Vibhor
Posts: 35 +0
Hello,
My computer has been infected with Win64/Patched.A and AVG gives up warnings, but can't really delete this thing. Been looking on internet but no help yet. Here's a FRST log file if that helps anyone.
THANKS IN ADVANCE.
--------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2012
Ran by SYSTEM at 04-11-2012 11:21:26
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [x]
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 [2188904 2011-04-25] (Realtek Semiconductor)
HKLM-x32\...\Run: [Autorun Eater] C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe [516216 2010-05-06] (Old McDonald's Farm)
HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKU\Guest\...\Run: [Google Update] "C:\Users\Guest\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-27] (Google Inc.)
HKU\Vibhor\...\Run: [DKADGmon] "C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe" [947520 2012-03-07] ()
Winlogon\Notify\WB: C:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\fast64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
IMEO\AcroRd32.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\emanual.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\facemgr.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\fancystart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\liveupdate.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\logmeintoolkit.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\logonmgr.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\p4gxui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\uninstall.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\vircam.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
==================== Services (Whitelisted) ===================
2 Akamai; C:\program files (x86)\common files\akamai/netsession_win_b5e8a4c.dll [4539200 2012-11-01] (Akamai Technologies, Inc.)
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-12] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
4 Giraffic; C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [2230416 2012-01-22] (Giraffic)
2 JTAGServer; C:\altera\11.1\quartus\bin64\jtagserver.exe [272384 2011-10-31] ()
4 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-19] (LogMeIn, Inc.)
4 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-19] (LogMeIn, Inc.)
4 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe" [227232 2010-09-02] (McAfee, Inc.)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-12-15] ()
2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe" [2143552 2012-02-09] (TuneUp Software)
4 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
3 ufad-ws60; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe" -d "C:\Program Files (x86)\VMware\VMware Workstation\\" -s ufad-p2v.xml [x]
2 VC10SecS; C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe [x]
==================== Drivers (Whitelisted) =====================
3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [36256 2009-11-13] (Google Inc)
1 ATKWMIACPIIO_; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS)
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-25] (AVG Technologies CZ, s.r.o.)
1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.)
3 HH10Help.sys; \??\C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 NPF; C:\Windows\System32\Drivers\NPF.sys [47632 2009-10-20] (CACE Technologies, Inc.)
3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-02-09] (TuneUp Software)
1 vdrv1000; C:\Windows\System32\Drivers\vdrv1000.sys [223256 2010-03-25] (H+H Software GmbH)
3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2012-01-07] (Jungo)
2 XilinxPC4Driver; C:\Windows\System32\drivers\xpc4drvr.sys [27384 2012-01-07] (Xilinx, Inc.)
4 bdselfpr; [x]
3 catchme; \??\C:\ComboFix\catchme.sys [x]
3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x]
4 LMIRfsClientNP; [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-11-03 22:09 - 2012-11-04 00:38 - 00013909 ____A C:\Windows\System32\avgrep.txt
2012-11-03 22:00 - 2012-11-03 22:00 - 00000000 ____D C:\Windows\pss
2012-11-03 21:56 - 2012-11-03 21:56 - 00000019 ____A C:\Users\Vibhor\Desktop\mn.txt
2012-11-03 21:51 - 2012-11-03 21:51 - 00000000 ____D C:\Users\Vibhor\AppData\Local\Ubisoft Game Launcher
2012-11-03 21:44 - 2012-11-03 21:44 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2012-11-03 20:21 - 2012-11-03 20:21 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-03 19:20 - 2012-11-03 20:04 - 00000000 ____D C:\Users\Vibhor\AppData\Roaming\Real
2012-11-03 19:20 - 2012-11-03 20:04 - 00000000 ____D C:\Program Files (x86)\Real
2012-11-03 19:19 - 2012-11-03 20:04 - 00000000 ____D C:\Users\All Users\Real
2012-11-03 18:22 - 2012-11-03 18:42 - 00000000 ____D C:\Users\Vibhor\Desktop\RAR'
2012-11-03 17:37 - 2012-11-03 17:37 - 00000498 ____A C:\Users\Vibhor\Desktop\Driver San Francisco - Shortcut.lnk
2012-10-05 06:37 - 2012-10-05 06:37 - 00000000 ____D C:\Program Files (x86)\QuickTime
==================== 3 Months Modified Files ==================
2012-11-04 08:02 - 2009-07-13 21:13 - 00759018 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-04 07:08 - 2011-11-19 09:42 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2533852507-2709772334-1735327317-1000UA.job
2012-11-04 07:03 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-04 07:03 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-04 06:55 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-11-04 00:38 - 2012-11-03 22:09 - 00013909 ____A C:\Windows\System32\avgrep.txt
2012-11-03 21:56 - 2012-11-03 21:56 - 00000019 ____A C:\Users\Vibhor\Desktop\mn.txt
2012-11-03 17:37 - 2012-11-03 17:37 - 00000498 ____A C:\Users\Vibhor\Desktop\Driver San Francisco - Shortcut.lnk
2012-11-02 05:27 - 2011-11-19 09:42 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2533852507-2709772334-1735327317-1000Core.job
2012-10-10 18:25 - 2011-11-05 15:08 - 00002497 ____A C:\Users\Vibhor\Desktop\Google Chrome.lnk
2012-09-27 20:38 - 2011-12-15 22:32 - 00183112 ____A C:\Windows\SysWOW64\PnkBstrB.exe
2012-09-24 05:11 - 2012-08-26 06:10 - 00002454 ____A C:\Users\Guest\Desktop\Google Chrome.lnk
2012-09-13 07:08 - 2012-09-13 07:08 - 00000024 ____A C:\Users\Vibhor\Desktop\followup.txt
2012-09-12 14:19 - 2012-06-27 21:05 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-12 14:19 - 2011-11-05 19:19 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-10 08:47 - 2012-06-07 18:34 - 00000967 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-08-24 11:43 - 2012-08-24 11:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys
2012-08-22 19:52 - 2012-08-22 19:52 - 00000970 ____A C:\Users\Public\Desktop\Virtual CD v10.lnk
2012-08-22 19:33 - 2012-07-01 20:22 - 00000697 ____A C:\user.js
2012-08-09 10:02 - 2012-08-09 10:02 - 00000050 ____A C:\Users\Vibhor\Desktop\Nadia Intl Admissns Office.txt
ZeroAccess:
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\L
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\L\00000004.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\00000004.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\00000008.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\000000cb.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\80000000.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\80000032.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-01 11:49:50
Restore point made on: 2012-08-02 12:08:56
==================== Memory info ===========================
Percentage of memory in use: 14%
Total physical RAM: 3874.21 MB
Available physical RAM: 3304.27 MB
Total Pagefile: 3872.36 MB
Available Pagefile: 3299 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:116.44 GB) (Free:19.89 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (DATA) (Fixed) (Total:327.83 GB) (Free:70.53 GB) NTFS
5 Drive g: (VIBHOR) (Removable) (Total:3.74 GB) (Free:0.52 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 1024 KB
Disk 1 No Media 0 B 0 B
Disk 2 Online 3836 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 21 GB 31 KB
Partition 2 Primary 116 GB 21 GB
Partition 0 Extended 327 GB 137 GB
Partition 3 Logical 327 GB 137 GB
==================================================================================
Disk: 0
Partition 1
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C OS NTFS Partition 116 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D DATA NTFS Partition 327 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G VIBHOR FAT32 Removable 3827 MB Healthy
*******************************************************
Farbar Recovery Scan Tool (x64) Version: 30-10-2012
Ran by SYSTEM at 2012-11-04 12:15:11
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC
C:\Windows\ERDNT\cache64\services.exe
[2012-02-07 15:00] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
=========================================================
Last Boot: 2012-10-26 07:51
==================== End Of Log =============================
My computer has been infected with Win64/Patched.A and AVG gives up warnings, but can't really delete this thing. Been looking on internet but no help yet. Here's a FRST log file if that helps anyone.
THANKS IN ADVANCE.
--------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2012
Ran by SYSTEM at 04-11-2012 11:21:26
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [x]
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 [2188904 2011-04-25] (Realtek Semiconductor)
HKLM-x32\...\Run: [Autorun Eater] C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe [516216 2010-05-06] (Old McDonald's Farm)
HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKU\Guest\...\Run: [Google Update] "C:\Users\Guest\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-27] (Google Inc.)
HKU\Vibhor\...\Run: [DKADGmon] "C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe" [947520 2012-03-07] ()
Winlogon\Notify\WB: C:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\fast64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
IMEO\AcroRd32.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\emanual.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\facemgr.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\fancystart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\liveupdate.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\logmeintoolkit.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\logonmgr.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\p4gxui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\uninstall.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
IMEO\vircam.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
==================== Services (Whitelisted) ===================
2 Akamai; C:\program files (x86)\common files\akamai/netsession_win_b5e8a4c.dll [4539200 2012-11-01] (Akamai Technologies, Inc.)
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-12] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
4 Giraffic; C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [2230416 2012-01-22] (Giraffic)
2 JTAGServer; C:\altera\11.1\quartus\bin64\jtagserver.exe [272384 2011-10-31] ()
4 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-19] (LogMeIn, Inc.)
4 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-19] (LogMeIn, Inc.)
4 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe" [227232 2010-09-02] (McAfee, Inc.)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-12-15] ()
2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe" [2143552 2012-02-09] (TuneUp Software)
4 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
3 ufad-ws60; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe" -d "C:\Program Files (x86)\VMware\VMware Workstation\\" -s ufad-p2v.xml [x]
2 VC10SecS; C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe [x]
==================== Drivers (Whitelisted) =====================
3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [36256 2009-11-13] (Google Inc)
1 ATKWMIACPIIO_; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS)
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-25] (AVG Technologies CZ, s.r.o.)
1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.)
3 HH10Help.sys; \??\C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 NPF; C:\Windows\System32\Drivers\NPF.sys [47632 2009-10-20] (CACE Technologies, Inc.)
3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-02-09] (TuneUp Software)
1 vdrv1000; C:\Windows\System32\Drivers\vdrv1000.sys [223256 2010-03-25] (H+H Software GmbH)
3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2012-01-07] (Jungo)
2 XilinxPC4Driver; C:\Windows\System32\drivers\xpc4drvr.sys [27384 2012-01-07] (Xilinx, Inc.)
4 bdselfpr; [x]
3 catchme; \??\C:\ComboFix\catchme.sys [x]
3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x]
4 LMIRfsClientNP; [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-11-03 22:09 - 2012-11-04 00:38 - 00013909 ____A C:\Windows\System32\avgrep.txt
2012-11-03 22:00 - 2012-11-03 22:00 - 00000000 ____D C:\Windows\pss
2012-11-03 21:56 - 2012-11-03 21:56 - 00000019 ____A C:\Users\Vibhor\Desktop\mn.txt
2012-11-03 21:51 - 2012-11-03 21:51 - 00000000 ____D C:\Users\Vibhor\AppData\Local\Ubisoft Game Launcher
2012-11-03 21:44 - 2012-11-03 21:44 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2012-11-03 20:21 - 2012-11-03 20:21 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-11-03 19:20 - 2012-11-03 20:04 - 00000000 ____D C:\Users\Vibhor\AppData\Roaming\Real
2012-11-03 19:20 - 2012-11-03 20:04 - 00000000 ____D C:\Program Files (x86)\Real
2012-11-03 19:19 - 2012-11-03 20:04 - 00000000 ____D C:\Users\All Users\Real
2012-11-03 18:22 - 2012-11-03 18:42 - 00000000 ____D C:\Users\Vibhor\Desktop\RAR'
2012-11-03 17:37 - 2012-11-03 17:37 - 00000498 ____A C:\Users\Vibhor\Desktop\Driver San Francisco - Shortcut.lnk
2012-10-05 06:37 - 2012-10-05 06:37 - 00000000 ____D C:\Program Files (x86)\QuickTime
==================== 3 Months Modified Files ==================
2012-11-04 08:02 - 2009-07-13 21:13 - 00759018 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-04 07:08 - 2011-11-19 09:42 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2533852507-2709772334-1735327317-1000UA.job
2012-11-04 07:03 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-04 07:03 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-04 06:55 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-11-04 00:38 - 2012-11-03 22:09 - 00013909 ____A C:\Windows\System32\avgrep.txt
2012-11-03 21:56 - 2012-11-03 21:56 - 00000019 ____A C:\Users\Vibhor\Desktop\mn.txt
2012-11-03 17:37 - 2012-11-03 17:37 - 00000498 ____A C:\Users\Vibhor\Desktop\Driver San Francisco - Shortcut.lnk
2012-11-02 05:27 - 2011-11-19 09:42 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2533852507-2709772334-1735327317-1000Core.job
2012-10-10 18:25 - 2011-11-05 15:08 - 00002497 ____A C:\Users\Vibhor\Desktop\Google Chrome.lnk
2012-09-27 20:38 - 2011-12-15 22:32 - 00183112 ____A C:\Windows\SysWOW64\PnkBstrB.exe
2012-09-24 05:11 - 2012-08-26 06:10 - 00002454 ____A C:\Users\Guest\Desktop\Google Chrome.lnk
2012-09-13 07:08 - 2012-09-13 07:08 - 00000024 ____A C:\Users\Vibhor\Desktop\followup.txt
2012-09-12 14:19 - 2012-06-27 21:05 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-12 14:19 - 2011-11-05 19:19 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-10 08:47 - 2012-06-07 18:34 - 00000967 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-08-24 11:43 - 2012-08-24 11:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys
2012-08-22 19:52 - 2012-08-22 19:52 - 00000970 ____A C:\Users\Public\Desktop\Virtual CD v10.lnk
2012-08-22 19:33 - 2012-07-01 20:22 - 00000697 ____A C:\user.js
2012-08-09 10:02 - 2012-08-09 10:02 - 00000050 ____A C:\Users\Vibhor\Desktop\Nadia Intl Admissns Office.txt
ZeroAccess:
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\L
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\L\00000004.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\00000004.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\00000008.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\000000cb.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\80000000.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\80000032.@
C:\Windows\Installer\{9ce6e964-1aaa-a36a-a94d-b658d72f2dcb}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-01 11:49:50
Restore point made on: 2012-08-02 12:08:56
==================== Memory info ===========================
Percentage of memory in use: 14%
Total physical RAM: 3874.21 MB
Available physical RAM: 3304.27 MB
Total Pagefile: 3872.36 MB
Available Pagefile: 3299 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:116.44 GB) (Free:19.89 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (DATA) (Fixed) (Total:327.83 GB) (Free:70.53 GB) NTFS
5 Drive g: (VIBHOR) (Removable) (Total:3.74 GB) (Free:0.52 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 1024 KB
Disk 1 No Media 0 B 0 B
Disk 2 Online 3836 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 21 GB 31 KB
Partition 2 Primary 116 GB 21 GB
Partition 0 Extended 327 GB 137 GB
Partition 3 Logical 327 GB 137 GB
==================================================================================
Disk: 0
Partition 1
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C OS NTFS Partition 116 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D DATA NTFS Partition 327 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G VIBHOR FAT32 Removable 3827 MB Healthy
*******************************************************
Farbar Recovery Scan Tool (x64) Version: 30-10-2012
Ran by SYSTEM at 2012-11-04 12:15:11
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC
C:\Windows\ERDNT\cache64\services.exe
[2012-02-07 15:00] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
=========================================================
Last Boot: 2012-10-26 07:51
==================== End Of Log =============================