Hello,
As I've seen earlier in the forum, I got the same problem as many user. I found the directions that Broni gave to the user Morat20 (Vista Sirefef.r problem -- rebooting every minute). Basically I used Farbar Recovery Scan Tool 32-Bit and got the two log files requested:
- FRST.txt
- Search.txt
I would really appreciate any help to solve this problem.
Thanks for the attention.
FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 28-08-2012
Ran by SYSTEM at 28-08-2012 19:01:33
Running from G:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7514656 2009-05-23] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-07] (Intel Corporation)
HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.)
HKLM\...\Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [203776 2009-11-12] (Microsoft)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-08-10] (Apple Inc.)
HKLM\...\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Jaime Jimenez Diaz\...\Run: [Spotify] "C:\Users\Jaime Jimenez Diaz\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [x]
HKU\Jaime Jimenez Diaz\...\Run: [Google Update] "C:\Users\Jaime Jimenez Diaz\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-02-24] (Google Inc.)
HKLM\...\RunOnce: [DBRMTray] C:\Dell\DBRM\Reminder\TrayApp.exe [7168 2009-10-18] (Microsoft)
Tcpip\Parameters: [DhcpNameServer] 132.198.201.10 132.198.202.10
Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{F3C1DE9E-5E16-4BA9-B854-7B53A45E3579}\Icon3E5562ED7.ico ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\WD Quick View.lnk
ShortcutTarget: WD Quick View.lnk -> C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe (Western Digital Technologies, Inc.)
Startup: C:\Users\Jaime Jimenez Diaz\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
========================== Services (Whitelisted) ========================
2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
2 CVPND; "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" [1528608 2009-01-13] (Cisco Systems, Inc.)
2 hasplms; C:\Windows\system32\hasplms.exe -run [3750400 2009-12-16] (SafeNet Inc.)
3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
==================== Drivers (Whitelisted) ===================
2 aksfridge; \??\C:\Windows\system32\drivers\aksfridge.sys [356864 2009-08-20] (Aladdin Knowledge Systems Ltd.)
3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [306811 2009-01-13] (Cisco Systems, Inc.)
3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131856 2008-08-28] (Deterministic Networks, Inc.)
2 hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [588800 2009-12-09] (SafeNet Inc.)
3 JRAID; C:\Windows\system32\DRIVERS\jraid.sys [89048 2009-05-21] (JMicron Technology Corp.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [507136 2006-12-05] (PixArt Imaging Inc.)
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [45200 2009-07-09] (Sonic Solutions)
2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2009-07-20] (Realtek )
3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [35328 2008-10-24] (Realtek Corporation)
3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [19968 2007-12-03] (Windows (R) Codename Longhorn DDK provider)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-06-02] (Duplex Secure Ltd.)
3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [35328 2008-10-24] (Realtek Corporation)
3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN60.sys [19968 2007-12-03] (Windows (R) Codename Longhorn DDK provider)
3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [195968 2010-08-31] (Jungo)
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-08-28 19:01 - 2012-08-28 19:01 - 00000000 ____D C:\FRST
2012-08-28 11:52 - 2012-08-28 11:52 - 00000000 ____D C:\301559e38a67b73c15
2012-08-28 11:36 - 2012-08-28 11:36 - 00000000 ____D C:\955f4a3f0f9aa52f975edd66ef36
2012-08-28 11:34 - 2012-08-28 11:34 - 00000000 ____D C:\788f4d6f3d13b37886
2012-08-16 07:32 - 2012-08-16 07:32 - 00000000 ____D C:\b564028b57e55afd5efc8f931ceb
============ 3 Months Modified Files ========================
2012-08-28 14:34 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-28 14:34 - 2009-07-13 20:39 - 00113220 ____A C:\Windows\setupact.log
2012-08-28 14:32 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-28 11:51 - 2009-07-13 20:55 - 01592443 ____A C:\Windows\WindowsUpdate.log
2012-08-24 06:35 - 2012-02-24 08:54 - 00000960 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1802305371-361273552-2540871469-1000UA.job
2012-08-16 07:35 - 2012-02-24 08:54 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1802305371-361273552-2540871469-1000Core.job
2012-07-26 11:29 - 2010-02-26 17:51 - 00732404 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-26 11:18 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-26 11:18 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-09 13:48 - 2011-11-14 09:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-09 13:46 - 2012-07-09 13:46 - 10288512 ____A (Microsoft Corporation) C:\Users\Jaime Jimenez Diaz\Desktop\mseinstall.exe
2012-07-08 19:33 - 2010-09-27 18:02 - 00725390 ____A C:\Users\Jaime Jimenez Diaz\Documents\My EndNote Library.enl
2012-07-08 15:16 - 2012-04-04 06:46 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-08 15:16 - 2011-05-20 05:41 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-06-29 17:12 - 2012-06-29 17:12 - 00043619 ____A C:\Users\Jaime Jimenez Diaz\Documents\Percent_Diff_PMN&EOs.pptx
2012-06-27 05:33 - 2009-07-13 20:53 - 00032572 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-02 14:19 - 2012-06-25 13:37 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-25 13:37 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-25 13:37 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-25 13:37 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-25 13:37 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-25 13:37 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-25 13:37 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-25 13:37 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-25 13:37 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
ZeroAccess:
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\@
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\L
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\n
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U\00000001.@
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U\80000000.@
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U\800000cb.@
ZeroAccess:
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}\@
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}\L
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-06-11 06:28:35
Restore point made on: 2012-06-18 05:57:29
Restore point made on: 2012-06-22 07:03:47
Restore point made on: 2012-06-25 13:37:30
Restore point made on: 2012-06-25 13:54:28
Restore point made on: 2012-06-29 08:22:58
Restore point made on: 2012-07-03 08:25:27
Restore point made on: 2012-07-08 11:26:53
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 3036.99 MB
Available physical RAM: 2567.66 MB
Total Pagefile: 3035.27 MB
Available Pagefile: 2572.62 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.7 MB
==================== Partitions ============================
1 Drive c: (OS) (Fixed) (Total:124.49 GB) (Free:62.42 GB) NTFS
2 Drive d: (Lab Drive) (Fixed) (Total:48.83 GB) (Free:47.44 GB) NTFS
4 Drive g: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (RECOVERY) (Fixed) (Total:7.93 GB) (Free:4.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 51 GB
Disk 1 Online 961 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 8118 MB 40 MB
Partition 3 Primary 124 GB 8158 MB
Partition 0 Extended 100 GB 132 GB
Partition 4 Logical 48 GB 132 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 8118 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 124 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Lab Drive NTFS Partition 48 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 961 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 961 MB Healthy
==================================================================================
Last Boot: 2012-07-02 12:50
==================== End Of Log =============================
SEARCH LOG
Farbar Recovery Scan Tool Version: 28-08-2012
Ran by SYSTEM at 2012-08-28 19:03:05
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-28 14:32] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
As I've seen earlier in the forum, I got the same problem as many user. I found the directions that Broni gave to the user Morat20 (Vista Sirefef.r problem -- rebooting every minute). Basically I used Farbar Recovery Scan Tool 32-Bit and got the two log files requested:
- FRST.txt
- Search.txt
I would really appreciate any help to solve this problem.
Thanks for the attention.
FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 28-08-2012
Ran by SYSTEM at 28-08-2012 19:01:33
Running from G:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7514656 2009-05-23] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-07] (Intel Corporation)
HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.)
HKLM\...\Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [203776 2009-11-12] (Microsoft)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-08-10] (Apple Inc.)
HKLM\...\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Jaime Jimenez Diaz\...\Run: [Spotify] "C:\Users\Jaime Jimenez Diaz\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [x]
HKU\Jaime Jimenez Diaz\...\Run: [Google Update] "C:\Users\Jaime Jimenez Diaz\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-02-24] (Google Inc.)
HKLM\...\RunOnce: [DBRMTray] C:\Dell\DBRM\Reminder\TrayApp.exe [7168 2009-10-18] (Microsoft)
Tcpip\Parameters: [DhcpNameServer] 132.198.201.10 132.198.202.10
Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{F3C1DE9E-5E16-4BA9-B854-7B53A45E3579}\Icon3E5562ED7.ico ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\WD Quick View.lnk
ShortcutTarget: WD Quick View.lnk -> C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe (Western Digital Technologies, Inc.)
Startup: C:\Users\Jaime Jimenez Diaz\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
========================== Services (Whitelisted) ========================
2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
2 CVPND; "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" [1528608 2009-01-13] (Cisco Systems, Inc.)
2 hasplms; C:\Windows\system32\hasplms.exe -run [3750400 2009-12-16] (SafeNet Inc.)
3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
==================== Drivers (Whitelisted) ===================
2 aksfridge; \??\C:\Windows\system32\drivers\aksfridge.sys [356864 2009-08-20] (Aladdin Knowledge Systems Ltd.)
3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [306811 2009-01-13] (Cisco Systems, Inc.)
3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131856 2008-08-28] (Deterministic Networks, Inc.)
2 hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [588800 2009-12-09] (SafeNet Inc.)
3 JRAID; C:\Windows\system32\DRIVERS\jraid.sys [89048 2009-05-21] (JMicron Technology Corp.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [507136 2006-12-05] (PixArt Imaging Inc.)
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [45200 2009-07-09] (Sonic Solutions)
2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2009-07-20] (Realtek )
3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [35328 2008-10-24] (Realtek Corporation)
3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [19968 2007-12-03] (Windows (R) Codename Longhorn DDK provider)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-06-02] (Duplex Secure Ltd.)
3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [35328 2008-10-24] (Realtek Corporation)
3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN60.sys [19968 2007-12-03] (Windows (R) Codename Longhorn DDK provider)
3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [195968 2010-08-31] (Jungo)
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-08-28 19:01 - 2012-08-28 19:01 - 00000000 ____D C:\FRST
2012-08-28 11:52 - 2012-08-28 11:52 - 00000000 ____D C:\301559e38a67b73c15
2012-08-28 11:36 - 2012-08-28 11:36 - 00000000 ____D C:\955f4a3f0f9aa52f975edd66ef36
2012-08-28 11:34 - 2012-08-28 11:34 - 00000000 ____D C:\788f4d6f3d13b37886
2012-08-16 07:32 - 2012-08-16 07:32 - 00000000 ____D C:\b564028b57e55afd5efc8f931ceb
============ 3 Months Modified Files ========================
2012-08-28 14:34 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-28 14:34 - 2009-07-13 20:39 - 00113220 ____A C:\Windows\setupact.log
2012-08-28 14:32 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-28 11:51 - 2009-07-13 20:55 - 01592443 ____A C:\Windows\WindowsUpdate.log
2012-08-24 06:35 - 2012-02-24 08:54 - 00000960 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1802305371-361273552-2540871469-1000UA.job
2012-08-16 07:35 - 2012-02-24 08:54 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1802305371-361273552-2540871469-1000Core.job
2012-07-26 11:29 - 2010-02-26 17:51 - 00732404 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-26 11:18 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-26 11:18 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-09 13:48 - 2011-11-14 09:16 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-09 13:46 - 2012-07-09 13:46 - 10288512 ____A (Microsoft Corporation) C:\Users\Jaime Jimenez Diaz\Desktop\mseinstall.exe
2012-07-08 19:33 - 2010-09-27 18:02 - 00725390 ____A C:\Users\Jaime Jimenez Diaz\Documents\My EndNote Library.enl
2012-07-08 15:16 - 2012-04-04 06:46 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-08 15:16 - 2011-05-20 05:41 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-06-29 17:12 - 2012-06-29 17:12 - 00043619 ____A C:\Users\Jaime Jimenez Diaz\Documents\Percent_Diff_PMN&EOs.pptx
2012-06-27 05:33 - 2009-07-13 20:53 - 00032572 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-02 14:19 - 2012-06-25 13:37 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-25 13:37 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-25 13:37 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-25 13:37 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-25 13:37 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-25 13:37 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-25 13:37 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-25 13:37 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-25 13:37 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
ZeroAccess:
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\@
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\L
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\n
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U\00000001.@
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U\80000000.@
C:\Windows\Installer\{83b30923-7a13-f959-b710-6db708302f2d}\U\800000cb.@
ZeroAccess:
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}\@
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}\L
C:\Users\Jaime Jimenez Diaz\AppData\Local\{83b30923-7a13-f959-b710-6db708302f2d}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-06-11 06:28:35
Restore point made on: 2012-06-18 05:57:29
Restore point made on: 2012-06-22 07:03:47
Restore point made on: 2012-06-25 13:37:30
Restore point made on: 2012-06-25 13:54:28
Restore point made on: 2012-06-29 08:22:58
Restore point made on: 2012-07-03 08:25:27
Restore point made on: 2012-07-08 11:26:53
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 3036.99 MB
Available physical RAM: 2567.66 MB
Total Pagefile: 3035.27 MB
Available Pagefile: 2572.62 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.7 MB
==================== Partitions ============================
1 Drive c: (OS) (Fixed) (Total:124.49 GB) (Free:62.42 GB) NTFS
2 Drive d: (Lab Drive) (Fixed) (Total:48.83 GB) (Free:47.44 GB) NTFS
4 Drive g: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (RECOVERY) (Fixed) (Total:7.93 GB) (Free:4.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 51 GB
Disk 1 Online 961 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 8118 MB 40 MB
Partition 3 Primary 124 GB 8158 MB
Partition 0 Extended 100 GB 132 GB
Partition 4 Logical 48 GB 132 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 8118 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 124 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Lab Drive NTFS Partition 48 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 961 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 961 MB Healthy
==================================================================================
Last Boot: 2012-07-02 12:50
==================== End Of Log =============================
SEARCH LOG
Farbar Recovery Scan Tool Version: 28-08-2012
Ran by SYSTEM at 2012-08-28 19:03:05
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-28 14:32] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===