RebootTech
Posts: 13 +0
Same as other posters, Sirefef.AH infection, MSE finds it, does nothing, computer reboots after a minute. I renamed C:\Windows\System32\services.exe to services.exe.bak just to stop the reboots. Here's the Farbar log:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) (x86) Version: 05-09-2012
Ran by SYSTEM at 06-09-2012 13:57:33
Running from F:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Adam\...\Run: [EPSON Stylus CX7800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAFA.EXE /FU "C:\Windows\TEMP\E_S7C96.tmp" /EF "HKCU" [177664 2007-01-23] (SEIKO EPSON CORPORATION)
Winlogon\Notify\VESWinlogon: VESWinlogon.dll (Sony Corporation)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220 205.171.3.25
Startup: C:\Users\All Users\Start Menu\Programs\Startup\MRI_DISABLED ()
==================== Services ================================
2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
3 MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [57344 2006-10-04] (Sony Corporation)
2 MSSQL$VAIO_VEDB; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sVAIO_VEDB [29293408 2010-12-10] (Microsoft Corporation)
3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-10-04] (Sony Corporation)
3 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-10-04] (Sony Corporation)
3 SSScsiSV; C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [69632 2006-11-13] (Sony Corporation)
3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe" [73728 2006-09-21] (Sony Corporation)
2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392 2006-11-24] (Sony Corporation)
3 VAIOMediaPlatform-IntegratedServer-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe [2523136 2006-10-24] (Sony Corporation)
3 VAIOMediaPlatform-IntegratedServer-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [1089536 2006-10-11] (Sony Corporation)
3 VAIOMediaPlatform-UCLS-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [741376 2006-10-11] (Sony Corporation)
3 VAIOMediaPlatform-UCLS-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [1089536 2006-10-11] (Sony Corporation)
3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM [274432 2006-08-23] (Sony Corporation)
2 Viewpoint Manager Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [24652 2007-01-04] (Viewpoint Corporation)
2 VzCdbSvc; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" [172032 2006-09-26] (Sony Corporation)
2 VzFw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [135168 2006-09-26] (Sony Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
3 VAIOMediaPlatform-IntegratedServer-HTTP; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" [x]
3 VAIOMediaPlatform-Mobile-Gateway; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server" [x]
3 VAIOMediaPlatform-UCLS-HTTP; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" [x]
==================== Drivers =================================
3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [6144 2007-01-09] (Chic)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [43872 2008-11-20] (Sonic Solutions)
3 R5U870FLx86; C:\Windows\System32\Drivers\R5U870FLx86.sys [72704 2006-11-28] (Ricoh)
3 R5U870FUx86; C:\Windows\System32\Drivers\R5U870FUx86.sys [43904 2006-11-28] (Ricoh)
4 SI3132; C:\Windows\system32\DRIVERS\SI3132.sys [74672 2006-11-20] (Silicon Image, Inc.)
0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17328 2006-11-20] (Silicon Image, Inc.)
0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12464 2006-11-20] (Silicon Image, Inc.)
3 SNC; C:\Windows\System32\Drivers\SonyNC.sys [27520 2006-11-06] (Sony Corporation)
3 SonyImgF; C:\Windows\System32\DRIVERS\SonyImgF.sys [30976 2006-11-08] (Sony Corporation)
3 ti21sony; C:\Windows\System32\drivers\ti21sony.sys [227328 2006-11-10] (Texas Instruments)
0 7ef8d626d959ac7d; C:\Windows\System32\Drivers\7ef8d626d959ac7d.sys [x]
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-09-06 13:57 - 2012-09-06 13:57 - 00000000 ____D C:\FRST
2012-09-06 11:43 - 2012-09-06 11:43 - 00007586 ____A C:\Users\Adam\Downloads\WinDefend.reg
2012-09-06 11:43 - 2012-09-06 11:42 - 00005256 ____A C:\Users\Adam\Downloads\wscsvc.reg
2012-09-06 11:18 - 2012-09-06 11:18 - 00176940 ____A C:\Users\Adam\Downloads\BFE.reg
2012-09-06 11:18 - 2012-09-06 11:18 - 00006396 ____A C:\Users\Adam\Downloads\MpsSvc.reg
2012-09-06 11:15 - 2012-09-06 11:15 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Adam\Downloads\tdsskiller.exe
2012-09-06 11:11 - 2012-09-06 11:12 - 00003193 ____A C:\Windows\WindowsUpdate.log
2012-09-06 11:10 - 2012-09-06 11:11 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-06 11:09 - 2012-08-28 19:10 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-09-06 11:09 - 2012-08-28 19:10 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-09-06 11:09 - 2012-08-28 19:09 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-09-06 11:01 - 2012-09-06 11:01 - 00000702 ____A C:\Windows\PFRO.log
2012-09-06 10:48 - 2012-09-06 10:48 - 00003304 ____N C:\bootsqm.dat
2012-08-26 12:48 - 2012-08-26 12:48 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.bak
2012-08-25 20:29 - 2012-09-06 11:34 - 00051706 ____A C:\Windows\setupact.log
2012-08-25 20:29 - 2012-08-25 20:29 - 00000000 ____A C:\Windows\setuperr.log
2012-08-25 19:26 - 2012-08-25 19:26 - 00282306 ____A C:\backup.reg
2012-08-25 17:50 - 2010-07-07 05:29 - 00363520 ____A C:\Users\Adam\Documents\rkill.exe
2012-08-25 16:00 - 2012-08-25 20:24 - 00000000 ____D C:\Users\Adam\Documents\a-squared Free
2012-08-25 16:00 - 2012-08-25 20:24 - 00000000 ____D C:\Program Files\a-squared Free
2012-08-24 07:19 - 2012-08-24 07:19 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-24 07:19 - 2012-08-24 07:19 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-22 15:22 - 2012-08-28 19:24 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-08-22 08:03 - 2012-08-22 08:03 - 00000000 ____D C:\Users\Adam\AppData\Local\{FDFD79AF-899A-D0B0-096B-A4A0E88FB9D2}
2012-08-21 14:04 - 2012-08-27 17:05 - 00000385 ____A C:\rkill.log
2012-08-20 14:39 - 2012-08-20 14:39 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-20 13:36 - 2012-08-20 13:36 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-08-20 13:35 - 2012-08-24 11:16 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-08-20 13:31 - 2012-08-20 13:31 - 00000000 ____D C:\Program Files\CCleaner
2012-08-20 13:02 - 2012-08-20 14:09 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-20 13:02 - 2012-08-20 13:02 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Malwarebytes
2012-08-20 13:01 - 2012-08-20 14:09 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-20 13:01 - 2012-08-20 13:01 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-18 13:58 - 2012-08-18 13:58 - 00000000 ____D C:\Users\All Users\Geek Squad
2012-08-16 06:51 - 2012-08-22 07:51 - 09826504 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-08-14 23:13 - 2012-08-14 23:15 - 00000000 ____D C:\Users\Adam\Documents\Lyrics
2012-08-09 10:57 - 2012-08-09 10:58 - 00000000 ___HD C:\Users\Adam\AppData\Local\CutePDF Writer
2012-08-09 10:55 - 2012-08-09 10:55 - 05254656 ____A C:\Users\Adam\Downloads\converter.exe
============ 3 Months Modified Files ========================
2012-09-06 12:38 - 2010-11-22 16:07 - 00808926 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-06 11:58 - 2010-11-22 16:04 - 00009728 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-06 11:58 - 2010-11-22 16:04 - 00009728 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-06 11:46 - 2009-12-21 16:14 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-06 11:44 - 2011-03-27 22:26 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2218131356-71786554-3709945380-1005UA.job
2012-09-06 11:43 - 2012-09-06 11:43 - 00007586 ____A C:\Users\Adam\Downloads\WinDefend.reg
2012-09-06 11:42 - 2012-09-06 11:43 - 00005256 ____A C:\Users\Adam\Downloads\wscsvc.reg
2012-09-06 11:35 - 2009-12-21 16:14 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-06 11:34 - 2012-08-25 20:29 - 00051706 ____A C:\Windows\setupact.log
2012-09-06 11:34 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-06 11:18 - 2012-09-06 11:18 - 00176940 ____A C:\Users\Adam\Downloads\BFE.reg
2012-09-06 11:18 - 2012-09-06 11:18 - 00006396 ____A C:\Users\Adam\Downloads\MpsSvc.reg
2012-09-06 11:15 - 2012-09-06 11:15 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Adam\Downloads\tdsskiller.exe
2012-09-06 11:12 - 2012-09-06 11:11 - 00003193 ____A C:\Windows\WindowsUpdate.log
2012-09-06 11:11 - 2012-06-25 06:58 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-06 11:01 - 2012-09-06 11:01 - 00000702 ____A C:\Windows\PFRO.log
2012-09-06 10:48 - 2012-09-06 10:48 - 00003304 ____N C:\bootsqm.dat
2012-08-28 19:24 - 2012-08-22 15:22 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-08-28 19:24 - 2010-06-12 08:23 - 00473072 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-08-28 19:10 - 2012-09-06 11:09 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-08-28 19:10 - 2012-09-06 11:09 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-08-28 19:09 - 2012-09-06 11:09 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-08-27 17:05 - 2012-08-21 14:04 - 00000385 ____A C:\rkill.log
2012-08-26 12:48 - 2012-08-26 12:48 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.bak
2012-08-26 12:46 - 2009-03-26 10:42 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job
2012-08-25 20:29 - 2012-08-25 20:29 - 00000000 ____A C:\Windows\setuperr.log
2012-08-25 19:26 - 2012-08-25 19:26 - 00282306 ____A C:\backup.reg
2012-08-25 17:43 - 2009-07-13 18:04 - 00002577 ____A C:\Windows\System32\config.nt
2012-08-24 07:19 - 2012-08-24 07:19 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-24 07:19 - 2012-08-24 07:19 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-23 16:36 - 2011-03-27 22:26 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2218131356-71786554-3709945380-1005Core.job
2012-08-22 07:51 - 2012-08-16 06:51 - 09826504 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-08-20 14:09 - 2012-08-20 13:02 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-18 20:17 - 2009-07-13 20:33 - 00421128 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 07:33 - 2011-08-21 16:13 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-09 10:55 - 2012-08-09 10:55 - 05254656 ____A C:\Users\Adam\Downloads\converter.exe
2012-08-05 13:13 - 2009-07-13 20:53 - 00032638 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-03 13:52 - 2012-03-26 18:07 - 00111296 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-02 11:21 - 2011-05-11 21:02 - 00014294 ____A C:\Users\Adam\Desktop\chrome - Shortcut.lnk
2012-07-17 13:51 - 2012-04-02 18:55 - 00001784 ____A C:\Users\All Users\hpzinstall.log
2012-07-11 11:04 - 2006-11-02 02:23 - 00000275 ____A C:\Windows\win.ini
2012-07-02 21:20 - 2012-07-02 21:16 - 00000035 ___AH C:\Users\Adam\Downloads\.picasa.ini
2012-06-25 06:54 - 2012-06-25 06:54 - 10288512 ____A (Microsoft Corporation) C:\Users\Adam\Downloads\mseinstall.exe
2012-06-17 21:55 - 2012-06-17 21:55 - 02541793 ___AH C:\Users\Adam\Downloads\IMG_0525.MOV
2012-06-12 10:16 - 2012-06-12 10:16 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 18:40 - 2012-07-11 10:56 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
ZeroAccess:
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\@
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\U
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L\00000004.@
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L\201d3dde
ZeroAccess:
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\@
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 19%
Total physical RAM: 2038.18 MB
Available physical RAM: 1636.9 MB
Total Pagefile: 2038.18 MB
Available Pagefile: 1642.61 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
==================== Partitions ============================
1 Drive c: () (Fixed) (Total:142.68 GB) (Free:97.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Recovery) (Fixed) (Total:6.36 GB) (Free:0.87 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive f: () (Removable) (Total:14.92 GB) (Free:14.92 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 3072 KB
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 6509 MB 1024 KB
Partition 2 Primary 142 GB 6510 MB
Partition 3 Primary 10 MB 149 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Recovery NTFS Partition 6509 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 142 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-08-21 16:59
==================== End Of Log =============================
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) (x86) Version: 05-09-2012
Ran by SYSTEM at 06-09-2012 13:57:33
Running from F:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Adam\...\Run: [EPSON Stylus CX7800 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAFA.EXE /FU "C:\Windows\TEMP\E_S7C96.tmp" /EF "HKCU" [177664 2007-01-23] (SEIKO EPSON CORPORATION)
Winlogon\Notify\VESWinlogon: VESWinlogon.dll (Sony Corporation)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220 205.171.3.25
Startup: C:\Users\All Users\Start Menu\Programs\Startup\MRI_DISABLED ()
==================== Services ================================
2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
3 MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [57344 2006-10-04] (Sony Corporation)
2 MSSQL$VAIO_VEDB; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sVAIO_VEDB [29293408 2010-12-10] (Microsoft Corporation)
3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-10-04] (Sony Corporation)
3 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-10-04] (Sony Corporation)
3 SSScsiSV; C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [69632 2006-11-13] (Sony Corporation)
3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe" [73728 2006-09-21] (Sony Corporation)
2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392 2006-11-24] (Sony Corporation)
3 VAIOMediaPlatform-IntegratedServer-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe [2523136 2006-10-24] (Sony Corporation)
3 VAIOMediaPlatform-IntegratedServer-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [1089536 2006-10-11] (Sony Corporation)
3 VAIOMediaPlatform-UCLS-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [741376 2006-10-11] (Sony Corporation)
3 VAIOMediaPlatform-UCLS-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [1089536 2006-10-11] (Sony Corporation)
3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM [274432 2006-08-23] (Sony Corporation)
2 Viewpoint Manager Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [24652 2007-01-04] (Viewpoint Corporation)
2 VzCdbSvc; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" [172032 2006-09-26] (Sony Corporation)
2 VzFw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [135168 2006-09-26] (Sony Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
3 VAIOMediaPlatform-IntegratedServer-HTTP; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" [x]
3 VAIOMediaPlatform-Mobile-Gateway; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server" [x]
3 VAIOMediaPlatform-UCLS-HTTP; "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" [x]
==================== Drivers =================================
3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [6144 2007-01-09] (Chic)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [43872 2008-11-20] (Sonic Solutions)
3 R5U870FLx86; C:\Windows\System32\Drivers\R5U870FLx86.sys [72704 2006-11-28] (Ricoh)
3 R5U870FUx86; C:\Windows\System32\Drivers\R5U870FUx86.sys [43904 2006-11-28] (Ricoh)
4 SI3132; C:\Windows\system32\DRIVERS\SI3132.sys [74672 2006-11-20] (Silicon Image, Inc.)
0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17328 2006-11-20] (Silicon Image, Inc.)
0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12464 2006-11-20] (Silicon Image, Inc.)
3 SNC; C:\Windows\System32\Drivers\SonyNC.sys [27520 2006-11-06] (Sony Corporation)
3 SonyImgF; C:\Windows\System32\DRIVERS\SonyImgF.sys [30976 2006-11-08] (Sony Corporation)
3 ti21sony; C:\Windows\System32\drivers\ti21sony.sys [227328 2006-11-10] (Texas Instruments)
0 7ef8d626d959ac7d; C:\Windows\System32\Drivers\7ef8d626d959ac7d.sys [x]
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-09-06 13:57 - 2012-09-06 13:57 - 00000000 ____D C:\FRST
2012-09-06 11:43 - 2012-09-06 11:43 - 00007586 ____A C:\Users\Adam\Downloads\WinDefend.reg
2012-09-06 11:43 - 2012-09-06 11:42 - 00005256 ____A C:\Users\Adam\Downloads\wscsvc.reg
2012-09-06 11:18 - 2012-09-06 11:18 - 00176940 ____A C:\Users\Adam\Downloads\BFE.reg
2012-09-06 11:18 - 2012-09-06 11:18 - 00006396 ____A C:\Users\Adam\Downloads\MpsSvc.reg
2012-09-06 11:15 - 2012-09-06 11:15 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Adam\Downloads\tdsskiller.exe
2012-09-06 11:11 - 2012-09-06 11:12 - 00003193 ____A C:\Windows\WindowsUpdate.log
2012-09-06 11:10 - 2012-09-06 11:11 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-06 11:09 - 2012-08-28 19:10 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-09-06 11:09 - 2012-08-28 19:10 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-09-06 11:09 - 2012-08-28 19:09 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-09-06 11:01 - 2012-09-06 11:01 - 00000702 ____A C:\Windows\PFRO.log
2012-09-06 10:48 - 2012-09-06 10:48 - 00003304 ____N C:\bootsqm.dat
2012-08-26 12:48 - 2012-08-26 12:48 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.bak
2012-08-25 20:29 - 2012-09-06 11:34 - 00051706 ____A C:\Windows\setupact.log
2012-08-25 20:29 - 2012-08-25 20:29 - 00000000 ____A C:\Windows\setuperr.log
2012-08-25 19:26 - 2012-08-25 19:26 - 00282306 ____A C:\backup.reg
2012-08-25 17:50 - 2010-07-07 05:29 - 00363520 ____A C:\Users\Adam\Documents\rkill.exe
2012-08-25 16:00 - 2012-08-25 20:24 - 00000000 ____D C:\Users\Adam\Documents\a-squared Free
2012-08-25 16:00 - 2012-08-25 20:24 - 00000000 ____D C:\Program Files\a-squared Free
2012-08-24 07:19 - 2012-08-24 07:19 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-24 07:19 - 2012-08-24 07:19 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-22 15:22 - 2012-08-28 19:24 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-08-22 08:03 - 2012-08-22 08:03 - 00000000 ____D C:\Users\Adam\AppData\Local\{FDFD79AF-899A-D0B0-096B-A4A0E88FB9D2}
2012-08-21 14:04 - 2012-08-27 17:05 - 00000385 ____A C:\rkill.log
2012-08-20 14:39 - 2012-08-20 14:39 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-20 13:36 - 2012-08-20 13:36 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-08-20 13:35 - 2012-08-24 11:16 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-08-20 13:31 - 2012-08-20 13:31 - 00000000 ____D C:\Program Files\CCleaner
2012-08-20 13:02 - 2012-08-20 14:09 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-20 13:02 - 2012-08-20 13:02 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Malwarebytes
2012-08-20 13:01 - 2012-08-20 14:09 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-20 13:01 - 2012-08-20 13:01 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-18 13:58 - 2012-08-18 13:58 - 00000000 ____D C:\Users\All Users\Geek Squad
2012-08-16 06:51 - 2012-08-22 07:51 - 09826504 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-08-14 23:13 - 2012-08-14 23:15 - 00000000 ____D C:\Users\Adam\Documents\Lyrics
2012-08-09 10:57 - 2012-08-09 10:58 - 00000000 ___HD C:\Users\Adam\AppData\Local\CutePDF Writer
2012-08-09 10:55 - 2012-08-09 10:55 - 05254656 ____A C:\Users\Adam\Downloads\converter.exe
============ 3 Months Modified Files ========================
2012-09-06 12:38 - 2010-11-22 16:07 - 00808926 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-06 11:58 - 2010-11-22 16:04 - 00009728 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-06 11:58 - 2010-11-22 16:04 - 00009728 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-06 11:46 - 2009-12-21 16:14 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-06 11:44 - 2011-03-27 22:26 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2218131356-71786554-3709945380-1005UA.job
2012-09-06 11:43 - 2012-09-06 11:43 - 00007586 ____A C:\Users\Adam\Downloads\WinDefend.reg
2012-09-06 11:42 - 2012-09-06 11:43 - 00005256 ____A C:\Users\Adam\Downloads\wscsvc.reg
2012-09-06 11:35 - 2009-12-21 16:14 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-06 11:34 - 2012-08-25 20:29 - 00051706 ____A C:\Windows\setupact.log
2012-09-06 11:34 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-06 11:18 - 2012-09-06 11:18 - 00176940 ____A C:\Users\Adam\Downloads\BFE.reg
2012-09-06 11:18 - 2012-09-06 11:18 - 00006396 ____A C:\Users\Adam\Downloads\MpsSvc.reg
2012-09-06 11:15 - 2012-09-06 11:15 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Adam\Downloads\tdsskiller.exe
2012-09-06 11:12 - 2012-09-06 11:11 - 00003193 ____A C:\Windows\WindowsUpdate.log
2012-09-06 11:11 - 2012-06-25 06:58 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-06 11:01 - 2012-09-06 11:01 - 00000702 ____A C:\Windows\PFRO.log
2012-09-06 10:48 - 2012-09-06 10:48 - 00003304 ____N C:\bootsqm.dat
2012-08-28 19:24 - 2012-08-22 15:22 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
2012-08-28 19:24 - 2010-06-12 08:23 - 00473072 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-08-28 19:10 - 2012-09-06 11:09 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-08-28 19:10 - 2012-09-06 11:09 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-08-28 19:09 - 2012-09-06 11:09 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-08-27 17:05 - 2012-08-21 14:04 - 00000385 ____A C:\rkill.log
2012-08-26 12:48 - 2012-08-26 12:48 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.bak
2012-08-26 12:46 - 2009-03-26 10:42 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job
2012-08-25 20:29 - 2012-08-25 20:29 - 00000000 ____A C:\Windows\setuperr.log
2012-08-25 19:26 - 2012-08-25 19:26 - 00282306 ____A C:\backup.reg
2012-08-25 17:43 - 2009-07-13 18:04 - 00002577 ____A C:\Windows\System32\config.nt
2012-08-24 07:19 - 2012-08-24 07:19 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-24 07:19 - 2012-08-24 07:19 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-23 16:36 - 2011-03-27 22:26 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2218131356-71786554-3709945380-1005Core.job
2012-08-22 07:51 - 2012-08-16 06:51 - 09826504 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-08-20 14:09 - 2012-08-20 13:02 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-18 20:17 - 2009-07-13 20:33 - 00421128 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 07:33 - 2011-08-21 16:13 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-09 10:55 - 2012-08-09 10:55 - 05254656 ____A C:\Users\Adam\Downloads\converter.exe
2012-08-05 13:13 - 2009-07-13 20:53 - 00032638 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-03 13:52 - 2012-03-26 18:07 - 00111296 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-02 11:21 - 2011-05-11 21:02 - 00014294 ____A C:\Users\Adam\Desktop\chrome - Shortcut.lnk
2012-07-17 13:51 - 2012-04-02 18:55 - 00001784 ____A C:\Users\All Users\hpzinstall.log
2012-07-11 11:04 - 2006-11-02 02:23 - 00000275 ____A C:\Windows\win.ini
2012-07-02 21:20 - 2012-07-02 21:16 - 00000035 ___AH C:\Users\Adam\Downloads\.picasa.ini
2012-06-25 06:54 - 2012-06-25 06:54 - 10288512 ____A (Microsoft Corporation) C:\Users\Adam\Downloads\mseinstall.exe
2012-06-17 21:55 - 2012-06-17 21:55 - 02541793 ___AH C:\Users\Adam\Downloads\IMG_0525.MOV
2012-06-12 10:16 - 2012-06-12 10:16 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 18:40 - 2012-07-11 10:56 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
ZeroAccess:
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\@
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\U
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L\00000004.@
C:\Windows\Installer\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L\201d3dde
ZeroAccess:
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\@
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\L
C:\Users\Adam\AppData\Local\{ee472909-d0be-7134-7b4e-ff34111e9ebc}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 19%
Total physical RAM: 2038.18 MB
Available physical RAM: 1636.9 MB
Total Pagefile: 2038.18 MB
Available Pagefile: 1642.61 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
==================== Partitions ============================
1 Drive c: () (Fixed) (Total:142.68 GB) (Free:97.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Recovery) (Fixed) (Total:6.36 GB) (Free:0.87 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive f: () (Removable) (Total:14.92 GB) (Free:14.92 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 3072 KB
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 6509 MB 1024 KB
Partition 2 Primary 142 GB 6510 MB
Partition 3 Primary 10 MB 149 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Recovery NTFS Partition 6509 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 142 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-08-21 16:59
==================== End Of Log =============================