _RASH C:\Users\All Users\ntuser.pol
2012-10-13 18:33 - 2012-10-13 18:33 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bedjzlli.sys
2012-10-13 18:31 - 2011-04-26 11:04 - 00037874 ____A C:\Windows\setupact.log
2012-10-13 18:31 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-13 18:29 - 2012-10-13 18:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17627B7B2776FEC4
2012-10-13 18:29 - 2012-10-13 18:29 - 00004096 ___AH C:\Users\joe\Desktop\._FRST64.exe
2012-10-13 18:29 - 2011-04-10 20:42 - 00021508 ____A C:\.DS_Store
2012-10-13 18:29 - 2010-10-28 19:24 - 01431865 ____A C:\Windows\WindowsUpdate.log
2012-10-13 18:28 - 2012-10-13 18:29 - 01456821 ____A (Farbar) C:\Users\joe\Desktop\FRST64.exe
2012-10-13 18:26 - 2012-10-13 18:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9341647272B507BE
2012-10-13 18:23 - 2012-10-13 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C37E765747901CC7
2012-10-13 18:19 - 2012-10-13 18:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60A7E533FFC9EA34
2012-10-13 18:19 - 2012-10-13 18:18 - 00000025 ____A C:\Users\joe\Desktop\stop shutdown.bat
2012-10-13 18:16 - 2012-10-13 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D92A35D1EF713FB
2012-10-13 18:13 - 2012-10-13 18:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1898A60DE2614A51
2012-10-13 18:09 - 2012-10-13 18:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.05ECC41AD079FFDD
2012-10-13 18:06 - 2012-10-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E07BD0F351D4B89C
2012-10-13 18:05 - 2012-10-13 18:05 - 04771502 ____R (Swearware) C:\Users\joe\Desktop\ComboFix.exe
2012-10-13 18:05 - 2012-10-13 18:05 - 00004096 ___AH C:\Users\joe\Desktop\._ComboFix.exe
2012-10-13 18:05 - 2010-10-29 16:59 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1328558-2458857526-3040891912-1000UA.job
2012-10-13 17:54 - 2012-10-13 17:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17D124396AE4C9A4
2012-10-13 17:53 - 2009-07-14 05:45 - 00020672 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-10-13 17:53 - 2009-07-14 05:45 - 00020672 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-10-13 17:48 - 2009-07-14 00:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-10-12 21:56 - 2012-10-12 21:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71C7F78B5F41D819
2012-10-12 21:55 - 2010-11-19 00:21 - 00822784 __ASH C:\Users\joe\Desktop\Thumbs.db
2012-10-12 21:46 - 2012-10-12 21:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.608850FFB1802BB4
2012-10-12 21:44 - 2011-01-23 06:48 - 00002155 ____A C:\Windows\epplauncher.mif
2012-10-12 20:05 - 2010-10-29 16:59 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1328558-2458857526-3040891912-1000Core.job
2012-10-12 20:04 - 2009-07-14 06:13 - 00967472 ____A C:\Windows\System32\PerfStringBackup.INI
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded.torrent
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded (1).torrent
2012-08-30 22:03 - 2012-08-30 22:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 22:03 - 2010-10-24 09:25 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-07-22 21:20 - 2012-07-22 21:03 - 00000044 ____A C:\Users\joe\Desktop\New Text Document.txt
2012-07-22 14:22 - 2010-11-17 16:16 - 00002034 ___AH C:\Users\joe\Documents\Default.rdp
ZeroAccess:
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\@
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\L
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\n
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\U
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\U\00000001.@
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\U\800000cb.@
ZeroAccess:
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\@
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\L
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U\00000001.@
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U\80000000.@
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U\800000cb.@
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 25%
Total physical RAM: 4095.55 MB
Available physical RAM: 3038.16 MB
Total Pagefile: 8189.3 MB
Available Pagefile: 6940.78 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
2 Drive c: (BOOTCAMP) (Fixed) (Total:447.03 GB) (Free:35.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
Last Boot: 2012-10-12 20:27
==================== End Of Log =============================
Looks like this is the place to come for help with this annoying problem.
Hadn't used computer for a while and after using it for a few hours noticed that the virus protection (MS Security Essentials) was not functioning well so I tried to reinstall it. After doing so it detected infected services.exe files and tried to clean them but then started rebooting with the 'Windows has encountered problem...' error.
I have downloaded FRST64.EXE and have pasted the FRST.TXT contents below. I'm not able to complete a file search before WIndows restarts.
Help with this problem would be greatly appreciated.
Thank you in advance for any assistance.
Joseph
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-10-2012
Ran by joe at 13-10-2012 18:32:42
Running from C:\Users\joe\Desktop
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
==================== One Month Created Files and Folders ========
2012-10-13 18:33 - 2012-10-13 18:33 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bedjzlli.sys
2012-10-13 18:29 - 2012-10-13 18:32 - 00000000 ____D C:\FRST
2012-10-13 18:29 - 2012-10-13 18:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17627B7B2776FEC4
2012-10-13 18:29 - 2012-10-13 18:29 - 00004096 ___AH C:\Users\joe\Desktop\._FRST64.exe
2012-10-13 18:29 - 2012-10-13 18:28 - 01456821 ____A (Farbar) C:\Users\joe\Desktop\FRST64.exe
2012-10-13 18:26 - 2012-10-13 18:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9341647272B507BE
2012-10-13 18:23 - 2012-10-13 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C37E765747901CC7
2012-10-13 18:19 - 2012-10-13 18:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60A7E533FFC9EA34
2012-10-13 18:18 - 2012-10-13 18:19 - 00000025 ____A C:\Users\joe\Desktop\stop shutdown.bat
2012-10-13 18:16 - 2012-10-13 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D92A35D1EF713FB
2012-10-13 18:13 - 2012-10-13 18:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1898A60DE2614A51
2012-10-13 18:09 - 2012-10-13 18:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.05ECC41AD079FFDD
2012-10-13 18:06 - 2012-10-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E07BD0F351D4B89C
2012-10-13 18:06 - 2012-10-13 18:06 - 00000000 ___SD C:\32788R22FWJFW
2012-10-13 18:06 - 2012-10-13 18:06 - 00000000 ____D C:\Windows\erdnt
2012-10-13 18:05 - 2012-10-13 18:05 - 04771502 ____R (Swearware) C:\Users\joe\Desktop\ComboFix.exe
2012-10-13 18:05 - 2012-10-13 18:05 - 00004096 ___AH C:\Users\joe\Desktop\._ComboFix.exe
2012-10-13 17:54 - 2012-10-13 17:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17D124396AE4C9A4
2012-10-12 21:56 - 2012-10-12 21:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71C7F78B5F41D819
2012-10-12 21:46 - 2012-10-12 21:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.608850FFB1802BB4
2012-10-12 20:03 - 2012-10-12 20:57 - 00000000 ____D C:\Users\joe\Desktop\The.Walking.Dead.Episode.3-RELOADED
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded.torrent
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded (1).torrent
==================== 3 Months Modified Files ==================
2012-10-13 18:34 - 2010-12-05 22:16 - 00000408 _RASH C:\Users\All Users\ntuser.pol
2012-10-13 18:33 - 2012-10-13 18:33 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bedjzlli.sys
2012-10-13 18:31 - 2011-04-26 11:04 - 00037874 ____A C:\Windows\setupact.log
2012-10-13 18:31 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-13 18:29 - 2012-10-13 18:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17627B7B2776FEC4
2012-10-13 18:29 - 2012-10-13 18:29 - 00004096 ___AH C:\Users\joe\Desktop\._FRST64.exe
2012-10-13 18:29 - 2011-04-10 20:42 - 00021508 ____A C:\.DS_Store
2012-10-13 18:29 - 2010-10-28 19:24 - 01431865 ____A C:\Windows\WindowsUpdate.log
2012-10-13 18:28 - 2012-10-13 18:29 - 01456821 ____A (Farbar) C:\Users\joe\Desktop\FRST64.exe
2012-10-13 18:26 - 2012-10-13 18:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9341647272B507BE
2012-10-13 18:23 - 2012-10-13 18:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C37E765747901CC7
2012-10-13 18:19 - 2012-10-13 18:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.60A7E533FFC9EA34
2012-10-13 18:19 - 2012-10-13 18:18 - 00000025 ____A C:\Users\joe\Desktop\stop shutdown.bat
2012-10-13 18:16 - 2012-10-13 18:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D92A35D1EF713FB
2012-10-13 18:13 - 2012-10-13 18:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1898A60DE2614A51
2012-10-13 18:09 - 2012-10-13 18:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.05ECC41AD079FFDD
2012-10-13 18:06 - 2012-10-13 18:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E07BD0F351D4B89C
2012-10-13 18:05 - 2012-10-13 18:05 - 04771502 ____R (Swearware) C:\Users\joe\Desktop\ComboFix.exe
2012-10-13 18:05 - 2012-10-13 18:05 - 00004096 ___AH C:\Users\joe\Desktop\._ComboFix.exe
2012-10-13 18:05 - 2010-10-29 16:59 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1328558-2458857526-3040891912-1000UA.job
2012-10-13 17:54 - 2012-10-13 17:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17D124396AE4C9A4
2012-10-13 17:53 - 2009-07-14 05:45 - 00020672 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-10-13 17:53 - 2009-07-14 05:45 - 00020672 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-10-13 17:48 - 2009-07-14 00:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-10-12 21:56 - 2012-10-12 21:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71C7F78B5F41D819
2012-10-12 21:55 - 2010-11-19 00:21 - 00822784 __ASH C:\Users\joe\Desktop\Thumbs.db
2012-10-12 21:46 - 2012-10-12 21:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.608850FFB1802BB4
2012-10-12 21:44 - 2011-01-23 06:48 - 00002155 ____A C:\Windows\epplauncher.mif
2012-10-12 20:05 - 2010-10-29 16:59 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1328558-2458857526-3040891912-1000Core.job
2012-10-12 20:04 - 2009-07-14 06:13 - 00967472 ____A C:\Windows\System32\PerfStringBackup.INI
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded.torrent
2012-10-12 20:03 - 2012-10-12 20:03 - 00043884 ____A C:\Users\joe\Downloads\[kat.ph]the.walking.dead.episode.3.reloaded (1).torrent
2012-08-30 22:03 - 2012-08-30 22:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 22:03 - 2010-10-24 09:25 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-07-22 21:20 - 2012-07-22 21:03 - 00000044 ____A C:\Users\joe\Desktop\New Text Document.txt
2012-07-22 14:22 - 2010-11-17 16:16 - 00002034 ___AH C:\Users\joe\Documents\Default.rdp
ZeroAccess:
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\@
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\L
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\n
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\U
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\U\00000001.@
C:\Windows\Installer\{0b57f992-415d-77db-3088-8f653b0e3437}\U\800000cb.@
ZeroAccess:
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\@
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\L
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U\00000001.@
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U\80000000.@
C:\Users\joe\AppData\Local\{0b57f992-415d-77db-3088-8f653b0e3437}\U\800000cb.@
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 25%
Total physical RAM: 4095.55 MB
Available physical RAM: 3038.16 MB
Total Pagefile: 8189.3 MB
Available Pagefile: 6940.78 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
2 Drive c: (BOOTCAMP) (Fixed) (Total:447.03 GB) (Free:35.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
Last Boot: 2012-10-12 20:27
==================== End Of Log =============================