Kutunluu
Posts: 13 +0
Hey,
I'm one of the people hit by the delightful Sirefef virus and my computer is now in the 1 minute reboot cycle. Any help would be really appreciated. I'm using Windows 7 and MSE.
I'm quite n00b with this stuff, but read enough about the problem to run Farbar. Here are the logs:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) (x86) Version: 05-09-2012
Ran by SYSTEM at 07-09-2012 19:05:38
Running from H:\
Windows 7 Home Premium (X86) OS Language: 040B
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [111936 2008-09-03] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [Lycosa] "C:\Program Files\Razer\Lycosa\razerhid.exe" [147456 2007-11-20] (Razer USA Ltd.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [SteelSeries World of Warcraft(R) MMO Gaming Mouse Legendary Edition] "C:\Program Files\SteelSeries\World of Warcraft(R) MMO Gaming Mouse Legendary Edition\WoWMHID4.exe" [1945600 2011-10-03] ()
HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] ()
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [40368 2011-08-31] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Miika Huttunen\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\Miika Huttunen\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-06-29] (Google Inc.)
HKU\Miika Huttunen\...\Run: [{56648676-72F0-2F72-FD54-802FED267567}] "C:\Users\Miika Huttunen\AppData\Roaming\Rybyun\moubifi.exe" [212992 2012-07-05] (Four Hundred paper)
HKU\Miika Huttunen\...\Run: [C3] [x]
HKU\UpdatusUser\...\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade [x]
HKU\UpdatusUser\...\RunOnce: [DPAPIKeyMig] %SystemRoot%\system32\dpapimig.exe -quiet [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
==================== Services ================================
3 Creative ALchemy AL6 Licensing Service; "C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe" [79360 2010-12-16] (Creative Labs)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-06-29] ()
2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [189248 2010-06-29] ()
3 WPFFontCache_v0400; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [x]
==================== Drivers =================================
1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12664 2006-10-18] ()
2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [83872 2012-07-03] ()
3 bfturboh; C:\Windows\System32\drivers\bfturboh.sys [17280 2008-07-22] (BUFFALO INC.)
3 busenum; C:\Windows\System32\DRIVERS\SteelBus.sys [83840 2010-08-28] (SteelSeries Corporation)
3 DynamicEDController; \??\C:\Windows\system32\drivers\TSSFSFD.SYS [52224 2006-11-30] (TSS - www.trinity-ss.com)
3 ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan)
2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2012-07-03] ()
3 LycoFltr; C:\Windows\System32\Drivers\Lycosa.sys [16128 2008-01-18] (Razer USA Ltd.)
3 Mo3Fltr; C:\Windows\System32\drivers\Mo3Fltr.sys [11136 2008-04-15] ()
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
1 MpKsl83391dc8; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{23515FBF-24D8-4497-88E1-B26C32A04612}\MpKsl83391dc8.sys [29904 2012-09-07] (Microsoft Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2006-10-18] ()
3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham.sys [31488 2010-09-08] (SteelSeries Corporation)
3 SSMO4Filter; C:\Windows\System32\drivers\MO4Driver.sys [16896 2011-07-26] (Sagatek Co. Ltd.)
2 TSSFLT; C:\Windows\System32\DRIVERS\tssflt.sys [52224 2006-11-30] (TSS - www.trinity-ss.com)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
3 CTMOV2; \??\D:\TTST\RJ096390\CTMOV.SYS [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-09-07 18:31 - 2012-09-07 18:32 - 00000000 ____D C:\FRST
2012-09-06 18:36 - 2012-09-06 18:37 - 00140248 ____A C:\Windows\Minidump\090612-29312-01.dmp
2012-09-06 18:36 - 2012-09-06 18:36 - 193430492 ____A C:\Windows\MEMORY.DMP
2012-09-06 18:36 - 2012-09-06 18:36 - 00000000 ____D C:\Windows\Minidump
2012-09-06 17:37 - 2012-09-06 17:37 - 00001853 ____A C:\Windows\WindowsUpdate.log
2012-09-06 17:37 - 2012-09-06 17:37 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-06 17:36 - 2012-09-06 17:36 - 10299264 ____A (Microsoft Corporation) C:\Users\Miika Huttunen\Desktop\mseinstall.exe
2012-09-06 16:57 - 2012-09-07 18:01 - 01488860 ____A C:\Windows\setupact.log
2012-09-06 16:57 - 2012-09-06 16:57 - 00000000 ____A C:\Windows\setuperr.log
2012-09-06 15:36 - 2012-09-06 15:36 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{92B76C5F-CC0F-442A-AB7C-FEBCA45C1F0B}
2012-09-05 17:53 - 2012-09-05 17:53 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{C70A293C-4562-4077-8274-9D8D1D61FD19}
2012-09-04 17:27 - 2012-09-04 17:27 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{BC4B2672-4CDD-46AA-ABD8-11DBA558DF6B}
2012-09-03 19:30 - 2012-09-03 19:30 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{A77477A1-C815-408F-8341-1DF2FF58C5FA}
2012-09-02 23:31 - 2012-09-02 23:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{F34AA137-1605-4E1F-80F7-FBBAC3636922}
2012-09-02 09:51 - 2012-09-02 09:51 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{6498052A-6F50-4960-8B4A-474B64D24E69}
2012-09-01 09:53 - 2012-09-01 09:53 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{277B7FC0-0CFC-4C05-AC9A-765F6C29B72B}
2012-08-31 16:51 - 2012-08-31 16:51 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{50E2F717-E410-4C18-8B17-3D1588AE78C8}
2012-08-30 21:37 - 2012-08-30 21:37 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{305D4370-F530-4D1F-AF7D-EA9D3692924F}
2012-08-30 09:03 - 2012-08-30 09:03 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{E929B1C4-55C0-4E52-AAF8-F5FAC98FFD2D}
2012-08-29 17:17 - 2012-08-29 17:17 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{F0DF6D00-FBFB-4DDE-93F9-5479DA73DCB4}
2012-08-28 18:07 - 2012-08-28 18:07 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B3576A8D-A775-4C3B-B4AD-195A28BA96A9}
2012-08-27 17:46 - 2012-08-27 17:46 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{72AA6832-FA0B-4407-AF31-CA54BB65100F}
2012-08-26 21:05 - 2012-08-26 21:05 - 00000000 ____D C:\Users\Miika Huttunen\Documents\My Curse
2012-08-26 21:04 - 2012-08-30 17:19 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\Deployment
2012-08-26 13:04 - 2012-08-26 13:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{69AE4896-851A-4B6F-B9E7-D62086F8F310}
2012-08-25 22:22 - 2012-08-25 22:22 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{851BEC68-ED53-427A-8D7C-935E2FC27D6C}
2012-08-25 09:14 - 2012-08-25 09:14 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{F23C13CE-A93F-464A-AB80-2D0B87E86787}
2012-08-24 17:04 - 2012-08-24 17:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{98AA78F1-CEAC-4E5E-BD63-21EC63B2817C}
2012-08-23 18:40 - 2012-08-23 18:40 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{42C89C6A-2CFE-45C8-9DA7-99CE6FE8A592}
2012-08-22 20:14 - 2012-08-22 20:14 - 150603838 ____A C:\Users\Miika Huttunen\Desktop\dbcjbsk2.zip
2012-08-22 20:14 - 2012-08-22 20:14 - 00000000 ____D C:\Users\Miika Huttunen\Desktop\dbcjbsk2
2012-08-22 18:06 - 2012-08-22 18:06 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{89008E8A-2CA1-44AD-80B4-338B5C89586E}
2012-08-21 16:57 - 2012-08-21 16:57 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{807303E0-A9B9-4ADA-B6BD-86FB2A4F44B4}
2012-08-20 21:31 - 2012-08-20 21:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\Vivox
2012-08-20 21:21 - 2012-08-20 21:21 - 00001959 ____A C:\Users\Miika Huttunen\Desktop\C3.lnk
2012-08-20 21:21 - 2012-08-20 21:21 - 00000000 ____D C:\Program Files\Vivox
2012-08-20 18:28 - 2012-08-20 18:28 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{FC77D3ED-3D61-4D0E-A33C-07CDE5AD820E}
2012-08-19 09:16 - 2012-08-19 09:16 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B84B6769-C41E-4BBE-AA54-DD5B9FF6D855}
2012-08-18 09:09 - 2012-08-18 09:09 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{82A1792E-CC23-4045-A504-9A2F1A5AEB4D}
2012-08-18 09:09 - 2012-08-18 09:09 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{5116AB71-947C-45B6-8BE2-B0967A449456}
2012-08-17 17:26 - 2012-08-17 17:26 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{FAA81FB5-9FE7-45BE-8D94-6A2B05BA368D}
2012-08-17 17:26 - 2012-08-17 17:26 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{14B1B6F1-2CA2-429F-9DA9-71A7F9531020}
2012-08-16 09:04 - 2012-08-16 09:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{124EA4A8-9300-4869-BF63-F851EE32F01F}
2012-08-16 09:03 - 2012-08-16 09:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{4697AFAD-23BA-4B6F-960B-F9A88B76900C}
2012-08-15 14:55 - 2012-08-15 14:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{EFE6855D-AAA7-454C-BF6E-D5647A8E1D04}
2012-08-15 14:55 - 2012-08-15 14:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{7A67C5CE-02F4-426B-8D6A-6E3472409116}
2012-08-14 19:18 - 2012-08-14 21:34 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Roaming\Atappo
2012-08-14 19:18 - 2012-08-14 19:18 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Roaming\Rybyun
2012-08-14 18:58 - 2012-08-14 18:58 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{C979CBF4-B506-40EF-AFB1-79DD9E0D6601}
2012-08-14 18:58 - 2012-08-14 18:58 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{40C096E8-303A-4FB6-A7C5-702C7B6CCB8D}
2012-08-13 16:57 - 2012-08-13 16:57 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-13 16:55 - 2012-08-13 16:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B58C9616-D20A-4678-BC4D-B3701D327007}
2012-08-13 16:55 - 2012-08-13 16:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B4B2864D-9151-42F9-A0C2-E4003BBC23AD}
2012-08-12 12:23 - 2012-08-12 12:23 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{54C30DF3-53AA-4278-AE79-43B15A5A3872}
2012-08-12 12:23 - 2012-08-12 12:23 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{484A1DC6-8F70-4F74-911F-2C8CC2411788}
2012-08-11 21:35 - 2012-08-11 21:35 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{846C10BA-DF1A-454B-B7CD-FCBDFEA4F588}
2012-08-11 21:35 - 2012-08-11 21:35 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{50A0A0E0-8CE0-462D-AC90-41BF598FF8D0}
2012-08-11 08:31 - 2012-08-11 08:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{D539C5E1-74CB-43BA-AA50-A07BE8F49AC5}
2012-08-11 08:31 - 2012-08-11 08:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{01C8530C-49D7-413F-A9DE-19A9EA03C50C}
2012-08-10 16:24 - 2012-08-10 16:24 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{E4C89827-4D6C-4F73-8EEE-315AA9D54F86}
2012-08-10 16:24 - 2012-08-10 16:24 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{7AE0A846-700C-4779-88EF-01D5B8F57886}
2012-08-08 17:52 - 2012-08-08 17:52 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{68C587F9-A1AA-4D1A-BF3A-ABE4B8B41EE9}
2012-08-08 17:52 - 2012-08-08 17:52 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{049B8D47-8B1C-4C95-B33B-EF3E569CD8DC}
============ 3 Months Modified Files ========================
2012-09-07 18:02 - 2012-06-29 15:52 - 00001008 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-07 18:02 - 2009-07-14 01:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-09-07 18:01 - 2012-09-06 16:57 - 01488860 ____A C:\Windows\setupact.log
2012-09-07 18:01 - 2009-07-14 06:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-07 17:25 - 2009-07-14 06:34 - 00015360 _____ C:\Windows\System32\umstartup.etl
2012-09-06 18:37 - 2012-09-06 18:36 - 00140248 ____A C:\Windows\Minidump\090612-29312-01.dmp
2012-09-06 18:36 - 2012-09-06 18:36 - 193430492 ____A C:\Windows\MEMORY.DMP
2012-09-06 17:37 - 2012-09-06 17:37 - 00001853 ____A C:\Windows\WindowsUpdate.log
2012-09-06 17:37 - 2012-07-03 18:49 - 01334164 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-06 17:37 - 2011-06-17 17:19 - 00001912 ____A C:\Windows\epplauncher.mif
2012-09-06 17:36 - 2012-09-06 17:36 - 10299264 ____A (Microsoft Corporation) C:\Users\Miika Huttunen\Desktop\mseinstall.exe
2012-09-06 17:08 - 2012-06-29 15:52 - 00001012 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-06 17:04 - 2012-07-03 17:59 - 00010048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-06 17:04 - 2012-07-03 17:59 - 00010048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-06 16:57 - 2012-09-06 16:57 - 00000000 ____A C:\Windows\setuperr.log
2012-09-06 15:31 - 2011-01-02 18:54 - 00000969 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-08-29 18:35 - 2008-08-08 21:45 - 00000770 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-08-28 18:07 - 2012-07-09 10:05 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-28 18:07 - 2011-05-15 07:52 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-22 20:14 - 2012-08-22 20:14 - 150603838 ____A C:\Users\Miika Huttunen\Desktop\dbcjbsk2.zip
2012-08-20 21:21 - 2012-08-20 21:21 - 00001959 ____A C:\Users\Miika Huttunen\Desktop\C3.lnk
2012-08-13 16:57 - 2012-08-13 16:57 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-12 21:14 - 2008-09-28 14:55 - 00000687 ____A C:\Users\Miika Huttunen\Desktop\lainat.txt
2012-08-04 15:25 - 2012-08-04 15:25 - 00000000 ____A C:\Windows\startup.INI
2012-08-04 09:17 - 2012-08-04 09:17 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 8.lnk
2012-08-02 18:00 - 2012-08-02 18:00 - 00001631 ____A C:\Users\Miika Huttunen\Desktop\MechWarrior Online.lnk
2012-07-15 19:24 - 2009-07-14 06:33 - 00285272 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-15 19:06 - 2012-07-04 19:37 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-06 11:21 - 2008-06-07 17:50 - 00062320 ____A C:\Users\Miika Huttunen\AppData\Roaming\GDIPFONTCACHEV1.DAT
2012-07-04 20:29 - 2009-07-14 04:05 - 00152576 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-07-04 00:21 - 2012-07-04 00:21 - 00353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-07-04 00:21 - 2012-07-04 00:21 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-07-04 00:21 - 2012-07-04 00:21 - 00063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-07-04 00:21 - 2012-07-04 00:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-07-04 00:20 - 2012-07-04 00:20 - 00580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 00123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-07-03 19:44 - 2012-07-03 19:44 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-03 19:33 - 2008-08-31 22:19 - 00083872 ____A C:\Windows\System32\Drivers\atksgt.sys
2012-07-03 19:33 - 2008-08-31 22:19 - 00025888 ____A C:\Windows\System32\Drivers\lirsgt.sys
2012-07-03 19:17 - 2012-07-03 19:17 - 00001086 ____A C:\Users\Public\Desktop\DivX Plus Player.lnk
2012-07-03 19:15 - 2008-07-09 12:39 - 00001950 ____A C:\Users\Public\Desktop\FileZilla Client.lnk
2012-07-03 18:57 - 2012-07-03 18:57 - 00062320 ____A C:\Users\Miika Huttunen\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-03 18:55 - 2012-07-03 18:55 - 00000020 ___SH C:\Users\Miika Huttunen\ntuser.ini
2012-07-03 18:54 - 2009-07-14 06:57 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG
2012-07-03 18:54 - 2009-07-14 06:52 - 00028672 ____A C:\Windows\System32\config\BCD-Template
2012-07-03 18:54 - 2008-05-29 19:35 - 00008192 _RASH C:\BOOTSECT.BAK
2012-07-03 18:52 - 2012-07-03 18:52 - 00262144 ____A C:\Windows\System32\config\userdiff
2012-07-03 18:44 - 2012-07-03 18:44 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2012-07-03 18:27 - 2012-07-03 18:27 - 00021460 ____A C:\Windows\System32\emptyregdb.dat
2012-07-03 17:59 - 2012-07-03 17:59 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2012-07-03 17:58 - 2012-07-03 17:58 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_MO4Driver_01009.Wdf
2012-07-03 17:32 - 2006-11-02 14:47 - 00004176 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-03 17:32 - 2006-11-02 14:47 - 00004176 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-03 16:52 - 2012-07-03 16:38 - 00002540 ____A C:\Windows\diagwrn.xml
2012-07-03 16:52 - 2012-07-03 16:38 - 00001890 ____A C:\Windows\diagerr.xml
2012-07-03 16:48 - 2008-05-30 17:58 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-07-03 16:02 - 2012-07-03 16:01 - 03536310 ____A (FreeDownloadManager.ORG ) C:\Users\Miika Huttunen\Desktop\fdminst-lite.exe
2012-06-30 14:13 - 2012-06-30 14:13 - 00000551 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-06-12 04:40 - 2012-07-15 19:06 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
ZeroAccess:
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\@
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\L
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\n
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\U
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\U\00000001.@
ZeroAccess:
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\@
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\L
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 11%
Total physical RAM: 4095.12 MB
Available physical RAM: 3622.61 MB
Total Pagefile: 4093.39 MB
Available Pagefile: 3626.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.62 MB
==================== Partitions ============================
2 Drive c: () (Fixed) (Total:97.66 GB) (Free:11.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive d: () (Fixed) (Total:368.1 GB) (Free:212.08 GB) NTFS
5 Drive f: (HD-PCU2) (Fixed) (Total:465.65 GB) (Free:70.93 GB) FAT32
7 Drive h: (USB DISK) (Fixed) (Total:0.93 GB) (Free:0.57 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Levy tila koko vapaana dyn GPT
-------- ------------- ------- ----------- --- ---
Levy 0 Online 465 Gt 0 tavua
Levy 1 Online 465 Gt 1024 Kt
Levy 2 Ei tietov„lin 0 tavua 0 tavua
Levy 3 Online 956 Mt 0 tavua
Suljetaan DiskPart...
Last Boot: 2012-08-26 23:12
==================== End Of Log =============================
I'm one of the people hit by the delightful Sirefef virus and my computer is now in the 1 minute reboot cycle. Any help would be really appreciated. I'm using Windows 7 and MSE.
I'm quite n00b with this stuff, but read enough about the problem to run Farbar. Here are the logs:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) (x86) Version: 05-09-2012
Ran by SYSTEM at 07-09-2012 19:05:38
Running from H:\
Windows 7 Home Premium (X86) OS Language: 040B
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [111936 2008-09-03] (Apple Inc.)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [Lycosa] "C:\Program Files\Razer\Lycosa\razerhid.exe" [147456 2007-11-20] (Razer USA Ltd.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [SteelSeries World of Warcraft(R) MMO Gaming Mouse Legendary Edition] "C:\Program Files\SteelSeries\World of Warcraft(R) MMO Gaming Mouse Legendary Edition\WoWMHID4.exe" [1945600 2011-10-03] ()
HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] ()
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [40368 2011-08-31] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Miika Huttunen\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\Miika Huttunen\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-06-29] (Google Inc.)
HKU\Miika Huttunen\...\Run: [{56648676-72F0-2F72-FD54-802FED267567}] "C:\Users\Miika Huttunen\AppData\Roaming\Rybyun\moubifi.exe" [212992 2012-07-05] (Four Hundred paper)
HKU\Miika Huttunen\...\Run: [C3] [x]
HKU\UpdatusUser\...\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade [x]
HKU\UpdatusUser\...\RunOnce: [DPAPIKeyMig] %SystemRoot%\system32\dpapimig.exe -quiet [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
==================== Services ================================
3 Creative ALchemy AL6 Licensing Service; "C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe" [79360 2010-12-16] (Creative Labs)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [214952 2012-03-26] (Microsoft Corporation)
2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2010-06-29] ()
2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [189248 2010-06-29] ()
3 WPFFontCache_v0400; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [x]
==================== Drivers =================================
1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12664 2006-10-18] ()
2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [83872 2012-07-03] ()
3 bfturboh; C:\Windows\System32\drivers\bfturboh.sys [17280 2008-07-22] (BUFFALO INC.)
3 busenum; C:\Windows\System32\DRIVERS\SteelBus.sys [83840 2010-08-28] (SteelSeries Corporation)
3 DynamicEDController; \??\C:\Windows\system32\drivers\TSSFSFD.SYS [52224 2006-11-30] (TSS - www.trinity-ss.com)
3 ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan)
2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2012-07-03] ()
3 LycoFltr; C:\Windows\System32\Drivers\Lycosa.sys [16128 2008-01-18] (Razer USA Ltd.)
3 Mo3Fltr; C:\Windows\System32\drivers\Mo3Fltr.sys [11136 2008-04-15] ()
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
1 MpKsl83391dc8; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{23515FBF-24D8-4497-88E1-B26C32A04612}\MpKsl83391dc8.sys [29904 2012-09-07] (Microsoft Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [7680 2006-10-18] ()
3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham.sys [31488 2010-09-08] (SteelSeries Corporation)
3 SSMO4Filter; C:\Windows\System32\drivers\MO4Driver.sys [16896 2011-07-26] (Sagatek Co. Ltd.)
2 TSSFLT; C:\Windows\System32\DRIVERS\tssflt.sys [52224 2006-11-30] (TSS - www.trinity-ss.com)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
3 CTMOV2; \??\D:\TTST\RJ096390\CTMOV.SYS [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-09-07 18:31 - 2012-09-07 18:32 - 00000000 ____D C:\FRST
2012-09-06 18:36 - 2012-09-06 18:37 - 00140248 ____A C:\Windows\Minidump\090612-29312-01.dmp
2012-09-06 18:36 - 2012-09-06 18:36 - 193430492 ____A C:\Windows\MEMORY.DMP
2012-09-06 18:36 - 2012-09-06 18:36 - 00000000 ____D C:\Windows\Minidump
2012-09-06 17:37 - 2012-09-06 17:37 - 00001853 ____A C:\Windows\WindowsUpdate.log
2012-09-06 17:37 - 2012-09-06 17:37 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-06 17:36 - 2012-09-06 17:36 - 10299264 ____A (Microsoft Corporation) C:\Users\Miika Huttunen\Desktop\mseinstall.exe
2012-09-06 16:57 - 2012-09-07 18:01 - 01488860 ____A C:\Windows\setupact.log
2012-09-06 16:57 - 2012-09-06 16:57 - 00000000 ____A C:\Windows\setuperr.log
2012-09-06 15:36 - 2012-09-06 15:36 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{92B76C5F-CC0F-442A-AB7C-FEBCA45C1F0B}
2012-09-05 17:53 - 2012-09-05 17:53 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{C70A293C-4562-4077-8274-9D8D1D61FD19}
2012-09-04 17:27 - 2012-09-04 17:27 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{BC4B2672-4CDD-46AA-ABD8-11DBA558DF6B}
2012-09-03 19:30 - 2012-09-03 19:30 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{A77477A1-C815-408F-8341-1DF2FF58C5FA}
2012-09-02 23:31 - 2012-09-02 23:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{F34AA137-1605-4E1F-80F7-FBBAC3636922}
2012-09-02 09:51 - 2012-09-02 09:51 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{6498052A-6F50-4960-8B4A-474B64D24E69}
2012-09-01 09:53 - 2012-09-01 09:53 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{277B7FC0-0CFC-4C05-AC9A-765F6C29B72B}
2012-08-31 16:51 - 2012-08-31 16:51 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{50E2F717-E410-4C18-8B17-3D1588AE78C8}
2012-08-30 21:37 - 2012-08-30 21:37 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{305D4370-F530-4D1F-AF7D-EA9D3692924F}
2012-08-30 09:03 - 2012-08-30 09:03 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{E929B1C4-55C0-4E52-AAF8-F5FAC98FFD2D}
2012-08-29 17:17 - 2012-08-29 17:17 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{F0DF6D00-FBFB-4DDE-93F9-5479DA73DCB4}
2012-08-28 18:07 - 2012-08-28 18:07 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B3576A8D-A775-4C3B-B4AD-195A28BA96A9}
2012-08-27 17:46 - 2012-08-27 17:46 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{72AA6832-FA0B-4407-AF31-CA54BB65100F}
2012-08-26 21:05 - 2012-08-26 21:05 - 00000000 ____D C:\Users\Miika Huttunen\Documents\My Curse
2012-08-26 21:04 - 2012-08-30 17:19 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\Deployment
2012-08-26 13:04 - 2012-08-26 13:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{69AE4896-851A-4B6F-B9E7-D62086F8F310}
2012-08-25 22:22 - 2012-08-25 22:22 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{851BEC68-ED53-427A-8D7C-935E2FC27D6C}
2012-08-25 09:14 - 2012-08-25 09:14 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{F23C13CE-A93F-464A-AB80-2D0B87E86787}
2012-08-24 17:04 - 2012-08-24 17:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{98AA78F1-CEAC-4E5E-BD63-21EC63B2817C}
2012-08-23 18:40 - 2012-08-23 18:40 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{42C89C6A-2CFE-45C8-9DA7-99CE6FE8A592}
2012-08-22 20:14 - 2012-08-22 20:14 - 150603838 ____A C:\Users\Miika Huttunen\Desktop\dbcjbsk2.zip
2012-08-22 20:14 - 2012-08-22 20:14 - 00000000 ____D C:\Users\Miika Huttunen\Desktop\dbcjbsk2
2012-08-22 18:06 - 2012-08-22 18:06 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{89008E8A-2CA1-44AD-80B4-338B5C89586E}
2012-08-21 16:57 - 2012-08-21 16:57 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{807303E0-A9B9-4ADA-B6BD-86FB2A4F44B4}
2012-08-20 21:31 - 2012-08-20 21:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\Vivox
2012-08-20 21:21 - 2012-08-20 21:21 - 00001959 ____A C:\Users\Miika Huttunen\Desktop\C3.lnk
2012-08-20 21:21 - 2012-08-20 21:21 - 00000000 ____D C:\Program Files\Vivox
2012-08-20 18:28 - 2012-08-20 18:28 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{FC77D3ED-3D61-4D0E-A33C-07CDE5AD820E}
2012-08-19 09:16 - 2012-08-19 09:16 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B84B6769-C41E-4BBE-AA54-DD5B9FF6D855}
2012-08-18 09:09 - 2012-08-18 09:09 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{82A1792E-CC23-4045-A504-9A2F1A5AEB4D}
2012-08-18 09:09 - 2012-08-18 09:09 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{5116AB71-947C-45B6-8BE2-B0967A449456}
2012-08-17 17:26 - 2012-08-17 17:26 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{FAA81FB5-9FE7-45BE-8D94-6A2B05BA368D}
2012-08-17 17:26 - 2012-08-17 17:26 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{14B1B6F1-2CA2-429F-9DA9-71A7F9531020}
2012-08-16 09:04 - 2012-08-16 09:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{124EA4A8-9300-4869-BF63-F851EE32F01F}
2012-08-16 09:03 - 2012-08-16 09:04 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{4697AFAD-23BA-4B6F-960B-F9A88B76900C}
2012-08-15 14:55 - 2012-08-15 14:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{EFE6855D-AAA7-454C-BF6E-D5647A8E1D04}
2012-08-15 14:55 - 2012-08-15 14:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{7A67C5CE-02F4-426B-8D6A-6E3472409116}
2012-08-14 19:18 - 2012-08-14 21:34 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Roaming\Atappo
2012-08-14 19:18 - 2012-08-14 19:18 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Roaming\Rybyun
2012-08-14 18:58 - 2012-08-14 18:58 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{C979CBF4-B506-40EF-AFB1-79DD9E0D6601}
2012-08-14 18:58 - 2012-08-14 18:58 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{40C096E8-303A-4FB6-A7C5-702C7B6CCB8D}
2012-08-13 16:57 - 2012-08-13 16:57 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-13 16:55 - 2012-08-13 16:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B58C9616-D20A-4678-BC4D-B3701D327007}
2012-08-13 16:55 - 2012-08-13 16:55 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{B4B2864D-9151-42F9-A0C2-E4003BBC23AD}
2012-08-12 12:23 - 2012-08-12 12:23 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{54C30DF3-53AA-4278-AE79-43B15A5A3872}
2012-08-12 12:23 - 2012-08-12 12:23 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{484A1DC6-8F70-4F74-911F-2C8CC2411788}
2012-08-11 21:35 - 2012-08-11 21:35 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{846C10BA-DF1A-454B-B7CD-FCBDFEA4F588}
2012-08-11 21:35 - 2012-08-11 21:35 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{50A0A0E0-8CE0-462D-AC90-41BF598FF8D0}
2012-08-11 08:31 - 2012-08-11 08:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{D539C5E1-74CB-43BA-AA50-A07BE8F49AC5}
2012-08-11 08:31 - 2012-08-11 08:31 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{01C8530C-49D7-413F-A9DE-19A9EA03C50C}
2012-08-10 16:24 - 2012-08-10 16:24 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{E4C89827-4D6C-4F73-8EEE-315AA9D54F86}
2012-08-10 16:24 - 2012-08-10 16:24 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{7AE0A846-700C-4779-88EF-01D5B8F57886}
2012-08-08 17:52 - 2012-08-08 17:52 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{68C587F9-A1AA-4D1A-BF3A-ABE4B8B41EE9}
2012-08-08 17:52 - 2012-08-08 17:52 - 00000000 ____D C:\Users\Miika Huttunen\AppData\Local\{049B8D47-8B1C-4C95-B33B-EF3E569CD8DC}
============ 3 Months Modified Files ========================
2012-09-07 18:02 - 2012-06-29 15:52 - 00001008 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-07 18:02 - 2009-07-14 01:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-09-07 18:01 - 2012-09-06 16:57 - 01488860 ____A C:\Windows\setupact.log
2012-09-07 18:01 - 2009-07-14 06:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-07 17:25 - 2009-07-14 06:34 - 00015360 _____ C:\Windows\System32\umstartup.etl
2012-09-06 18:37 - 2012-09-06 18:36 - 00140248 ____A C:\Windows\Minidump\090612-29312-01.dmp
2012-09-06 18:36 - 2012-09-06 18:36 - 193430492 ____A C:\Windows\MEMORY.DMP
2012-09-06 17:37 - 2012-09-06 17:37 - 00001853 ____A C:\Windows\WindowsUpdate.log
2012-09-06 17:37 - 2012-07-03 18:49 - 01334164 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-06 17:37 - 2011-06-17 17:19 - 00001912 ____A C:\Windows\epplauncher.mif
2012-09-06 17:36 - 2012-09-06 17:36 - 10299264 ____A (Microsoft Corporation) C:\Users\Miika Huttunen\Desktop\mseinstall.exe
2012-09-06 17:08 - 2012-06-29 15:52 - 00001012 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-06 17:04 - 2012-07-03 17:59 - 00010048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-06 17:04 - 2012-07-03 17:59 - 00010048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-06 16:57 - 2012-09-06 16:57 - 00000000 ____A C:\Windows\setuperr.log
2012-09-06 15:31 - 2011-01-02 18:54 - 00000969 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-08-29 18:35 - 2008-08-08 21:45 - 00000770 ____A C:\Users\Public\Desktop\World of Warcraft.lnk
2012-08-28 18:07 - 2012-07-09 10:05 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-28 18:07 - 2011-05-15 07:52 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-22 20:14 - 2012-08-22 20:14 - 150603838 ____A C:\Users\Miika Huttunen\Desktop\dbcjbsk2.zip
2012-08-20 21:21 - 2012-08-20 21:21 - 00001959 ____A C:\Users\Miika Huttunen\Desktop\C3.lnk
2012-08-13 16:57 - 2012-08-13 16:57 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-12 21:14 - 2008-09-28 14:55 - 00000687 ____A C:\Users\Miika Huttunen\Desktop\lainat.txt
2012-08-04 15:25 - 2012-08-04 15:25 - 00000000 ____A C:\Windows\startup.INI
2012-08-04 09:17 - 2012-08-04 09:17 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 8.lnk
2012-08-02 18:00 - 2012-08-02 18:00 - 00001631 ____A C:\Users\Miika Huttunen\Desktop\MechWarrior Online.lnk
2012-07-15 19:24 - 2009-07-14 06:33 - 00285272 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-15 19:06 - 2012-07-04 19:37 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-06 11:21 - 2008-06-07 17:50 - 00062320 ____A C:\Users\Miika Huttunen\AppData\Roaming\GDIPFONTCACHEV1.DAT
2012-07-04 20:29 - 2009-07-14 04:05 - 00152576 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-07-04 00:21 - 2012-07-04 00:21 - 00353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-07-04 00:21 - 2012-07-04 00:21 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-07-04 00:21 - 2012-07-04 00:21 - 00063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-07-04 00:21 - 2012-07-04 00:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-07-04 00:21 - 2012-07-04 00:21 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-07-04 00:20 - 2012-07-04 00:20 - 00580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 00123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-07-04 00:20 - 2012-07-04 00:20 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-07-04 00:20 - 2012-07-04 00:20 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-07-03 19:44 - 2012-07-03 19:44 - 00001753 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-03 19:33 - 2008-08-31 22:19 - 00083872 ____A C:\Windows\System32\Drivers\atksgt.sys
2012-07-03 19:33 - 2008-08-31 22:19 - 00025888 ____A C:\Windows\System32\Drivers\lirsgt.sys
2012-07-03 19:17 - 2012-07-03 19:17 - 00001086 ____A C:\Users\Public\Desktop\DivX Plus Player.lnk
2012-07-03 19:15 - 2008-07-09 12:39 - 00001950 ____A C:\Users\Public\Desktop\FileZilla Client.lnk
2012-07-03 18:57 - 2012-07-03 18:57 - 00062320 ____A C:\Users\Miika Huttunen\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-03 18:55 - 2012-07-03 18:55 - 00000020 ___SH C:\Users\Miika Huttunen\ntuser.ini
2012-07-03 18:54 - 2009-07-14 06:57 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG
2012-07-03 18:54 - 2009-07-14 06:52 - 00028672 ____A C:\Windows\System32\config\BCD-Template
2012-07-03 18:54 - 2008-05-29 19:35 - 00008192 _RASH C:\BOOTSECT.BAK
2012-07-03 18:52 - 2012-07-03 18:52 - 00262144 ____A C:\Windows\System32\config\userdiff
2012-07-03 18:44 - 2012-07-03 18:44 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2012-07-03 18:27 - 2012-07-03 18:27 - 00021460 ____A C:\Windows\System32\emptyregdb.dat
2012-07-03 17:59 - 2012-07-03 17:59 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2012-07-03 17:58 - 2012-07-03 17:58 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_MO4Driver_01009.Wdf
2012-07-03 17:32 - 2006-11-02 14:47 - 00004176 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-03 17:32 - 2006-11-02 14:47 - 00004176 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-03 16:52 - 2012-07-03 16:38 - 00002540 ____A C:\Windows\diagwrn.xml
2012-07-03 16:52 - 2012-07-03 16:38 - 00001890 ____A C:\Windows\diagerr.xml
2012-07-03 16:48 - 2008-05-30 17:58 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-07-03 16:02 - 2012-07-03 16:01 - 03536310 ____A (FreeDownloadManager.ORG ) C:\Users\Miika Huttunen\Desktop\fdminst-lite.exe
2012-06-30 14:13 - 2012-06-30 14:13 - 00000551 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-06-12 04:40 - 2012-07-15 19:06 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
ZeroAccess:
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\@
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\L
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\n
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\U
C:\Windows\Installer\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\U\00000001.@
ZeroAccess:
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\@
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\L
C:\Users\Miika Huttunen\AppData\Local\{ba90aa56-8e63-0963-13b5-8a8e7278b06b}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 11%
Total physical RAM: 4095.12 MB
Available physical RAM: 3622.61 MB
Total Pagefile: 4093.39 MB
Available Pagefile: 3626.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.62 MB
==================== Partitions ============================
2 Drive c: () (Fixed) (Total:97.66 GB) (Free:11.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive d: () (Fixed) (Total:368.1 GB) (Free:212.08 GB) NTFS
5 Drive f: (HD-PCU2) (Fixed) (Total:465.65 GB) (Free:70.93 GB) FAT32
7 Drive h: (USB DISK) (Fixed) (Total:0.93 GB) (Free:0.57 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Levy tila koko vapaana dyn GPT
-------- ------------- ------- ----------- --- ---
Levy 0 Online 465 Gt 0 tavua
Levy 1 Online 465 Gt 1024 Kt
Levy 2 Ei tietov„lin 0 tavua 0 tavua
Levy 3 Online 956 Mt 0 tavua
Suljetaan DiskPart...
Last Boot: 2012-08-26 23:12
==================== End Of Log =============================