Hello,
So I have caught sirefef.ah and sirefef.r too.. which are quite popular here as I can see.
First there was Live Security Platinum but probably I have successfully removed it. I reinstalled MSE and I think that only then my computer has started to get restarted after like three minutes because of these sirefef.ah and sirefef.r.. So here are the FRST logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 03-08-2012 12:39:20
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE [x]
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252136 2011-05-04] (Sun Microsystems, Inc.)
HKLM\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [417792 2008-09-26] (Chicony)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Julius\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 212.59.1.1 212.59.2.2
Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico ()
Startup: C:\Users\Julius\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 ABBYY.Licensing.FineReader.Professional.10.0; "C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe" -service [814344 2010-07-22] (ABBYY)
2 AcronisOSSReinstallSvc; "C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe" [2217416 2007-02-22] ()
2 astcc; C:\Windows\system32\ASTSRV.EXE [61760 2009-09-14] (Nalpeiron Ltd.)
2 CVPND; "C:\Program Files\VPN Client\VU VPN Client\cvpnd.exe" [1528616 2010-03-23] (Cisco Systems, Inc.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 NitroDriverReadSpool; "C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe" [188736 2009-09-14] (Nitro PDF Software)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
2 TemproMonitoringService; "C:\Program Files\Toshiba TEMPRO\TemproSvc.exe" [124368 2010-10-26] (Toshiba Europe GmbH)
2 TosCoSrv; "C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe" [468320 2009-11-05] (TOSHIBA Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 postgresql-9.1; C:/Program Files/PostgreSQL/9.1/bin/pg_ctl.exe runservice -N "postgresql-9.1" -D "C:/Program Files/PostgreSQL/9.1/data" -w [x]
========================== Drivers (Whitelisted) =============
3 AgereSoftModem; C:\Windows\System32\DRIVERS\AGRSM.sys [1035776 2009-07-13] (LSI Corp)
3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.)
3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
3 GdmUWm; C:\Windows\System32\DRIVERS\gdmuwm.sys [92160 2009-11-13] (GCT Semiconductor, Inc.)
0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [6656 2011-03-09] (Windows (R) Codename Longhorn DDK provider)
3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28560 2009-06-17] (Logitech, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [159776 2009-06-24] (Realtek Semiconductor Corp.)
3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [17960 2008-07-15] (Chicony Electronics Co., Ltd.)
3 catchme; \??\C:\Users\Julius\AppData\Local\Temp\catchme.sys [x]
3 GdmFilt; C:\Windows\System32\DRIVERS\GdmFilt.sys [x]
2 GdmWmPrt; C:\Windows\System32\DRIVERS\gdmwmprt.sys [x]
3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfd.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
0 vmci; C:\Windows\System32\DRIVERS\vmci.sys [x]
3 VMnetAdapter; C:\Windows\System32\DRIVERS\vmnetadapter.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-03 12:39 - 2012-08-03 12:39 - 00000000 ____D C:\FRST
2012-08-02 12:40 - 2012-08-02 12:40 - 00000000 ___SD C:\32788R22FWJFW
2012-08-02 12:28 - 2012-08-02 12:29 - 04722680 ____R (Swearware) C:\Users\Julius\Downloads\ComboFix.exe
2012-08-02 12:23 - 2012-08-02 12:23 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-02 12:20 - 2012-08-02 12:20 - 10288512 ____A (Microsoft Corporation) C:\Users\Julius\Downloads\mseinstall.exe
2012-08-02 12:16 - 2012-08-02 12:16 - 00105536 ____A C:\Users\Julius\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-02 09:46 - 2012-08-02 09:47 - 00000000 ____D C:\Users\Julius\Downloads\Season 1
2012-07-30 06:22 - 2012-07-30 06:22 - 04212409 ____A C:\Users\Julius\1.rar
2012-07-29 03:19 - 2012-07-29 03:31 - 00000000 ____D C:\Users\Julius\Downloads\Season 09
2012-07-24 09:34 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-24 09:32 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-24 09:32 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-24 09:32 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-24 09:32 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-24 09:32 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-24 09:31 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-24 09:31 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-24 09:31 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-24 09:31 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-24 09:31 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-21 04:44 - 2012-07-22 01:09 - 00000000 ____D C:\Users\Julius\Downloads\A Wednesday 2008 Hindi 720 BDRip x264 E-SuB xRG
2012-07-17 12:50 - 2012-07-17 12:50 - 00000040 ____A C:\Users\Julius\.RData
2012-07-17 01:25 - 2012-07-17 01:25 - 00000000 ____D C:\Program Files\Klok2
2012-07-15 14:42 - 2012-07-15 14:47 - 00000000 ____D C:\Users\Julius\AppData\Roaming\Opera
2012-07-15 14:42 - 2012-07-15 14:47 - 00000000 ____D C:\Users\Julius\AppData\Local\Opera
2012-07-15 14:41 - 2012-07-15 14:47 - 00000000 ____D C:\Program Files\Opera
2012-07-15 01:19 - 2012-07-16 15:20 - 00000098 ___AH C:\Users\Julius\Downloads\f.txt
2012-07-13 04:15 - 2012-07-13 04:21 - 00000000 ____D C:\Users\Julius\Downloads\Conviction[2010]DvDrip[Eng]-FXG
2012-07-08 11:51 - 2012-07-08 11:51 - 00000000 ____D C:\Program Files\Valve
2012-07-05 11:55 - 2012-07-05 11:56 - 01526426 ____A C:\Users\Julius\Downloads\Mastering.Regular.Expressions.3rd.Edition.Aug.2006.chm
2012-07-05 11:55 - 2012-07-05 11:56 - 00210515 ____A C:\Users\Julius\Downloads\Regular.Expressions.in.10.Minutes.chm
2012-07-04 08:04 - 2012-07-04 08:05 - 00000000 ____D C:\Program Files\RStudio
2012-07-04 04:45 - 2012-07-04 04:45 - 00002015 ____A C:\Users\Julius\Downloads\agregbars.rar
============ 3 Months Modified Files ========================
2012-08-03 01:34 - 2012-06-07 22:04 - 00001176 ____A C:\Windows\setupact.log
2012-08-03 01:34 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-02 13:02 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-02 12:29 - 2012-08-02 12:28 - 04722680 ____R (Swearware) C:\Users\Julius\Downloads\ComboFix.exe
2012-08-02 12:27 - 2012-04-06 07:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-02 12:24 - 2009-08-08 05:59 - 01508923 ____A C:\Windows\WindowsUpdate.log
2012-08-02 12:23 - 2011-01-26 03:18 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-02 12:23 - 2009-08-08 06:01 - 00787942 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-02 12:23 - 2009-07-13 20:34 - 00021456 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-02 12:23 - 2009-07-13 20:34 - 00021456 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-02 12:20 - 2012-08-02 12:20 - 10288512 ____A (Microsoft Corporation) C:\Users\Julius\Downloads\mseinstall.exe
2012-08-02 12:16 - 2012-08-02 12:16 - 00105536 ____A C:\Users\Julius\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-30 06:22 - 2012-07-30 06:22 - 04212409 ____A C:\Users\Julius\1.rar
2012-07-26 13:16 - 2012-04-06 07:04 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-26 13:16 - 2011-05-18 22:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-24 10:02 - 2009-07-13 20:33 - 02328496 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-24 09:34 - 2009-09-09 07:49 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-17 12:50 - 2012-07-17 12:50 - 00000040 ____A C:\Users\Julius\.RData
2012-07-17 07:31 - 2012-07-17 07:14 - 781728420 ___AH C:\Users\Julius\Downloads\x-art_kitty_after_hours_1080.mov
2012-07-16 15:20 - 2012-07-15 01:19 - 00000098 ___AH C:\Users\Julius\Downloads\f.txt
2012-07-15 06:09 - 2009-12-23 08:32 - 00416768 __ASH C:\Users\Julius\Thumbs.db
2012-07-05 11:56 - 2012-07-05 11:55 - 01526426 ____A C:\Users\Julius\Downloads\Mastering.Regular.Expressions.3rd.Edition.Aug.2006.chm
2012-07-05 11:56 - 2012-07-05 11:55 - 00210515 ____A C:\Users\Julius\Downloads\Regular.Expressions.in.10.Minutes.chm
2012-07-04 04:45 - 2012-07-04 04:45 - 00002015 ____A C:\Users\Julius\Downloads\agregbars.rar
2012-06-24 05:05 - 2009-09-22 03:33 - 00000600 ____A C:\Users\Julius\AppData\Roaming\winscp.rnd
2012-06-22 12:34 - 2012-06-22 12:29 - 00001525 ____A C:\Users\Julius\Documents\pgadmin.log
2012-06-11 18:40 - 2012-07-24 09:34 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-24 09:31 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-07 22:04 - 2012-06-07 22:04 - 00000000 ____A C:\Windows\setuperr.log
2012-06-07 05:12 - 2012-06-07 05:12 - 00061950 ____A C:\Windows\cc_20120607_161208.reg
2012-06-06 02:09 - 2012-06-06 02:09 - 00000961 ____A C:\Users\postgres\Desktop\Texmaker.lnk
2012-06-06 01:55 - 2012-06-06 01:55 - 00017955 ____A C:\ComboFix.txt
2012-06-06 01:52 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini
2012-06-05 21:05 - 2012-07-24 09:31 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-24 09:31 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-24 09:31 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 00:16 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 00:16 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 00:16 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 04:19 - 2012-06-21 00:16 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 04:12 - 2012-06-21 00:16 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:45 - 2012-07-24 09:32 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-24 09:32 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-24 09:32 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-24 09:32 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-24 09:32 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-10 23:43 - 2012-05-10 23:41 - 00001582 ____A C:\Windows\VPNInstall.MIF
2012-05-08 10:54 - 2010-10-03 10:00 - 00000600 ____A C:\Users\Julius\AppData\Local\PUTTY.RND
ZeroAccess:
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\@
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\L
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\n
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U\00000001.@
ZeroAccess:
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\@
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\L
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\n
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3069.99 MB
Available physical RAM: 2595.81 MB
Total Pagefile: 3068.27 MB
Available Pagefile: 2601.5 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.7 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:297.99 GB) (Free:143.72 GB) NTFS
3 Drive f: (KINGSTON) (Removable) (Total:3.6 GB) (Free:3.51 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3690 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 297 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 297 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3689 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 3689 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 05:25
======================= End Of Log ==========================
and Search.txt
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-03 12:41:40
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-02 13:02] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
C:\Windows\ERDNT\cache\services.exe
[2012-06-06 01:53] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===
Thank you!
So I have caught sirefef.ah and sirefef.r too.. which are quite popular here as I can see.
First there was Live Security Platinum but probably I have successfully removed it. I reinstalled MSE and I think that only then my computer has started to get restarted after like three minutes because of these sirefef.ah and sirefef.r.. So here are the FRST logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 03-08-2012 12:39:20
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE [x]
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252136 2011-05-04] (Sun Microsystems, Inc.)
HKLM\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [417792 2008-09-26] (Chicony)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Julius\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 212.59.1.1 212.59.2.2
Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico ()
Startup: C:\Users\Julius\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
================================ Services (Whitelisted) ==================
2 ABBYY.Licensing.FineReader.Professional.10.0; "C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe" -service [814344 2010-07-22] (ABBYY)
2 AcronisOSSReinstallSvc; "C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe" [2217416 2007-02-22] ()
2 astcc; C:\Windows\system32\ASTSRV.EXE [61760 2009-09-14] (Nalpeiron Ltd.)
2 CVPND; "C:\Program Files\VPN Client\VU VPN Client\cvpnd.exe" [1528616 2010-03-23] (Cisco Systems, Inc.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 NitroDriverReadSpool; "C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe" [188736 2009-09-14] (Nitro PDF Software)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
2 TemproMonitoringService; "C:\Program Files\Toshiba TEMPRO\TemproSvc.exe" [124368 2010-10-26] (Toshiba Europe GmbH)
2 TosCoSrv; "C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe" [468320 2009-11-05] (TOSHIBA Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 postgresql-9.1; C:/Program Files/PostgreSQL/9.1/bin/pg_ctl.exe runservice -N "postgresql-9.1" -D "C:/Program Files/PostgreSQL/9.1/data" -w [x]
========================== Drivers (Whitelisted) =============
3 AgereSoftModem; C:\Windows\System32\DRIVERS\AGRSM.sys [1035776 2009-07-13] (LSI Corp)
3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-03-23] (Cisco Systems, Inc.)
3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
3 GdmUWm; C:\Windows\System32\DRIVERS\gdmuwm.sys [92160 2009-11-13] (GCT Semiconductor, Inc.)
0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [6656 2011-03-09] (Windows (R) Codename Longhorn DDK provider)
3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28560 2009-06-17] (Logitech, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [159776 2009-06-24] (Realtek Semiconductor Corp.)
3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [17960 2008-07-15] (Chicony Electronics Co., Ltd.)
3 catchme; \??\C:\Users\Julius\AppData\Local\Temp\catchme.sys [x]
3 GdmFilt; C:\Windows\System32\DRIVERS\GdmFilt.sys [x]
2 GdmWmPrt; C:\Windows\System32\DRIVERS\gdmwmprt.sys [x]
3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfd.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
0 vmci; C:\Windows\System32\DRIVERS\vmci.sys [x]
3 VMnetAdapter; C:\Windows\System32\DRIVERS\vmnetadapter.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-03 12:39 - 2012-08-03 12:39 - 00000000 ____D C:\FRST
2012-08-02 12:40 - 2012-08-02 12:40 - 00000000 ___SD C:\32788R22FWJFW
2012-08-02 12:28 - 2012-08-02 12:29 - 04722680 ____R (Swearware) C:\Users\Julius\Downloads\ComboFix.exe
2012-08-02 12:23 - 2012-08-02 12:23 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-02 12:20 - 2012-08-02 12:20 - 10288512 ____A (Microsoft Corporation) C:\Users\Julius\Downloads\mseinstall.exe
2012-08-02 12:16 - 2012-08-02 12:16 - 00105536 ____A C:\Users\Julius\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-02 09:46 - 2012-08-02 09:47 - 00000000 ____D C:\Users\Julius\Downloads\Season 1
2012-07-30 06:22 - 2012-07-30 06:22 - 04212409 ____A C:\Users\Julius\1.rar
2012-07-29 03:19 - 2012-07-29 03:31 - 00000000 ____D C:\Users\Julius\Downloads\Season 09
2012-07-24 09:34 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-24 09:32 - 2012-06-01 20:45 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-24 09:32 - 2012-06-01 20:45 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-24 09:32 - 2012-06-01 20:40 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-24 09:32 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-24 09:32 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-24 09:31 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-24 09:31 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-24 09:31 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-24 09:31 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-24 09:31 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-21 04:44 - 2012-07-22 01:09 - 00000000 ____D C:\Users\Julius\Downloads\A Wednesday 2008 Hindi 720 BDRip x264 E-SuB xRG
2012-07-17 12:50 - 2012-07-17 12:50 - 00000040 ____A C:\Users\Julius\.RData
2012-07-17 01:25 - 2012-07-17 01:25 - 00000000 ____D C:\Program Files\Klok2
2012-07-15 14:42 - 2012-07-15 14:47 - 00000000 ____D C:\Users\Julius\AppData\Roaming\Opera
2012-07-15 14:42 - 2012-07-15 14:47 - 00000000 ____D C:\Users\Julius\AppData\Local\Opera
2012-07-15 14:41 - 2012-07-15 14:47 - 00000000 ____D C:\Program Files\Opera
2012-07-15 01:19 - 2012-07-16 15:20 - 00000098 ___AH C:\Users\Julius\Downloads\f.txt
2012-07-13 04:15 - 2012-07-13 04:21 - 00000000 ____D C:\Users\Julius\Downloads\Conviction[2010]DvDrip[Eng]-FXG
2012-07-08 11:51 - 2012-07-08 11:51 - 00000000 ____D C:\Program Files\Valve
2012-07-05 11:55 - 2012-07-05 11:56 - 01526426 ____A C:\Users\Julius\Downloads\Mastering.Regular.Expressions.3rd.Edition.Aug.2006.chm
2012-07-05 11:55 - 2012-07-05 11:56 - 00210515 ____A C:\Users\Julius\Downloads\Regular.Expressions.in.10.Minutes.chm
2012-07-04 08:04 - 2012-07-04 08:05 - 00000000 ____D C:\Program Files\RStudio
2012-07-04 04:45 - 2012-07-04 04:45 - 00002015 ____A C:\Users\Julius\Downloads\agregbars.rar
============ 3 Months Modified Files ========================
2012-08-03 01:34 - 2012-06-07 22:04 - 00001176 ____A C:\Windows\setupact.log
2012-08-03 01:34 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-02 13:02 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-02 12:29 - 2012-08-02 12:28 - 04722680 ____R (Swearware) C:\Users\Julius\Downloads\ComboFix.exe
2012-08-02 12:27 - 2012-04-06 07:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-02 12:24 - 2009-08-08 05:59 - 01508923 ____A C:\Windows\WindowsUpdate.log
2012-08-02 12:23 - 2011-01-26 03:18 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-02 12:23 - 2009-08-08 06:01 - 00787942 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-02 12:23 - 2009-07-13 20:34 - 00021456 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-02 12:23 - 2009-07-13 20:34 - 00021456 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-02 12:20 - 2012-08-02 12:20 - 10288512 ____A (Microsoft Corporation) C:\Users\Julius\Downloads\mseinstall.exe
2012-08-02 12:16 - 2012-08-02 12:16 - 00105536 ____A C:\Users\Julius\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-30 06:22 - 2012-07-30 06:22 - 04212409 ____A C:\Users\Julius\1.rar
2012-07-26 13:16 - 2012-04-06 07:04 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-26 13:16 - 2011-05-18 22:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-24 10:02 - 2009-07-13 20:33 - 02328496 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-24 09:34 - 2009-09-09 07:49 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-17 12:50 - 2012-07-17 12:50 - 00000040 ____A C:\Users\Julius\.RData
2012-07-17 07:31 - 2012-07-17 07:14 - 781728420 ___AH C:\Users\Julius\Downloads\x-art_kitty_after_hours_1080.mov
2012-07-16 15:20 - 2012-07-15 01:19 - 00000098 ___AH C:\Users\Julius\Downloads\f.txt
2012-07-15 06:09 - 2009-12-23 08:32 - 00416768 __ASH C:\Users\Julius\Thumbs.db
2012-07-05 11:56 - 2012-07-05 11:55 - 01526426 ____A C:\Users\Julius\Downloads\Mastering.Regular.Expressions.3rd.Edition.Aug.2006.chm
2012-07-05 11:56 - 2012-07-05 11:55 - 00210515 ____A C:\Users\Julius\Downloads\Regular.Expressions.in.10.Minutes.chm
2012-07-04 04:45 - 2012-07-04 04:45 - 00002015 ____A C:\Users\Julius\Downloads\agregbars.rar
2012-06-24 05:05 - 2009-09-22 03:33 - 00000600 ____A C:\Users\Julius\AppData\Roaming\winscp.rnd
2012-06-22 12:34 - 2012-06-22 12:29 - 00001525 ____A C:\Users\Julius\Documents\pgadmin.log
2012-06-11 18:40 - 2012-07-24 09:34 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-24 09:31 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-07 22:04 - 2012-06-07 22:04 - 00000000 ____A C:\Windows\setuperr.log
2012-06-07 05:12 - 2012-06-07 05:12 - 00061950 ____A C:\Windows\cc_20120607_161208.reg
2012-06-06 02:09 - 2012-06-06 02:09 - 00000961 ____A C:\Users\postgres\Desktop\Texmaker.lnk
2012-06-06 01:55 - 2012-06-06 01:55 - 00017955 ____A C:\ComboFix.txt
2012-06-06 01:52 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini
2012-06-05 21:05 - 2012-07-24 09:31 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-24 09:31 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-24 09:31 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 00:16 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 00:16 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 00:16 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 00:16 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 04:19 - 2012-06-21 00:16 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 04:12 - 2012-06-21 00:16 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:45 - 2012-07-24 09:32 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-24 09:32 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-24 09:32 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-24 09:32 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-24 09:32 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-10 23:43 - 2012-05-10 23:41 - 00001582 ____A C:\Windows\VPNInstall.MIF
2012-05-08 10:54 - 2010-10-03 10:00 - 00000600 ____A C:\Users\Julius\AppData\Local\PUTTY.RND
ZeroAccess:
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\@
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\L
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\n
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U
C:\Windows\Installer\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U\00000001.@
ZeroAccess:
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\@
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\L
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\n
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U
C:\Users\Julius\AppData\Local\{ce4d4c51-61a0-ccf3-9a84-34ee173c2bde}\U\00000001.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3069.99 MB
Available physical RAM: 2595.81 MB
Total Pagefile: 3068.27 MB
Available Pagefile: 2601.5 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.7 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:297.99 GB) (Free:143.72 GB) NTFS
3 Drive f: (KINGSTON) (Removable) (Total:3.6 GB) (Free:3.51 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3690 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 297 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 297 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3689 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 3689 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 05:25
======================= End Of Log ==========================
and Search.txt
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-03 12:41:40
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-02 13:02] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
C:\Windows\ERDNT\cache\services.exe
[2012-06-06 01:53] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===
Thank you!