jjs1584
Posts: 17 +0
Hello,
I, like many others apparently, I have had my computer infected with the sirefef trojan. I am running Windows 7 (32 bit) on my Equus CS Nobilis laptop. I am almost positive I got the virus from a bogus Adobe Reader update. Below is the result of scanning using the Farbar tool. Thank you in advance for your help!
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-07-2012 01
Ran by SYSTEM at 09-07-2012 18:11:43
Running from E:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe [708608 2008-08-26] (Mirco-Star International CO., LTD.)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13556256 2008-09-24] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2008-09-24] (NVIDIA Corporation)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM\...\Run: [EKAIO2StatusMonitor] C:\Windows\system32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe [2717696 2011-08-26] (Eastman Kodak Company)
HKLM\...\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [71216 2007-03-14] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [52256 2007-01-08] ()
HKLM\...\Run: [Corel Photo Downloader] "C:\Program Files\Corel\Corel MediaOne\Corel PhotoDownloader.exe" -startup [x]
HKLM\...\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel MediaOne\CorelIOMonitor.exe [38400 2007-12-01] ()
HKLM\...\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" [159456 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [1446760 2012-01-06] (Garmin)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Administrator\...\Run: [EPSON Stylus CX4800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /FU "C:\Windows\TEMP\E_SDF0A.tmp" /EF "HKCU" [177664 2007-01-19] (SEIKO EPSON CORPORATION)
HKU\Administrator\...\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [1446760 2012-01-06] (Garmin)
HKU\Administrator\...\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup [2491688 2007-07-12] (Cyberlink)
HKU\Justin Silvi\...\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [1446760 2012-01-06] (Garmin)
HKU\Justin Silvi\...\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [x]
HKU\Justin Silvi\...\Policies\system: [NoHotStart] 1
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Justin Silvi\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 IntuitUpdateService; "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" [13672 2010-08-23] (Intuit Inc.)
2 McciCMService; "C:\Program Files\Common Files\Motive\McciCMService.exe" [319488 2011-02-07] (Alcatel-Lucent)
2 McciServiceHost; "C:\Program Files\Common Files\Motive\McciServiceHost.exe" [315392 2010-07-27] (Alcatel-Lucent)
2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [159744 2008-08-26] ()
2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [272024 2006-12-19] ()
2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.)
2 McMPFSvc; "C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
3 WMZuneComm; "c:\Program Files\Zune\WMZuneComm.exe" [x]
3 ZuneNetworkSvc; "c:\Program Files\Zune\ZuneNss.exe" [x]
3 ZuneWlanCfgSvc; "c:\Program Files\Zune\ZuneWlanCfgSvc.exe" [x]
========================== Drivers (Whitelisted) =============
3 Bridge; C:\Windows\System32\DRIVERS\bridge.sys [78336 2009-07-13] (Microsoft Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MRESP50; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [20096 2010-07-27] (Printing Communications Assoc., Inc. (PCAUSA))
3 smserial; C:\Windows\System32\DRIVERS\smserial.sys [1068032 2009-07-13] (Motorola Inc.)
3 WSDScan; C:\Windows\System32\DRIVERS\WSDScan.sys [20480 2009-07-13] (Microsoft Corporation)
1 ixgdublj; \??\C:\Windows\system32\drivers\ixgdublj.sys [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-09 18:11 - 2012-07-09 18:11 - 00000000 ____D C:\FRST
2012-07-09 12:25 - 2012-07-09 12:25 - 00008224 ____A C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-09 12:25 - 2012-07-09 12:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Garmin
2012-07-09 12:25 - 2012-07-09 12:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
2012-07-09 11:34 - 2012-07-09 11:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-09 11:34 - 2012-07-09 11:34 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-09 11:32 - 2012-07-09 11:32 - 10288512 ____A (Microsoft Corporation) C:\Users\Justin Silvi\Downloads\mseinstall.exe
2012-07-09 10:29 - 2012-07-09 10:29 - 00000000 ____D C:\Windows\System32\appmgmt
2012-07-06 17:27 - 2012-07-09 10:06 - 00000000 ____D C:\Users\Justin Silvi\Downloads\Family Guy - The Complete Season 9 [HDTV]
2012-06-29 05:57 - 2012-06-29 06:34 - 00000000 ____D C:\Users\Justin Silvi\Downloads\Hells Kitchen US S10E08 PDTV x264-LOL[ettv]
2012-06-29 05:33 - 2012-06-29 06:15 - 355284929 ____A C:\Users\Justin Silvi\Downloads\Hells.Kitchen.US.S10E07.PDTV.x264-LOL.mp4
2012-06-23 20:22 - 2012-06-23 20:22 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-06-21 10:01 - 2012-06-21 10:29 - 00000000 ____D C:\Users\Justin Silvi\Documents\Paychecks
2012-06-21 05:47 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 05:47 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 05:47 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 05:47 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 05:47 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 05:47 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 05:47 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 05:47 - 2012-06-02 11:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 05:47 - 2012-06-02 11:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 08:06 - 2012-06-19 08:40 - 00000000 ____D C:\Users\Justin Silvi\Downloads\Hells Kitchen US S10.E5 (xCrazy0328x)
2012-06-18 10:41 - 2012-06-18 10:41 - 00000000 ____D C:\Users\Justin Silvi\Documents\New folder
2012-06-18 04:31 - 2012-06-18 04:53 - 00000000 ____D C:\Users\Justin Silvi\Downloads\[ www.TorrentDay.com ] - Heat.Seekers.S01E07.Philadelphia.HDTV.XviD-CRiMSON2
2012-06-17 08:50 - 2012-06-17 08:55 - 00000000 ____D C:\Users\Justin Silvi\Documents\2812 inventory
2012-06-14 07:19 - 2012-07-06 07:36 - 48522240 ____A C:\Users\Justin Silvi\Documents\Personal Folders(1) backup.pst
2012-06-14 07:17 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 07:17 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 07:17 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 07:17 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 07:17 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 07:17 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 07:17 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 07:17 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 07:17 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 07:17 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 07:17 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 07:17 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 07:17 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 07:17 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 18:53 - 2012-05-14 17:05 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 18:53 - 2012-04-30 20:44 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 18:53 - 2012-04-27 19:17 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 18:53 - 2012-04-25 20:45 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 18:53 - 2012-04-25 20:45 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 18:53 - 2012-04-25 20:41 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 18:53 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 18:52 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 18:52 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 18:52 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-11 07:42 - 2012-06-11 07:42 - 00000000 ____D C:\Users\Justin Silvi\AppData\Local\Macromedia
============ 3 Months Modified Files ========================
2012-07-09 13:29 - 2011-03-22 19:21 - 00372688 ____A C:\Users\All Users\nvModes.001
2012-07-09 13:29 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-09 13:29 - 2009-07-13 20:39 - 00101938 ____A C:\Windows\setupact.log
2012-07-09 12:25 - 2012-07-09 12:25 - 00008224 ____A C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-09 12:21 - 2011-02-23 09:00 - 00082370 ____A C:\Windows\PFRO.log
2012-07-09 11:37 - 2009-07-13 20:34 - 00014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-09 11:37 - 2009-07-13 20:34 - 00014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-09 11:36 - 2011-02-23 10:40 - 01413271 ____A C:\Windows\WindowsUpdate.log
2012-07-09 11:34 - 2012-07-09 11:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-09 11:34 - 2011-02-23 07:50 - 00743534 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-09 11:32 - 2012-07-09 11:32 - 10288512 ____A (Microsoft Corporation) C:\Users\Justin Silvi\Downloads\mseinstall.exe
2012-07-09 10:34 - 2011-03-22 19:21 - 00372688 ____A C:\Users\All Users\nvModes.dat
2012-07-09 10:22 - 2012-04-12 07:38 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-09 05:31 - 2012-04-12 07:38 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-09 05:31 - 2011-05-14 08:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-06 07:36 - 2012-06-14 07:19 - 48522240 ____A C:\Users\Justin Silvi\Documents\Personal Folders(1) backup.pst
2012-06-29 06:15 - 2012-06-29 05:33 - 355284929 ____A C:\Users\Justin Silvi\Downloads\Hells.Kitchen.US.S10E07.PDTV.x264-LOL.mp4
2012-06-23 20:22 - 2012-06-23 20:22 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-06-22 20:22 - 2009-07-13 20:53 - 00032656 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-14 07:55 - 2009-07-13 20:33 - 00443904 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 07:22 - 2011-02-24 05:29 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-02 14:19 - 2012-06-21 05:47 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:47 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 05:47 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 05:47 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 05:47 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-21 05:47 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-17 15:11 - 2012-06-14 07:17 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-06-14 07:17 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-06-14 07:17 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-06-14 07:17 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-06-14 07:17 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 07:17 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-06-14 07:17 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-06-14 07:17 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 07:17 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:29 - 2012-06-14 07:17 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 07:17 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-06-14 07:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 07:17 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 07:17 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-14 17:05 - 2012-06-12 18:53 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 18:22 - 2012-05-13 18:22 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-05-13 18:22 - 2012-05-13 18:22 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-05-13 18:22 - 2012-05-13 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-05-13 18:22 - 2012-05-13 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-05-13 18:22 - 2011-02-27 09:21 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-04-30 20:44 - 2012-06-12 18:53 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:17 - 2012-06-12 18:53 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 20:45 - 2012-06-12 18:53 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-12 18:53 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-12 18:53 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 10:27 - 2011-12-30 16:51 - 00002828 __ASH C:\Windows\System32\KGyGaAvL.sys
2012-04-24 10:27 - 2011-12-30 16:51 - 00000088 __RSH C:\Windows\System32\8F109DC930.sys
2012-04-23 20:36 - 2012-06-12 18:52 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-06-12 18:52 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 18:52 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\@
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\L
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\U
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\L\00000004.@
ZeroAccess:
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}\@
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}\L
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 4095.16 MB
Available physical RAM: 3622.3 MB
Total Pagefile: 4093.44 MB
Available Pagefile: 3626.89 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
1 Drive c: (1137152) (Fixed) (Total:298.09 GB) (Free:122.93 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (USB20FD) (Removable) (Total:3.8 GB) (Free:2.37 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3894 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 298 GB 24 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C 1137152 NTFS Partition 298 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3894 MB 28 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E USB20FD FAT32 Removable 3894 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 20:32
======================= End Of Log ==========================
I, like many others apparently, I have had my computer infected with the sirefef trojan. I am running Windows 7 (32 bit) on my Equus CS Nobilis laptop. I am almost positive I got the virus from a bogus Adobe Reader update. Below is the result of scanning using the Farbar tool. Thank you in advance for your help!
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-07-2012 01
Ran by SYSTEM at 09-07-2012 18:11:43
Running from E:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe [708608 2008-08-26] (Mirco-Star International CO., LTD.)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13556256 2008-09-24] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2008-09-24] (NVIDIA Corporation)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM\...\Run: [EKAIO2StatusMonitor] C:\Windows\system32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe [2717696 2011-08-26] (Eastman Kodak Company)
HKLM\...\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [71216 2007-03-14] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [52256 2007-01-08] ()
HKLM\...\Run: [Corel Photo Downloader] "C:\Program Files\Corel\Corel MediaOne\Corel PhotoDownloader.exe" -startup [x]
HKLM\...\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel MediaOne\CorelIOMonitor.exe [38400 2007-12-01] ()
HKLM\...\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" [159456 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [1446760 2012-01-06] (Garmin)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Administrator\...\Run: [EPSON Stylus CX4800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /FU "C:\Windows\TEMP\E_SDF0A.tmp" /EF "HKCU" [177664 2007-01-19] (SEIKO EPSON CORPORATION)
HKU\Administrator\...\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [1446760 2012-01-06] (Garmin)
HKU\Administrator\...\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup [2491688 2007-07-12] (Cyberlink)
HKU\Justin Silvi\...\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized [1446760 2012-01-06] (Garmin)
HKU\Justin Silvi\...\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [x]
HKU\Justin Silvi\...\Policies\system: [NoHotStart] 1
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Justin Silvi\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 IntuitUpdateService; "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" [13672 2010-08-23] (Intuit Inc.)
2 McciCMService; "C:\Program Files\Common Files\Motive\McciCMService.exe" [319488 2011-02-07] (Alcatel-Lucent)
2 McciServiceHost; "C:\Program Files\Common Files\Motive\McciServiceHost.exe" [315392 2010-07-27] (Alcatel-Lucent)
2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [159744 2008-08-26] ()
2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [272024 2006-12-19] ()
2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.)
2 McMPFSvc; "C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
3 WMZuneComm; "c:\Program Files\Zune\WMZuneComm.exe" [x]
3 ZuneNetworkSvc; "c:\Program Files\Zune\ZuneNss.exe" [x]
3 ZuneWlanCfgSvc; "c:\Program Files\Zune\ZuneWlanCfgSvc.exe" [x]
========================== Drivers (Whitelisted) =============
3 Bridge; C:\Windows\System32\DRIVERS\bridge.sys [78336 2009-07-13] (Microsoft Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 MRESP50; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [20096 2010-07-27] (Printing Communications Assoc., Inc. (PCAUSA))
3 smserial; C:\Windows\System32\DRIVERS\smserial.sys [1068032 2009-07-13] (Motorola Inc.)
3 WSDScan; C:\Windows\System32\DRIVERS\WSDScan.sys [20480 2009-07-13] (Microsoft Corporation)
1 ixgdublj; \??\C:\Windows\system32\drivers\ixgdublj.sys [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-09 18:11 - 2012-07-09 18:11 - 00000000 ____D C:\FRST
2012-07-09 12:25 - 2012-07-09 12:25 - 00008224 ____A C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-09 12:25 - 2012-07-09 12:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Garmin
2012-07-09 12:25 - 2012-07-09 12:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
2012-07-09 11:34 - 2012-07-09 11:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-09 11:34 - 2012-07-09 11:34 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-09 11:32 - 2012-07-09 11:32 - 10288512 ____A (Microsoft Corporation) C:\Users\Justin Silvi\Downloads\mseinstall.exe
2012-07-09 10:29 - 2012-07-09 10:29 - 00000000 ____D C:\Windows\System32\appmgmt
2012-07-06 17:27 - 2012-07-09 10:06 - 00000000 ____D C:\Users\Justin Silvi\Downloads\Family Guy - The Complete Season 9 [HDTV]
2012-06-29 05:57 - 2012-06-29 06:34 - 00000000 ____D C:\Users\Justin Silvi\Downloads\Hells Kitchen US S10E08 PDTV x264-LOL[ettv]
2012-06-29 05:33 - 2012-06-29 06:15 - 355284929 ____A C:\Users\Justin Silvi\Downloads\Hells.Kitchen.US.S10E07.PDTV.x264-LOL.mp4
2012-06-23 20:22 - 2012-06-23 20:22 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-06-21 10:01 - 2012-06-21 10:29 - 00000000 ____D C:\Users\Justin Silvi\Documents\Paychecks
2012-06-21 05:47 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 05:47 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 05:47 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 05:47 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 05:47 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 05:47 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 05:47 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 05:47 - 2012-06-02 11:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 05:47 - 2012-06-02 11:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 08:06 - 2012-06-19 08:40 - 00000000 ____D C:\Users\Justin Silvi\Downloads\Hells Kitchen US S10.E5 (xCrazy0328x)
2012-06-18 10:41 - 2012-06-18 10:41 - 00000000 ____D C:\Users\Justin Silvi\Documents\New folder
2012-06-18 04:31 - 2012-06-18 04:53 - 00000000 ____D C:\Users\Justin Silvi\Downloads\[ www.TorrentDay.com ] - Heat.Seekers.S01E07.Philadelphia.HDTV.XviD-CRiMSON2
2012-06-17 08:50 - 2012-06-17 08:55 - 00000000 ____D C:\Users\Justin Silvi\Documents\2812 inventory
2012-06-14 07:19 - 2012-07-06 07:36 - 48522240 ____A C:\Users\Justin Silvi\Documents\Personal Folders(1) backup.pst
2012-06-14 07:17 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-14 07:17 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-14 07:17 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-14 07:17 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-14 07:17 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-14 07:17 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-14 07:17 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-14 07:17 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-14 07:17 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-14 07:17 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-14 07:17 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-14 07:17 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-14 07:17 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-14 07:17 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 18:53 - 2012-05-14 17:05 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 18:53 - 2012-04-30 20:44 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 18:53 - 2012-04-27 19:17 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 18:53 - 2012-04-25 20:45 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 18:53 - 2012-04-25 20:45 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 18:53 - 2012-04-25 20:41 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 18:53 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 18:52 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 18:52 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 18:52 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-11 07:42 - 2012-06-11 07:42 - 00000000 ____D C:\Users\Justin Silvi\AppData\Local\Macromedia
============ 3 Months Modified Files ========================
2012-07-09 13:29 - 2011-03-22 19:21 - 00372688 ____A C:\Users\All Users\nvModes.001
2012-07-09 13:29 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-09 13:29 - 2009-07-13 20:39 - 00101938 ____A C:\Windows\setupact.log
2012-07-09 12:25 - 2012-07-09 12:25 - 00008224 ____A C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-09 12:21 - 2011-02-23 09:00 - 00082370 ____A C:\Windows\PFRO.log
2012-07-09 11:37 - 2009-07-13 20:34 - 00014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-09 11:37 - 2009-07-13 20:34 - 00014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-09 11:36 - 2011-02-23 10:40 - 01413271 ____A C:\Windows\WindowsUpdate.log
2012-07-09 11:34 - 2012-07-09 11:34 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-09 11:34 - 2011-02-23 07:50 - 00743534 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-09 11:32 - 2012-07-09 11:32 - 10288512 ____A (Microsoft Corporation) C:\Users\Justin Silvi\Downloads\mseinstall.exe
2012-07-09 10:34 - 2011-03-22 19:21 - 00372688 ____A C:\Users\All Users\nvModes.dat
2012-07-09 10:22 - 2012-04-12 07:38 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-09 05:31 - 2012-04-12 07:38 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-09 05:31 - 2011-05-14 08:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-06 07:36 - 2012-06-14 07:19 - 48522240 ____A C:\Users\Justin Silvi\Documents\Personal Folders(1) backup.pst
2012-06-29 06:15 - 2012-06-29 05:33 - 355284929 ____A C:\Users\Justin Silvi\Downloads\Hells.Kitchen.US.S10E07.PDTV.x264-LOL.mp4
2012-06-23 20:22 - 2012-06-23 20:22 - 09815752 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-06-22 20:22 - 2009-07-13 20:53 - 00032656 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-14 07:55 - 2009-07-13 20:33 - 00443904 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-14 07:22 - 2011-02-24 05:29 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-02 14:19 - 2012-06-21 05:47 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 05:47 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 05:47 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 05:47 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 05:47 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-21 05:47 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-21 05:47 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-17 15:11 - 2012-06-14 07:17 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-06-14 07:17 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-06-14 07:17 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-06-14 07:17 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-06-14 07:17 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-06-14 07:17 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-06-14 07:17 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-06-14 07:17 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-06-14 07:17 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:29 - 2012-06-14 07:17 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:27 - 2012-06-14 07:17 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-06-14 07:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-06-14 07:17 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-06-14 07:17 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-14 17:05 - 2012-06-12 18:53 - 02343936 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 18:22 - 2012-05-13 18:22 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-05-13 18:22 - 2012-05-13 18:22 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-05-13 18:22 - 2012-05-13 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-05-13 18:22 - 2012-05-13 18:22 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-05-13 18:22 - 2011-02-27 09:21 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-04-30 20:44 - 2012-06-12 18:53 - 00164352 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:17 - 2012-06-12 18:53 - 00183808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 20:45 - 2012-06-12 18:53 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 20:45 - 2012-06-12 18:53 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 20:41 - 2012-06-12 18:53 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 10:27 - 2011-12-30 16:51 - 00002828 __ASH C:\Windows\System32\KGyGaAvL.sys
2012-04-24 10:27 - 2011-12-30 16:51 - 00000088 __RSH C:\Windows\System32\8F109DC930.sys
2012-04-23 20:36 - 2012-06-12 18:52 - 01158656 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 20:36 - 2012-06-12 18:52 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 18:52 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\@
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\L
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\U
C:\Windows\Installer\{e3548377-8591-a44f-836f-596136f77833}\L\00000004.@
ZeroAccess:
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}\@
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}\L
C:\Users\Justin Silvi\AppData\Local\{e3548377-8591-a44f-836f-596136f77833}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 4095.16 MB
Available physical RAM: 3622.3 MB
Total Pagefile: 4093.44 MB
Available Pagefile: 3626.89 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
1 Drive c: (1137152) (Fixed) (Total:298.09 GB) (Free:122.93 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (USB20FD) (Removable) (Total:3.8 GB) (Free:2.37 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3894 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 298 GB 24 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C 1137152 NTFS Partition 298 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3894 MB 28 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E USB20FD FAT32 Removable 3894 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 20:32
======================= End Of Log ==========================