My wife's laptop has got an awful infection that I can't even begin to tackle. It's managed to, so far, involve what I suspect are fake Blue Screen crashes, invalidation of my Windows Activation Key (or a fake version of that -- until I've got this sorted out, I'm not retyping my key), and the "Windows has encountered a critical error, rebooting in one minute" issue.
Oh, also it's got a browser redirect in IE I can't find, and Microsoft Security Essentials (when it runs) will identify Sirefef.r, but it tends to trigger the fake Blue Screen and reboot the system. Oh, and Windows Firewall is not only down, it refuses to come back up -- I can't even access the on/off switch on that.
I've tried to run the Farbar tool (plugged into a USB drive) -- except I don't seem to HAVE a "Systems Recovery Option". I hit F8 and get a choice between Safe Mode, Safe Mode with Command Prompt, Safe Mode with Networking, and some other stuff -- but no recovery option. So I had to run it from the command line. So I'm giving you what I have in the fond hopes someone can talk me through doing it right.
The laptop is running Vista Home Premium SP2, and the infection happened yesterday or the day before and the system seems to be getting progressively worse. Here's the abbreviated (from the Safe Mode Command Prompt) frst file:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by HRH Queen Adminia at 29-07-2012 13:15:09
Running from F:\
Service Pack 2 (X86) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-29 13:15 - 2012-07-29 13:15 - 00000000 ____D C:\FRST
2012-07-29 12:46 - 2012-07-29 12:47 - 00000000 ___SD C:\32788R22FWJFW
2012-07-29 12:41 - 2012-07-29 12:42 - 00000680 ____A C:\Users\Megan Hutchison\AppData\Local\d3d9caps.dat
2012-07-29 12:31 - 2012-07-29 12:35 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:31 - 2012-07-29 12:35 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:31 - 2012-07-29 12:31 - 00000552 ____A C:\Windows\System32\spsys.log
2012-07-29 11:52 - 2012-07-29 11:52 - 00134352 ____A C:\Windows\Minidump\Mini072912-02.dmp
2012-07-29 11:41 - 2012-07-29 11:41 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 11:16 - 2012-07-29 11:52 - 124869831 ____A C:\Windows\MEMORY.DMP
2012-07-29 11:16 - 2012-07-29 11:16 - 00134352 ____A C:\Windows\Minidump\Mini072912-01.dmp
2012-07-27 17:04 - 2012-07-27 17:04 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{CCFB4819-0083-4B7C-B858-08DB5DB51345}
2012-07-27 17:04 - 2012-07-27 17:04 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{62F1FC55-045E-48FF-B5C4-22B828CD522B}
2012-07-26 12:52 - 2012-07-26 12:52 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{FDF71062-D6B2-4E50-BF18-A09BDEB0D35B}
2012-07-26 12:52 - 2012-07-26 12:52 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{18B286B8-4B13-4242-AEF5-1D2D356C8CF3}
2012-07-19 13:07 - 2012-07-19 13:08 - 00000000 ____D C:\Program Files\iTunes(6)
2012-07-19 13:07 - 2012-07-19 13:07 - 00000000 ____D C:\Program Files\iPod(5)
2012-07-19 13:02 - 2012-07-29 10:13 - 00000000 ____D C:\Users\HRH Queen Adminia\{bc5d5687-a2ae-4897-a157-f7c7a3ff18d0}
2012-07-19 12:40 - 2012-07-19 12:40 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{749BCDBD-E25A-40E7-A232-C2D3539382E6}
2012-07-19 12:40 - 2012-07-19 12:40 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{310A49D1-68D2-4A0D-98E6-E0C2B16A5306}
2012-07-13 11:38 - 2012-07-13 11:38 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{9E17CE1F-D70B-4854-B235-30FF6DF1B731}
2012-07-13 11:38 - 2012-07-13 11:38 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{63B94AA8-4FCA-494E-8AB7-BDE856786435}
2012-07-13 03:10 - 2012-06-13 08:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-13 03:04 - 2012-06-02 04:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-13 03:04 - 2012-06-02 03:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-13 03:04 - 2012-06-02 03:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-13 03:04 - 2012-06-02 03:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-13 03:04 - 2012-06-02 03:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-13 03:04 - 2012-06-02 03:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-13 03:04 - 2012-06-02 03:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-13 03:04 - 2012-06-02 03:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-13 03:04 - 2012-06-02 03:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-13 03:04 - 2012-06-02 03:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-13 03:04 - 2012-06-02 03:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-13 03:04 - 2012-06-02 03:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-13 03:04 - 2012-06-02 03:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-13 03:04 - 2012-06-02 03:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 14:46 - 2012-06-08 12:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-12 14:46 - 2012-06-05 11:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-12 14:46 - 2012-06-05 11:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-12 14:45 - 2012-06-04 10:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-12 14:45 - 2012-06-01 19:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-12 14:45 - 2012-06-01 19:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-08 17:26 - 2012-07-08 17:26 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\Deployment
2012-07-02 11:35 - 2012-07-02 11:35 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{F4B1FB6B-9C61-41FC-BA5E-96646570DA86}
2012-07-02 11:35 - 2012-07-02 11:35 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{A625F159-C2B6-417E-A268-D95AD2454482}
2012-06-30 04:15 - 2012-06-30 04:15 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{01FF88FB-646F-462E-9ACD-07412B4A2247}
2012-06-30 04:13 - 2012-06-30 04:15 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{9082990B-C52B-469E-B78E-784FCEB77709}
2012-06-29 13:24 - 2012-06-29 13:25 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{29938411-1890-4A7D-ACA7-1A0F0C260F52}
============ 3 Months Modified Files ========================
2012-07-29 13:14 - 2006-11-02 07:52 - 01591348 ____A C:\Windows\WindowsUpdate.log
2012-07-29 13:13 - 2011-11-23 18:28 - 00021780 ____A C:\aaw7boot.log
2012-07-29 12:43 - 2011-01-13 20:25 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-29 12:42 - 2012-07-29 12:41 - 00000680 ____A C:\Users\Megan Hutchison\AppData\Local\d3d9caps.dat
2012-07-29 12:41 - 2011-04-23 21:50 - 00002281 ____A C:\Users\Public\Desktop\Safari.lnk
2012-07-29 12:36 - 2011-01-17 18:31 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-29 12:35 - 2012-07-29 12:31 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:35 - 2012-07-29 12:31 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:35 - 2006-11-02 08:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-29 12:31 - 2012-07-29 12:31 - 00000552 ____A C:\Windows\System32\spsys.log
2012-07-29 11:52 - 2012-07-29 11:52 - 00134352 ____A C:\Windows\Minidump\Mini072912-02.dmp
2012-07-29 11:52 - 2012-07-29 11:16 - 124869831 ____A C:\Windows\MEMORY.DMP
2012-07-29 11:52 - 2011-01-12 08:56 - 00029256 ____A C:\Windows\PFRO.log
2012-07-29 11:38 - 2011-01-13 19:46 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 11:31 - 2011-01-17 18:31 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-29 11:16 - 2012-07-29 11:16 - 00134352 ____A C:\Windows\Minidump\Mini072912-01.dmp
2012-07-29 10:40 - 2006-11-02 08:01 - 00032624 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-29 10:13 - 2006-11-02 05:22 - 51904512 ____A C:\Windows\System32\config\software_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 36438016 ____A C:\Windows\System32\config\components_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 17301504 ____A C:\Windows\System32\config\system_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 04980736 ____A C:\Windows\System32\config\default_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-07-28 19:30 - 2011-01-11 20:24 - 00090952 ____A C:\Users\HRH Queen Adminia\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-13 03:31 - 2006-11-02 07:47 - 00355168 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-13 03:09 - 2006-11-02 05:23 - 00000219 ____A C:\Windows\win.ini
2012-07-13 03:05 - 2006-11-02 05:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-12 22:48 - 2011-02-18 22:46 - 00017408 ____A C:\Users\Megan Hutchison\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-29 15:06 - 2011-02-16 18:18 - 00090952 ____A C:\Users\Caleb\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-28 11:22 - 2012-06-22 18:23 - 00000059 ____A C:\Users\Megan Hutchison\Downloads\d50810c0.js
2012-06-28 11:21 - 2012-06-28 11:11 - 642373584 ____A C:\Users\Megan Hutchison\Downloads\AP English Files.zip
2012-06-22 15:04 - 2011-01-12 09:53 - 00090952 ____A C:\Users\Megan Hutchison\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-17 16:39 - 2011-11-29 18:26 - 00000064 ____A C:\Windows\System32\rp_stats.dat
2012-06-17 16:39 - 2011-11-29 18:26 - 00000044 ____A C:\Windows\System32\rp_rules.dat
2012-06-13 08:40 - 2012-07-13 03:10 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 12:47 - 2012-07-12 14:46 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 11:47 - 2012-07-12 14:46 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 11:47 - 2012-07-12 14:46 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 10:26 - 2012-07-12 14:45 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 17:19 - 2012-06-24 13:24 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 17:19 - 2012-06-24 13:24 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 17:19 - 2012-06-24 13:24 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 17:19 - 2012-06-24 13:23 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 17:19 - 2012-06-24 13:23 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 17:12 - 2012-06-24 13:24 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 17:12 - 2012-06-24 13:23 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-24 13:23 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:12 - 2012-06-24 13:23 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:07 - 2012-07-13 03:04 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 03:43 - 2012-07-13 03:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 03:33 - 2012-07-13 03:04 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 03:26 - 2012-07-13 03:04 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 03:25 - 2012-07-13 03:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 03:25 - 2012-07-13 03:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 03:23 - 2012-07-13 03:04 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 03:21 - 2012-07-13 03:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 03:20 - 2012-07-13 03:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 03:19 - 2012-07-13 03:04 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:19 - 2012-07-13 03:04 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:17 - 2012-07-13 03:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:16 - 2012-07-13 03:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:14 - 2012-07-13 03:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 19:04 - 2012-07-12 14:45 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 19:03 - 2012-07-12 14:45 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-22 22:00 - 2011-08-30 20:25 - 00001992 ____A C:\Users\Public\Desktop\Amazon Cloud Player.lnk
2012-05-19 00:24 - 2012-05-19 00:24 - 00001726 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-01 09:03 - 2012-06-14 12:41 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
ZeroAccess:
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\@
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\L
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\n
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\U
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\L\00000004.@
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\L\201d3dde
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 1917.32 MB
Available physical RAM: 1592.82 MB
Total Pagefile: 4077.18 MB
Available Pagefile: 3903.14 MB
Total Virtual: 2047.88 MB
Available Virtual: 1962.2 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:298.09 GB) (Free:144.85 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
4 Drive f: (Cruzer) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 1 Online 1908 MB 0 B
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1908 MB 65 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 F Cruzer FAT Removable 1908 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-29 12:07
======================= End Of Log ==========================
Oh, also it's got a browser redirect in IE I can't find, and Microsoft Security Essentials (when it runs) will identify Sirefef.r, but it tends to trigger the fake Blue Screen and reboot the system. Oh, and Windows Firewall is not only down, it refuses to come back up -- I can't even access the on/off switch on that.
I've tried to run the Farbar tool (plugged into a USB drive) -- except I don't seem to HAVE a "Systems Recovery Option". I hit F8 and get a choice between Safe Mode, Safe Mode with Command Prompt, Safe Mode with Networking, and some other stuff -- but no recovery option. So I had to run it from the command line. So I'm giving you what I have in the fond hopes someone can talk me through doing it right.
The laptop is running Vista Home Premium SP2, and the infection happened yesterday or the day before and the system seems to be getting progressively worse. Here's the abbreviated (from the Safe Mode Command Prompt) frst file:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by HRH Queen Adminia at 29-07-2012 13:15:09
Running from F:\
Service Pack 2 (X86) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-29 13:15 - 2012-07-29 13:15 - 00000000 ____D C:\FRST
2012-07-29 12:46 - 2012-07-29 12:47 - 00000000 ___SD C:\32788R22FWJFW
2012-07-29 12:41 - 2012-07-29 12:42 - 00000680 ____A C:\Users\Megan Hutchison\AppData\Local\d3d9caps.dat
2012-07-29 12:31 - 2012-07-29 12:35 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:31 - 2012-07-29 12:35 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:31 - 2012-07-29 12:31 - 00000552 ____A C:\Windows\System32\spsys.log
2012-07-29 11:52 - 2012-07-29 11:52 - 00134352 ____A C:\Windows\Minidump\Mini072912-02.dmp
2012-07-29 11:41 - 2012-07-29 11:41 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-29 11:16 - 2012-07-29 11:52 - 124869831 ____A C:\Windows\MEMORY.DMP
2012-07-29 11:16 - 2012-07-29 11:16 - 00134352 ____A C:\Windows\Minidump\Mini072912-01.dmp
2012-07-27 17:04 - 2012-07-27 17:04 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{CCFB4819-0083-4B7C-B858-08DB5DB51345}
2012-07-27 17:04 - 2012-07-27 17:04 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{62F1FC55-045E-48FF-B5C4-22B828CD522B}
2012-07-26 12:52 - 2012-07-26 12:52 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{FDF71062-D6B2-4E50-BF18-A09BDEB0D35B}
2012-07-26 12:52 - 2012-07-26 12:52 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{18B286B8-4B13-4242-AEF5-1D2D356C8CF3}
2012-07-19 13:07 - 2012-07-19 13:08 - 00000000 ____D C:\Program Files\iTunes(6)
2012-07-19 13:07 - 2012-07-19 13:07 - 00000000 ____D C:\Program Files\iPod(5)
2012-07-19 13:02 - 2012-07-29 10:13 - 00000000 ____D C:\Users\HRH Queen Adminia\{bc5d5687-a2ae-4897-a157-f7c7a3ff18d0}
2012-07-19 12:40 - 2012-07-19 12:40 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{749BCDBD-E25A-40E7-A232-C2D3539382E6}
2012-07-19 12:40 - 2012-07-19 12:40 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{310A49D1-68D2-4A0D-98E6-E0C2B16A5306}
2012-07-13 11:38 - 2012-07-13 11:38 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{9E17CE1F-D70B-4854-B235-30FF6DF1B731}
2012-07-13 11:38 - 2012-07-13 11:38 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{63B94AA8-4FCA-494E-8AB7-BDE856786435}
2012-07-13 03:10 - 2012-06-13 08:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-13 03:04 - 2012-06-02 04:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-13 03:04 - 2012-06-02 03:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-13 03:04 - 2012-06-02 03:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-13 03:04 - 2012-06-02 03:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-13 03:04 - 2012-06-02 03:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-13 03:04 - 2012-06-02 03:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-13 03:04 - 2012-06-02 03:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-13 03:04 - 2012-06-02 03:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-13 03:04 - 2012-06-02 03:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-13 03:04 - 2012-06-02 03:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-13 03:04 - 2012-06-02 03:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-13 03:04 - 2012-06-02 03:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-13 03:04 - 2012-06-02 03:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-13 03:04 - 2012-06-02 03:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 14:46 - 2012-06-08 12:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-12 14:46 - 2012-06-05 11:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-12 14:46 - 2012-06-05 11:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-12 14:45 - 2012-06-04 10:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-12 14:45 - 2012-06-01 19:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-12 14:45 - 2012-06-01 19:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-08 17:26 - 2012-07-08 17:26 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\Deployment
2012-07-02 11:35 - 2012-07-02 11:35 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{F4B1FB6B-9C61-41FC-BA5E-96646570DA86}
2012-07-02 11:35 - 2012-07-02 11:35 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{A625F159-C2B6-417E-A268-D95AD2454482}
2012-06-30 04:15 - 2012-06-30 04:15 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{01FF88FB-646F-462E-9ACD-07412B4A2247}
2012-06-30 04:13 - 2012-06-30 04:15 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{9082990B-C52B-469E-B78E-784FCEB77709}
2012-06-29 13:24 - 2012-06-29 13:25 - 00000000 ____D C:\Users\Megan Hutchison\AppData\Local\{29938411-1890-4A7D-ACA7-1A0F0C260F52}
============ 3 Months Modified Files ========================
2012-07-29 13:14 - 2006-11-02 07:52 - 01591348 ____A C:\Windows\WindowsUpdate.log
2012-07-29 13:13 - 2011-11-23 18:28 - 00021780 ____A C:\aaw7boot.log
2012-07-29 12:43 - 2011-01-13 20:25 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-29 12:42 - 2012-07-29 12:41 - 00000680 ____A C:\Users\Megan Hutchison\AppData\Local\d3d9caps.dat
2012-07-29 12:41 - 2011-04-23 21:50 - 00002281 ____A C:\Users\Public\Desktop\Safari.lnk
2012-07-29 12:36 - 2011-01-17 18:31 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-29 12:35 - 2012-07-29 12:31 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:35 - 2012-07-29 12:31 - 00000736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-29 12:35 - 2006-11-02 08:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-29 12:31 - 2012-07-29 12:31 - 00000552 ____A C:\Windows\System32\spsys.log
2012-07-29 11:52 - 2012-07-29 11:52 - 00134352 ____A C:\Windows\Minidump\Mini072912-02.dmp
2012-07-29 11:52 - 2012-07-29 11:16 - 124869831 ____A C:\Windows\MEMORY.DMP
2012-07-29 11:52 - 2011-01-12 08:56 - 00029256 ____A C:\Windows\PFRO.log
2012-07-29 11:38 - 2011-01-13 19:46 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-29 11:31 - 2011-01-17 18:31 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-29 11:16 - 2012-07-29 11:16 - 00134352 ____A C:\Windows\Minidump\Mini072912-01.dmp
2012-07-29 10:40 - 2006-11-02 08:01 - 00032624 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-29 10:13 - 2006-11-02 05:22 - 51904512 ____A C:\Windows\System32\config\software_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 36438016 ____A C:\Windows\System32\config\components_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 17301504 ____A C:\Windows\System32\config\system_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 04980736 ____A C:\Windows\System32\config\default_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-07-29 10:13 - 2006-11-02 05:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-07-28 19:30 - 2011-01-11 20:24 - 00090952 ____A C:\Users\HRH Queen Adminia\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-13 03:31 - 2006-11-02 07:47 - 00355168 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-13 03:09 - 2006-11-02 05:23 - 00000219 ____A C:\Windows\win.ini
2012-07-13 03:05 - 2006-11-02 05:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-12 22:48 - 2011-02-18 22:46 - 00017408 ____A C:\Users\Megan Hutchison\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-29 15:06 - 2011-02-16 18:18 - 00090952 ____A C:\Users\Caleb\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-28 11:22 - 2012-06-22 18:23 - 00000059 ____A C:\Users\Megan Hutchison\Downloads\d50810c0.js
2012-06-28 11:21 - 2012-06-28 11:11 - 642373584 ____A C:\Users\Megan Hutchison\Downloads\AP English Files.zip
2012-06-22 15:04 - 2011-01-12 09:53 - 00090952 ____A C:\Users\Megan Hutchison\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-17 16:39 - 2011-11-29 18:26 - 00000064 ____A C:\Windows\System32\rp_stats.dat
2012-06-17 16:39 - 2011-11-29 18:26 - 00000044 ____A C:\Windows\System32\rp_rules.dat
2012-06-13 08:40 - 2012-07-13 03:10 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 12:47 - 2012-07-12 14:46 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 11:47 - 2012-07-12 14:46 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 11:47 - 2012-07-12 14:46 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 10:26 - 2012-07-12 14:45 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 17:19 - 2012-06-24 13:24 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 17:19 - 2012-06-24 13:24 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 17:19 - 2012-06-24 13:24 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 17:19 - 2012-06-24 13:23 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 17:19 - 2012-06-24 13:23 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 17:12 - 2012-06-24 13:24 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 17:12 - 2012-06-24 13:23 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-24 13:23 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:12 - 2012-06-24 13:23 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:07 - 2012-07-13 03:04 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 03:43 - 2012-07-13 03:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 03:33 - 2012-07-13 03:04 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 03:26 - 2012-07-13 03:04 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 03:25 - 2012-07-13 03:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 03:25 - 2012-07-13 03:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 03:23 - 2012-07-13 03:04 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 03:21 - 2012-07-13 03:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 03:20 - 2012-07-13 03:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 03:19 - 2012-07-13 03:04 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:19 - 2012-07-13 03:04 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:17 - 2012-07-13 03:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:16 - 2012-07-13 03:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:14 - 2012-07-13 03:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 19:04 - 2012-07-12 14:45 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 19:03 - 2012-07-12 14:45 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-22 22:00 - 2011-08-30 20:25 - 00001992 ____A C:\Users\Public\Desktop\Amazon Cloud Player.lnk
2012-05-19 00:24 - 2012-05-19 00:24 - 00001726 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-01 09:03 - 2012-06-14 12:41 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
ZeroAccess:
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\@
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\L
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\n
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\U
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\L\00000004.@
C:\Windows\Installer\{4b093b68-8c67-1628-5af8-f8e50037688c}\L\201d3dde
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 1917.32 MB
Available physical RAM: 1592.82 MB
Total Pagefile: 4077.18 MB
Available Pagefile: 3903.14 MB
Total Virtual: 2047.88 MB
Available Virtual: 1962.2 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:298.09 GB) (Free:144.85 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
3 Drive e: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
4 Drive f: (Cruzer) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 1 Online 1908 MB 0 B
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1908 MB 65 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 F Cruzer FAT Removable 1908 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-29 12:07
======================= End Of Log ==========================