ESET found this, with the infected file being "Services.exe" in at least one instance, and it is always trying to access system things like Svchost and taskman.
DNS and internet have been extremely flaky. 2 other people on my router - 1 has had trouble, 1 hasn't. As of around 11:30 PST DNS hasn't been able to resolve even though Pidgin was connecting, so I wonder if I was hit in that FBI DNS shutdown. Not sure because I have been having a ton of DNS issues anyway so it all may be the big DNS thing or it may be independent. Now I can't get on Pidgin now either even though Win7 says I have internet...it is fine on this old XP computer though.
Here is my log.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-07-2012 01
Ran by SYSTEM at 09-07-2012 01:04:44
Running from H:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [egui] "D:\Run\Tools\ESET\egui.exe" /hide /waitservice [x]
HKLM\...\Run: [UnlockerAssistant] "D:\Run\Tools\Unlocker\UnlockerAssistant.exe" [x]
HKLM\...\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup [358336 2011-08-11] (Citrix Systems, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2008-02-15] (IDT, Inc.)
HKLM\...\Run: [boincmgr] "D:\Run\Internet\BOINC\boincmgr.exe" /a /s [x]
HKLM\...\Run: [boinctray] "D:\Run\Internet\BOINC\boinctray.exe" [x]
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [LogMeIn Hamachi Ui] "D:\Run\Tools\Internet\Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKLM\...\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-23] (CANON INC.)
HKU\Bosh\...\Run: [SpybotSD TeaTimer] D:\Run\Tools\Spybot\TeaTimer.exe [x]
HKU\Bosh\...\Run: [TrueCrypt] "D:\Run\Tools\TC\TrueCrypt.exe" /q preferences /a logon /a favorites [x]
HKU\Bosh\...\Run: [MusicManager] "D:\Users\Bosh\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [x]
HKU\Bosh\...\Run: [Google Update] "D:\Users\Bosh\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-05-25] (Google Inc.)
HKU\Bosh\...\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
HKU\Bosh\...\Run: [306E1B8E2C99E83119C42FCB48AAF71FCAC5BD78._service_run] "D:\Users\Bosh\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service [x]
HKU\Bosh\...\Run: [DAEMON Tools Lite] "D:\Run\Tools\DAEMON Tools Pro\DTLite.exe" -autorun [x]
HKU\Bosh\...\Run: [iCloudServices] D:\Run\Internet\iCloud\iCloudServices.exe [x]
HKU\Bosh\...\Run: [ApplePhotoStreams] D:\Run\Internet\iCloud\ApplePhotoStreams.exe [x]
HKU\Bosh\...\Run: [com.apple.dav.bookmarks.daemon] D:\Run\Internet\iCloud\BookmarkDAV_client.exe [x]
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll [X]
Winlogon\Notify\psfus: C:\Windows\system32\psqlpwd.dll (UPEK Inc.)
Lsa: [Notification Packages] scecli
psqlpwd
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
================================ Services (Whitelisted) ==================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [804528 2011-02-01] (Acronis)
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_24288096a5cd99f6\aestsrv.exe [73728 2007-09-20] (Andrea Electronics Corporation)
2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3246040 2011-05-25] (Acronis)
2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [775968 2012-02-01] (Broadcom Corporation.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 IntuitUpdateService; "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" [13672 2010-08-23] (Intuit Inc.)
2 PanInstaller; C:\Program Files\Palo Alto Networks\Pan Connect\PanInstaller.exe [234824 2011-04-12] ()
2 PanService; C:\Program Files\Palo Alto Networks\Pan Connect\PanService.exe [947528 2011-04-12] (Palo Alto Networks)
4 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)
3 EhttpSrv; C:\Run\Tools\ESET\EHttpSrv.exe [x]
2 ekrn; C:\Run\Tools\ESET\ekrn.exe [x]
2 Hamachi2Svc; C:\Run\Tools\Internet\Hamachi\hamachi-2.exe -s [x]
4 NitroReaderDriverReadSpool; C:\Run\Internet\Nitro\NitroPDFReaderDriverService.exe [x]
3 SbieSvc; "C:\Run\Tools\Sandboxie\SbieSvc.exe" [x]
2 SBSDWSCService; C:\Run\Tools\Spybot\SDWinSec.exe [x]
4 WMPControllerService; "C:\Dell\Utilities\Dell Premium Remote Control\WMPControllerService.exe" [x]
========================== Drivers (Whitelisted) =============
3 afcdp; C:\Windows\System32\DRIVERS\afcdp.sys [167968 2011-05-25] (Acronis)
3 BTWAMPFL; C:\Windows\System32\DRIVERS\btwampfl.sys [522280 2012-02-27] (Broadcom Corporation.)
1 ctxusbm; C:\Windows\System32\DRIVERS\ctxusbm.sys [66776 2011-08-10] (Citrix Systems, Inc.)
2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [137144 2010-12-21] (ESET)
1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [115008 2010-12-21] (ESET)
2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [134000 2010-12-21] (ESET)
3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33120 2010-12-21] (ESET)
2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [41336 2010-12-21] (ESET)
3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
3 motandroidusb; C:\Windows\System32\Drivers\motoandroid.sys [25856 2009-07-10] (Motorola)
3 MotDev; C:\Windows\System32\DRIVERS\motodrv.sys [42752 2009-05-08] (Motorola Inc)
3 PanSvd; C:\Windows\System32\DRIVERS\pansvd.sys [27136 2011-04-12] (Palo Alto Networks)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [473656 2012-03-03] (Duplex Secure Ltd.)
0 tdrpman273; C:\Windows\System32\DRIVERS\tdrpm273.sys [752128 2011-05-25] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [600928 2011-05-25] (Acronis)
1 truecrypt; C:\Windows\System32\drivers\truecrypt.sys [231248 2011-05-25] (TrueCrypt Foundation)
3 WSDScan; C:\Windows\System32\DRIVERS\WSDScan.sys [20480 2009-07-13] (Microsoft Corporation)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
3 SbieDrv; \??\D:\Run\Tools\Sandboxie\SbieDrv.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-09 01:04 - 2012-07-09 01:04 - 00000000 ____D C:\FRST
2012-07-08 21:09 - 2011-05-25 00:16 - 00434608 ____A C:\Windows\System32\Drivers\etc\hosts.20120708-220900.backup
2012-07-08 20:35 - 2012-07-08 20:35 - 00001967 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-07-08 20:35 - 2012-07-08 20:35 - 00000000 ____D C:\Program Files\Canon
2012-07-08 20:35 - 2011-01-06 12:08 - 01310720 ____A (CANON INC.) C:\Windows\System32\CNC870C.dll
2012-07-08 20:35 - 2011-01-06 12:08 - 00110592 ____A (CANON INC.) C:\Windows\System32\CNC870I.dll
2012-07-08 20:35 - 2011-01-06 12:07 - 00102400 ____A (CANON INC.) C:\Windows\System32\CNC870U.dll
2012-07-08 20:35 - 2009-10-19 15:29 - 00307200 ____A (CANON INC.) C:\Windows\System32\CNC870L.dll
2012-07-08 20:35 - 2009-06-26 09:45 - 00015360 ____A C:\Windows\System32\CNC1743D.TBL
2012-07-08 20:35 - 2008-08-25 17:02 - 00015872 ____A (CANON INC.) C:\Windows\System32\CNHMCA.dll
2012-07-08 20:33 - 2012-07-08 20:33 - 00000000 ___HD C:\Program Files\CanonBJ
2012-07-08 20:33 - 2012-07-08 20:33 - 00000000 ____D C:\Windows\System32\STRING
2012-07-08 20:33 - 2012-07-08 20:33 - 00000000 ____D C:\Windows\System32\CHM
2012-07-08 20:33 - 2009-10-09 14:01 - 00354816 ____A (CANON INC.) C:\Windows\System32\CNMNPPM.DLL
2012-07-08 20:33 - 2009-10-09 14:01 - 00137216 ____A (CANON INC.) C:\Windows\System32\CNMNPUI.DLL
2012-06-28 20:00 - 2009-03-18 16:35 - 00026176 ___AH (LogMeIn, Inc.) C:\Windows\System32\hamachi.sys
2012-06-26 21:58 - 2012-06-26 21:58 - 00000000 ____D C:\Program Files\Common Files\Java
2012-06-26 21:57 - 2012-06-26 21:57 - 00000000 ____D C:\Program Files\Oracle
2012-06-26 21:57 - 2012-05-04 18:29 - 00772504 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-06-26 21:57 - 2012-05-04 18:29 - 00227720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-06-26 21:55 - 2012-06-26 21:55 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-21 10:14 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 10:14 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 10:14 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 10:14 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 10:14 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 10:14 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 10:14 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 10:14 - 2012-06-02 12:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 10:14 - 2012-06-02 12:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-18 22:50 - 2012-06-18 22:50 - 00000000 ____D C:\Users\All Users\Apple
2012-06-18 11:15 - 2012-05-15 01:28 - 03931456 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-06-18 11:15 - 2012-05-15 01:28 - 02561344 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-06-18 11:15 - 2012-05-15 01:28 - 00645440 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-06-18 11:15 - 2012-05-15 01:28 - 00108352 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-06-18 11:15 - 2012-05-15 01:28 - 00062272 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-06-18 11:15 - 2012-05-15 01:27 - 02759488 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 19607872 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv32.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 17551680 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 11354944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-06-18 11:11 - 2012-05-15 02:26 - 08105280 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2um.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 05982528 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 02524992 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 02445120 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 02368832 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 01000768 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco32.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 00883008 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco32.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 00011190 ____A C:\Windows\System32\nvinfo.pb
2012-06-18 11:10 - 2012-06-18 11:10 - 00000000 ____D C:\NVIDIA
2012-06-18 10:57 - 2012-06-18 11:15 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-18 10:47 - 2012-07-08 21:00 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-06-18 10:47 - 2012-06-18 11:21 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-18 10:46 - 2012-06-21 12:19 - 00000000 ____D C:\Users\All Users\PCDr
2012-06-18 10:46 - 2012-06-18 10:46 - 00000000 ____D C:\Users\All Users\Dell
2012-06-18 10:45 - 2012-06-18 10:47 - 00000000 ____D C:\Program Files\Dell Support Center
2012-06-18 10:32 - 2012-06-18 10:32 - 00103784 ____A C:\Users\Bosh\GoToAssistDownloadHelper.exe
============ 3 Months Modified Files ========================
2012-07-09 00:00 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-09 00:00 - 2009-07-13 20:39 - 00089065 ____A C:\Windows\setupact.log
2012-07-08 23:20 - 2011-05-25 00:18 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2537561138-1596547413-242098265-1000UA.job
2012-07-08 22:44 - 2011-05-25 00:01 - 01683143 ____A C:\Windows\WindowsUpdate.log
2012-07-08 21:20 - 2011-05-25 00:18 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2537561138-1596547413-242098265-1000Core.job
2012-07-08 21:08 - 2009-07-13 20:34 - 00013808 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-08 21:08 - 2009-07-13 20:34 - 00013808 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-08 21:07 - 2011-05-25 00:04 - 00782748 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-08 21:00 - 2012-06-18 10:47 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-07-08 20:35 - 2012-07-08 20:35 - 00001967 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-06-26 21:56 - 2011-07-15 16:57 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-06-26 21:56 - 2011-07-15 16:57 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-06-20 11:54 - 2011-05-25 00:54 - 00028352 ____A C:\Windows\PFRO.log
2012-06-18 11:21 - 2012-06-18 10:47 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-18 10:32 - 2012-06-18 10:32 - 00103784 ____A C:\Users\Bosh\GoToAssistDownloadHelper.exe
2012-06-05 10:05 - 2009-07-13 20:33 - 04307016 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-02 14:19 - 2012-06-21 10:14 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 10:14 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 10:14 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 10:14 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 10:14 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 10:14 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 10:14 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-21 10:14 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:12 - 2012-06-21 10:14 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-22 11:34 - 2012-05-22 11:34 - 00060304 ____A C:\Users\Bosh\g2mdlhlpx.exe
2012-05-15 02:26 - 2012-06-18 11:11 - 19607872 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv32.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 17551680 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 11354944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:26 - 2012-06-18 11:11 - 08105280 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2um.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 05982528 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 02524992 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 02445120 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 02368832 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 01000768 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco32.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 00883008 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco32.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 00011190 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:26 - 2010-10-17 00:55 - 15322432 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dum.dll
2012-05-15 02:26 - 2010-10-17 00:55 - 00061248 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 03931456 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 02561344 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 00645440 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:28 - 2012-06-18 11:15 - 00108352 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 00062272 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:27 - 2012-06-18 11:15 - 02759488 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc.dll
2012-05-04 18:29 - 2012-06-26 21:57 - 00772504 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-05-04 18:29 - 2012-06-26 21:57 - 00227720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-05-04 18:29 - 2011-07-15 16:57 - 00687504 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-04-26 19:08 - 2011-05-25 00:27 - 55656824 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-04-17 18:55 - 2011-05-25 00:12 - 00100944 ____A C:\Users\Bosh\AppData\Local\GDIPFONTCACHEV1.DAT
ZeroAccess:
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\@
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\L
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\U
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\U\00000001.@
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 4094.06 MB
Available physical RAM: 3570.16 MB
Total Pagefile: 4092.34 MB
Available Pagefile: 3572.94 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.73 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:50.04 GB) (Free:12.84 GB) NTFS
3 Drive f: (Data) (Fixed) (Total:350 GB) (Free:34.72 GB) NTFS
4 Drive g: (GRMCPRFRER_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
5 Drive h: () (Removable) (Total:15.11 GB) (Free:15.1 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 1024 KB
Disk 1 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 50 GB 101 MB
Partition 3 Primary 350 GB 50 GB
Partition 0 Extended 65 GB 400 GB
Partition 4 Logical 65 GB 400 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 50 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Data NTFS Partition 350 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D RAW Partition 65 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 23:38
======================= End Of Log ==========================
DNS and internet have been extremely flaky. 2 other people on my router - 1 has had trouble, 1 hasn't. As of around 11:30 PST DNS hasn't been able to resolve even though Pidgin was connecting, so I wonder if I was hit in that FBI DNS shutdown. Not sure because I have been having a ton of DNS issues anyway so it all may be the big DNS thing or it may be independent. Now I can't get on Pidgin now either even though Win7 says I have internet...it is fine on this old XP computer though.
Here is my log.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-07-2012 01
Ran by SYSTEM at 09-07-2012 01:04:44
Running from H:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [egui] "D:\Run\Tools\ESET\egui.exe" /hide /waitservice [x]
HKLM\...\Run: [UnlockerAssistant] "D:\Run\Tools\Unlocker\UnlockerAssistant.exe" [x]
HKLM\...\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup [358336 2011-08-11] (Citrix Systems, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2008-02-15] (IDT, Inc.)
HKLM\...\Run: [boincmgr] "D:\Run\Internet\BOINC\boincmgr.exe" /a /s [x]
HKLM\...\Run: [boinctray] "D:\Run\Internet\BOINC\boinctray.exe" [x]
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [LogMeIn Hamachi Ui] "D:\Run\Tools\Internet\Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKLM\...\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-23] (CANON INC.)
HKU\Bosh\...\Run: [SpybotSD TeaTimer] D:\Run\Tools\Spybot\TeaTimer.exe [x]
HKU\Bosh\...\Run: [TrueCrypt] "D:\Run\Tools\TC\TrueCrypt.exe" /q preferences /a logon /a favorites [x]
HKU\Bosh\...\Run: [MusicManager] "D:\Users\Bosh\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [x]
HKU\Bosh\...\Run: [Google Update] "D:\Users\Bosh\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-05-25] (Google Inc.)
HKU\Bosh\...\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
HKU\Bosh\...\Run: [306E1B8E2C99E83119C42FCB48AAF71FCAC5BD78._service_run] "D:\Users\Bosh\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service [x]
HKU\Bosh\...\Run: [DAEMON Tools Lite] "D:\Run\Tools\DAEMON Tools Pro\DTLite.exe" -autorun [x]
HKU\Bosh\...\Run: [iCloudServices] D:\Run\Internet\iCloud\iCloudServices.exe [x]
HKU\Bosh\...\Run: [ApplePhotoStreams] D:\Run\Internet\iCloud\ApplePhotoStreams.exe [x]
HKU\Bosh\...\Run: [com.apple.dav.bookmarks.daemon] D:\Run\Internet\iCloud\BookmarkDAV_client.exe [x]
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll [X]
Winlogon\Notify\psfus: C:\Windows\system32\psqlpwd.dll (UPEK Inc.)
Lsa: [Notification Packages] scecli
psqlpwd
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
================================ Services (Whitelisted) ==================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [804528 2011-02-01] (Acronis)
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_24288096a5cd99f6\aestsrv.exe [73728 2007-09-20] (Andrea Electronics Corporation)
2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3246040 2011-05-25] (Acronis)
2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [775968 2012-02-01] (Broadcom Corporation.)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 IntuitUpdateService; "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" [13672 2010-08-23] (Intuit Inc.)
2 PanInstaller; C:\Program Files\Palo Alto Networks\Pan Connect\PanInstaller.exe [234824 2011-04-12] ()
2 PanService; C:\Program Files\Palo Alto Networks\Pan Connect\PanService.exe [947528 2011-04-12] (Palo Alto Networks)
4 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)
3 EhttpSrv; C:\Run\Tools\ESET\EHttpSrv.exe [x]
2 ekrn; C:\Run\Tools\ESET\ekrn.exe [x]
2 Hamachi2Svc; C:\Run\Tools\Internet\Hamachi\hamachi-2.exe -s [x]
4 NitroReaderDriverReadSpool; C:\Run\Internet\Nitro\NitroPDFReaderDriverService.exe [x]
3 SbieSvc; "C:\Run\Tools\Sandboxie\SbieSvc.exe" [x]
2 SBSDWSCService; C:\Run\Tools\Spybot\SDWinSec.exe [x]
4 WMPControllerService; "C:\Dell\Utilities\Dell Premium Remote Control\WMPControllerService.exe" [x]
========================== Drivers (Whitelisted) =============
3 afcdp; C:\Windows\System32\DRIVERS\afcdp.sys [167968 2011-05-25] (Acronis)
3 BTWAMPFL; C:\Windows\System32\DRIVERS\btwampfl.sys [522280 2012-02-27] (Broadcom Corporation.)
1 ctxusbm; C:\Windows\System32\DRIVERS\ctxusbm.sys [66776 2011-08-10] (Citrix Systems, Inc.)
2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [137144 2010-12-21] (ESET)
1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [115008 2010-12-21] (ESET)
2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [134000 2010-12-21] (ESET)
3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33120 2010-12-21] (ESET)
2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [41336 2010-12-21] (ESET)
3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
3 motandroidusb; C:\Windows\System32\Drivers\motoandroid.sys [25856 2009-07-10] (Motorola)
3 MotDev; C:\Windows\System32\DRIVERS\motodrv.sys [42752 2009-05-08] (Motorola Inc)
3 PanSvd; C:\Windows\System32\DRIVERS\pansvd.sys [27136 2011-04-12] (Palo Alto Networks)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [473656 2012-03-03] (Duplex Secure Ltd.)
0 tdrpman273; C:\Windows\System32\DRIVERS\tdrpm273.sys [752128 2011-05-25] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [600928 2011-05-25] (Acronis)
1 truecrypt; C:\Windows\System32\drivers\truecrypt.sys [231248 2011-05-25] (TrueCrypt Foundation)
3 WSDScan; C:\Windows\System32\DRIVERS\WSDScan.sys [20480 2009-07-13] (Microsoft Corporation)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
3 SbieDrv; \??\D:\Run\Tools\Sandboxie\SbieDrv.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-09 01:04 - 2012-07-09 01:04 - 00000000 ____D C:\FRST
2012-07-08 21:09 - 2011-05-25 00:16 - 00434608 ____A C:\Windows\System32\Drivers\etc\hosts.20120708-220900.backup
2012-07-08 20:35 - 2012-07-08 20:35 - 00001967 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-07-08 20:35 - 2012-07-08 20:35 - 00000000 ____D C:\Program Files\Canon
2012-07-08 20:35 - 2011-01-06 12:08 - 01310720 ____A (CANON INC.) C:\Windows\System32\CNC870C.dll
2012-07-08 20:35 - 2011-01-06 12:08 - 00110592 ____A (CANON INC.) C:\Windows\System32\CNC870I.dll
2012-07-08 20:35 - 2011-01-06 12:07 - 00102400 ____A (CANON INC.) C:\Windows\System32\CNC870U.dll
2012-07-08 20:35 - 2009-10-19 15:29 - 00307200 ____A (CANON INC.) C:\Windows\System32\CNC870L.dll
2012-07-08 20:35 - 2009-06-26 09:45 - 00015360 ____A C:\Windows\System32\CNC1743D.TBL
2012-07-08 20:35 - 2008-08-25 17:02 - 00015872 ____A (CANON INC.) C:\Windows\System32\CNHMCA.dll
2012-07-08 20:33 - 2012-07-08 20:33 - 00000000 ___HD C:\Program Files\CanonBJ
2012-07-08 20:33 - 2012-07-08 20:33 - 00000000 ____D C:\Windows\System32\STRING
2012-07-08 20:33 - 2012-07-08 20:33 - 00000000 ____D C:\Windows\System32\CHM
2012-07-08 20:33 - 2009-10-09 14:01 - 00354816 ____A (CANON INC.) C:\Windows\System32\CNMNPPM.DLL
2012-07-08 20:33 - 2009-10-09 14:01 - 00137216 ____A (CANON INC.) C:\Windows\System32\CNMNPUI.DLL
2012-06-28 20:00 - 2009-03-18 16:35 - 00026176 ___AH (LogMeIn, Inc.) C:\Windows\System32\hamachi.sys
2012-06-26 21:58 - 2012-06-26 21:58 - 00000000 ____D C:\Program Files\Common Files\Java
2012-06-26 21:57 - 2012-06-26 21:57 - 00000000 ____D C:\Program Files\Oracle
2012-06-26 21:57 - 2012-05-04 18:29 - 00772504 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-06-26 21:57 - 2012-05-04 18:29 - 00227720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-06-26 21:55 - 2012-06-26 21:55 - 00000000 ____D C:\Users\All Users\McAfee
2012-06-21 10:14 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 10:14 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 10:14 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 10:14 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 10:14 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 10:14 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 10:14 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 10:14 - 2012-06-02 12:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 10:14 - 2012-06-02 12:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-18 22:50 - 2012-06-18 22:50 - 00000000 ____D C:\Users\All Users\Apple
2012-06-18 11:15 - 2012-05-15 01:28 - 03931456 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-06-18 11:15 - 2012-05-15 01:28 - 02561344 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-06-18 11:15 - 2012-05-15 01:28 - 00645440 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-06-18 11:15 - 2012-05-15 01:28 - 00108352 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-06-18 11:15 - 2012-05-15 01:28 - 00062272 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-06-18 11:15 - 2012-05-15 01:27 - 02759488 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 19607872 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv32.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 17551680 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 11354944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-06-18 11:11 - 2012-05-15 02:26 - 08105280 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2um.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 05982528 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 02524992 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 02445120 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 02368832 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 01000768 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco32.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 00883008 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco32.dll
2012-06-18 11:11 - 2012-05-15 02:26 - 00011190 ____A C:\Windows\System32\nvinfo.pb
2012-06-18 11:10 - 2012-06-18 11:10 - 00000000 ____D C:\NVIDIA
2012-06-18 10:57 - 2012-06-18 11:15 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-18 10:47 - 2012-07-08 21:00 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-06-18 10:47 - 2012-06-18 11:21 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-18 10:46 - 2012-06-21 12:19 - 00000000 ____D C:\Users\All Users\PCDr
2012-06-18 10:46 - 2012-06-18 10:46 - 00000000 ____D C:\Users\All Users\Dell
2012-06-18 10:45 - 2012-06-18 10:47 - 00000000 ____D C:\Program Files\Dell Support Center
2012-06-18 10:32 - 2012-06-18 10:32 - 00103784 ____A C:\Users\Bosh\GoToAssistDownloadHelper.exe
============ 3 Months Modified Files ========================
2012-07-09 00:00 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-09 00:00 - 2009-07-13 20:39 - 00089065 ____A C:\Windows\setupact.log
2012-07-08 23:20 - 2011-05-25 00:18 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2537561138-1596547413-242098265-1000UA.job
2012-07-08 22:44 - 2011-05-25 00:01 - 01683143 ____A C:\Windows\WindowsUpdate.log
2012-07-08 21:20 - 2011-05-25 00:18 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2537561138-1596547413-242098265-1000Core.job
2012-07-08 21:08 - 2009-07-13 20:34 - 00013808 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-08 21:08 - 2009-07-13 20:34 - 00013808 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-08 21:07 - 2011-05-25 00:04 - 00782748 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-08 21:00 - 2012-06-18 10:47 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-07-08 20:35 - 2012-07-08 20:35 - 00001967 ____A C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2012-06-26 21:56 - 2011-07-15 16:57 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-06-26 21:56 - 2011-07-15 16:57 - 00174064 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-06-20 11:54 - 2011-05-25 00:54 - 00028352 ____A C:\Windows\PFRO.log
2012-06-18 11:21 - 2012-06-18 10:47 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-18 10:32 - 2012-06-18 10:32 - 00103784 ____A C:\Users\Bosh\GoToAssistDownloadHelper.exe
2012-06-05 10:05 - 2009-07-13 20:33 - 04307016 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-02 14:19 - 2012-06-21 10:14 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 10:14 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 10:14 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 10:14 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 10:14 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 10:14 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 10:14 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-21 10:14 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:12 - 2012-06-21 10:14 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-22 11:34 - 2012-05-22 11:34 - 00060304 ____A C:\Users\Bosh\g2mdlhlpx.exe
2012-05-15 02:26 - 2012-06-18 11:11 - 19607872 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv32.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 17551680 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 11354944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:26 - 2012-06-18 11:11 - 08105280 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2um.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 05982528 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 02524992 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 02445120 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 02368832 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 01000768 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco32.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 00883008 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco32.dll
2012-05-15 02:26 - 2012-06-18 11:11 - 00011190 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 02:26 - 2010-10-17 00:55 - 15322432 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dum.dll
2012-05-15 02:26 - 2010-10-17 00:55 - 00061248 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 03931456 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 02561344 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 00645440 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:28 - 2012-06-18 11:15 - 00108352 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:28 - 2012-06-18 11:15 - 00062272 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:27 - 2012-06-18 11:15 - 02759488 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc.dll
2012-05-04 18:29 - 2012-06-26 21:57 - 00772504 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-05-04 18:29 - 2012-06-26 21:57 - 00227720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-05-04 18:29 - 2011-07-15 16:57 - 00687504 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-04-26 19:08 - 2011-05-25 00:27 - 55656824 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-04-17 18:55 - 2011-05-25 00:12 - 00100944 ____A C:\Users\Bosh\AppData\Local\GDIPFONTCACHEV1.DAT
ZeroAccess:
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\@
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\L
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\U
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\U\00000001.@
C:\Windows\Installer\{72c25dc5-dc4e-ca0f-08b4-af45d073eab5}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 4094.06 MB
Available physical RAM: 3570.16 MB
Total Pagefile: 4092.34 MB
Available Pagefile: 3572.94 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.73 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:50.04 GB) (Free:12.84 GB) NTFS
3 Drive f: (Data) (Fixed) (Total:350 GB) (Free:34.72 GB) NTFS
4 Drive g: (GRMCPRFRER_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
5 Drive h: () (Removable) (Total:15.11 GB) (Free:15.1 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 1024 KB
Disk 1 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 50 GB 101 MB
Partition 3 Primary 350 GB 50 GB
Partition 0 Extended 65 GB 400 GB
Partition 4 Logical 65 GB 400 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 50 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Data NTFS Partition 350 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D RAW Partition 65 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 23:38
======================= End Of Log ==========================