Jerevicious
Posts: 13 +0
Hey all. I, like a number of people have gotten hit by this virus. I'm getting the error where it says windows has a critical error and will restart in one minute. I downloaded frst64 and ran that and also did the search for services.txt. I'll c/p them now. Thanks so much in advance.
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 29-07-2012 11:14:01
Running from D:\Tools
Windows 7 Enterprise (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [855608 2007-09-26] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2010-06-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [976832 2010-06-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [D-Link RangeBooster G WDA-2320] C:\Program Files (x86)\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe [1662976 2007-08-29] (D-Link)
HKLM-x32\...\Run: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe [49152 2007-01-19] (Wireless Service)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKU\TGizz\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [369200 2009-10-30] (DT Soft Ltd)
HKU\TGizz\...\Run: [EPSON Stylus Photo RX595 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICLA.EXE /FU "C:\Windows\TEMP\E_SA9B3.tmp" /EF "HKCU" [213504 2007-03-30] (SEIKO EPSON CORPORATION)
HKU\TGizz\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\TGizz\...\Run: [Google Update] "C:\Users\TGizz\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-22] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
4 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 A3AB; C:\Windows\System32\DRIVERS\A3ABvx.sys [924672 2007-08-02] (D-Link Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-07-03] (Malwarebytes Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-03-21] (Duplex Secure Ltd.)
3 ALSysIO; \??\C:\Users\TGizz\AppData\Local\Temp\ALSysIO64.sys [x]
3 dump_wmimmc; \??\C:\Games\Pangya\GameGuard\dump_wmimmc.sys [x]
3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-29 11:13 - 2012-07-29 11:14 - 00000000 ____D C:\FRST
2012-07-29 01:05 - 2012-07-29 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96207E9719CBEB45
2012-07-29 01:02 - 2012-07-29 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28CD424564394946
2012-07-29 00:58 - 2012-07-29 00:59 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe (2).lnk
2012-07-29 00:58 - 2012-07-29 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.657AAC65192604D9
2012-07-29 00:55 - 2012-07-29 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DCBD345DF1523588
2012-07-29 00:55 - 2012-07-29 00:55 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe.lnk
2012-07-29 00:52 - 2012-07-29 00:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2DE491674F1AE16
2012-07-29 00:49 - 2012-07-29 00:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8229C7916A950F5C
2012-07-29 00:40 - 2012-07-29 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E9B4693BD17E645
2012-07-29 00:37 - 2012-07-29 00:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A96C8E1B1E6E8B4
2012-07-29 00:29 - 2012-07-29 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7FC008249AAB82B0
2012-07-29 00:17 - 2012-07-29 00:17 - 00730464 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 00:17 - 2012-07-29 00:17 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 00:17 - 2012-07-29 00:17 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 00:17 - 2012-07-29 00:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-29 00:15 - 2012-07-29 00:15 - 12621696 ____A (Microsoft Corporation) C:\Users\TGizz\Downloads\mseinstall.exe
2012-07-28 22:17 - 2012-07-28 22:17 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-28 21:46 - 2012-07-28 21:46 - 00285512 ____A C:\Windows\Minidump\072912-35037-01.dmp
2012-07-28 21:42 - 2012-07-28 21:43 - 00292184 ____A C:\Windows\Minidump\072912-31200-01.dmp
2012-07-27 23:12 - 2012-07-27 23:12 - 06723616 ____A (Adobe Systems Inc.) C:\Users\TGizz\Downloads\Shockwave_Installer_Slim.exe
2012-07-27 22:55 - 2012-07-27 22:55 - 00000000 ____D C:\Users\TGizz\Documents\My Games
2012-07-27 22:54 - 2012-07-27 22:54 - 00002106 ____A C:\Users\Public\Desktop\Path of Exile.lnk
2012-07-27 22:54 - 2012-07-27 22:54 - 00000000 ____D C:\Program Files (x86)\Grinding Gear Games
2012-07-25 18:59 - 2012-07-25 18:59 - 06603776 ____A C:\Users\TGizz\Downloads\PathOfExileInstaller.msi
2012-07-17 00:24 - 2012-07-17 00:24 - 00003947 ____A C:\Users\TGizz\Downloads\DIABLO 3.TXT
2012-07-14 17:30 - 2012-07-14 17:30 - 00292184 ____A C:\Windows\Minidump\071412-36317-01.dmp
2012-07-11 15:18 - 2012-07-11 15:18 - 00651538 ____A C:\Users\TGizz\Downloads\Unconfirmed 9862.crdownload
2012-07-11 00:12 - 2012-07-11 00:14 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2012-07-11 00:12 - 2012-07-11 00:12 - 00001068 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-08 13:56 - 2012-07-08 13:56 - 32409936 ____A C:\Users\TGizz\Downloads\WOW-4.3.4.15050-enUS-Trial.exe
2012-07-03 01:22 - 2012-07-03 01:22 - 00292184 ____A C:\Windows\Minidump\070312-39265-01.dmp
============ 3 Months Modified Files ========================
2012-07-29 07:08 - 2012-05-29 20:57 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3568411142-4073580314-4145923839-1000UA.job
2012-07-29 07:07 - 2010-06-30 11:55 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-29 07:07 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-29 07:06 - 2011-05-14 21:00 - 00004491 ____A C:\Windows\setupact.log
2012-07-29 01:05 - 2012-07-29 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96207E9719CBEB45
2012-07-29 01:02 - 2012-07-29 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28CD424564394946
2012-07-29 00:59 - 2012-07-29 00:58 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe (2).lnk
2012-07-29 00:58 - 2012-07-29 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.657AAC65192604D9
2012-07-29 00:55 - 2012-07-29 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DCBD345DF1523588
2012-07-29 00:55 - 2012-07-29 00:55 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe.lnk
2012-07-29 00:52 - 2012-07-29 00:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2DE491674F1AE16
2012-07-29 00:49 - 2012-07-29 00:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8229C7916A950F5C
2012-07-29 00:45 - 2010-06-30 11:55 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-29 00:44 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-29 00:40 - 2012-07-29 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E9B4693BD17E645
2012-07-29 00:37 - 2012-07-29 00:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A96C8E1B1E6E8B4
2012-07-29 00:31 - 2011-07-23 17:33 - 00010596 ____A C:\Windows\PFRO.log
2012-07-29 00:29 - 2012-07-29 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7FC008249AAB82B0
2012-07-29 00:18 - 2010-03-14 21:37 - 00445799 ____A C:\Windows\WindowsUpdate.log
2012-07-29 00:17 - 2012-07-29 00:17 - 00730464 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 00:17 - 2012-07-29 00:17 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 00:15 - 2012-07-29 00:15 - 12621696 ____A (Microsoft Corporation) C:\Users\TGizz\Downloads\mseinstall.exe
2012-07-28 21:53 - 2009-07-13 20:45 - 00015136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-28 21:53 - 2009-07-13 20:45 - 00015136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-28 21:52 - 2009-07-13 21:13 - 00713888 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-28 21:46 - 2012-07-28 21:46 - 00285512 ____A C:\Windows\Minidump\072912-35037-01.dmp
2012-07-28 21:46 - 2011-07-23 17:33 - 347942359 ____A C:\Windows\MEMORY.DMP
2012-07-28 21:43 - 2012-07-28 21:42 - 00292184 ____A C:\Windows\Minidump\072912-31200-01.dmp
2012-07-28 02:07 - 2012-05-29 20:57 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3568411142-4073580314-4145923839-1000Core.job
2012-07-27 23:12 - 2012-07-27 23:12 - 06723616 ____A (Adobe Systems Inc.) C:\Users\TGizz\Downloads\Shockwave_Installer_Slim.exe
2012-07-27 22:54 - 2012-07-27 22:54 - 00002106 ____A C:\Users\Public\Desktop\Path of Exile.lnk
2012-07-25 18:59 - 2012-07-25 18:59 - 06603776 ____A C:\Users\TGizz\Downloads\PathOfExileInstaller.msi
2012-07-17 00:24 - 2012-07-17 00:24 - 00003947 ____A C:\Users\TGizz\Downloads\DIABLO 3.TXT
2012-07-14 17:30 - 2012-07-14 17:30 - 00292184 ____A C:\Windows\Minidump\071412-36317-01.dmp
2012-07-11 19:04 - 2012-05-29 20:57 - 00002401 ____A C:\Users\TGizz\Desktop\Google Chrome.lnk
2012-07-11 15:18 - 2012-07-11 15:18 - 00651538 ____A C:\Users\TGizz\Downloads\Unconfirmed 9862.crdownload
2012-07-11 00:12 - 2012-07-11 00:12 - 00001068 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-08 13:56 - 2012-07-08 13:56 - 32409936 ____A C:\Users\TGizz\Downloads\WOW-4.3.4.15050-enUS-Trial.exe
2012-07-08 13:37 - 2012-06-08 19:14 - 00029184 __ASH C:\Users\TGizz\Documents\Thumbs.db
2012-07-03 09:46 - 2010-03-14 19:29 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-03 01:22 - 2012-07-03 01:22 - 00292184 ____A C:\Windows\Minidump\070312-39265-01.dmp
2012-06-15 07:13 - 2012-06-15 07:13 - 00019397 ____A C:\Users\TGizz\Downloads\Rock_Band_Unplugged_USA_REPACK_PSP-pSyPSP.torrent
2012-06-13 12:05 - 2012-06-13 12:05 - 00666724 ____A C:\Users\TGizz\Downloads\Lollipop.Chainsaw.XBOX360-SPARE.torrent
2012-06-01 10:25 - 2012-06-01 10:25 - 22267083 ____A C:\Users\TGizz\Downloads\Diablo III Extreme Theme by VikiTech.zip
2012-06-01 01:16 - 2012-06-01 01:16 - 11639286 ____A C:\Users\TGizz\Downloads\Diablo3.themepack.exe
2012-06-01 01:16 - 2012-06-01 01:16 - 11639286 ____A C:\Users\TGizz\Downloads\Diablo3.themepack (1).exe
2012-05-29 20:46 - 2012-05-29 20:47 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-05-29 20:46 - 2012-05-29 20:47 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-05-14 23:06 - 2012-05-14 23:06 - 00000000 ____A C:\Users\TGizz\Desktop\New Text Document.txt
2012-05-14 19:09 - 2012-05-14 18:53 - 00000894 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-13 22:14 - 2012-05-13 22:14 - 07336648 ____A (Blizzard Entertainment) C:\Users\TGizz\Downloads\Diablo-III-8370-enUS-Installer-downloader.exe
2012-05-13 21:34 - 2012-05-13 21:34 - 04815840 ____A (Make The Cut, LLC.) C:\Users\TGizz\Downloads\iRinger.exe
2012-05-01 17:57 - 2012-05-01 17:57 - 00013429 ____A C:\Users\TGizz\Downloads\epic-meal-time-Bacon-Strips.m4r
2012-05-01 17:54 - 2012-05-01 17:54 - 00027697 ____A C:\Users\TGizz\Downloads\old-spice-whistle.m4r
ZeroAccess:
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\@
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\L
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\U
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\U\00000001.@
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\U\800000cb.@
Possible partition infection:
C:\Windows\svchost.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4095.05 MB
Available physical RAM: 3537.86 MB
Total Pagefile: 4093.2 MB
Available Pagefile: 3521.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:931.41 GB) (Free:269.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Removable) (Total:7.53 GB) (Free:7.52 GB) FAT32
3 Drive e: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
5 Drive g: (DVD_ROM) (CDROM) (Total:0.18 GB) (Free:0 GB) UDF
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 7712 MB 0 B
Disk 2 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 7712 MB 0 B
==================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-07-08 02:20
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-29 11:15:26
Running from D:\Tools
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-29 00:44] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 29-07-2012 11:14:01
Running from D:\Tools
Windows 7 Enterprise (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [855608 2007-09-26] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2010-06-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [976832 2010-06-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [D-Link RangeBooster G WDA-2320] C:\Program Files (x86)\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe [1662976 2007-08-29] (D-Link)
HKLM-x32\...\Run: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe [49152 2007-01-19] (Wireless Service)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKU\TGizz\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [369200 2009-10-30] (DT Soft Ltd)
HKU\TGizz\...\Run: [EPSON Stylus Photo RX595 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICLA.EXE /FU "C:\Windows\TEMP\E_SA9B3.tmp" /EF "HKCU" [213504 2007-03-30] (SEIKO EPSON CORPORATION)
HKU\TGizz\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\TGizz\...\Run: [Google Update] "C:\Users\TGizz\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-22] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
4 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 A3AB; C:\Windows\System32\DRIVERS\A3ABvx.sys [924672 2007-08-02] (D-Link Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-07-03] (Malwarebytes Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-03-21] (Duplex Secure Ltd.)
3 ALSysIO; \??\C:\Users\TGizz\AppData\Local\Temp\ALSysIO64.sys [x]
3 dump_wmimmc; \??\C:\Games\Pangya\GameGuard\dump_wmimmc.sys [x]
3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-29 11:13 - 2012-07-29 11:14 - 00000000 ____D C:\FRST
2012-07-29 01:05 - 2012-07-29 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96207E9719CBEB45
2012-07-29 01:02 - 2012-07-29 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28CD424564394946
2012-07-29 00:58 - 2012-07-29 00:59 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe (2).lnk
2012-07-29 00:58 - 2012-07-29 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.657AAC65192604D9
2012-07-29 00:55 - 2012-07-29 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DCBD345DF1523588
2012-07-29 00:55 - 2012-07-29 00:55 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe.lnk
2012-07-29 00:52 - 2012-07-29 00:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2DE491674F1AE16
2012-07-29 00:49 - 2012-07-29 00:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8229C7916A950F5C
2012-07-29 00:40 - 2012-07-29 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E9B4693BD17E645
2012-07-29 00:37 - 2012-07-29 00:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A96C8E1B1E6E8B4
2012-07-29 00:29 - 2012-07-29 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7FC008249AAB82B0
2012-07-29 00:17 - 2012-07-29 00:17 - 00730464 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 00:17 - 2012-07-29 00:17 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 00:17 - 2012-07-29 00:17 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 00:17 - 2012-07-29 00:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-29 00:15 - 2012-07-29 00:15 - 12621696 ____A (Microsoft Corporation) C:\Users\TGizz\Downloads\mseinstall.exe
2012-07-28 22:17 - 2012-07-28 22:17 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-28 21:46 - 2012-07-28 21:46 - 00285512 ____A C:\Windows\Minidump\072912-35037-01.dmp
2012-07-28 21:42 - 2012-07-28 21:43 - 00292184 ____A C:\Windows\Minidump\072912-31200-01.dmp
2012-07-27 23:12 - 2012-07-27 23:12 - 06723616 ____A (Adobe Systems Inc.) C:\Users\TGizz\Downloads\Shockwave_Installer_Slim.exe
2012-07-27 22:55 - 2012-07-27 22:55 - 00000000 ____D C:\Users\TGizz\Documents\My Games
2012-07-27 22:54 - 2012-07-27 22:54 - 00002106 ____A C:\Users\Public\Desktop\Path of Exile.lnk
2012-07-27 22:54 - 2012-07-27 22:54 - 00000000 ____D C:\Program Files (x86)\Grinding Gear Games
2012-07-25 18:59 - 2012-07-25 18:59 - 06603776 ____A C:\Users\TGizz\Downloads\PathOfExileInstaller.msi
2012-07-17 00:24 - 2012-07-17 00:24 - 00003947 ____A C:\Users\TGizz\Downloads\DIABLO 3.TXT
2012-07-14 17:30 - 2012-07-14 17:30 - 00292184 ____A C:\Windows\Minidump\071412-36317-01.dmp
2012-07-11 15:18 - 2012-07-11 15:18 - 00651538 ____A C:\Users\TGizz\Downloads\Unconfirmed 9862.crdownload
2012-07-11 00:12 - 2012-07-11 00:14 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2012-07-11 00:12 - 2012-07-11 00:12 - 00001068 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-08 13:56 - 2012-07-08 13:56 - 32409936 ____A C:\Users\TGizz\Downloads\WOW-4.3.4.15050-enUS-Trial.exe
2012-07-03 01:22 - 2012-07-03 01:22 - 00292184 ____A C:\Windows\Minidump\070312-39265-01.dmp
============ 3 Months Modified Files ========================
2012-07-29 07:08 - 2012-05-29 20:57 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3568411142-4073580314-4145923839-1000UA.job
2012-07-29 07:07 - 2010-06-30 11:55 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-29 07:07 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-29 07:06 - 2011-05-14 21:00 - 00004491 ____A C:\Windows\setupact.log
2012-07-29 01:05 - 2012-07-29 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96207E9719CBEB45
2012-07-29 01:02 - 2012-07-29 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.28CD424564394946
2012-07-29 00:59 - 2012-07-29 00:58 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe (2).lnk
2012-07-29 00:58 - 2012-07-29 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.657AAC65192604D9
2012-07-29 00:55 - 2012-07-29 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DCBD345DF1523588
2012-07-29 00:55 - 2012-07-29 00:55 - 00001270 ____A C:\Users\TGizz\Desktop\shutdown.exe.lnk
2012-07-29 00:52 - 2012-07-29 00:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2DE491674F1AE16
2012-07-29 00:49 - 2012-07-29 00:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8229C7916A950F5C
2012-07-29 00:45 - 2010-06-30 11:55 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-29 00:44 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-29 00:40 - 2012-07-29 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E9B4693BD17E645
2012-07-29 00:37 - 2012-07-29 00:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A96C8E1B1E6E8B4
2012-07-29 00:31 - 2011-07-23 17:33 - 00010596 ____A C:\Windows\PFRO.log
2012-07-29 00:29 - 2012-07-29 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7FC008249AAB82B0
2012-07-29 00:18 - 2010-03-14 21:37 - 00445799 ____A C:\Windows\WindowsUpdate.log
2012-07-29 00:17 - 2012-07-29 00:17 - 00730464 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-29 00:17 - 2012-07-29 00:17 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 00:15 - 2012-07-29 00:15 - 12621696 ____A (Microsoft Corporation) C:\Users\TGizz\Downloads\mseinstall.exe
2012-07-28 21:53 - 2009-07-13 20:45 - 00015136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-28 21:53 - 2009-07-13 20:45 - 00015136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-28 21:52 - 2009-07-13 21:13 - 00713888 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-28 21:46 - 2012-07-28 21:46 - 00285512 ____A C:\Windows\Minidump\072912-35037-01.dmp
2012-07-28 21:46 - 2011-07-23 17:33 - 347942359 ____A C:\Windows\MEMORY.DMP
2012-07-28 21:43 - 2012-07-28 21:42 - 00292184 ____A C:\Windows\Minidump\072912-31200-01.dmp
2012-07-28 02:07 - 2012-05-29 20:57 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3568411142-4073580314-4145923839-1000Core.job
2012-07-27 23:12 - 2012-07-27 23:12 - 06723616 ____A (Adobe Systems Inc.) C:\Users\TGizz\Downloads\Shockwave_Installer_Slim.exe
2012-07-27 22:54 - 2012-07-27 22:54 - 00002106 ____A C:\Users\Public\Desktop\Path of Exile.lnk
2012-07-25 18:59 - 2012-07-25 18:59 - 06603776 ____A C:\Users\TGizz\Downloads\PathOfExileInstaller.msi
2012-07-17 00:24 - 2012-07-17 00:24 - 00003947 ____A C:\Users\TGizz\Downloads\DIABLO 3.TXT
2012-07-14 17:30 - 2012-07-14 17:30 - 00292184 ____A C:\Windows\Minidump\071412-36317-01.dmp
2012-07-11 19:04 - 2012-05-29 20:57 - 00002401 ____A C:\Users\TGizz\Desktop\Google Chrome.lnk
2012-07-11 15:18 - 2012-07-11 15:18 - 00651538 ____A C:\Users\TGizz\Downloads\Unconfirmed 9862.crdownload
2012-07-11 00:12 - 2012-07-11 00:12 - 00001068 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-07-08 13:56 - 2012-07-08 13:56 - 32409936 ____A C:\Users\TGizz\Downloads\WOW-4.3.4.15050-enUS-Trial.exe
2012-07-08 13:37 - 2012-06-08 19:14 - 00029184 __ASH C:\Users\TGizz\Documents\Thumbs.db
2012-07-03 09:46 - 2010-03-14 19:29 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-03 01:22 - 2012-07-03 01:22 - 00292184 ____A C:\Windows\Minidump\070312-39265-01.dmp
2012-06-15 07:13 - 2012-06-15 07:13 - 00019397 ____A C:\Users\TGizz\Downloads\Rock_Band_Unplugged_USA_REPACK_PSP-pSyPSP.torrent
2012-06-13 12:05 - 2012-06-13 12:05 - 00666724 ____A C:\Users\TGizz\Downloads\Lollipop.Chainsaw.XBOX360-SPARE.torrent
2012-06-01 10:25 - 2012-06-01 10:25 - 22267083 ____A C:\Users\TGizz\Downloads\Diablo III Extreme Theme by VikiTech.zip
2012-06-01 01:16 - 2012-06-01 01:16 - 11639286 ____A C:\Users\TGizz\Downloads\Diablo3.themepack.exe
2012-06-01 01:16 - 2012-06-01 01:16 - 11639286 ____A C:\Users\TGizz\Downloads\Diablo3.themepack (1).exe
2012-05-29 20:46 - 2012-05-29 20:47 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-05-29 20:46 - 2012-05-29 20:47 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-05-14 23:06 - 2012-05-14 23:06 - 00000000 ____A C:\Users\TGizz\Desktop\New Text Document.txt
2012-05-14 19:09 - 2012-05-14 18:53 - 00000894 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-13 22:14 - 2012-05-13 22:14 - 07336648 ____A (Blizzard Entertainment) C:\Users\TGizz\Downloads\Diablo-III-8370-enUS-Installer-downloader.exe
2012-05-13 21:34 - 2012-05-13 21:34 - 04815840 ____A (Make The Cut, LLC.) C:\Users\TGizz\Downloads\iRinger.exe
2012-05-01 17:57 - 2012-05-01 17:57 - 00013429 ____A C:\Users\TGizz\Downloads\epic-meal-time-Bacon-Strips.m4r
2012-05-01 17:54 - 2012-05-01 17:54 - 00027697 ____A C:\Users\TGizz\Downloads\old-spice-whistle.m4r
ZeroAccess:
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\@
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\L
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\U
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\U\00000001.@
C:\Windows\Installer\{2c09a3b0-5747-e3af-45e1-05c244adca82}\U\800000cb.@
Possible partition infection:
C:\Windows\svchost.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 13%
Total physical RAM: 4095.05 MB
Available physical RAM: 3537.86 MB
Total Pagefile: 4093.2 MB
Available Pagefile: 3521.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:931.41 GB) (Free:269.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Removable) (Total:7.53 GB) (Free:7.52 GB) FAT32
3 Drive e: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
5 Drive g: (DVD_ROM) (CDROM) (Total:0.18 GB) (Free:0 GB) UDF
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 7712 MB 0 B
Disk 2 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 7712 MB 0 B
==================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-07-08 02:20
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-29 11:15:26
Running from D:\Tools
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-29 00:44] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======