Scan result of Farbar Recovery Scan Tool Version: 05-08-2012 03
Ran by SYSTEM at 06-08-2012 09:50:34
Running from G:\techtools
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [912688 2008-09-23] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-21] (IDT, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM-x32\...\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [1148200 2008-09-26] (CyberLink Corp.)
HKLM-x32\...\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [1152296 2008-09-25] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [189736 2008-09-25] (CyberLink)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x]
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x]
HKU\Owner\...\Run: [LightScribe Control Panel] "C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\Owner\...\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [x]
HKU\Owner\...\Run: [Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun [1555968 2009-04-10] (Microsoft Corporation)
HKU\Owner\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5244216 2009-11-10] (Yahoo! Inc.)
HKU\Owner\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Owner\...\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKU\Owner\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5661056 2012-07-09] (SUPERAntiSpyware.com)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
==================== Services (Whitelisted) ======
4 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com)
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
4 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365904 2008-09-23] ()
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [241734 2008-06-29] ()
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe [240128 2009-07-21] (IDT, Inc.)
4 WebrootSpySweeperService; "C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe" [4048240 2009-04-02] (Webroot Software, Inc. (
www.webroot.com))
4 Norton Internet Security; "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1 [x]
3 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]
========================== Drivers (Whitelisted) =============
3 PTDUBus; C:\Windows\System32\Drivers\PTDUBus.sys [70672 2009-08-12] (DEVGURU Co., LTD.)
3 PTDUMdm; C:\Windows\System32\Drivers\PTDUMdm.sys [173456 2009-08-12] (DEVGURU Co., LTD.(
www.devguru.co.kr))
3 PTDUVsp; C:\Windows\System32\Drivers\PTDUVsp.sys [173456 2009-08-12] (DEVGURU Co., LTD.(
www.devguru.co.kr))
3 PTDUWFLT; C:\Windows\System32\Drivers\PTDUWFLT.sys [12688 2009-08-12] (DEVGURU Co., LTD.)
3 PTDUWWAN; C:\Windows\System32\Drivers\PTDUWWAN.sys [141840 2009-08-12] (DEVGURU Co., LTD.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
0 ssfs0bbc; C:\Windows\System32\Drivers\ssfs0bbc.sys [37488 2009-04-02] (Webroot Software, Inc. (
www.webroot.com))
0 ssidrv; C:\Windows\System32\Drivers\ssidrv.sys [135280 2009-04-02] (Webroot Software, Inc. (
www.webroot.com))
2 {55662437-DA8C-40c0-AADA-2C816A897A49}; \??\C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [27632 2008-09-26] (Cyberlink Corp.)
1 Beep; [x]
3 catchme; \??\C:\1ombox\catchme.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\ENG64.SYS [x]
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\EX64.SYS [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
1 SRTSP; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSP64.SYS [x]
1 SRTSPX; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSPX64.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 08:47 - 2012-08-06 08:47 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jotnbxmr.sys
2012-08-06 08:43 - 2012-08-06 08:43 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9F726B9816858747
2012-08-06 08:34 - 2012-08-06 08:34 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B99976C11C08FFC
2012-08-06 08:30 - 2012-08-06 08:30 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC119F2587F25F3E
2012-08-06 07:53 - 2012-08-06 07:53 - 00000000 ____D C:\Users\Owner\Application Data\SUPERAntiSpyware.com
2012-08-06 07:53 - 2012-08-06 07:53 - 00000000 ____D C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com
2012-08-06 07:52 - 2012-08-06 08:45 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-06 07:52 - 2012-08-06 08:21 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-06 07:52 - 2012-08-06 07:53 - 00000000 ____D C:\Program Files (x86)\Google
2012-08-06 07:52 - 2012-08-06 07:52 - 00001655 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-08-06 07:52 - 2012-08-06 07:52 - 00001655 ____A C:\Users\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-08-06 07:52 - 2012-08-06 07:52 - 00000000 ____D C:\Users\Owner\Local Settings\Google
2012-08-06 07:52 - 2012-08-06 07:52 - 00000000 ____D C:\Users\Owner\Local Settings\Application Data\Google
2012-08-06 07:52 - 2012-08-06 07:52 - 00000000 ____D C:\Users\Owner\AppData\Local\Google
2012-08-06 07:52 - 2012-08-06 07:52 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-08-06 07:52 - 2012-08-06 07:52 - 00000000 ____D C:\Users\All Users\Application Data\SUPERAntiSpyware.com
2012-08-06 07:52 - 2012-08-06 07:52 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-08-06 07:40 - 2012-08-06 07:40 - 00000000 ____D C:\Users\All Users\SUPERSetup
2012-08-06 07:40 - 2012-08-06 07:40 - 00000000 ____D C:\Users\All Users\Application Data\SUPERSetup
2012-08-06 07:40 - 2012-08-06 07:12 - 18976248 ____A (SUPERAntiSpyware.com) C:\Users\Owner\Desktop\SAS_939C88.EXE
2012-08-06 06:24 - 2012-08-06 06:59 - 00000000 ____D C:\1ombox
2012-08-06 06:03 - 2012-08-06 06:25 - 00000000 ____D C:\Users\Owner\Desktop\sirefef removal
2012-08-06 05:53 - 2012-08-06 07:40 - 00001016 ____A C:\Users\Owner\Desktop\Rkill.txt
2012-08-06 05:53 - 2012-08-06 05:53 - 00000000 ____D C:\Users\Owner\Desktop\rkill-backup
2012-08-06 01:40 - 2012-08-06 01:41 - 00000000 ____D C:\FRST
2012-08-06 00:09 - 2012-08-06 00:09 - 00014986 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.09.01.txt
2012-08-06 00:05 - 2012-08-06 00:06 - 00015310 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.05.08.txt
2012-08-06 00:04 - 2012-08-06 00:05 - 00006788 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.04.48.txt
2012-08-06 00:03 - 2012-08-06 00:04 - 00016072 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.03.21.txt
2012-08-05 23:56 - 2012-08-05 23:56 - 00000000 ____D C:\Users\Owner\Desktop\Samples
2012-08-05 23:42 - 2012-08-05 23:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-05 23:09 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-08-05 23:09 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-08-05 23:09 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-08-05 23:09 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-08-05 23:09 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-08-05 23:09 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-08-05 23:09 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-08-05 23:09 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-08-05 23:03 - 2012-08-06 08:22 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-08-05 23:03 - 2012-08-06 08:22 - 00000000 ____D C:\Users\All Users\Desktop\CC Support
2012-08-05 23:03 - 2012-08-05 23:03 - 04009167 ____A C:\Users\Owner\Downloads\ServicesRepair.exe
2012-08-05 23:02 - 2012-08-05 23:02 - 02030547 ____A C:\Users\Owner\Downloads\EZ_Sirefix.exe
2012-08-05 23:02 - 2012-08-05 23:02 - 00138120 ____A (ESET) C:\Users\Owner\Downloads\ESETSirefefRemover.exe
2012-08-05 23:00 - 2012-08-05 23:07 - 00065015 ____A C:\Users\Owner\Downloads\yorkyt.exe.log
2012-08-05 22:59 - 2012-08-05 23:00 - 01415784 ____A C:\Users\Owner\Downloads\yorkyt.exe
2012-08-05 22:32 - 2012-08-05 21:18 - 04725168 ____R (Swearware) C:\Users\Owner\Desktop\1ombox.com
2012-08-05 21:45 - 2012-08-05 22:03 - 00000000 ____D C:\Users\Owner\Application Data\vlc
2012-08-05 21:45 - 2012-08-05 22:03 - 00000000 ____D C:\Users\Owner\AppData\Roaming\vlc
2012-08-05 21:44 - 2012-08-05 21:44 - 00000861 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-08-05 21:44 - 2012-08-05 21:44 - 00000861 ____A C:\Users\All Users\Desktop\VLC media player.lnk
2012-08-05 21:43 - 2012-08-05 21:43 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2012-08-05 21:42 - 2012-08-05 21:43 - 00000000 ____D C:\Users\Owner\Desktop\August 4th show for the zoo
2012-08-05 21:41 - 2012-08-05 21:42 - 22617148 ____A C:\Users\Owner\Downloads\vlc-2.0.3-win32.exe
2012-08-05 21:32 - 2012-08-05 21:32 - 00000000 ____D C:\Users\Public\CyberLink
2012-08-05 20:51 - 2012-08-05 20:53 - 12621696 ____A (Microsoft Corporation) C:\Users\Owner\Downloads\mseinstall.exe
2012-08-05 20:31 - 2012-08-05 20:38 - 00015345 ____A C:\Users\Owner\Desktop\MBRCheck_08.05.12_21.31.22.txt
2012-08-05 20:25 - 2012-08-06 06:56 - 00000000 ____D C:\Windows\erdnt
2012-08-05 20:25 - 2012-08-05 23:09 - 00000000 ____D C:\Qoobox
2012-08-05 20:25 - 2012-08-05 20:25 - 04725168 ____R (Swearware) C:\Users\Owner\Downloads\z123ComboFix.com
2012-08-05 20:04 - 2012-08-05 21:24 - 00000734 ____A C:\Windows\System32\Drivers\etc\hosts.new
2012-08-05 20:04 - 2012-08-05 20:04 - 00000000 ____D C:\Users\Owner\Application Data\Malwarebytes
2012-08-05 20:04 - 2012-08-05 20:04 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Malwarebytes
2012-08-05 20:02 - 2012-08-05 20:12 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 20:02 - 2012-08-05 20:12 - 00000908 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 20:02 - 2012-08-05 20:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-05 20:02 - 2012-08-05 20:02 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-05 20:02 - 2012-08-05 20:02 - 00000000 ____D C:\Users\All Users\Application Data\Malwarebytes
2012-08-05 20:02 - 2012-07-03 12:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-29 22:04 - 2012-07-29 22:06 - 00000000 ____D C:\Users\All Users\Application Data\0C1CFB1300547533199543F32F3B707C
2012-07-29 22:04 - 2012-07-29 22:06 - 00000000 ____D C:\Users\All Users\0C1CFB1300547533199543F32F3B707C
2012-07-29 22:04 - 2012-07-29 22:04 - 00000000 ____D C:\Users\Owner\Local Settings\Application Data\{65B180A3-DA0C-11E1-8270-B8AC6F996F26}
2012-07-29 22:04 - 2012-07-29 22:04 - 00000000 ____D C:\Users\Owner\Local Settings\{65B180A3-DA0C-11E1-8270-B8AC6F996F26}
2012-07-29 22:04 - 2012-07-29 22:04 - 00000000 ____D C:\Users\Owner\AppData\Local\{65B180A3-DA0C-11E1-8270-B8AC6F996F26}
2012-07-29 22:03 - 2012-07-29 22:03 - 00063488 ___AH (FRISK Software International) C:\Windows\System32\Systeout64.dll
2012-07-24 12:22 - 2012-07-24 12:22 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe
2012-07-11 20:45 - 2012-06-13 05:58 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 21:10 - 2012-06-08 09:59 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 21:10 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 21:10 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 21:10 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 21:10 - 2012-06-05 08:22 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 21:10 - 2012-06-05 08:22 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 21:10 - 2012-06-04 07:29 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 21:10 - 2012-06-01 16:22 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 21:10 - 2012-06-01 16:22 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 21:10 - 2012-06-01 16:05 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 21:10 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 21:10 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
============ 3 Months Modified Files ========================
2012-08-06 08:47 - 2012-08-06 08:47 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D81E605E6624FDA
2012-08-06 08:47 - 2012-08-06 08:47 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jotnbxmr.sys
2012-08-06 08:45 - 2012-08-06 07:52 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-06 08:45 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-06 08:45 - 2006-11-02 07:22 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 08:45 - 2006-11-02 07:22 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 08:45 - 2006-11-02 07:21 - 00316224 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-06 08:43 - 2012-08-06 08:43 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9F726B9816858747
2012-08-06 08:39 - 2009-12-04 12:31 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-06 08:34 - 2012-08-06 08:34 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0B99976C11C08FFC
2012-08-06 08:30 - 2012-08-06 08:30 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC119F2587F25F3E
2012-08-06 08:27 - 2009-07-19 21:34 - 00000434 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{F132627D-0981-4A20-B84D-9DEE68BE3C90}.job
2012-08-06 08:21 - 2012-08-06 07:52 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-06 07:52 - 2012-08-06 07:52 - 00001655 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-08-06 07:52 - 2012-08-06 07:52 - 00001655 ____A C:\Users\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-08-06 07:40 - 2012-08-06 05:53 - 00001016 ____A C:\Users\Owner\Desktop\Rkill.txt
2012-08-06 07:12 - 2012-08-06 07:40 - 18976248 ____A (SUPERAntiSpyware.com) C:\Users\Owner\Desktop\SAS_939C88.EXE
2012-08-06 07:00 - 2006-11-02 07:42 - 00032552 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-06 06:56 - 2008-01-20 19:26 - 00177086 ____A C:\Windows\PFRO.log
2012-08-06 06:56 - 2006-11-02 04:34 - 00000215 ____A C:\Windows\system.ini
2012-08-06 06:55 - 2009-03-05 00:08 - 01093739 ____A C:\Windows\WindowsUpdate.log
2012-08-06 06:26 - 2006-11-02 04:46 - 00706916 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-06 00:09 - 2012-08-06 00:09 - 00014986 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.09.01.txt
2012-08-06 00:06 - 2012-08-06 00:05 - 00015310 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.05.08.txt
2012-08-06 00:05 - 2012-08-06 00:04 - 00006788 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.04.48.txt
2012-08-06 00:04 - 2012-08-06 00:03 - 00016072 ____A C:\Users\Owner\Desktop\MBRCheck_08.06.12_01.03.21.txt
2012-08-05 23:49 - 2011-07-23 23:21 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 23:42 - 2011-07-23 23:20 - 00722256 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-05 23:07 - 2012-08-05 23:00 - 00065015 ____A C:\Users\Owner\Downloads\yorkyt.exe.log
2012-08-05 23:03 - 2012-08-05 23:03 - 04009167 ____A C:\Users\Owner\Downloads\ServicesRepair.exe
2012-08-05 23:02 - 2012-08-05 23:02 - 02030547 ____A C:\Users\Owner\Downloads\EZ_Sirefix.exe
2012-08-05 23:02 - 2012-08-05 23:02 - 00138120 ____A (ESET) C:\Users\Owner\Downloads\ESETSirefefRemover.exe
2012-08-05 23:00 - 2012-08-05 22:59 - 01415784 ____A C:\Users\Owner\Downloads\yorkyt.exe
2012-08-05 21:44 - 2012-08-05 21:44 - 00000861 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-08-05 21:44 - 2012-08-05 21:44 - 00000861 ____A C:\Users\All Users\Desktop\VLC media player.lnk
2012-08-05 21:42 - 2012-08-05 21:41 - 22617148 ____A C:\Users\Owner\Downloads\vlc-2.0.3-win32.exe
2012-08-05 21:24 - 2012-08-05 20:04 - 00000734 ____A C:\Windows\System32\Drivers\etc\hosts.new
2012-08-05 21:18 - 2012-08-05 22:32 - 04725168 ____R (Swearware) C:\Users\Owner\Desktop\1ombox.com
2012-08-05 20:53 - 2012-08-05 20:51 - 12621696 ____A (Microsoft Corporation) C:\Users\Owner\Downloads\mseinstall.exe
2012-08-05 20:38 - 2012-08-05 20:31 - 00015345 ____A C:\Users\Owner\Desktop\MBRCheck_08.05.12_21.31.22.txt
2012-08-05 20:25 - 2012-08-05 20:25 - 04725168 ____R (Swearware) C:\Users\Owner\Downloads\z123ComboFix.com
2012-08-05 20:12 - 2012-08-05 20:02 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 20:12 - 2012-08-05 20:02 - 00000908 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-05 20:01 - 2009-10-03 19:10 - 00049664 ____A C:\Users\Owner\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-05 20:01 - 2009-10-03 19:10 - 00049664 ____A C:\Users\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-05 20:01 - 2009-10-03 19:10 - 00049664 ____A C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-05 20:01 - 2006-11-02 07:27 - 00124578 ____A C:\Windows\setupact.log
2012-08-05 19:56 - 2009-04-15 21:33 - 00000680 ____A C:\Users\Owner\Local Settings\d3d9caps.dat
2012-08-05 19:56 - 2009-04-15 21:33 - 00000680 ____A C:\Users\Owner\Local Settings\Application Data\d3d9caps.dat
2012-08-05 19:56 - 2009-04-15 21:33 - 00000680 ____A C:\Users\Owner\AppData\Local\d3d9caps.dat
2012-07-29 22:03 - 2012-07-29 22:03 - 00063488 ___AH (FRISK Software International) C:\Windows\System32\Systeout64.dll
2012-07-24 12:22 - 2012-07-24 12:22 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe
2012-07-11 20:46 - 2006-11-02 04:35 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-03 12:46 - 2012-08-05 20:02 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-13 05:58 - 2012-07-11 20:45 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-10 18:48 - 2011-05-28 12:10 - 00001784 ____A C:\Users\Owner\Application Data\wklnhst.dat
2012-06-10 18:48 - 2011-05-28 12:10 - 00001784 ____A C:\Users\Owner\AppData\Roaming\wklnhst.dat
2012-06-08 09:59 - 2012-07-10 21:10 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 09:47 - 2012-07-10 21:10 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 08:47 - 2012-07-10 21:10 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 08:47 - 2012-07-10 21:10 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 08:22 - 2012-07-10 21:10 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 08:22 - 2012-07-10 21:10 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-04 07:29 - 2012-07-10 21:10 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-23 14:23 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-23 14:23 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-23 14:23 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-23 14:23 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-23 14:23 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-23 14:23 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 14:12 - 2012-06-23 14:23 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 14:12 - 2012-06-23 14:23 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-01 16:22 - 2012-07-10 21:10 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:22 - 2012-07-10 21:10 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:05 - 2012-07-10 21:10 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 16:04 - 2012-07-10 21:10 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 16:03 - 2012-07-10 21:10 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-05-14 22:37 - 2012-06-12 21:12 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-14 22:37 - 2012-06-12 21:12 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-14 22:37 - 2012-06-12 21:12 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-14 22:35 - 2012-06-12 21:12 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-14 22:33 - 2012-06-12 21:12 - 06007808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-14 22:33 - 2012-06-12 21:12 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-14 22:33 - 2012-06-12 21:12 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-05-14 22:33 - 2012-06-12 21:12 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-14 22:33 - 2012-06-12 21:12 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-14 22:32 - 2012-06-12 21:12 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-14 22:32 - 2012-06-12 21:12 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-14 22:32 - 2012-06-12 21:12 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-14 22:31 - 2012-06-12 21:12 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-14 21:01 - 2012-06-12 21:12 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-14 19:26 - 2012-06-12 21:12 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-14 19:25 - 2012-06-12 21:12 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-14 19:24 - 2012-06-12 21:12 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-14 19:23 - 2012-06-12 21:12 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-14 18:19 - 2012-06-12 21:12 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-14 18:19 - 2012-06-12 21:12 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 18:19 - 2012-06-12 21:12 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-14 18:18 - 2012-06-12 21:12 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-14 18:16 - 2012-06-12 21:12 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-05-14 18:15 - 2012-06-12 21:12 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-14 18:15 - 2012-06-12 21:12 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-14 18:15 - 2012-06-12 21:12 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-14 18:15 - 2012-06-12 21:12 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-14 18:15 - 2012-06-12 21:12 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-14 18:15 - 2012-06-12 21:12 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-14 18:14 - 2012-06-12 21:12 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-14 18:14 - 2012-06-12 21:12 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-14 17:21 - 2012-06-12 21:12 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-14 16:40 - 2012-06-12 21:12 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-14 16:40 - 2012-06-12 21:12 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-14 16:39 - 2012-06-12 21:12 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-14 16:39 - 2012-06-12 21:12 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
ZeroAccess:
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
ZeroAccess:
C:\Users\Owner\AppData\Local\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}
C:\Users\Owner\AppData\Local\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
C:\Users\Owner\AppData\Local\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
C:\Users\Owner\AppData\Local\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe BC81150939BD52DBC7A08C245F1FB229 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 3998.27 MB
Available physical RAM: 3335.36 MB
Total Pagefile: 3675.46 MB
Available Pagefile: 3315.82 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:285.62 GB) (Free:216.24 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:12.47 GB) (Free:1.98 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive g: () (Removable) (Total:7.53 GB) (Free:2.59 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 No Media 0 B 0 B
Disk 2 Online 7728 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 286 GB 32 KB
Partition 2 Primary 12 GB 286 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 286 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D RECOVERY NTFS Partition 12 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7728 MB 32 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7728 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-06 06:31
======================= End Of Log ==========================