himynameisping
Posts: 9 +0
Hi all,
ESET NOD32 is having trouble getting rid of these 2 trojans (Win64/Sirefef.AE trojan & Win64/Agent.BA trojan) from my computer. The error is, "Event occurred during an attempt to access the file by the application: C:\Windows\System32\services.exe." Here's my FRST log.
Scan result of Farbar Recovery Scan Tool Version: 28-06-2012
Ran by SYSTEM at 28-06-2012 11:47:34
Running from F:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2918656 2011-01-12] (ESET)
HKLM\...\Run: [Cm108Sound] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd [8146944 2009-10-09] (C-Media Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-06-23] (Logitech, Inc.)
HKLM\...\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" [371712 2009-09-24] (Microsoft Corporation)
HKLM\...\Run: [dinhea] rundll32.exe "C:\Users\Ping\AppData\Roaming\dinhea.dll",SetQoSql [133632 2012-06-27] (DT Soft Ltd)
HKLM\...\Run: [smpcat] "C:\Windows\System32\rundll32.exe" "C:\Users\Ping\AppData\Roaming\smpcat.dll",FreeObjectInfo [394752 2012-06-27] (C-Media Electronics Inc.)
HKLM\...\Run: [TNOD UP] "C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe" /I [x]
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-03-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Ping\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3481408 2012-02-13] (DT Soft Ltd)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [462408 2012-04-04] (Malwarebytes Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit [1712176 2012-01-25] (Soluto)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 68.238.64.12
AppInit_DLLs: acaptuser64.dll
Startup: C:\Users\Ping\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
4 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42360 2011-01-12] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810144 2011-01-12] (ESET)
2 ExpatShieldService; C:\Program Files (x86)\Expat Shield\bin\openvpnas.exe [331608 2012-01-17] ()
3 ExpatSrv; C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe [363336 2012-01-04] (AnchorFree Inc.)
3 ExpatTrayService; C:\Program Files (x86)\Expat Shield\bin\ExpatTrayService.EXE [77520 2012-01-17] ()
3 ExpatWd; C:\Program Files (x86)\Expat Shield\bin\hsswd.exe -product Expat [329544 2012-01-04] ()
3 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [5352960 2011-04-07] (Native Instruments GmbH)
4 SolutoService; "C:\Program Files\Soluto\SolutoService.exe" [547872 2012-01-25] (Soluto)
========================== Drivers (Whitelisted) =============
3 a2djavs; C:\Windows\System32\Drivers\a2djavs.sys [358480 2011-04-11] (Native Instruments GmbH)
3 a2djusb_svc; C:\Windows\System32\Drivers\a2djusb.sys [96848 2011-04-11] (Native Instruments GmbH)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [170640 2010-12-21] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [141264 2010-12-21] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [125296 2010-12-21] (ESET)
3 ks4avs; C:\Windows\System32\Drivers\ks4avs.sys [357968 2011-09-15] (Native Instruments GmbH)
3 ks4usb_svc; C:\Windows\System32\Drivers\ks4usb.sys [98896 2011-09-15] (Native Instruments GmbH)
3 kx1avs; C:\Windows\System32\Drivers\kx1avs.sys [358480 2011-04-11] (Native Instruments GmbH)
3 kx1usb_svc; C:\Windows\System32\Drivers\kx1usb.sys [70224 2011-04-11] (Native Instruments GmbH)
3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.sys [76056 2011-04-30] (Logitech, Inc.)
3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.sys [15128 2011-04-30] (Logitech, Inc.)
0 Soluto; C:\Windows\System32\Drivers\Soluto.sys [54728 2012-01-25] (Soluto LTD.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [564792 2012-03-31] (Duplex Secure Ltd.)
3 USBPNPA; C:\Windows\System32\drivers\CM10864.sys [1307648 2009-09-29] (C-Media Electronics Inc)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-28 11:47 - 2012-06-28 11:47 - 00000000 ____D C:\FRST
2012-06-28 10:26 - 2012-06-28 10:26 - 01427939 ____A C:\Users\Ping\Downloads\FRST64.exe
2012-06-28 10:21 - 2012-06-28 10:21 - 00607260 ____R (Swearware) C:\Users\Ping\Downloads\dds.scr
2012-06-28 10:18 - 2012-06-28 10:18 - 00302592 ____A C:\Users\Ping\Downloads\coj6789i.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Ping\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-28 10:15 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-28 09:27 - 2012-06-28 09:27 - 00000324 ____A C:\Windows\PFRO.log
2012-06-28 01:29 - 2012-06-28 01:40 - 03306209 ____A C:\Users\Ping\Downloads\ASAP-Rocky-Ft.-Lana-Del-Ray---Ridin--EM0612.mp3
2012-06-27 23:44 - 2012-06-27 23:53 - 00000000 ____D C:\Program Files (x86)\TNod User & Password Finder
2012-06-27 23:38 - 2012-06-27 23:38 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-27 23:30 - 2012-06-27 23:43 - 00000000 ____D C:\Users\Ping\Desktop\TNod-1.4.1.0-Final
2012-06-27 23:25 - 2012-06-28 02:20 - 89988630 ____A C:\Users\Ping\Desktop\[SaHa] Charlie Nishinaka - Cheers Vol.07 (English).rar
2012-06-27 23:25 - 2012-06-27 23:25 - 00394752 ____A (C-Media Electronics Inc.) C:\Users\Ping\AppData\Roaming\smpcat.dll
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Ping\AppData\Local\{622C0C3A-C0F2-11E1-8270-B8AC6F996F26}
2012-06-27 23:24 - 2012-06-27 23:27 - 00000000 ____D C:\Users\All Users\B7E8587A00007C620003E42AA6014588
2012-06-27 23:24 - 2012-06-27 23:24 - 00133632 __ASH (DT Soft Ltd) C:\Users\Ping\AppData\Roaming\dinhea.dll
2012-06-24 19:36 - 2012-06-24 19:39 - 00000000 ____D C:\Users\Ping\Desktop\fun.-Some Nights (2012) 320Kbit(mp3) DMT
2012-06-17 10:21 - 2012-06-17 10:22 - 00000000 ____D C:\Program Files\iTunes
2012-06-17 10:21 - 2012-06-17 10:21 - 00000000 ____D C:\Program Files\iPod
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Users\Ping\AppData\Local\Xenocode
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key LLC
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key 4
2012-06-16 16:19 - 2012-06-16 16:19 - 00000100 ____A C:\Users\All Users\Microsoft.SqlServer.Compact.400.32.bc
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed_In_Key_LLC
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed In Key
2012-06-16 16:17 - 2012-06-16 16:17 - 00000000 ____D C:\Users\Ping\Desktop\Mash-Up 1.5, Mixed In Key 4, Platinum Notes 3 + Serials
2012-06-13 07:04 - 2012-06-13 07:04 - 00000000 ____D C:\Users\Ping\AppData\Local\Macromedia
2012-06-06 22:35 - 2012-06-06 22:35 - 00000000 ____D C:\Users\Ping\AppData\Roaming\LOVE
============ 3 Months Modified Files and Folders =============
2012-06-28 10:45 - 2010-08-19 00:00 - 01917560 ____A C:\Windows\WindowsUpdate.log
2012-06-28 10:43 - 2011-05-08 23:08 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-28 10:40 - 2009-07-13 21:13 - 00778150 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-28 10:26 - 2012-06-28 10:26 - 01427939 ____A C:\Users\Ping\Downloads\FRST64.exe
2012-06-28 10:21 - 2012-06-28 10:21 - 00607260 ____R (Swearware) C:\Users\Ping\Downloads\dds.scr
2012-06-28 10:18 - 2012-06-28 10:18 - 00302592 ____A C:\Users\Ping\Downloads\coj6789i.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Ping\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-28 09:33 - 2009-07-13 20:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-28 09:33 - 2009-07-13 20:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-28 09:27 - 2012-06-28 09:27 - 00000324 ____A C:\Windows\PFRO.log
2012-06-28 09:27 - 2012-04-15 23:57 - 00019515 ____A C:\Windows\setupact.log
2012-06-28 09:27 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-28 02:20 - 2012-06-27 23:25 - 89988630 ____A C:\Users\Ping\Desktop\[SaHa] Charlie Nishinaka - Cheers Vol.07 (English).rar
2012-06-28 01:40 - 2012-06-28 01:29 - 03306209 ____A C:\Users\Ping\Downloads\ASAP-Rocky-Ft.-Lana-Del-Ray---Ridin--EM0612.mp3
2012-06-28 01:40 - 2010-08-19 00:58 - 00000000 ____D C:\Users\Ping\AppData\Roaming\uTorrent
2012-06-27 23:53 - 2012-06-27 23:44 - 00000000 ____D C:\Program Files (x86)\TNod User & Password Finder
2012-06-27 23:53 - 2012-03-11 20:08 - 00000000 ____D C:\Users\All Users\Skype
2012-06-27 23:43 - 2012-06-27 23:30 - 00000000 ____D C:\Users\Ping\Desktop\TNod-1.4.1.0-Final
2012-06-27 23:38 - 2012-06-27 23:38 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-27 23:27 - 2012-06-27 23:24 - 00000000 ____D C:\Users\All Users\B7E8587A00007C620003E42AA6014588
2012-06-27 23:25 - 2012-06-27 23:25 - 00394752 ____A (C-Media Electronics Inc.) C:\Users\Ping\AppData\Roaming\smpcat.dll
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Ping\AppData\Local\{622C0C3A-C0F2-11E1-8270-B8AC6F996F26}
2012-06-27 23:24 - 2012-06-27 23:24 - 00133632 __ASH (DT Soft Ltd) C:\Users\Ping\AppData\Roaming\dinhea.dll
2012-06-27 11:52 - 2012-03-06 00:55 - 00000000 ____D C:\Users\All Users\boost_interprocess
2012-06-24 19:39 - 2012-06-24 19:36 - 00000000 ____D C:\Users\Ping\Desktop\fun.-Some Nights (2012) 320Kbit(mp3) DMT
2012-06-17 10:22 - 2012-06-17 10:21 - 00000000 ____D C:\Program Files\iTunes
2012-06-17 10:22 - 2011-04-14 00:07 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-17 10:21 - 2012-06-17 10:21 - 00000000 ____D C:\Program Files\iPod
2012-06-17 10:08 - 2012-04-25 19:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Users\Ping\AppData\Local\Xenocode
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key LLC
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key 4
2012-06-16 16:19 - 2012-06-16 16:19 - 00000100 ____A C:\Users\All Users\Microsoft.SqlServer.Compact.400.32.bc
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed_In_Key_LLC
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed In Key
2012-06-16 16:17 - 2012-06-16 16:17 - 00000000 ____D C:\Users\Ping\Desktop\Mash-Up 1.5, Mixed In Key 4, Platinum Notes 3 + Serials
2012-06-16 07:57 - 2010-08-19 00:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 3
2012-06-15 23:50 - 2010-08-19 02:32 - 00000000 ____D C:\Program Files (x86)\Opera
2012-06-13 07:04 - 2012-06-13 07:04 - 00000000 ____D C:\Users\Ping\AppData\Local\Macromedia
2012-06-13 07:04 - 2012-04-03 09:56 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-13 07:04 - 2011-06-06 02:28 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-08 11:00 - 2010-11-04 14:06 - 00000454 ____A C:\Windows\Tasks\Intel_C_CVPO008404HL080BGN.job
2012-06-06 22:35 - 2012-06-06 22:35 - 00000000 ____D C:\Users\Ping\AppData\Roaming\LOVE
2012-06-05 09:01 - 2009-07-13 21:08 - 00032582 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-02 23:36 - 2012-03-11 20:08 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Skype
2012-05-25 00:52 - 2012-05-25 00:52 - 00007812 ____A C:\Windows\DPINST.LOG
2012-05-25 00:52 - 2012-05-25 00:52 - 00000000 __HDC C:\Users\All Users\{DF02C15B-D0DC-409D-9C10-D19A19DF7A42}
2012-05-25 00:52 - 2011-03-18 19:15 - 00000000 ____D C:\Program Files\Native Instruments
2012-05-25 00:46 - 2012-05-25 00:46 - 00000000 __HDC C:\Users\All Users\{4A818508-3355-4FBC-B302-D53B599DD9D5}
2012-05-25 00:46 - 2012-05-25 00:46 - 00000000 ____D C:\Users\Ping\Documents\Native Instruments
2012-05-25 00:44 - 2012-05-25 00:43 - 00000000 ____D C:\Users\Ping\Desktop\NI-Traktor.Pro.2.v2.0.1-UNION
2012-05-24 10:33 - 2012-05-24 10:32 - 114025605 ____A C:\Users\Ping\Desktop\97639217.mp4
2012-05-20 01:23 - 2012-05-20 01:23 - 00000000 ____D C:\Users\All Users\ATI
2012-05-20 01:23 - 2012-05-20 01:23 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2012-05-20 01:23 - 2012-05-20 01:23 - 00000000 ____D C:\Program Files (x86)\ATI
2012-05-20 01:22 - 2012-05-20 01:22 - 00000000 ____D C:\Program Files\ATI Technologies
2012-05-20 01:22 - 2012-05-20 01:22 - 00000000 ____D C:\Program Files\ATI
2012-05-20 01:22 - 2012-05-20 01:22 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2012-05-20 01:14 - 2012-03-19 10:54 - 00000000 ____D C:\Users\All Users\AMD
2012-05-17 23:57 - 2012-05-17 23:57 - 00000000 ____D C:\Users\All Users\Battle.net
2012-05-16 14:34 - 2012-05-16 23:05 - 07733859 ____A C:\Users\Ping\Desktop\untitled (prod. Childish Gambino & Ludwig).mp3
2012-05-11 03:07 - 2012-05-11 03:07 - 14528070 ____A C:\Users\Ping\Downloads\George_Acosta_-_To_The_Sky_(Gerry_Cueto_Remix).mp3
2012-05-04 15:33 - 2012-04-17 10:33 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-02 23:34 - 2012-05-02 23:34 - 00000755 ____A C:\Windows\LkmdfCoInst.log
2012-05-02 23:34 - 2010-08-19 00:15 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-04-27 18:32 - 2012-04-27 18:27 - 00000000 ____D C:\Users\Ping\jagexcache
2012-04-27 18:31 - 2012-04-27 18:28 - 00000001 ____A C:\Users\Ping\random.dat
2012-04-27 18:28 - 2012-04-27 18:28 - 00000043 ____A C:\Users\Ping\jagex_cl_runescape_LIVE.dat
2012-04-27 18:28 - 2012-04-27 18:28 - 00000012 ____A C:\Users\Ping\jagexappletviewer.preferences
2012-04-27 18:28 - 2012-04-27 18:28 - 00000000 ____D C:\Windows\.jagex_cache_32
2012-04-27 18:28 - 2010-08-18 23:58 - 00000000 ____D C:\users\Ping
2012-04-25 19:53 - 2012-04-25 19:53 - 00000000 ____D C:\Users\All Users\Mozilla
2012-04-25 19:31 - 2010-12-11 17:37 - 00000000 ____D C:\Users\Ping\AppData\Roaming\.minecraft
2012-04-15 23:57 - 2012-04-15 23:57 - 00000000 ____A C:\Windows\setuperr.log
2012-04-15 23:49 - 2012-02-24 23:25 - 00000000 ____D C:\Program Files (x86)\Steam
2012-04-15 23:49 - 2011-08-26 13:34 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Ventrilo
2012-04-15 23:49 - 2011-07-28 01:34 - 00000000 ____D C:\Users\Ping\AppData\Roaming\DAEMON Tools Lite
2012-04-15 23:49 - 2009-10-14 05:08 - 00000000 ____D C:\Windows\Panther
2012-04-15 23:45 - 2012-04-15 23:45 - 00000000 ____D C:\Program Files\CCleaner
2012-04-05 21:34 - 2012-04-05 21:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-04-05 21:34 - 2012-04-05 21:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-04-04 14:56 - 2012-06-28 10:15 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-02 01:07 - 2011-01-04 22:22 - 00000000 ____D C:\Program Files\PeerBlock
2012-03-31 17:10 - 2010-12-21 01:27 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-03-31 17:05 - 2012-03-31 17:05 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2012-03-31 17:05 - 2011-07-28 01:38 - 00564792 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
ZeroAccess:
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L\00000004.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L\201d3dde
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L\55490ac4
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\00000004.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\000000cb.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\80000032.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\80000064.@
ZeroAccess:
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\@
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\L
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\n
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 4095.18 MB
Available physical RAM: 3490.56 MB
Total Pagefile: 4093.33 MB
Available Pagefile: 3472.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:74.43 GB) (Free:4.55 GB) NTFS
3 Drive d: (Ping Backup) (Fixed) (Total:465.76 GB) (Free:117.9 GB) NTFS
4 Drive f: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 74 GB 0 B
Disk 1 Online 465 GB 1024 KB
Disk 2 Online 3824 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 74 GB 101 MB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 74 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 1024 KB
======================================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Ping Backup NTFS Partition 465 GB Healthy
======================================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3823 MB 24 KB
======================================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 3823 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-18 00:22
======================= End Of Log ==========================
ESET NOD32 is having trouble getting rid of these 2 trojans (Win64/Sirefef.AE trojan & Win64/Agent.BA trojan) from my computer. The error is, "Event occurred during an attempt to access the file by the application: C:\Windows\System32\services.exe." Here's my FRST log.
Scan result of Farbar Recovery Scan Tool Version: 28-06-2012
Ran by SYSTEM at 28-06-2012 11:47:34
Running from F:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2918656 2011-01-12] (ESET)
HKLM\...\Run: [Cm108Sound] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd [8146944 2009-10-09] (C-Media Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-06-23] (Logitech, Inc.)
HKLM\...\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" [371712 2009-09-24] (Microsoft Corporation)
HKLM\...\Run: [dinhea] rundll32.exe "C:\Users\Ping\AppData\Roaming\dinhea.dll",SetQoSql [133632 2012-06-27] (DT Soft Ltd)
HKLM\...\Run: [smpcat] "C:\Windows\System32\rundll32.exe" "C:\Users\Ping\AppData\Roaming\smpcat.dll",FreeObjectInfo [394752 2012-06-27] (C-Media Electronics Inc.)
HKLM\...\Run: [TNOD UP] "C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe" /I [x]
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-08-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-03-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Ping\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3481408 2012-02-13] (DT Soft Ltd)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [462408 2012-04-04] (Malwarebytes Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit [1712176 2012-01-25] (Soluto)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 68.238.64.12
AppInit_DLLs: acaptuser64.dll
Startup: C:\Users\Ping\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
4 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42360 2011-01-12] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810144 2011-01-12] (ESET)
2 ExpatShieldService; C:\Program Files (x86)\Expat Shield\bin\openvpnas.exe [331608 2012-01-17] ()
3 ExpatSrv; C:\Program Files (x86)\Expat Shield\HssWPR\hsssrv.exe [363336 2012-01-04] (AnchorFree Inc.)
3 ExpatTrayService; C:\Program Files (x86)\Expat Shield\bin\ExpatTrayService.EXE [77520 2012-01-17] ()
3 ExpatWd; C:\Program Files (x86)\Expat Shield\bin\hsswd.exe -product Expat [329544 2012-01-04] ()
3 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [5352960 2011-04-07] (Native Instruments GmbH)
4 SolutoService; "C:\Program Files\Soluto\SolutoService.exe" [547872 2012-01-25] (Soluto)
========================== Drivers (Whitelisted) =============
3 a2djavs; C:\Windows\System32\Drivers\a2djavs.sys [358480 2011-04-11] (Native Instruments GmbH)
3 a2djusb_svc; C:\Windows\System32\Drivers\a2djusb.sys [96848 2011-04-11] (Native Instruments GmbH)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [170640 2010-12-21] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [141264 2010-12-21] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [125296 2010-12-21] (ESET)
3 ks4avs; C:\Windows\System32\Drivers\ks4avs.sys [357968 2011-09-15] (Native Instruments GmbH)
3 ks4usb_svc; C:\Windows\System32\Drivers\ks4usb.sys [98896 2011-09-15] (Native Instruments GmbH)
3 kx1avs; C:\Windows\System32\Drivers\kx1avs.sys [358480 2011-04-11] (Native Instruments GmbH)
3 kx1usb_svc; C:\Windows\System32\Drivers\kx1usb.sys [70224 2011-04-11] (Native Instruments GmbH)
3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.sys [76056 2011-04-30] (Logitech, Inc.)
3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.sys [15128 2011-04-30] (Logitech, Inc.)
0 Soluto; C:\Windows\System32\Drivers\Soluto.sys [54728 2012-01-25] (Soluto LTD.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [564792 2012-03-31] (Duplex Secure Ltd.)
3 USBPNPA; C:\Windows\System32\drivers\CM10864.sys [1307648 2009-09-29] (C-Media Electronics Inc)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-28 11:47 - 2012-06-28 11:47 - 00000000 ____D C:\FRST
2012-06-28 10:26 - 2012-06-28 10:26 - 01427939 ____A C:\Users\Ping\Downloads\FRST64.exe
2012-06-28 10:21 - 2012-06-28 10:21 - 00607260 ____R (Swearware) C:\Users\Ping\Downloads\dds.scr
2012-06-28 10:18 - 2012-06-28 10:18 - 00302592 ____A C:\Users\Ping\Downloads\coj6789i.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Ping\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-28 10:15 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-28 09:27 - 2012-06-28 09:27 - 00000324 ____A C:\Windows\PFRO.log
2012-06-28 01:29 - 2012-06-28 01:40 - 03306209 ____A C:\Users\Ping\Downloads\ASAP-Rocky-Ft.-Lana-Del-Ray---Ridin--EM0612.mp3
2012-06-27 23:44 - 2012-06-27 23:53 - 00000000 ____D C:\Program Files (x86)\TNod User & Password Finder
2012-06-27 23:38 - 2012-06-27 23:38 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-27 23:30 - 2012-06-27 23:43 - 00000000 ____D C:\Users\Ping\Desktop\TNod-1.4.1.0-Final
2012-06-27 23:25 - 2012-06-28 02:20 - 89988630 ____A C:\Users\Ping\Desktop\[SaHa] Charlie Nishinaka - Cheers Vol.07 (English).rar
2012-06-27 23:25 - 2012-06-27 23:25 - 00394752 ____A (C-Media Electronics Inc.) C:\Users\Ping\AppData\Roaming\smpcat.dll
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Ping\AppData\Local\{622C0C3A-C0F2-11E1-8270-B8AC6F996F26}
2012-06-27 23:24 - 2012-06-27 23:27 - 00000000 ____D C:\Users\All Users\B7E8587A00007C620003E42AA6014588
2012-06-27 23:24 - 2012-06-27 23:24 - 00133632 __ASH (DT Soft Ltd) C:\Users\Ping\AppData\Roaming\dinhea.dll
2012-06-24 19:36 - 2012-06-24 19:39 - 00000000 ____D C:\Users\Ping\Desktop\fun.-Some Nights (2012) 320Kbit(mp3) DMT
2012-06-17 10:21 - 2012-06-17 10:22 - 00000000 ____D C:\Program Files\iTunes
2012-06-17 10:21 - 2012-06-17 10:21 - 00000000 ____D C:\Program Files\iPod
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Users\Ping\AppData\Local\Xenocode
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key LLC
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key 4
2012-06-16 16:19 - 2012-06-16 16:19 - 00000100 ____A C:\Users\All Users\Microsoft.SqlServer.Compact.400.32.bc
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed_In_Key_LLC
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed In Key
2012-06-16 16:17 - 2012-06-16 16:17 - 00000000 ____D C:\Users\Ping\Desktop\Mash-Up 1.5, Mixed In Key 4, Platinum Notes 3 + Serials
2012-06-13 07:04 - 2012-06-13 07:04 - 00000000 ____D C:\Users\Ping\AppData\Local\Macromedia
2012-06-06 22:35 - 2012-06-06 22:35 - 00000000 ____D C:\Users\Ping\AppData\Roaming\LOVE
============ 3 Months Modified Files and Folders =============
2012-06-28 10:45 - 2010-08-19 00:00 - 01917560 ____A C:\Windows\WindowsUpdate.log
2012-06-28 10:43 - 2011-05-08 23:08 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-28 10:40 - 2009-07-13 21:13 - 00778150 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-28 10:26 - 2012-06-28 10:26 - 01427939 ____A C:\Users\Ping\Downloads\FRST64.exe
2012-06-28 10:21 - 2012-06-28 10:21 - 00607260 ____R (Swearware) C:\Users\Ping\Downloads\dds.scr
2012-06-28 10:18 - 2012-06-28 10:18 - 00302592 ____A C:\Users\Ping\Downloads\coj6789i.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Ping\Downloads\mbam-setup-1.61.0.1400.exe
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-28 10:15 - 2012-06-28 10:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-28 09:33 - 2009-07-13 20:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-28 09:33 - 2009-07-13 20:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-28 09:27 - 2012-06-28 09:27 - 00000324 ____A C:\Windows\PFRO.log
2012-06-28 09:27 - 2012-04-15 23:57 - 00019515 ____A C:\Windows\setupact.log
2012-06-28 09:27 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-28 02:20 - 2012-06-27 23:25 - 89988630 ____A C:\Users\Ping\Desktop\[SaHa] Charlie Nishinaka - Cheers Vol.07 (English).rar
2012-06-28 01:40 - 2012-06-28 01:29 - 03306209 ____A C:\Users\Ping\Downloads\ASAP-Rocky-Ft.-Lana-Del-Ray---Ridin--EM0612.mp3
2012-06-28 01:40 - 2010-08-19 00:58 - 00000000 ____D C:\Users\Ping\AppData\Roaming\uTorrent
2012-06-27 23:53 - 2012-06-27 23:44 - 00000000 ____D C:\Program Files (x86)\TNod User & Password Finder
2012-06-27 23:53 - 2012-03-11 20:08 - 00000000 ____D C:\Users\All Users\Skype
2012-06-27 23:43 - 2012-06-27 23:30 - 00000000 ____D C:\Users\Ping\Desktop\TNod-1.4.1.0-Final
2012-06-27 23:38 - 2012-06-27 23:38 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-27 23:27 - 2012-06-27 23:24 - 00000000 ____D C:\Users\All Users\B7E8587A00007C620003E42AA6014588
2012-06-27 23:25 - 2012-06-27 23:25 - 00394752 ____A (C-Media Electronics Inc.) C:\Users\Ping\AppData\Roaming\smpcat.dll
2012-06-27 23:25 - 2012-06-27 23:25 - 00000000 ____D C:\Users\Ping\AppData\Local\{622C0C3A-C0F2-11E1-8270-B8AC6F996F26}
2012-06-27 23:24 - 2012-06-27 23:24 - 00133632 __ASH (DT Soft Ltd) C:\Users\Ping\AppData\Roaming\dinhea.dll
2012-06-27 11:52 - 2012-03-06 00:55 - 00000000 ____D C:\Users\All Users\boost_interprocess
2012-06-24 19:39 - 2012-06-24 19:36 - 00000000 ____D C:\Users\Ping\Desktop\fun.-Some Nights (2012) 320Kbit(mp3) DMT
2012-06-17 10:22 - 2012-06-17 10:21 - 00000000 ____D C:\Program Files\iTunes
2012-06-17 10:22 - 2011-04-14 00:07 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-06-17 10:21 - 2012-06-17 10:21 - 00000000 ____D C:\Program Files\iPod
2012-06-17 10:08 - 2012-04-25 19:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Users\Ping\AppData\Local\Xenocode
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key LLC
2012-06-16 16:20 - 2012-06-16 16:20 - 00000000 ____D C:\Program Files (x86)\Mixed In Key 4
2012-06-16 16:19 - 2012-06-16 16:19 - 00000100 ____A C:\Users\All Users\Microsoft.SqlServer.Compact.400.32.bc
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed_In_Key_LLC
2012-06-16 16:19 - 2012-06-16 16:19 - 00000000 ____D C:\Users\Ping\AppData\Local\Mixed In Key
2012-06-16 16:17 - 2012-06-16 16:17 - 00000000 ____D C:\Users\Ping\Desktop\Mash-Up 1.5, Mixed In Key 4, Platinum Notes 3 + Serials
2012-06-16 07:57 - 2010-08-19 00:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 3
2012-06-15 23:50 - 2010-08-19 02:32 - 00000000 ____D C:\Program Files (x86)\Opera
2012-06-13 07:04 - 2012-06-13 07:04 - 00000000 ____D C:\Users\Ping\AppData\Local\Macromedia
2012-06-13 07:04 - 2012-04-03 09:56 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-13 07:04 - 2011-06-06 02:28 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-08 11:00 - 2010-11-04 14:06 - 00000454 ____A C:\Windows\Tasks\Intel_C_CVPO008404HL080BGN.job
2012-06-06 22:35 - 2012-06-06 22:35 - 00000000 ____D C:\Users\Ping\AppData\Roaming\LOVE
2012-06-05 09:01 - 2009-07-13 21:08 - 00032582 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-02 23:36 - 2012-03-11 20:08 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Skype
2012-05-25 00:52 - 2012-05-25 00:52 - 00007812 ____A C:\Windows\DPINST.LOG
2012-05-25 00:52 - 2012-05-25 00:52 - 00000000 __HDC C:\Users\All Users\{DF02C15B-D0DC-409D-9C10-D19A19DF7A42}
2012-05-25 00:52 - 2011-03-18 19:15 - 00000000 ____D C:\Program Files\Native Instruments
2012-05-25 00:46 - 2012-05-25 00:46 - 00000000 __HDC C:\Users\All Users\{4A818508-3355-4FBC-B302-D53B599DD9D5}
2012-05-25 00:46 - 2012-05-25 00:46 - 00000000 ____D C:\Users\Ping\Documents\Native Instruments
2012-05-25 00:44 - 2012-05-25 00:43 - 00000000 ____D C:\Users\Ping\Desktop\NI-Traktor.Pro.2.v2.0.1-UNION
2012-05-24 10:33 - 2012-05-24 10:32 - 114025605 ____A C:\Users\Ping\Desktop\97639217.mp4
2012-05-20 01:23 - 2012-05-20 01:23 - 00000000 ____D C:\Users\All Users\ATI
2012-05-20 01:23 - 2012-05-20 01:23 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2012-05-20 01:23 - 2012-05-20 01:23 - 00000000 ____D C:\Program Files (x86)\ATI
2012-05-20 01:22 - 2012-05-20 01:22 - 00000000 ____D C:\Program Files\ATI Technologies
2012-05-20 01:22 - 2012-05-20 01:22 - 00000000 ____D C:\Program Files\ATI
2012-05-20 01:22 - 2012-05-20 01:22 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2012-05-20 01:14 - 2012-03-19 10:54 - 00000000 ____D C:\Users\All Users\AMD
2012-05-17 23:57 - 2012-05-17 23:57 - 00000000 ____D C:\Users\All Users\Battle.net
2012-05-16 14:34 - 2012-05-16 23:05 - 07733859 ____A C:\Users\Ping\Desktop\untitled (prod. Childish Gambino & Ludwig).mp3
2012-05-11 03:07 - 2012-05-11 03:07 - 14528070 ____A C:\Users\Ping\Downloads\George_Acosta_-_To_The_Sky_(Gerry_Cueto_Remix).mp3
2012-05-04 15:33 - 2012-04-17 10:33 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-02 23:34 - 2012-05-02 23:34 - 00000755 ____A C:\Windows\LkmdfCoInst.log
2012-05-02 23:34 - 2010-08-19 00:15 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-04-27 18:32 - 2012-04-27 18:27 - 00000000 ____D C:\Users\Ping\jagexcache
2012-04-27 18:31 - 2012-04-27 18:28 - 00000001 ____A C:\Users\Ping\random.dat
2012-04-27 18:28 - 2012-04-27 18:28 - 00000043 ____A C:\Users\Ping\jagex_cl_runescape_LIVE.dat
2012-04-27 18:28 - 2012-04-27 18:28 - 00000012 ____A C:\Users\Ping\jagexappletviewer.preferences
2012-04-27 18:28 - 2012-04-27 18:28 - 00000000 ____D C:\Windows\.jagex_cache_32
2012-04-27 18:28 - 2010-08-18 23:58 - 00000000 ____D C:\users\Ping
2012-04-25 19:53 - 2012-04-25 19:53 - 00000000 ____D C:\Users\All Users\Mozilla
2012-04-25 19:31 - 2010-12-11 17:37 - 00000000 ____D C:\Users\Ping\AppData\Roaming\.minecraft
2012-04-15 23:57 - 2012-04-15 23:57 - 00000000 ____A C:\Windows\setuperr.log
2012-04-15 23:49 - 2012-02-24 23:25 - 00000000 ____D C:\Program Files (x86)\Steam
2012-04-15 23:49 - 2011-08-26 13:34 - 00000000 ____D C:\Users\Ping\AppData\Roaming\Ventrilo
2012-04-15 23:49 - 2011-07-28 01:34 - 00000000 ____D C:\Users\Ping\AppData\Roaming\DAEMON Tools Lite
2012-04-15 23:49 - 2009-10-14 05:08 - 00000000 ____D C:\Windows\Panther
2012-04-15 23:45 - 2012-04-15 23:45 - 00000000 ____D C:\Program Files\CCleaner
2012-04-05 21:34 - 2012-04-05 21:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-04-05 21:34 - 2012-04-05 21:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-04-04 14:56 - 2012-06-28 10:15 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-02 01:07 - 2011-01-04 22:22 - 00000000 ____D C:\Program Files\PeerBlock
2012-03-31 17:10 - 2010-12-21 01:27 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-03-31 17:05 - 2012-03-31 17:05 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2012-03-31 17:05 - 2011-07-28 01:38 - 00564792 ____A (Duplex Secure Ltd.) C:\Windows\System32\Drivers\sptd.sys
ZeroAccess:
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L\00000004.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L\201d3dde
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\L\55490ac4
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\00000004.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\000000cb.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\80000032.@
C:\Windows\Installer\{c2e10626-0264-9911-dd23-8391d9de90cd}\U\80000064.@
ZeroAccess:
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\@
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\L
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\n
C:\Users\Ping\AppData\Local\{c2e10626-0264-9911-dd23-8391d9de90cd}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 4095.18 MB
Available physical RAM: 3490.56 MB
Total Pagefile: 4093.33 MB
Available Pagefile: 3472.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:74.43 GB) (Free:4.55 GB) NTFS
3 Drive d: (Ping Backup) (Fixed) (Total:465.76 GB) (Free:117.9 GB) NTFS
4 Drive f: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 74 GB 0 B
Disk 1 Online 465 GB 1024 KB
Disk 2 Online 3824 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 74 GB 101 MB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 74 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 1024 KB
======================================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D Ping Backup NTFS Partition 465 GB Healthy
======================================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3823 MB 24 KB
======================================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 3823 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-18 00:22
======================= End Of Log ==========================