Hi !
I've got the same problem as everyone else : I tried to run microsoft security essentials, and now it restarts every minute. Then, I've followed the instructions and here are my FRST.txt and services search.txt log files.
Just a thing : as my copy/paste was apparently too strong for the forum, I had to cut the older lines of one month created and three months modified.
Thank you very much for the help !
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 01-08-2012 13:52:24
Running from G:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [10959464 2012-01-15] (Realtek Semiconductor)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini [301 2012-07-30] ()
HKLM\...\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_MX_Premium_Version_a_telecharger\TrayServer_fr.exe [90112 2008-09-01] (Magix)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641704 2012-06-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml [20992 2012-03-19] ()
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Guillaume\...\Run: [Google Update] "C:\Users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-03-06] (Google Inc.)
HKU\Guillaume\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\Guillaume\...\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart [3297280 2007-11-20] (Google)
HKU\Guillaume\...\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe [955392 2009-08-16] (SFX TEAM)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Guillaume\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
================================ Services (Whitelisted) ==================
2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [291840 2012-06-11] (Advanced Micro Devices, Inc.)
2 DragonSvc; C:\Program Files\Common Files\Nuance\dgnsvc.exe [296808 2010-08-12] (Nuance Communications, Inc.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe /DisableUI [1840128 2011-05-24] (MAGIX AG)
3 FirebirdServerMAGIXInstance; "C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe" [2702848 2011-04-26] (MAGIX®)
2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe" [335872 2006-10-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-07-03] (Skype Technologies)
3 WajamUpdater; "C:\Program Files\Wajam\Updater\WajamUpdater.exe" [109064 2012-06-14] (Wajam)
========================== Drivers (Whitelisted) =============
2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
2 AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [199528 2011-12-02] (Realtek Semiconductor Corp.)
2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2010-12-13] (Realtek )
3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2010-12-13] (Realtek Corporation)
3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [19968 2010-12-13] (Windows (R) Codename Longhorn DDK provider)
3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2010-12-13] (Realtek Corporation)
3 TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys [14080 2012-08-01] ()
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-01 13:51 - 2012-08-01 13:52 - 00000000 ____D C:\FRST
2012-08-01 03:22 - 2012-08-01 03:22 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nkzzphgc.sys
2012-08-01 03:07 - 2012-08-01 03:07 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-01 03:03 - 2012-08-01 03:03 - 10299264 ____A (Microsoft Corporation) C:\Users\Guillaume\Downloads\mseinstall (1).exe
2012-08-01 02:53 - 2012-08-01 02:53 - 01552384 ____A C:\Users\Guillaume\Downloads\RogueKiller-7.6.4.exe
2012-08-01 02:53 - 2012-08-01 02:53 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-01 02:47 - 2012-08-01 02:47 - 00000000 ____D C:\Users\Guillaume\AppData\Local\Wajam
2012-08-01 02:47 - 2012-08-01 02:47 - 00000000 ____D C:\Program Files\Wajam
2012-08-01 02:46 - 2012-08-01 02:47 - 00014572 ____A C:\INSTALLHELPER.LOG
2012-08-01 02:46 - 2012-08-01 02:46 - 00665696 ____A (OptimumInstaller) C:\Users\Guillaume\Downloads\Setup.exe
2012-08-01 02:34 - 2012-08-01 02:34 - 00388608 ____A (Trend Micro Inc.) C:\Users\Guillaume\Downloads\HijackThis.exe
2012-08-01 02:31 - 2012-08-01 02:31 - 01402880 ____A C:\Users\Guillaume\Downloads\hijackthis_hijackthis_2.0.4_anglais_17891.msi
2012-08-01 02:19 - 2012-08-01 02:19 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-01 02:16 - 2012-08-01 02:16 - 00138752 ____A C:\Users\Guillaume\AppData\Roaming\deo0_sar.exe
2012-08-01 00:33 - 2012-08-01 00:34 - 00000000 ____D C:\Users\Guillaume\AppData\Local\{89DE1A0B-B4DE-49E8-A511-757B47164C43}
2012-08-01 00:33 - 2012-08-01 00:33 - 00000000 ____D C:\Users\Guillaume\AppData\Local\{406E7CE8-4A76-45C5-B4F3-F5759F0990FE}
============ 3 Months Modified Files ========================
2012-08-01 03:40 - 2012-07-15 15:00 - 00001176 ____A C:\Windows\setupact.log
2012-08-01 03:40 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-01 03:22 - 2012-08-01 03:22 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nkzzphgc.sys
2012-08-01 03:20 - 2012-03-06 19:05 - 00001094 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1266765766-3627827974-3855528514-1000UA.job
2012-08-01 03:08 - 2012-03-06 20:33 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-01 03:08 - 2012-03-06 17:51 - 01299142 ____A C:\Windows\WindowsUpdate.log
2012-08-01 03:07 - 2012-03-06 17:59 - 01603068 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-01 03:03 - 2012-08-01 03:03 - 10299264 ____A (Microsoft Corporation) C:\Users\Guillaume\Downloads\mseinstall (1).exe
2012-08-01 02:59 - 2012-07-30 13:12 - 00002168 ____A C:\Windows\PFRO.log
2012-08-01 02:53 - 2012-08-01 02:53 - 01552384 ____A C:\Users\Guillaume\Downloads\RogueKiller-7.6.4.exe
2012-08-01 02:53 - 2012-08-01 02:53 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-01 02:47 - 2012-08-01 02:46 - 00014572 ____A C:\INSTALLHELPER.LOG
2012-08-01 02:46 - 2012-08-01 02:46 - 00665696 ____A (OptimumInstaller) C:\Users\Guillaume\Downloads\Setup.exe
2012-08-01 02:34 - 2012-08-01 02:34 - 00388608 ____A (Trend Micro Inc.) C:\Users\Guillaume\Downloads\HijackThis.exe
2012-08-01 02:31 - 2012-08-01 02:31 - 01402880 ____A C:\Users\Guillaume\Downloads\hijackthis_hijackthis_2.0.4_anglais_17891.msi
2012-08-01 02:16 - 2012-08-01 02:16 - 00138752 ____A C:\Users\Guillaume\AppData\Roaming\deo0_sar.exe
2012-08-01 02:13 - 2012-04-03 18:47 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-01 02:13 - 2012-03-06 19:40 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-31 21:20 - 2012-03-06 19:05 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1266765766-3627827974-3855528514-1000Core.job
2012-07-31 12:51 - 2012-07-31 12:51 - 00052936 ____A C:\Users\Guillaume\.recently-used.xbel
ZeroAccess:
C:\Windows\Installer\{955b7c99-12db-61e4-d051-b536dcac8f4c}
C:\Windows\Installer\{955b7c99-12db-61e4-d051-b536dcac8f4c}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 4093.55 MB
Available physical RAM: 3580.32 MB
Total Pagefile: 4091.83 MB
Available Pagefile: 3589.02 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.7 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:146.39 GB) (Free:26 GB) NTFS
2 Drive e: () (Fixed) (Total:785.03 GB) (Free:155.85 GB) NTFS
4 Drive g: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 961 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 146 GB 101 MB
Partition 3 Primary 785 GB 146 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 146 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 785 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 961 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 961 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-30 13:59
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-01 13:57:35
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
Thank again a lot !
I've got the same problem as everyone else : I tried to run microsoft security essentials, and now it restarts every minute. Then, I've followed the instructions and here are my FRST.txt and services search.txt log files.
Just a thing : as my copy/paste was apparently too strong for the forum, I had to cut the older lines of one month created and three months modified.
Thank you very much for the help !
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 01-08-2012 13:52:24
Running from G:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [10959464 2012-01-15] (Realtek Semiconductor)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini [301 2012-07-30] ()
HKLM\...\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_MX_Premium_Version_a_telecharger\TrayServer_fr.exe [90112 2008-09-01] (Magix)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641704 2012-06-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml [20992 2012-03-19] ()
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Guillaume\...\Run: [Google Update] "C:\Users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-03-06] (Google Inc.)
HKU\Guillaume\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\Guillaume\...\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart [3297280 2007-11-20] (Google)
HKU\Guillaume\...\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe [955392 2009-08-16] (SFX TEAM)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\Guillaume\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
================================ Services (Whitelisted) ==================
2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [291840 2012-06-11] (Advanced Micro Devices, Inc.)
2 DragonSvc; C:\Program Files\Common Files\Nuance\dgnsvc.exe [296808 2010-08-12] (Nuance Communications, Inc.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe /DisableUI [1840128 2011-05-24] (MAGIX AG)
3 FirebirdServerMAGIXInstance; "C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe" [2702848 2011-04-26] (MAGIX®)
2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe" [335872 2006-10-26] (Microsoft Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-07-03] (Skype Technologies)
3 WajamUpdater; "C:\Program Files\Wajam\Updater\WajamUpdater.exe" [109064 2012-06-14] (Wajam)
========================== Drivers (Whitelisted) =============
2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
2 AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [199528 2011-12-02] (Realtek Semiconductor Corp.)
2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2010-12-13] (Realtek )
3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2010-12-13] (Realtek Corporation)
3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [19968 2010-12-13] (Windows (R) Codename Longhorn DDK provider)
3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2010-12-13] (Realtek Corporation)
3 TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys [14080 2012-08-01] ()
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-01 13:51 - 2012-08-01 13:52 - 00000000 ____D C:\FRST
2012-08-01 03:22 - 2012-08-01 03:22 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nkzzphgc.sys
2012-08-01 03:07 - 2012-08-01 03:07 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-01 03:03 - 2012-08-01 03:03 - 10299264 ____A (Microsoft Corporation) C:\Users\Guillaume\Downloads\mseinstall (1).exe
2012-08-01 02:53 - 2012-08-01 02:53 - 01552384 ____A C:\Users\Guillaume\Downloads\RogueKiller-7.6.4.exe
2012-08-01 02:53 - 2012-08-01 02:53 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-01 02:47 - 2012-08-01 02:47 - 00000000 ____D C:\Users\Guillaume\AppData\Local\Wajam
2012-08-01 02:47 - 2012-08-01 02:47 - 00000000 ____D C:\Program Files\Wajam
2012-08-01 02:46 - 2012-08-01 02:47 - 00014572 ____A C:\INSTALLHELPER.LOG
2012-08-01 02:46 - 2012-08-01 02:46 - 00665696 ____A (OptimumInstaller) C:\Users\Guillaume\Downloads\Setup.exe
2012-08-01 02:34 - 2012-08-01 02:34 - 00388608 ____A (Trend Micro Inc.) C:\Users\Guillaume\Downloads\HijackThis.exe
2012-08-01 02:31 - 2012-08-01 02:31 - 01402880 ____A C:\Users\Guillaume\Downloads\hijackthis_hijackthis_2.0.4_anglais_17891.msi
2012-08-01 02:19 - 2012-08-01 02:19 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-01 02:16 - 2012-08-01 02:16 - 00138752 ____A C:\Users\Guillaume\AppData\Roaming\deo0_sar.exe
2012-08-01 00:33 - 2012-08-01 00:34 - 00000000 ____D C:\Users\Guillaume\AppData\Local\{89DE1A0B-B4DE-49E8-A511-757B47164C43}
2012-08-01 00:33 - 2012-08-01 00:33 - 00000000 ____D C:\Users\Guillaume\AppData\Local\{406E7CE8-4A76-45C5-B4F3-F5759F0990FE}
============ 3 Months Modified Files ========================
2012-08-01 03:40 - 2012-07-15 15:00 - 00001176 ____A C:\Windows\setupact.log
2012-08-01 03:40 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-01 03:22 - 2012-08-01 03:22 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nkzzphgc.sys
2012-08-01 03:20 - 2012-03-06 19:05 - 00001094 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1266765766-3627827974-3855528514-1000UA.job
2012-08-01 03:08 - 2012-03-06 20:33 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-01 03:08 - 2012-03-06 17:51 - 01299142 ____A C:\Windows\WindowsUpdate.log
2012-08-01 03:07 - 2012-03-06 17:59 - 01603068 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-01 03:03 - 2012-08-01 03:03 - 10299264 ____A (Microsoft Corporation) C:\Users\Guillaume\Downloads\mseinstall (1).exe
2012-08-01 02:59 - 2012-07-30 13:12 - 00002168 ____A C:\Windows\PFRO.log
2012-08-01 02:53 - 2012-08-01 02:53 - 01552384 ____A C:\Users\Guillaume\Downloads\RogueKiller-7.6.4.exe
2012-08-01 02:53 - 2012-08-01 02:53 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-01 02:47 - 2012-08-01 02:46 - 00014572 ____A C:\INSTALLHELPER.LOG
2012-08-01 02:46 - 2012-08-01 02:46 - 00665696 ____A (OptimumInstaller) C:\Users\Guillaume\Downloads\Setup.exe
2012-08-01 02:34 - 2012-08-01 02:34 - 00388608 ____A (Trend Micro Inc.) C:\Users\Guillaume\Downloads\HijackThis.exe
2012-08-01 02:31 - 2012-08-01 02:31 - 01402880 ____A C:\Users\Guillaume\Downloads\hijackthis_hijackthis_2.0.4_anglais_17891.msi
2012-08-01 02:16 - 2012-08-01 02:16 - 00138752 ____A C:\Users\Guillaume\AppData\Roaming\deo0_sar.exe
2012-08-01 02:13 - 2012-04-03 18:47 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-01 02:13 - 2012-03-06 19:40 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-31 21:20 - 2012-03-06 19:05 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1266765766-3627827974-3855528514-1000Core.job
2012-07-31 12:51 - 2012-07-31 12:51 - 00052936 ____A C:\Users\Guillaume\.recently-used.xbel
ZeroAccess:
C:\Windows\Installer\{955b7c99-12db-61e4-d051-b536dcac8f4c}
C:\Windows\Installer\{955b7c99-12db-61e4-d051-b536dcac8f4c}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 4093.55 MB
Available physical RAM: 3580.32 MB
Total Pagefile: 4091.83 MB
Available Pagefile: 3589.02 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.7 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:146.39 GB) (Free:26 GB) NTFS
2 Drive e: () (Fixed) (Total:785.03 GB) (Free:155.85 GB) NTFS
4 Drive g: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 961 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 146 GB 101 MB
Partition 3 Primary 785 GB 146 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 146 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 785 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 961 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 961 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-30 13:59
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-01 13:57:35
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
Thank again a lot !