Iván Campos
Posts: 23 +0
Hi there! Let me introduce myself with a help claim. My win7 has infected by sirefef.r & sirefef.ah, and I can't clean because the file services.exe seems to be the one has been infected.
Like I could read in other posts, ran the FRST.exe downloaded with a clean pc in restore mode. This is the log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-10-2012
Ran by SYSTEM at 14-10-2012 17:07:07
Running from H:\
Windows 7 Professional Service Pack 1 (X86) OS Language: Spanish Modern Sort
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [M-Audio Taskbar Icon] C:\Windows\system32\DeltaIITray.exe [237872 2012-01-25] ()
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [] [x]
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36800 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [823224 2012-07-27] (Adobe Systems Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [947176 2012-09-12] (Microsoft Corporation)
HKU\Pikis\...\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe" -automount [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\Pikis\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [x]
HKU\Pikis\...\Run: [Google Update] "C:\Users\Pikis\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-20] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
==================== Services (Whitelisted) ===================
2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [20472 2012-09-12] (Microsoft Corporation)
4 msvsmon90; "C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon90 [3201024 2008-07-29] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [287824 2012-09-12] (Microsoft Corporation)
2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
==================== Drivers (Whitelisted) ====================
3 DELTAII; C:\Windows\System32\DRIVERS\MAudioDelta.sys [306096 2012-01-25] (Avid Technology, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [193552 2012-08-30] (Microsoft Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2012-07-22] (Duplex Secure Ltd.)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-10-14 17:06 - 2012-10-14 17:06 - 00000000 ____D C:\FRST
2012-10-14 15:50 - 2012-10-14 15:50 - 00000000 ____D C:\Users\Pikis\AppData\Roaming\QuickScan
2012-10-14 10:35 - 2012-10-14 10:35 - 16985648 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\Windows-KB890830-V4.13.exe
2012-10-14 10:16 - 2012-10-14 10:16 - 00347424 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\MicrosoftFixit.wu.RNP.2227363698113788.1.1.Run.exe
2012-10-14 09:53 - 2012-10-14 09:53 - 11101672 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\mseinstall.exe
2012-10-07 19:13 - 2012-10-07 19:14 - 00000200 ____A C:\Users\Pikis\.pilar
2012-10-07 19:13 - 2012-10-07 19:13 - 00000000 ____D C:\Program Files\PILAR_5.2
2012-09-28 11:06 - 2012-09-28 11:52 - 00001543 ____A C:\Users\Pikis\Desktop\SP Panel de Gestión.lnk
2012-09-28 11:05 - 2012-09-28 11:51 - 00000000 ____D C:\GrupoSP
2012-09-28 09:24 - 2012-09-28 09:24 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc3A0C.tmp
2012-09-28 09:03 - 2012-09-28 09:03 - 00000103 ____A C:\Users\Public\sdelevURL.tmp
2012-09-28 08:58 - 2012-09-28 08:58 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc1C52.tmp
2012-09-28 08:53 - 2012-09-28 08:53 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcEFAD.tmp
2012-09-28 08:49 - 2012-09-28 08:49 - 00000000 ____D C:\Users\All Users\Sage
2012-09-28 08:45 - 2012-09-28 08:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc43EA.tmp
2012-09-28 08:33 - 2012-09-28 08:33 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc6A7.tmp
2012-09-27 16:45 - 2012-09-27 16:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcB31A.tmp
2012-09-27 16:14 - 2012-09-27 16:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5A24.tmp
2012-09-27 16:02 - 2012-09-27 16:02 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5EAE.tmp
2012-09-27 15:56 - 2012-09-27 15:56 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc566E.tmp
2012-09-27 10:31 - 2012-10-10 19:50 - 00000000 ____D C:\Ejercicios Facturaplus
2012-09-27 10:05 - 2012-09-27 10:05 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc8FF6.tmp
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Upca.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Code39.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\c128btt.fot
2012-09-26 09:15 - 2012-09-26 09:15 - 00000000 ____D C:\Program Files\MSXML 4.0
2012-09-26 09:14 - 2012-09-26 09:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc53DE.tmp
2012-09-26 09:14 - 2011-10-06 12:51 - 04833792 ____A (Amyuni Technologies
2012-09-26 09:12 - 2011-10-06 12:50 - 00024496 ____A C:\Windows\c128btt.ttf
2012-09-26 09:12 - 2011-10-06 12:50 - 00017056 ____A C:\Windows\Upca.ttf
2012-09-26 09:12 - 2011-10-06 12:50 - 00007280 ____A C:\Windows\Code39.ttf
2012-09-23 08:13 - 2012-09-23 08:13 - 00000693 ____A C:\Users\Pikis\Desktop\Reorganizar - Acceso directo.lnk
2012-09-16 19:54 - 2012-09-16 19:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl_01009.Wdf
==================== 3 Months Modified Files ==================
2012-10-14 15:57 - 2012-09-09 20:23 - 00003641 ____A C:\Windows\setupact.log
2012-10-14 15:57 - 2012-04-06 22:33 - 00001082 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-10-14 15:57 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-14 15:52 - 2012-08-20 09:42 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2186753102-28003779-2570860475-1000UA.job
2012-10-14 15:48 - 2012-04-06 22:33 - 00001086 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-10-14 15:45 - 2012-09-09 20:35 - 00760551 ____A C:\Windows\WindowsUpdate.log
2012-10-14 15:45 - 2012-04-06 22:08 - 00000838 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-10-14 10:38 - 2009-07-14 05:34 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-10-14 10:38 - 2009-07-14 05:34 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-10-14 10:35 - 2012-10-14 10:35 - 16985648 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\Windows-KB890830-V4.13.exe
2012-10-14 10:16 - 2012-10-14 10:16 - 00347424 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\MicrosoftFixit.wu.RNP.2227363698113788.1.1.Run.exe
2012-10-14 09:55 - 2012-03-21 23:03 - 00001912 ____A C:\Windows\epplauncher.mif
2012-10-14 09:53 - 2012-10-14 09:53 - 11101672 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\mseinstall.exe
2012-10-10 20:45 - 2012-04-06 22:08 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-10-10 20:45 - 2012-03-21 23:40 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-10-10 19:52 - 2012-08-20 09:42 - 00001058 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2186753102-28003779-2570860475-1000Core.job
2012-10-07 19:14 - 2012-10-07 19:13 - 00000200 ____A C:\Users\Pikis\.pilar
2012-09-28 11:52 - 2012-09-28 11:06 - 00001543 ____A C:\Users\Pikis\Desktop\SP Panel de Gestión.lnk
2012-09-28 09:24 - 2012-09-28 09:24 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc3A0C.tmp
2012-09-28 09:03 - 2012-09-28 09:03 - 00000103 ____A C:\Users\Public\sdelevURL.tmp
2012-09-28 08:58 - 2012-09-28 08:58 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc1C52.tmp
2012-09-28 08:53 - 2012-09-28 08:53 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcEFAD.tmp
2012-09-28 08:45 - 2012-09-28 08:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc43EA.tmp
2012-09-28 08:33 - 2012-09-28 08:33 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc6A7.tmp
2012-09-27 23:32 - 2012-03-22 00:29 - 62968832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-09-27 16:45 - 2012-09-27 16:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcB31A.tmp
2012-09-27 16:14 - 2012-09-27 16:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5A24.tmp
2012-09-27 16:02 - 2012-09-27 16:02 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5EAE.tmp
2012-09-27 15:56 - 2012-09-27 15:56 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc566E.tmp
2012-09-27 10:05 - 2012-09-27 10:05 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc8FF6.tmp
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Upca.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Code39.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\c128btt.fot
2012-09-26 09:14 - 2012-09-26 09:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc53DE.tmp
2012-09-24 08:27 - 2010-11-20 22:01 - 00005244 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-23 08:13 - 2012-09-23 08:13 - 00000693 ____A C:\Users\Pikis\Desktop\Reorganizar - Acceso directo.lnk
2012-09-16 19:54 - 2012-09-16 19:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl_01009.Wdf
2012-09-11 17:45 - 2012-09-11 17:45 - 00000602 ____A C:\Windows\PFRO.log
2012-09-09 20:36 - 2012-09-09 20:36 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-09-09 20:23 - 2012-09-09 20:23 - 00000000 ____A C:\Windows\setuperr.log
2012-09-05 20:52 - 2012-09-05 20:52 - 00007602 ____A C:\Users\Pikis\AppData\Local\Resmon.ResmonCfg
2012-09-03 19:23 - 2009-07-14 05:53 - 00032518 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-30 21:03 - 2012-08-30 21:03 - 00193552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 21:03 - 2011-04-27 15:25 - 00099272 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-21 12:01 - 2012-09-13 22:07 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-08-21 12:01 - 2012-03-24 13:03 - 00106928 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi.dll
2012-08-06 14:32 - 2012-08-06 14:32 - 00000000 ___AH C:\Users\Pikis\Documents\Default.rdp
2012-07-22 18:29 - 2012-07-22 18:29 - 00406528 ____A (Propellerhead Software AB) C:\Windows\System32\ReWire.dll
2012-07-22 18:29 - 2012-07-22 18:29 - 00338432 ____A (Propellerhead Software AB) C:\Windows\System32\REX Shared Library.dll
2012-07-22 18:18 - 2012-07-22 18:18 - 00000322 ____A C:\Users\Pikis\Documents\ax_files.xml
2012-07-22 18:13 - 2012-07-22 09:26 - 00477240 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
ZeroAccess:
C:\Windows\Installer\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}
C:\Windows\Installer\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\L
C:\Windows\Installer\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\U
ZeroAccess:
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\@
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\L
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 16%
Total physical RAM: 2942.3 MB
Available physical RAM: 2467.1 MB
Total Pagefile: 2938.54 MB
Available Pagefile: 2468.25 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.28 MB
==================== Partitions =============================
2 Drive c: (Win7) (Fixed) (Total:39.06 GB) (Free:1.07 GB) NTFS
3 Drive e: (Datos) (Fixed) (Total:107.81 GB) (Free:32.79 GB) NTFS
6 Drive h: (VIDEOS) (Removable) (Total:7.84 GB) (Free:1.95 GB) FAT32
7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
8 Drive y: (WinXP) (Fixed) (Total:19.53 GB) (Free:7.33 GB) NTFS ==>[System with boot components (obtained from reading drive)]
N£m Disco Estado Tama¤o Disp Din Gpt
---------- ---------- ------- ------- --- ---
Disco 0 En l¡nea 186 GB 19 GB
Disco 1 En l¡nea 8044 MB 0 B
Partitions of Disk 0:
===============
N£m Partici¢n Tipo Tama¤o Desplazamiento
------------- ---------------- ------- ---------------
Partici¢n 1 Principal 19 GB 31 KB
Partici¢n 2 Principal 39 GB 19 GB
Partici¢n 3 Principal 107 GB 58 GB
=========================================================
Disk: 0
Partici¢n 1
Tipo : 07
Oculta : No
Activa : S¡
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 2 Y WinXP NTFS Partici¢n 19 GB Correcto
=========================================================
Disk: 0
Partici¢n 2
Tipo : 07
Oculta : No
Activa : No
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 3 C Win7 NTFS Partici¢n 39 GB Correcto
=========================================================
Disk: 0
Partici¢n 3
Tipo : 07
Oculta : No
Activa : No
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 4 E Datos NTFS Partici¢n 107 GB Correcto
=========================================================
Partitions of Disk 1:
===============
N£m Partici¢n Tipo Tama¤o Desplazamiento
------------- ---------------- ------- ---------------
Partici¢n 1 Principal 8043 MB 31 KB
=========================================================
Disk: 1
Partici¢n 1
Tipo : 0C
Oculta : No
Activa : S¡
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 5 H VIDEOS FAT32 Extra¡ble 8043 MB Correcto
=========================================================
Last Boot: 2012-10-07 09:42
==================== End Of Log ============================
At this point, I wish some of you can help me.
Thanks for all indeed!
Like I could read in other posts, ran the FRST.exe downloaded with a clean pc in restore mode. This is the log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-10-2012
Ran by SYSTEM at 14-10-2012 17:07:07
Running from H:\
Windows 7 Professional Service Pack 1 (X86) OS Language: Spanish Modern Sort
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [M-Audio Taskbar Icon] C:\Windows\system32\DeltaIITray.exe [237872 2012-01-25] ()
HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2010-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [] [x]
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36800 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [823224 2012-07-27] (Adobe Systems Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [947176 2012-09-12] (Microsoft Corporation)
HKU\Pikis\...\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe" -automount [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\Pikis\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [x]
HKU\Pikis\...\Run: [Google Update] "C:\Users\Pikis\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-20] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
==================== Services (Whitelisted) ===================
2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [20472 2012-09-12] (Microsoft Corporation)
4 msvsmon90; "C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon90 [3201024 2008-07-29] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [287824 2012-09-12] (Microsoft Corporation)
2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
==================== Drivers (Whitelisted) ====================
3 DELTAII; C:\Windows\System32\DRIVERS\MAudioDelta.sys [306096 2012-01-25] (Avid Technology, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [193552 2012-08-30] (Microsoft Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2012-07-22] (Duplex Secure Ltd.)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-10-14 17:06 - 2012-10-14 17:06 - 00000000 ____D C:\FRST
2012-10-14 15:50 - 2012-10-14 15:50 - 00000000 ____D C:\Users\Pikis\AppData\Roaming\QuickScan
2012-10-14 10:35 - 2012-10-14 10:35 - 16985648 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\Windows-KB890830-V4.13.exe
2012-10-14 10:16 - 2012-10-14 10:16 - 00347424 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\MicrosoftFixit.wu.RNP.2227363698113788.1.1.Run.exe
2012-10-14 09:53 - 2012-10-14 09:53 - 11101672 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\mseinstall.exe
2012-10-07 19:13 - 2012-10-07 19:14 - 00000200 ____A C:\Users\Pikis\.pilar
2012-10-07 19:13 - 2012-10-07 19:13 - 00000000 ____D C:\Program Files\PILAR_5.2
2012-09-28 11:06 - 2012-09-28 11:52 - 00001543 ____A C:\Users\Pikis\Desktop\SP Panel de Gestión.lnk
2012-09-28 11:05 - 2012-09-28 11:51 - 00000000 ____D C:\GrupoSP
2012-09-28 09:24 - 2012-09-28 09:24 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc3A0C.tmp
2012-09-28 09:03 - 2012-09-28 09:03 - 00000103 ____A C:\Users\Public\sdelevURL.tmp
2012-09-28 08:58 - 2012-09-28 08:58 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc1C52.tmp
2012-09-28 08:53 - 2012-09-28 08:53 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcEFAD.tmp
2012-09-28 08:49 - 2012-09-28 08:49 - 00000000 ____D C:\Users\All Users\Sage
2012-09-28 08:45 - 2012-09-28 08:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc43EA.tmp
2012-09-28 08:33 - 2012-09-28 08:33 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc6A7.tmp
2012-09-27 16:45 - 2012-09-27 16:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcB31A.tmp
2012-09-27 16:14 - 2012-09-27 16:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5A24.tmp
2012-09-27 16:02 - 2012-09-27 16:02 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5EAE.tmp
2012-09-27 15:56 - 2012-09-27 15:56 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc566E.tmp
2012-09-27 10:31 - 2012-10-10 19:50 - 00000000 ____D C:\Ejercicios Facturaplus
2012-09-27 10:05 - 2012-09-27 10:05 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc8FF6.tmp
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Upca.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Code39.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\c128btt.fot
2012-09-26 09:15 - 2012-09-26 09:15 - 00000000 ____D C:\Program Files\MSXML 4.0
2012-09-26 09:14 - 2012-09-26 09:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc53DE.tmp
2012-09-26 09:14 - 2011-10-06 12:51 - 04833792 ____A (Amyuni Technologies
2012-09-26 09:12 - 2011-10-06 12:50 - 00024496 ____A C:\Windows\c128btt.ttf
2012-09-26 09:12 - 2011-10-06 12:50 - 00017056 ____A C:\Windows\Upca.ttf
2012-09-26 09:12 - 2011-10-06 12:50 - 00007280 ____A C:\Windows\Code39.ttf
2012-09-23 08:13 - 2012-09-23 08:13 - 00000693 ____A C:\Users\Pikis\Desktop\Reorganizar - Acceso directo.lnk
2012-09-16 19:54 - 2012-09-16 19:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl_01009.Wdf
==================== 3 Months Modified Files ==================
2012-10-14 15:57 - 2012-09-09 20:23 - 00003641 ____A C:\Windows\setupact.log
2012-10-14 15:57 - 2012-04-06 22:33 - 00001082 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-10-14 15:57 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-14 15:52 - 2012-08-20 09:42 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2186753102-28003779-2570860475-1000UA.job
2012-10-14 15:48 - 2012-04-06 22:33 - 00001086 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-10-14 15:45 - 2012-09-09 20:35 - 00760551 ____A C:\Windows\WindowsUpdate.log
2012-10-14 15:45 - 2012-04-06 22:08 - 00000838 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-10-14 10:38 - 2009-07-14 05:34 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-10-14 10:38 - 2009-07-14 05:34 - 00022032 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-10-14 10:35 - 2012-10-14 10:35 - 16985648 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\Windows-KB890830-V4.13.exe
2012-10-14 10:16 - 2012-10-14 10:16 - 00347424 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\MicrosoftFixit.wu.RNP.2227363698113788.1.1.Run.exe
2012-10-14 09:55 - 2012-03-21 23:03 - 00001912 ____A C:\Windows\epplauncher.mif
2012-10-14 09:53 - 2012-10-14 09:53 - 11101672 ____A (Microsoft Corporation) C:\Users\Pikis\Downloads\mseinstall.exe
2012-10-10 20:45 - 2012-04-06 22:08 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-10-10 20:45 - 2012-03-21 23:40 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-10-10 19:52 - 2012-08-20 09:42 - 00001058 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2186753102-28003779-2570860475-1000Core.job
2012-10-07 19:14 - 2012-10-07 19:13 - 00000200 ____A C:\Users\Pikis\.pilar
2012-09-28 11:52 - 2012-09-28 11:06 - 00001543 ____A C:\Users\Pikis\Desktop\SP Panel de Gestión.lnk
2012-09-28 09:24 - 2012-09-28 09:24 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc3A0C.tmp
2012-09-28 09:03 - 2012-09-28 09:03 - 00000103 ____A C:\Users\Public\sdelevURL.tmp
2012-09-28 08:58 - 2012-09-28 08:58 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc1C52.tmp
2012-09-28 08:53 - 2012-09-28 08:53 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcEFAD.tmp
2012-09-28 08:45 - 2012-09-28 08:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc43EA.tmp
2012-09-28 08:33 - 2012-09-28 08:33 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc6A7.tmp
2012-09-27 23:32 - 2012-03-22 00:29 - 62968832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-09-27 16:45 - 2012-09-27 16:45 - 00000000 ____N C:\Users\Pikis\AppData\Local\slcB31A.tmp
2012-09-27 16:14 - 2012-09-27 16:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5A24.tmp
2012-09-27 16:02 - 2012-09-27 16:02 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc5EAE.tmp
2012-09-27 15:56 - 2012-09-27 15:56 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc566E.tmp
2012-09-27 10:05 - 2012-09-27 10:05 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc8FF6.tmp
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Upca.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\Code39.fot
2012-09-26 09:17 - 2012-09-26 09:17 - 00001409 ____A C:\Windows\c128btt.fot
2012-09-26 09:14 - 2012-09-26 09:14 - 00000000 ____N C:\Users\Pikis\AppData\Local\slc53DE.tmp
2012-09-24 08:27 - 2010-11-20 22:01 - 00005244 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-23 08:13 - 2012-09-23 08:13 - 00000693 ____A C:\Users\Pikis\Desktop\Reorganizar - Acceso directo.lnk
2012-09-16 19:54 - 2012-09-16 19:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl_01009.Wdf
2012-09-11 17:45 - 2012-09-11 17:45 - 00000602 ____A C:\Windows\PFRO.log
2012-09-09 20:36 - 2012-09-09 20:36 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-09-09 20:23 - 2012-09-09 20:23 - 00000000 ____A C:\Windows\setuperr.log
2012-09-05 20:52 - 2012-09-05 20:52 - 00007602 ____A C:\Users\Pikis\AppData\Local\Resmon.ResmonCfg
2012-09-03 19:23 - 2009-07-14 05:53 - 00032518 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-30 21:03 - 2012-08-30 21:03 - 00193552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 21:03 - 2011-04-27 15:25 - 00099272 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-21 12:01 - 2012-09-13 22:07 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-08-21 12:01 - 2012-03-24 13:03 - 00106928 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi.dll
2012-08-06 14:32 - 2012-08-06 14:32 - 00000000 ___AH C:\Users\Pikis\Documents\Default.rdp
2012-07-22 18:29 - 2012-07-22 18:29 - 00406528 ____A (Propellerhead Software AB) C:\Windows\System32\ReWire.dll
2012-07-22 18:29 - 2012-07-22 18:29 - 00338432 ____A (Propellerhead Software AB) C:\Windows\System32\REX Shared Library.dll
2012-07-22 18:18 - 2012-07-22 18:18 - 00000322 ____A C:\Users\Pikis\Documents\ax_files.xml
2012-07-22 18:13 - 2012-07-22 09:26 - 00477240 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
ZeroAccess:
C:\Windows\Installer\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}
C:\Windows\Installer\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\L
C:\Windows\Installer\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\U
ZeroAccess:
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\@
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\L
C:\Users\Pikis\AppData\Local\{9d1431b4-0fd4-78b1-095e-f2e3b8f6f85a}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 16%
Total physical RAM: 2942.3 MB
Available physical RAM: 2467.1 MB
Total Pagefile: 2938.54 MB
Available Pagefile: 2468.25 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.28 MB
==================== Partitions =============================
2 Drive c: (Win7) (Fixed) (Total:39.06 GB) (Free:1.07 GB) NTFS
3 Drive e: (Datos) (Fixed) (Total:107.81 GB) (Free:32.79 GB) NTFS
6 Drive h: (VIDEOS) (Removable) (Total:7.84 GB) (Free:1.95 GB) FAT32
7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
8 Drive y: (WinXP) (Fixed) (Total:19.53 GB) (Free:7.33 GB) NTFS ==>[System with boot components (obtained from reading drive)]
N£m Disco Estado Tama¤o Disp Din Gpt
---------- ---------- ------- ------- --- ---
Disco 0 En l¡nea 186 GB 19 GB
Disco 1 En l¡nea 8044 MB 0 B
Partitions of Disk 0:
===============
N£m Partici¢n Tipo Tama¤o Desplazamiento
------------- ---------------- ------- ---------------
Partici¢n 1 Principal 19 GB 31 KB
Partici¢n 2 Principal 39 GB 19 GB
Partici¢n 3 Principal 107 GB 58 GB
=========================================================
Disk: 0
Partici¢n 1
Tipo : 07
Oculta : No
Activa : S¡
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 2 Y WinXP NTFS Partici¢n 19 GB Correcto
=========================================================
Disk: 0
Partici¢n 2
Tipo : 07
Oculta : No
Activa : No
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 3 C Win7 NTFS Partici¢n 39 GB Correcto
=========================================================
Disk: 0
Partici¢n 3
Tipo : 07
Oculta : No
Activa : No
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 4 E Datos NTFS Partici¢n 107 GB Correcto
=========================================================
Partitions of Disk 1:
===============
N£m Partici¢n Tipo Tama¤o Desplazamiento
------------- ---------------- ------- ---------------
Partici¢n 1 Principal 8043 MB 31 KB
=========================================================
Disk: 1
Partici¢n 1
Tipo : 0C
Oculta : No
Activa : S¡
N£m Volumen Ltr Etiqueta Fs Tipo Tama¤o Estado Info
----------- --- ----------- ----- ---------- ------- --------- --------
* Volumen 5 H VIDEOS FAT32 Extra¡ble 8043 MB Correcto
=========================================================
Last Boot: 2012-10-07 09:42
==================== End Of Log ============================
At this point, I wish some of you can help me.
Thanks for all indeed!