PopeInnocentXIV
Posts: 9 +0
This evening I got the services.exe Win64/patched.a message from AVG.
When I boot up I get these two messages:
Location is not available
C:\Windows\system32\config\systemprofile\Desktop refers to a location that is unavailable. It could be on a hard drive on this computer, or on a network. Check to make sure that the disk is properly inserted, or that you are connected to the Internet or your network, and then try again. If it still cannot be located, the information might have been moved to a different location.
Failed to connect to a windows service
Windows could not connect to the System Event Notification Service service. This problem prevents standard users from logging on to the system. As an administrative user, you can review the System Event Log for details about why the service didn't respond.
I tried installing Combofix, which created a directory in C: called 32788R22FWJFW, however it would not run correctly, and I got a registry error when trying to delete it. (I apologize for not having the actual error message.) I suspect the Desktop problem is related to an incomplete uninstall of Combofix.
I did download FRST. Logs follow.
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-09-2012
Ran by SYSTEM at 24-09-2012 22:06:37
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2010-10-01] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-09-17] (CyberLink Corp.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe" [17408 2010-07-04] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Jim\...\Run: [Google Update] "C:\Users\Jim\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-03-14] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) ===================
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-12] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
2 PEVSystemStart; "C:\32788R22FWJFW\pev.3XE" EXEC /I CSCRIPT.exe //NOLOGO //E:VBSCRIPT //B //T:15 "C:\32788R22FWJFW\KNetSvcs.vbs" [322 2012-09-03] ()
==================== Drivers (Whitelisted) =====================
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-25] (AVG Technologies CZ, s.r.o.)
1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.)
1 NEOFLTR_710_19243; C:\Windows\System32\Drivers\NEOFLTR_710_19243.sys [99152 2011-09-07] (Juniper Networks)
3 PCDSRVC{67F2314B-25F2B3C0-06020101}_0; \??\c:\gencotst\pcdsrvc_x64.pkms [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-09-24 22:06 - 2012-09-24 22:06 - 00000000 ____D C:\FRST
2012-09-24 17:39 - 2012-09-24 17:39 - 00016712 ____A (Sysinternals - www.sysinternals.com) C:\Windows\System32\Drivers\PROCEXP113.SYS
2012-09-24 17:36 - 2012-09-24 17:39 - 00000000 ___SD C:\32788R22FWJFW
2012-09-24 17:36 - 2012-09-24 17:39 - 00000000 ____D C:\Qoobox
2012-09-24 17:36 - 2012-09-24 17:36 - 00000000 ____D C:\Windows\erdnt
2012-09-24 17:34 - 2012-09-24 17:34 - 04759205 ____R (Swearware) C:\Users\Jim\Desktop\username123.exe
2012-09-24 17:18 - 2012-09-24 17:18 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-09-22 23:00 - 2012-08-24 03:15 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-09-22 23:00 - 2012-08-24 02:39 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-09-22 23:00 - 2012-08-24 02:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-09-22 23:00 - 2012-08-24 02:22 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-09-22 23:00 - 2012-08-24 02:21 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-09-22 23:00 - 2012-08-24 02:20 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-09-22 23:00 - 2012-08-24 02:18 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-09-22 23:00 - 2012-08-24 02:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-09-22 23:00 - 2012-08-24 02:14 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-09-22 23:00 - 2012-08-24 02:14 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-09-22 23:00 - 2012-08-24 02:13 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-09-22 23:00 - 2012-08-24 02:12 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-09-22 23:00 - 2012-08-24 02:11 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-09-22 23:00 - 2012-08-24 02:10 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-09-22 23:00 - 2012-08-24 02:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-09-22 23:00 - 2012-08-24 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-09-22 23:00 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-09-22 23:00 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-09-22 23:00 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-09-22 23:00 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-09-22 23:00 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-09-22 23:00 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-09-22 23:00 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-09-22 23:00 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-09-22 23:00 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-09-22 23:00 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-09-22 23:00 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-09-22 23:00 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-09-22 23:00 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-09-22 23:00 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-09-22 23:00 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-09-22 23:00 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-09-18 15:34 - 2012-09-18 15:34 - 00000000 ____D C:\Users\Jim\AppData\Local\TechSmith
2012-09-16 08:31 - 2012-09-16 08:31 - 04929052 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3125_setup.exe
2012-09-15 13:10 - 2012-09-15 13:10 - 00927691 ____A C:\Users\Jim\Downloads\XML-Editor_1.0.0.1.zip
2012-09-15 06:44 - 2012-09-15 06:45 - 00000000 ____D C:\Users\Jim\AppData\Local\Deployment
2012-09-15 06:44 - 2012-09-15 06:44 - 00428544 ____A () C:\Users\Jim\Downloads\setup.exe
2012-09-15 06:44 - 2012-09-15 06:44 - 00000000 ____D C:\Users\Jim\AppData\Local\Apps\2.0
2012-09-12 16:23 - 2012-08-02 09:55 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-09-12 16:23 - 2012-08-02 09:05 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-09-11 06:02 - 2012-09-11 06:02 - 00000000 ___HD C:\$AVG
2012-09-07 21:05 - 2012-09-15 20:59 - 00119296 ____A C:\Users\Jim\Copy of Big Band Theory 2.xls
2012-09-06 18:44 - 2012-09-06 18:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-09-05 17:52 - 2012-09-05 17:52 - 00000000 ____D C:\tmp
2012-09-04 20:43 - 2012-09-04 20:43 - 00000000 ___AH C:\Users\Jim\Documents\Default.rdp
2012-08-27 20:09 - 2012-08-27 20:09 - 00001073 ____A C:\Users\Public\Desktop\XMedia Recode.lnk
2012-08-27 20:08 - 2012-08-27 20:08 - 04914244 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3120_setup.exe
==================== 3 Months Modified Files ==================
2012-09-24 18:03 - 2011-05-25 19:43 - 01974469 ____A C:\Windows\WindowsUpdate.log
2012-09-24 18:03 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-24 18:03 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-24 18:02 - 2009-07-13 21:13 - 00727160 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-24 18:00 - 2012-04-01 08:59 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-24 18:00 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-24 17:59 - 2009-07-13 21:08 - 00032644 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-24 17:59 - 2009-07-13 20:51 - 00034878 ____A C:\Windows\setupact.log
2012-09-24 17:39 - 2012-09-24 17:39 - 00016712 ____A (Sysinternals - www.sysinternals.com) C:\Windows\System32\Drivers\PROCEXP113.SYS
2012-09-24 17:34 - 2012-09-24 17:34 - 04759205 ____R (Swearware) C:\Users\Jim\Desktop\username123.exe
2012-09-24 17:14 - 2012-04-01 08:59 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-24 17:12 - 2012-03-30 14:53 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-24 17:12 - 2012-03-14 14:52 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3400246598-1791276097-185665454-1002UA.job
2012-09-24 17:12 - 2011-07-29 18:20 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-24 16:12 - 2012-03-14 14:52 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3400246598-1791276097-185665454-1002Core.job
2012-09-16 18:36 - 2012-04-14 08:30 - 00001471 ____A C:\Users\Jim\Desktop\quotes.txt
2012-09-16 08:31 - 2012-09-16 08:31 - 04929052 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3125_setup.exe
2012-09-15 20:59 - 2012-09-07 21:05 - 00119296 ____A C:\Users\Jim\Copy of Big Band Theory 2.xls
2012-09-15 13:10 - 2012-09-15 13:10 - 00927691 ____A C:\Users\Jim\Downloads\XML-Editor_1.0.0.1.zip
2012-09-15 07:44 - 2011-08-16 19:01 - 00000069 ____A C:\Users\Jim\AppData\Roaming\AVSDVDPlayer.m3u
2012-09-15 06:44 - 2012-09-15 06:44 - 00428544 ____A () C:\Users\Jim\Downloads\setup.exe
2012-09-12 17:02 - 2011-08-04 20:22 - 00007602 ____A C:\Users\Jim\AppData\Local\Resmon.ResmonCfg
2012-09-12 16:14 - 2011-07-27 16:12 - 00467808 ____A C:\Windows\PFRO.log
2012-09-11 06:03 - 2011-10-03 18:08 - 00000971 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-09-10 16:46 - 2011-08-09 17:47 - 00000600 ____A C:\Users\Jim\AppData\Local\PUTTY.RND
2012-09-09 09:27 - 2012-04-25 16:22 - 00000778 ____A C:\Users\Jim\Documents\eros.txt
2012-09-06 21:11 - 2011-11-14 21:11 - 00018833 ____A C:\Users\Jim\Documents\Good Eats HD.xlsx
2012-09-04 20:43 - 2012-09-04 20:43 - 00000000 ___AH C:\Users\Jim\Documents\Default.rdp
2012-09-04 10:07 - 2012-03-14 14:53 - 00002448 ____A C:\Users\Jim\Desktop\Google Chrome.lnk
2012-09-03 15:21 - 2009-07-13 20:45 - 00361504 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-27 20:09 - 2012-08-27 20:09 - 00001073 ____A C:\Users\Public\Desktop\XMedia Recode.lnk
2012-08-27 20:08 - 2012-08-27 20:08 - 04914244 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3120_setup.exe
2012-08-24 11:43 - 2012-08-24 11:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys
2012-08-24 03:15 - 2012-09-22 23:00 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-24 02:39 - 2012-09-22 23:00 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-24 02:31 - 2012-09-22 23:00 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-24 02:22 - 2012-09-22 23:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-24 02:21 - 2012-09-22 23:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-24 02:20 - 2012-09-22 23:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-24 02:18 - 2012-09-22 23:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-24 02:17 - 2012-09-22 23:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-24 02:14 - 2012-09-22 23:00 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-24 02:14 - 2012-09-22 23:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-24 02:13 - 2012-09-22 23:00 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-24 02:12 - 2012-09-22 23:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-24 02:11 - 2012-09-22 23:00 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-24 02:10 - 2012-09-22 23:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-24 02:09 - 2012-09-22 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-24 02:04 - 2012-09-22 23:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-23 23:27 - 2012-09-22 23:00 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-23 23:03 - 2012-09-22 23:00 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-23 22:59 - 2012-09-22 23:00 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-08-23 22:51 - 2012-09-22 23:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-23 22:51 - 2012-09-22 23:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-23 22:51 - 2012-09-22 23:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-23 22:49 - 2012-09-22 23:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-23 22:48 - 2012-09-22 23:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-23 22:47 - 2012-09-22 23:00 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-23 22:47 - 2012-09-22 23:00 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-08-23 22:47 - 2012-09-22 23:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-23 22:45 - 2012-09-22 23:00 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-08-23 22:44 - 2012-09-22 23:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-23 22:44 - 2012-09-22 23:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-23 22:43 - 2012-09-22 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-23 22:40 - 2012-09-22 23:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-22 20:46 - 2011-07-28 15:37 - 00000600 ____A C:\Users\Jim\AppData\Roaming\winscp.rnd
2012-08-22 20:39 - 2011-07-27 16:20 - 00084616 ____A C:\Users\Jim\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-19 05:20 - 2012-08-19 05:20 - 00282976 ____A C:\Windows\Minidump\081912-21496-01.dmp
2012-08-19 05:20 - 2012-08-18 15:49 - 694553353 ____A C:\Windows\MEMORY.DMP
2012-08-18 20:17 - 2012-08-18 20:17 - 00282976 ____A C:\Windows\Minidump\081912-19390-01.dmp
2012-08-18 15:50 - 2012-08-18 15:49 - 00282976 ____A C:\Windows\Minidump\081812-24117-01.dmp
2012-08-08 15:53 - 2012-08-08 15:53 - 00000076 ____A C:\Users\Jim\Documents\galleries.txt
2012-08-05 06:52 - 2012-08-05 06:51 - 04912733 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3118_setup.exe
2012-08-02 09:55 - 2012-09-12 16:23 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-08-02 09:05 - 2012-09-12 16:23 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-07-28 07:26 - 2012-07-28 07:23 - 00011377 ____A C:\Users\Jim\Documents\Star Notes.xlsx
2012-07-25 23:21 - 2012-07-25 23:21 - 00291680 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgldx64.sys
2012-07-24 19:36 - 2012-07-24 19:36 - 00110736 ____A C:\Users\Jim\Downloads\wootwatcher_9.zip
2012-07-18 09:31 - 2012-08-15 14:56 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-14 07:42 - 2012-07-14 07:42 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-07-14 07:42 - 2012-07-14 07:42 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-14 07:42 - 2012-07-14 07:42 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-14 07:42 - 2012-07-14 07:42 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-14 07:42 - 2011-08-16 19:18 - 00472880 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-07-12 18:45 - 2012-07-12 18:45 - 04837559 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3114_setup.exe
2012-07-04 14:04 - 2012-08-15 14:56 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 14:01 - 2012-08-15 14:56 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 14:01 - 2012-08-15 14:56 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 13:26 - 2012-08-15 14:56 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 13:23 - 2012-08-15 14:56 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-01 09:44 - 2012-07-01 09:44 - 02709534 ____A C:\Users\Jim\Downloads\leggy-babe-flashing-003.wmv
2012-07-01 09:42 - 2012-07-01 09:42 - 02725534 ____A C:\Users\Jim\Downloads\busty-and-skinny-004.wmv
2012-07-01 09:42 - 2012-07-01 09:42 - 02709534 ____A C:\Users\Jim\Downloads\busty-and-skinny-003.wmv
2012-07-01 09:41 - 2012-07-01 09:41 - 02725534 ____A C:\Users\Jim\Downloads\sexy-schoolgirl-003.wmv
2012-07-01 09:40 - 2012-07-01 09:40 - 02717534 ____A C:\Users\Jim\Downloads\sexy-schoolgirl-002.wmv
2012-07-01 09:38 - 2012-07-01 09:38 - 03614624 ____A C:\Users\Jim\Downloads\02.wmv
2012-07-01 09:38 - 2012-07-01 09:38 - 03343064 ____A C:\Users\Jim\Downloads\04.wmv
ZeroAccess:
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\L
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\L\00000004.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\00000004.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\00000008.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\000000cb.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\80000000.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\80000032.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 11%
Total physical RAM: 8174.45 MB
Available physical RAM: 7258.09 MB
Total Pagefile: 8172.59 MB
Available Pagefile: 7249.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Partitions =============================
1 Drive c: (OSDisk) (Fixed) (Total:1383.59 GB) (Free:143.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Recovery) (Fixed) (Total:13.67 GB) (Free:7.06 GB) NTFS
4 Drive f: (KINGSTON) (Removable) (Total:3.65 GB) (Free:3.13 GB) FAT32
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 1397 GB 0 B
Disk 1 Online 3745 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1383 GB 1024 KB
Partition 2 Primary 13 GB 1383 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C OSDisk NTFS Partition 1383 GB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Recovery NTFS Partition 13 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3741 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 3741 MB Healthy
=========================================================
Last Boot: 2012-09-16 17:30
==================== End Of Log =============================
Search.txt:
Farbar Recovery Scan Tool (x64) Version: 24-09-2012
Ran by SYSTEM at 2012-09-24 22:07:45
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC
====== End Of Search ======
Thanks
When I boot up I get these two messages:
Location is not available
C:\Windows\system32\config\systemprofile\Desktop refers to a location that is unavailable. It could be on a hard drive on this computer, or on a network. Check to make sure that the disk is properly inserted, or that you are connected to the Internet or your network, and then try again. If it still cannot be located, the information might have been moved to a different location.
Failed to connect to a windows service
Windows could not connect to the System Event Notification Service service. This problem prevents standard users from logging on to the system. As an administrative user, you can review the System Event Log for details about why the service didn't respond.
I tried installing Combofix, which created a directory in C: called 32788R22FWJFW, however it would not run correctly, and I got a registry error when trying to delete it. (I apologize for not having the actual error message.) I suspect the Desktop problem is related to an incomplete uninstall of Combofix.
I did download FRST. Logs follow.
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-09-2012
Ran by SYSTEM at 24-09-2012 22:06:37
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2010-10-01] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-09-17] (CyberLink Corp.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe" [17408 2010-07-04] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\Jim\...\Run: [Google Update] "C:\Users\Jim\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-03-14] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) ===================
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-12] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
2 PEVSystemStart; "C:\32788R22FWJFW\pev.3XE" EXEC /I CSCRIPT.exe //NOLOGO //E:VBSCRIPT //B //T:15 "C:\32788R22FWJFW\KNetSvcs.vbs" [322 2012-09-03] ()
==================== Drivers (Whitelisted) =====================
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-25] (AVG Technologies CZ, s.r.o.)
1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.)
1 NEOFLTR_710_19243; C:\Windows\System32\Drivers\NEOFLTR_710_19243.sys [99152 2011-09-07] (Juniper Networks)
3 PCDSRVC{67F2314B-25F2B3C0-06020101}_0; \??\c:\gencotst\pcdsrvc_x64.pkms [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-09-24 22:06 - 2012-09-24 22:06 - 00000000 ____D C:\FRST
2012-09-24 17:39 - 2012-09-24 17:39 - 00016712 ____A (Sysinternals - www.sysinternals.com) C:\Windows\System32\Drivers\PROCEXP113.SYS
2012-09-24 17:36 - 2012-09-24 17:39 - 00000000 ___SD C:\32788R22FWJFW
2012-09-24 17:36 - 2012-09-24 17:39 - 00000000 ____D C:\Qoobox
2012-09-24 17:36 - 2012-09-24 17:36 - 00000000 ____D C:\Windows\erdnt
2012-09-24 17:34 - 2012-09-24 17:34 - 04759205 ____R (Swearware) C:\Users\Jim\Desktop\username123.exe
2012-09-24 17:18 - 2012-09-24 17:18 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-09-22 23:00 - 2012-08-24 03:15 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-09-22 23:00 - 2012-08-24 02:39 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-09-22 23:00 - 2012-08-24 02:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-09-22 23:00 - 2012-08-24 02:22 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-09-22 23:00 - 2012-08-24 02:21 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-09-22 23:00 - 2012-08-24 02:20 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-09-22 23:00 - 2012-08-24 02:18 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-09-22 23:00 - 2012-08-24 02:17 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-09-22 23:00 - 2012-08-24 02:14 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-09-22 23:00 - 2012-08-24 02:14 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-09-22 23:00 - 2012-08-24 02:13 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-09-22 23:00 - 2012-08-24 02:12 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-09-22 23:00 - 2012-08-24 02:11 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-09-22 23:00 - 2012-08-24 02:10 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-09-22 23:00 - 2012-08-24 02:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-09-22 23:00 - 2012-08-24 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-09-22 23:00 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-09-22 23:00 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-09-22 23:00 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-09-22 23:00 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-09-22 23:00 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-09-22 23:00 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-09-22 23:00 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-09-22 23:00 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-09-22 23:00 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-09-22 23:00 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-09-22 23:00 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-09-22 23:00 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-09-22 23:00 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-09-22 23:00 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-09-22 23:00 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-09-22 23:00 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-09-18 15:34 - 2012-09-18 15:34 - 00000000 ____D C:\Users\Jim\AppData\Local\TechSmith
2012-09-16 08:31 - 2012-09-16 08:31 - 04929052 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3125_setup.exe
2012-09-15 13:10 - 2012-09-15 13:10 - 00927691 ____A C:\Users\Jim\Downloads\XML-Editor_1.0.0.1.zip
2012-09-15 06:44 - 2012-09-15 06:45 - 00000000 ____D C:\Users\Jim\AppData\Local\Deployment
2012-09-15 06:44 - 2012-09-15 06:44 - 00428544 ____A () C:\Users\Jim\Downloads\setup.exe
2012-09-15 06:44 - 2012-09-15 06:44 - 00000000 ____D C:\Users\Jim\AppData\Local\Apps\2.0
2012-09-12 16:23 - 2012-08-02 09:55 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-09-12 16:23 - 2012-08-02 09:05 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-09-11 06:02 - 2012-09-11 06:02 - 00000000 ___HD C:\$AVG
2012-09-07 21:05 - 2012-09-15 20:59 - 00119296 ____A C:\Users\Jim\Copy of Big Band Theory 2.xls
2012-09-06 18:44 - 2012-09-06 18:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-09-05 17:52 - 2012-09-05 17:52 - 00000000 ____D C:\tmp
2012-09-04 20:43 - 2012-09-04 20:43 - 00000000 ___AH C:\Users\Jim\Documents\Default.rdp
2012-08-27 20:09 - 2012-08-27 20:09 - 00001073 ____A C:\Users\Public\Desktop\XMedia Recode.lnk
2012-08-27 20:08 - 2012-08-27 20:08 - 04914244 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3120_setup.exe
==================== 3 Months Modified Files ==================
2012-09-24 18:03 - 2011-05-25 19:43 - 01974469 ____A C:\Windows\WindowsUpdate.log
2012-09-24 18:03 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-24 18:03 - 2009-07-13 20:45 - 00014416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-24 18:02 - 2009-07-13 21:13 - 00727160 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-24 18:00 - 2012-04-01 08:59 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-24 18:00 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-24 17:59 - 2009-07-13 21:08 - 00032644 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-24 17:59 - 2009-07-13 20:51 - 00034878 ____A C:\Windows\setupact.log
2012-09-24 17:39 - 2012-09-24 17:39 - 00016712 ____A (Sysinternals - www.sysinternals.com) C:\Windows\System32\Drivers\PROCEXP113.SYS
2012-09-24 17:34 - 2012-09-24 17:34 - 04759205 ____R (Swearware) C:\Users\Jim\Desktop\username123.exe
2012-09-24 17:14 - 2012-04-01 08:59 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-24 17:12 - 2012-03-30 14:53 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-24 17:12 - 2012-03-14 14:52 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3400246598-1791276097-185665454-1002UA.job
2012-09-24 17:12 - 2011-07-29 18:20 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-24 16:12 - 2012-03-14 14:52 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3400246598-1791276097-185665454-1002Core.job
2012-09-16 18:36 - 2012-04-14 08:30 - 00001471 ____A C:\Users\Jim\Desktop\quotes.txt
2012-09-16 08:31 - 2012-09-16 08:31 - 04929052 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3125_setup.exe
2012-09-15 20:59 - 2012-09-07 21:05 - 00119296 ____A C:\Users\Jim\Copy of Big Band Theory 2.xls
2012-09-15 13:10 - 2012-09-15 13:10 - 00927691 ____A C:\Users\Jim\Downloads\XML-Editor_1.0.0.1.zip
2012-09-15 07:44 - 2011-08-16 19:01 - 00000069 ____A C:\Users\Jim\AppData\Roaming\AVSDVDPlayer.m3u
2012-09-15 06:44 - 2012-09-15 06:44 - 00428544 ____A () C:\Users\Jim\Downloads\setup.exe
2012-09-12 17:02 - 2011-08-04 20:22 - 00007602 ____A C:\Users\Jim\AppData\Local\Resmon.ResmonCfg
2012-09-12 16:14 - 2011-07-27 16:12 - 00467808 ____A C:\Windows\PFRO.log
2012-09-11 06:03 - 2011-10-03 18:08 - 00000971 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-09-10 16:46 - 2011-08-09 17:47 - 00000600 ____A C:\Users\Jim\AppData\Local\PUTTY.RND
2012-09-09 09:27 - 2012-04-25 16:22 - 00000778 ____A C:\Users\Jim\Documents\eros.txt
2012-09-06 21:11 - 2011-11-14 21:11 - 00018833 ____A C:\Users\Jim\Documents\Good Eats HD.xlsx
2012-09-04 20:43 - 2012-09-04 20:43 - 00000000 ___AH C:\Users\Jim\Documents\Default.rdp
2012-09-04 10:07 - 2012-03-14 14:53 - 00002448 ____A C:\Users\Jim\Desktop\Google Chrome.lnk
2012-09-03 15:21 - 2009-07-13 20:45 - 00361504 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-27 20:09 - 2012-08-27 20:09 - 00001073 ____A C:\Users\Public\Desktop\XMedia Recode.lnk
2012-08-27 20:08 - 2012-08-27 20:08 - 04914244 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3120_setup.exe
2012-08-24 11:43 - 2012-08-24 11:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys
2012-08-24 03:15 - 2012-09-22 23:00 - 17810944 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-24 02:39 - 2012-09-22 23:00 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-24 02:31 - 2012-09-22 23:00 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-24 02:22 - 2012-09-22 23:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-24 02:21 - 2012-09-22 23:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-24 02:20 - 2012-09-22 23:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-24 02:18 - 2012-09-22 23:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-24 02:17 - 2012-09-22 23:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-24 02:14 - 2012-09-22 23:00 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-24 02:14 - 2012-09-22 23:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-24 02:13 - 2012-09-22 23:00 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-24 02:12 - 2012-09-22 23:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-24 02:11 - 2012-09-22 23:00 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-24 02:10 - 2012-09-22 23:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-24 02:09 - 2012-09-22 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-24 02:04 - 2012-09-22 23:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-23 23:27 - 2012-09-22 23:00 - 12319744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-23 23:03 - 2012-09-22 23:00 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-23 22:59 - 2012-09-22 23:00 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-08-23 22:51 - 2012-09-22 23:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-23 22:51 - 2012-09-22 23:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-23 22:51 - 2012-09-22 23:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-23 22:49 - 2012-09-22 23:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-23 22:48 - 2012-09-22 23:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-23 22:47 - 2012-09-22 23:00 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-23 22:47 - 2012-09-22 23:00 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-08-23 22:47 - 2012-09-22 23:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-23 22:45 - 2012-09-22 23:00 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-08-23 22:44 - 2012-09-22 23:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-23 22:44 - 2012-09-22 23:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-23 22:43 - 2012-09-22 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-23 22:40 - 2012-09-22 23:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-22 20:46 - 2011-07-28 15:37 - 00000600 ____A C:\Users\Jim\AppData\Roaming\winscp.rnd
2012-08-22 20:39 - 2011-07-27 16:20 - 00084616 ____A C:\Users\Jim\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-19 05:20 - 2012-08-19 05:20 - 00282976 ____A C:\Windows\Minidump\081912-21496-01.dmp
2012-08-19 05:20 - 2012-08-18 15:49 - 694553353 ____A C:\Windows\MEMORY.DMP
2012-08-18 20:17 - 2012-08-18 20:17 - 00282976 ____A C:\Windows\Minidump\081912-19390-01.dmp
2012-08-18 15:50 - 2012-08-18 15:49 - 00282976 ____A C:\Windows\Minidump\081812-24117-01.dmp
2012-08-08 15:53 - 2012-08-08 15:53 - 00000076 ____A C:\Users\Jim\Documents\galleries.txt
2012-08-05 06:52 - 2012-08-05 06:51 - 04912733 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3118_setup.exe
2012-08-02 09:55 - 2012-09-12 16:23 - 00574464 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-08-02 09:05 - 2012-09-12 16:23 - 00490496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2012-07-28 07:26 - 2012-07-28 07:23 - 00011377 ____A C:\Users\Jim\Documents\Star Notes.xlsx
2012-07-25 23:21 - 2012-07-25 23:21 - 00291680 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgldx64.sys
2012-07-24 19:36 - 2012-07-24 19:36 - 00110736 ____A C:\Users\Jim\Downloads\wootwatcher_9.zip
2012-07-18 09:31 - 2012-08-15 14:56 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-14 07:42 - 2012-07-14 07:42 - 00476976 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-07-14 07:42 - 2012-07-14 07:42 - 00157488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-07-14 07:42 - 2012-07-14 07:42 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-07-14 07:42 - 2012-07-14 07:42 - 00149296 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-07-14 07:42 - 2011-08-16 19:18 - 00472880 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-07-12 18:45 - 2012-07-12 18:45 - 04837559 ____A (XMedia Recode ) C:\Users\Jim\Downloads\XMediaRecode3114_setup.exe
2012-07-04 14:04 - 2012-08-15 14:56 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 14:01 - 2012-08-15 14:56 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 14:01 - 2012-08-15 14:56 - 00058880 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 13:26 - 2012-08-15 14:56 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 13:23 - 2012-08-15 14:56 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-01 09:44 - 2012-07-01 09:44 - 02709534 ____A C:\Users\Jim\Downloads\leggy-babe-flashing-003.wmv
2012-07-01 09:42 - 2012-07-01 09:42 - 02725534 ____A C:\Users\Jim\Downloads\busty-and-skinny-004.wmv
2012-07-01 09:42 - 2012-07-01 09:42 - 02709534 ____A C:\Users\Jim\Downloads\busty-and-skinny-003.wmv
2012-07-01 09:41 - 2012-07-01 09:41 - 02725534 ____A C:\Users\Jim\Downloads\sexy-schoolgirl-003.wmv
2012-07-01 09:40 - 2012-07-01 09:40 - 02717534 ____A C:\Users\Jim\Downloads\sexy-schoolgirl-002.wmv
2012-07-01 09:38 - 2012-07-01 09:38 - 03614624 ____A C:\Users\Jim\Downloads\02.wmv
2012-07-01 09:38 - 2012-07-01 09:38 - 03343064 ____A C:\Users\Jim\Downloads\04.wmv
ZeroAccess:
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\L
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\L\00000004.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\00000004.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\00000008.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\000000cb.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\80000000.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\80000032.@
C:\Windows\Installer\{6a417f29-ed51-7446-8917-dbfcd7f278d4}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 11%
Total physical RAM: 8174.45 MB
Available physical RAM: 7258.09 MB
Total Pagefile: 8172.59 MB
Available Pagefile: 7249.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
==================== Partitions =============================
1 Drive c: (OSDisk) (Fixed) (Total:1383.59 GB) (Free:143.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Recovery) (Fixed) (Total:13.67 GB) (Free:7.06 GB) NTFS
4 Drive f: (KINGSTON) (Removable) (Total:3.65 GB) (Free:3.13 GB) FAT32
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 1397 GB 0 B
Disk 1 Online 3745 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1383 GB 1024 KB
Partition 2 Primary 13 GB 1383 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C OSDisk NTFS Partition 1383 GB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Recovery NTFS Partition 13 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3741 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 3741 MB Healthy
=========================================================
Last Boot: 2012-09-16 17:30
==================== End Of Log =============================
Search.txt:
Farbar Recovery Scan Tool (x64) Version: 24-09-2012
Ran by SYSTEM at 2012-09-24 22:07:45
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC
====== End Of Search ======
Thanks