BobbyShanks
Posts: 15 +0
Hello,
Noticed strange pop-ups and when I tried to scan with MSE, noticed that it wasn't letting me do anything. Firewall down as well. Searched the net and followed advice to install some registry edits. Reinstalled MSE and Firewall started to work. Scanned with MSE and noticed many Sirefef infections.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-09-2012
Ran by SYSTEM at 28-09-2012 22:23:49
Running from E:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10775584 2010-06-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2040352 2010-06-21] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [212480 2010-05-14] (Alps Electric Co., Ltd.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [SmartWiHelper] "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup [89080 2010-07-15] (Sony Electronics Corporation)
HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [RemoteControl11] "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe" [234792 2011-04-19] (CyberLink Corp.)
HKU\AAA\...\Run: [Ghostery] rundll32.exe C:\Users\AAA\AppData\Local\Ghostery\mwqgmpyk.dll,IZDSP_SetRoom [823296 2012-06-30] (iZotope, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$02c12bab5ca1d9e077617c7109507ddc\n. ATTENTION! ====> ZeroAccess
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ===================
3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
3 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-19] ()
3 CyberLink PowerDVD 11.0 Monitor Service; "C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe" [70952 2011-03-31] (CyberLink)
3 CyberLink PowerDVD 11.0 Service; "C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe" [312616 2011-03-31] (CyberLink)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
4 Oasis2Service; "C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe" [46080 2010-06-23] ()
2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" [259192 2011-01-29] (Sony Corporation)
3 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [994360 2011-10-14] (Secunia)
2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
==================== Drivers (Whitelisted) =====================
3 ACRUSBTM; C:\Windows\SysWow64\Drivers\ACRUSBTM.sys [28672 2007-08-02] ()
3 ArcSoftKsUFilter; C:\Windows\System32\Drivers\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
1 cbfs3; C:\Windows\System32\Drivers\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
3 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [254528 2011-04-03] (DT Soft Ltd)
1 dvdfabio; C:\Windows\System32\Drivers\dvdfabio.sys [13728 2012-07-11] (Fengtao Software Inc.)
0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18232 2011-02-23] ()
3 SNP2STD; C:\Windows\System32\DRIVERS\snp2sxp.sys [12263552 2006-08-11] ()
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2011-04-03] (Duplex Secure Ltd.)
3 vdrive; C:\Windows\System32\Drivers\vdrive.sys [46496 2012-07-11] (Fengtao Software Inc.)
2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-04-12] (CyberLink Corp.)
3 ALSysIO; \??\C:\Users\AAA\AppData\Local\Temp\ALSysIO64.sys [x]
1 ArcSec; [x]
2 MSSQL$DDNI; [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-09-28 21:15 - 2012-09-28 21:15 - 00000056 ____A C:\Windows\setupact.log
2012-09-28 21:15 - 2012-09-28 21:15 - 00000000 ____A C:\Windows\setuperr.log
2012-09-28 20:55 - 2012-09-28 20:59 - 00000000 ____D C:\FRST
2012-09-28 20:44 - 2012-09-28 20:44 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-09-28 20:43 - 2012-09-28 20:55 - 00000000 ____D C:\Windows\8C5C34C7BC6B48318B2C6535FE63E502.TMP
2012-09-28 20:25 - 2012-09-28 20:25 - 00002187 ____A C:\Users\AAA\Desktop\FIX.txt
2012-09-28 20:05 - 2012-09-28 20:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-28 20:05 - 2012-09-28 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-09-27 21:48 - 2012-09-27 21:48 - 00000000 ____D C:\Users\AAA\AppData\Local\Ghostery
2012-09-18 19:18 - 2012-05-21 15:11 - 00000074 ____A C:\Users\AAA\Downloads\Google+.url
2012-09-17 22:09 - 2012-09-17 22:09 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-09-17 21:45 - 2012-09-17 21:45 - 15224295 ____A C:\Users\AAA\Desktop\Zoom Tones.zip
2012-09-16 17:20 - 2012-09-16 17:20 - 08684307 ____A C:\Users\AAA\Downloads\CopyTransManagerv0.981.zip
2012-09-15 07:29 - 2012-08-22 13:12 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-09-15 07:29 - 2012-08-22 13:12 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-09-15 07:29 - 2012-08-22 13:12 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-09-15 07:29 - 2012-08-22 13:12 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-09-15 07:29 - 2012-08-02 12:58 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-09-15 07:29 - 2012-08-02 11:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-09-15 07:29 - 2012-07-04 15:26 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2012-09-11 20:19 - 2012-09-11 20:19 - 00000000 ____D C:\Users\AAA\Desktop\MGS
2012-09-09 09:12 - 2012-09-09 09:12 - 00000000 ____D C:\Users\AAA\AppData\Roaming\Moonchild Productions
2012-09-09 09:12 - 2012-09-09 09:12 - 00000000 ____D C:\Users\AAA\AppData\Local\Moonchild Productions
2012-08-30 21:03 - 2012-08-30 21:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 21:03 - 2012-08-30 21:03 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-29 19:11 - 2012-08-29 19:11 - 00000098 ____A C:\Users\AAA\Documents\ING DIRECT.txt
==================== 3 Months Modified Files ==================
2012-09-28 21:18 - 2009-07-13 23:45 - 00009888 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-28 21:18 - 2009-07-13 23:45 - 00009888 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-28 21:15 - 2012-09-28 21:15 - 00000056 ____A C:\Windows\setupact.log
2012-09-28 21:15 - 2012-09-28 21:15 - 00000000 ____A C:\Windows\setuperr.log
2012-09-28 21:15 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-28 21:04 - 2011-01-25 21:37 - 01644746 ____A C:\Windows\WindowsUpdate.log
2012-09-28 21:03 - 2009-07-14 00:13 - 00779092 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-28 20:38 - 2011-01-27 20:41 - 00007614 ____A C:\Users\AAA\AppData\Local\Resmon.ResmonCfg
2012-09-28 20:25 - 2012-09-28 20:25 - 00002187 ____A C:\Users\AAA\Desktop\FIX.txt
2012-09-28 20:06 - 2011-02-12 12:26 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-17 21:45 - 2012-09-17 21:45 - 15224295 ____A C:\Users\AAA\Desktop\Zoom Tones.zip
2012-09-16 17:20 - 2012-09-16 17:20 - 08684307 ____A C:\Users\AAA\Downloads\CopyTransManagerv0.981.zip
2012-09-16 09:36 - 2011-01-27 22:21 - 00007429 ____A C:\test.xml
2012-09-15 07:30 - 2011-01-26 07:13 - 64462936 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-30 21:03 - 2012-08-30 21:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 21:03 - 2012-08-30 21:03 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-29 19:11 - 2012-08-29 19:11 - 00000098 ____A C:\Users\AAA\Documents\ING DIRECT.txt
2012-08-27 16:56 - 2011-06-20 07:00 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-08-26 21:53 - 2012-08-26 21:53 - 00000761 ____A C:\Windows\System32\Drivers\etc\hosts.txt
2012-08-26 06:06 - 2009-07-13 23:45 - 00385008 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-25 22:21 - 2012-08-25 22:21 - 11404800 ____A C:\Users\AAA\Downloads\MicrosoftCodecPack_amd64.msi
2012-08-24 06:45 - 2011-09-02 07:12 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-08-22 13:12 - 2012-09-15 07:29 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-08-22 13:12 - 2012-09-15 07:29 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-08-22 13:12 - 2012-09-15 07:29 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-08-22 13:12 - 2012-09-15 07:29 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-08-18 20:51 - 2012-08-18 20:51 - 00002217 ____A C:\Users\AAA\Desktop\Kindle.lnk
2012-08-18 13:05 - 2011-01-25 23:30 - 00097360 ____A C:\Users\AAA\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-18 12:22 - 2012-08-18 12:22 - 00001025 ____A C:\Windows\SysWOW64\sysprs7.tgz
2012-08-18 12:22 - 2012-08-18 12:22 - 00001025 ____A C:\Windows\SysWOW64\sysprs7.dll
2012-08-18 12:22 - 2012-08-18 12:22 - 00000219 ____A C:\Windows\SysWOW64\lsprst7.tgz
2012-08-18 12:22 - 2012-08-18 12:22 - 00000205 ____A C:\Windows\SysWOW64\lsprst7.dll
2012-08-18 12:22 - 2012-08-18 12:22 - 00000016 ____H C:\Windows\SysWOW64\servdat.slm
2012-08-07 21:41 - 2012-07-28 21:30 - 00000928 ____A C:\Users\AAA\Desktop\DVDFab Virtual Drive.lnk
2012-08-02 12:58 - 2012-09-15 07:29 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-08-02 11:57 - 2012-09-15 07:29 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-07-28 17:53 - 2012-07-28 17:53 - 00002188 ____A C:\Users\Public\Desktop\CyberLink PowerDVD 11.lnk
2012-07-21 12:48 - 2012-07-21 12:48 - 00001901 ____A C:\Users\AAA\Downloads\mTABWebApp.jnlp
2012-07-18 13:15 - 2012-08-15 06:14 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 14:32 - 2012-07-28 21:30 - 00046496 ____A (Fengtao Software Inc.) C:\Windows\System32\Drivers\vdrive.sys
2012-07-11 14:32 - 2012-07-28 21:30 - 00013728 ____A (Fengtao Software Inc.) C:\Windows\System32\Drivers\dvdfabio.sys
2012-07-06 15:07 - 2012-08-15 06:21 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-07-04 17:16 - 2012-08-15 06:14 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 17:13 - 2012-08-15 06:14 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 17:13 - 2012-08-15 06:14 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 16:16 - 2012-08-15 06:14 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 16:14 - 2012-08-15 06:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-04 15:26 - 2012-09-15 07:29 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2012-07-02 19:15 - 2011-01-26 21:24 - 00000021 ____A C:\Windows\Model.txt
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2513201644-174381648-3567618102-1000\$02c12bab5ca1d9e077617c7109507ddc
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$02c12bab5ca1d9e077617c7109507ddc
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-13 22:10:31
Restore point made on: 2012-09-15 07:29:25
Restore point made on: 2012-09-22 10:13:04
Restore point made on: 2012-09-28 20:44:10
Restore point made on: 2012-09-28 20:52:03
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 4012.96 MB
Available physical RAM: 3385.74 MB
Total Pagefile: 4011.11 MB
Available Pagefile: 3383.28 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:452.47 GB) (Free:162.78 GB) NTFS
2 Drive d: (VERBATIM) (Fixed) (Total:1863 GB) (Free:1125.62 GB) exFAT
3 Drive e: (KINGSTON) (Removable) (Total:7.55 GB) (Free:2.1 GB) FAT32
4 Drive g: (Recovery) (Fixed) (Total:13.19 GB) (Free:0.76 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: (71C403_V) (CDROM) (Total:2.28 GB) (Free:0 GB) UDF
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 1863 GB 1024 KB
Disk 2 Online 7751 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 452 GB 13 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 G Recovery NTFS Partition 13 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 452 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D VERBATIM exFAT Partition 1863 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7747 MB 4032 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 E KINGSTON FAT32 Removable 7747 MB Healthy
=========================================================
Last Boot: 2012-09-26 11:16
==================== End Of Log =============================
Farbar Recovery Scan Tool (x64) Version: 25-09-2012
Ran by SYSTEM at 2012-09-28 22:25:27
Running from E:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
Noticed strange pop-ups and when I tried to scan with MSE, noticed that it wasn't letting me do anything. Firewall down as well. Searched the net and followed advice to install some registry edits. Reinstalled MSE and Firewall started to work. Scanned with MSE and noticed many Sirefef infections.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-09-2012
Ran by SYSTEM at 28-09-2012 22:23:49
Running from E:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10775584 2010-06-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2040352 2010-06-21] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [212480 2010-05-14] (Alps Electric Co., Ltd.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [SmartWiHelper] "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup [89080 2010-07-15] (Sony Electronics Corporation)
HKLM-x32\...\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [RemoteControl11] "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe" [234792 2011-04-19] (CyberLink Corp.)
HKU\AAA\...\Run: [Ghostery] rundll32.exe C:\Users\AAA\AppData\Local\Ghostery\mwqgmpyk.dll,IZDSP_SetRoom [823296 2012-06-30] (iZotope, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$02c12bab5ca1d9e077617c7109507ddc\n. ATTENTION! ====> ZeroAccess
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ===================
3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
3 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-19] ()
3 CyberLink PowerDVD 11.0 Monitor Service; "C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe" [70952 2011-03-31] (CyberLink)
3 CyberLink PowerDVD 11.0 Service; "C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe" [312616 2011-03-31] (CyberLink)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
4 Oasis2Service; "C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe" [46080 2010-06-23] ()
2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" [259192 2011-01-29] (Sony Corporation)
3 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [994360 2011-10-14] (Secunia)
2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
==================== Drivers (Whitelisted) =====================
3 ACRUSBTM; C:\Windows\SysWow64\Drivers\ACRUSBTM.sys [28672 2007-08-02] ()
3 ArcSoftKsUFilter; C:\Windows\System32\Drivers\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
1 cbfs3; C:\Windows\System32\Drivers\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
3 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [254528 2011-04-03] (DT Soft Ltd)
1 dvdfabio; C:\Windows\System32\Drivers\dvdfabio.sys [13728 2012-07-11] (Fengtao Software Inc.)
0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18232 2011-02-23] ()
3 SNP2STD; C:\Windows\System32\DRIVERS\snp2sxp.sys [12263552 2006-08-11] ()
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2011-04-03] (Duplex Secure Ltd.)
3 vdrive; C:\Windows\System32\Drivers\vdrive.sys [46496 2012-07-11] (Fengtao Software Inc.)
2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-04-12] (CyberLink Corp.)
3 ALSysIO; \??\C:\Users\AAA\AppData\Local\Temp\ALSysIO64.sys [x]
1 ArcSec; [x]
2 MSSQL$DDNI; [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-09-28 21:15 - 2012-09-28 21:15 - 00000056 ____A C:\Windows\setupact.log
2012-09-28 21:15 - 2012-09-28 21:15 - 00000000 ____A C:\Windows\setuperr.log
2012-09-28 20:55 - 2012-09-28 20:59 - 00000000 ____D C:\FRST
2012-09-28 20:44 - 2012-09-28 20:44 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-09-28 20:43 - 2012-09-28 20:55 - 00000000 ____D C:\Windows\8C5C34C7BC6B48318B2C6535FE63E502.TMP
2012-09-28 20:25 - 2012-09-28 20:25 - 00002187 ____A C:\Users\AAA\Desktop\FIX.txt
2012-09-28 20:05 - 2012-09-28 20:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-28 20:05 - 2012-09-28 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-09-27 21:48 - 2012-09-27 21:48 - 00000000 ____D C:\Users\AAA\AppData\Local\Ghostery
2012-09-18 19:18 - 2012-05-21 15:11 - 00000074 ____A C:\Users\AAA\Downloads\Google+.url
2012-09-17 22:09 - 2012-09-17 22:09 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-09-17 21:45 - 2012-09-17 21:45 - 15224295 ____A C:\Users\AAA\Desktop\Zoom Tones.zip
2012-09-16 17:20 - 2012-09-16 17:20 - 08684307 ____A C:\Users\AAA\Downloads\CopyTransManagerv0.981.zip
2012-09-15 07:29 - 2012-08-22 13:12 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-09-15 07:29 - 2012-08-22 13:12 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-09-15 07:29 - 2012-08-22 13:12 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-09-15 07:29 - 2012-08-22 13:12 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-09-15 07:29 - 2012-08-02 12:58 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-09-15 07:29 - 2012-08-02 11:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-09-15 07:29 - 2012-07-04 15:26 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2012-09-11 20:19 - 2012-09-11 20:19 - 00000000 ____D C:\Users\AAA\Desktop\MGS
2012-09-09 09:12 - 2012-09-09 09:12 - 00000000 ____D C:\Users\AAA\AppData\Roaming\Moonchild Productions
2012-09-09 09:12 - 2012-09-09 09:12 - 00000000 ____D C:\Users\AAA\AppData\Local\Moonchild Productions
2012-08-30 21:03 - 2012-08-30 21:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 21:03 - 2012-08-30 21:03 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-29 19:11 - 2012-08-29 19:11 - 00000098 ____A C:\Users\AAA\Documents\ING DIRECT.txt
==================== 3 Months Modified Files ==================
2012-09-28 21:18 - 2009-07-13 23:45 - 00009888 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-28 21:18 - 2009-07-13 23:45 - 00009888 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-28 21:15 - 2012-09-28 21:15 - 00000056 ____A C:\Windows\setupact.log
2012-09-28 21:15 - 2012-09-28 21:15 - 00000000 ____A C:\Windows\setuperr.log
2012-09-28 21:15 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-28 21:04 - 2011-01-25 21:37 - 01644746 ____A C:\Windows\WindowsUpdate.log
2012-09-28 21:03 - 2009-07-14 00:13 - 00779092 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-28 20:38 - 2011-01-27 20:41 - 00007614 ____A C:\Users\AAA\AppData\Local\Resmon.ResmonCfg
2012-09-28 20:25 - 2012-09-28 20:25 - 00002187 ____A C:\Users\AAA\Desktop\FIX.txt
2012-09-28 20:06 - 2011-02-12 12:26 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-17 21:45 - 2012-09-17 21:45 - 15224295 ____A C:\Users\AAA\Desktop\Zoom Tones.zip
2012-09-16 17:20 - 2012-09-16 17:20 - 08684307 ____A C:\Users\AAA\Downloads\CopyTransManagerv0.981.zip
2012-09-16 09:36 - 2011-01-27 22:21 - 00007429 ____A C:\test.xml
2012-09-15 07:30 - 2011-01-26 07:13 - 64462936 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-30 21:03 - 2012-08-30 21:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 21:03 - 2012-08-30 21:03 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-29 19:11 - 2012-08-29 19:11 - 00000098 ____A C:\Users\AAA\Documents\ING DIRECT.txt
2012-08-27 16:56 - 2011-06-20 07:00 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-08-26 21:53 - 2012-08-26 21:53 - 00000761 ____A C:\Windows\System32\Drivers\etc\hosts.txt
2012-08-26 06:06 - 2009-07-13 23:45 - 00385008 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-25 22:21 - 2012-08-25 22:21 - 11404800 ____A C:\Users\AAA\Downloads\MicrosoftCodecPack_amd64.msi
2012-08-24 06:45 - 2011-09-02 07:12 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-08-22 13:12 - 2012-09-15 07:29 - 01913200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-08-22 13:12 - 2012-09-15 07:29 - 00950128 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-08-22 13:12 - 2012-09-15 07:29 - 00376688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-08-22 13:12 - 2012-09-15 07:29 - 00288624 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-08-18 20:51 - 2012-08-18 20:51 - 00002217 ____A C:\Users\AAA\Desktop\Kindle.lnk
2012-08-18 13:05 - 2011-01-25 23:30 - 00097360 ____A C:\Users\AAA\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-18 12:22 - 2012-08-18 12:22 - 00001025 ____A C:\Windows\SysWOW64\sysprs7.tgz
2012-08-18 12:22 - 2012-08-18 12:22 - 00001025 ____A C:\Windows\SysWOW64\sysprs7.dll
2012-08-18 12:22 - 2012-08-18 12:22 - 00000219 ____A C:\Windows\SysWOW64\lsprst7.tgz
2012-08-18 12:22 - 2012-08-18 12:22 - 00000205 ____A C:\Windows\SysWOW64\lsprst7.dll
2012-08-18 12:22 - 2012-08-18 12:22 - 00000016 ____H C:\Windows\SysWOW64\servdat.slm
2012-08-07 21:41 - 2012-07-28 21:30 - 00000928 ____A C:\Users\AAA\Desktop\DVDFab Virtual Drive.lnk
2012-08-02 12:58 - 2012-09-15 07:29 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-08-02 11:57 - 2012-09-15 07:29 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-07-28 17:53 - 2012-07-28 17:53 - 00002188 ____A C:\Users\Public\Desktop\CyberLink PowerDVD 11.lnk
2012-07-21 12:48 - 2012-07-21 12:48 - 00001901 ____A C:\Users\AAA\Downloads\mTABWebApp.jnlp
2012-07-18 13:15 - 2012-08-15 06:14 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 14:32 - 2012-07-28 21:30 - 00046496 ____A (Fengtao Software Inc.) C:\Windows\System32\Drivers\vdrive.sys
2012-07-11 14:32 - 2012-07-28 21:30 - 00013728 ____A (Fengtao Software Inc.) C:\Windows\System32\Drivers\dvdfabio.sys
2012-07-06 15:07 - 2012-08-15 06:21 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-07-04 17:16 - 2012-08-15 06:14 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 17:13 - 2012-08-15 06:14 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 17:13 - 2012-08-15 06:14 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 16:16 - 2012-08-15 06:14 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 16:14 - 2012-08-15 06:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-04 15:26 - 2012-09-15 07:29 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2012-07-02 19:15 - 2011-01-26 21:24 - 00000021 ____A C:\Windows\Model.txt
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2513201644-174381648-3567618102-1000\$02c12bab5ca1d9e077617c7109507ddc
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$02c12bab5ca1d9e077617c7109507ddc
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-13 22:10:31
Restore point made on: 2012-09-15 07:29:25
Restore point made on: 2012-09-22 10:13:04
Restore point made on: 2012-09-28 20:44:10
Restore point made on: 2012-09-28 20:52:03
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 4012.96 MB
Available physical RAM: 3385.74 MB
Total Pagefile: 4011.11 MB
Available Pagefile: 3383.28 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:452.47 GB) (Free:162.78 GB) NTFS
2 Drive d: (VERBATIM) (Fixed) (Total:1863 GB) (Free:1125.62 GB) exFAT
3 Drive e: (KINGSTON) (Removable) (Total:7.55 GB) (Free:2.1 GB) FAT32
4 Drive g: (Recovery) (Fixed) (Total:13.19 GB) (Free:0.76 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: (71C403_V) (CDROM) (Total:2.28 GB) (Free:0 GB) UDF
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 1863 GB 1024 KB
Disk 2 Online 7751 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 452 GB 13 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 G Recovery NTFS Partition 13 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 452 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D VERBATIM exFAT Partition 1863 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7747 MB 4032 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 E KINGSTON FAT32 Removable 7747 MB Healthy
=========================================================
Last Boot: 2012-09-26 11:16
==================== End Of Log =============================
Farbar Recovery Scan Tool (x64) Version: 25-09-2012
Ran by SYSTEM at 2012-09-28 22:25:27
Running from E:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======