Hi. Just started getting those pop-up notifications from Microsoft Security Essentials and started getting redirected to random websites and stuff. Found out it was a Win64/sirefef trojan, and went looking to find ways to remove it.
I know I'm not meant to follow instructions given to others... I read through some other posts and realized that the FRST program should be run first, right? but that's as far as I went. I'm really not too sure about the rest of the process... I've posted the logs for the first FRST run, and the one where services.exe is searched for. Can someone please help me?
Thanks,
Alicia.
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 18:05:33
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-08-09] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-08-09] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-08-09] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-02] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2011-10-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe" [47616 2011-08-11] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-05-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\AliciaSueYee\...\Run: [Google Update] "C:\Users\AliciaSueYee\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-04-11] (Google Inc.)
HKU\AliciaSueYee\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3672384 2012-04-11] (DT Soft Ltd)
HKU\AliciaSueYee\...\Run: [Facebook Update] "C:\Users\AliciaSueYee\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-16] (Facebook Inc.)
HKU\AliciaSueYee\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-04-11] (Google Inc.)
HKU\AliciaSueYee\...\Run: [AdobeBridge] [x]
HKU\AliciaSueYee\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\AliciaSueYee\...\Run: [IBM] rundll32.exe "C:\Users\AliciaSueYee\AppData\Local\Mozilla\IBM\uctnh.dll",CreateInstance [425984 2012-07-30] (SEIKO EPSON CORPORATION)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\Facebook Messenger.lnk
ShortcutTarget: Facebook Messenger.lnk -> (No File)
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
2 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [241648 2011-02-24] (CyberLink)
2 FPLService; "C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe" [260424 2011-08-26] (HP)
2 HPAuto; "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" [682040 2011-02-16] (Hewlett-Packard)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656536 2011-08-09] (Intel Corporation)
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-04-12] (DT Soft Ltd)
3 FLxHCIh; C:\Windows\System32\Drivers\FLxHCIh.sys [65536 2012-03-02] (Fresco Logic)
2 IDMWFP; C:\Windows\System32\Drivers\IDMWFP.sys [149640 2012-02-07] (Tonec Inc.)
1 bzauzhtw; \??\C:\Windows\system32\drivers\bzauzhtw.sys [x]
1 ybtsrbid; \??\C:\Windows\system32\drivers\ybtsrbid.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-30 13:28 - 2012-07-30 13:28 - 02322184 ____A (ESET) C:\Users\AliciaSueYee\Downloads\esetsmartinstaller_enu.exe
2012-07-30 13:24 - 2012-07-30 13:25 - 12621696 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\mseinstall(1).exe
2012-07-30 13:18 - 2012-07-30 13:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9FE2FAF2B94D1F6
2012-07-30 13:13 - 2012-07-30 13:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24A4F1AA4A338769
2012-07-30 13:09 - 2012-07-30 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.646E8EFA69971057
2012-07-30 13:04 - 2012-07-30 13:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.257A8B78D33AFE34
2012-07-30 13:01 - 2012-07-30 13:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.65E703590D180112
2012-07-30 12:58 - 2012-07-30 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E96F3C519A57F521
2012-07-30 12:55 - 2012-07-30 12:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD88C9432A0901BE
2012-07-30 12:52 - 2012-07-30 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.19FA7CD7D4577A2D
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.954A9076AC008D1F
2012-07-30 12:46 - 2012-07-30 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3180FB7F7C42E7D7
2012-07-30 12:24 - 2012-07-30 12:24 - 00347424 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\MicrosoftFixit.WindowsFirewall.RNP.133267110647199226.1.1.Run.exe
2012-07-29 12:15 - 2012-07-29 12:15 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-29 12:08 - 2012-07-29 12:08 - 00000012 ____A C:\Windows\srun.log
2012-07-28 08:54 - 2012-07-28 08:54 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\{1D823631-B05E-41E6-8A14-10CA591DB209}
2012-07-26 14:55 - 2012-07-26 14:55 - 00000425 ____A C:\Users\AliciaSueYee\Desktop\gaiman sandman.txt
2012-07-26 12:08 - 2012-07-26 12:08 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\HorizonWimba
2012-07-26 08:43 - 2012-07-26 08:43 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\Macromedia
2012-07-26 06:32 - 2012-07-26 06:32 - 00054544 ____A C:\Users\AliciaSueYee\Downloads\16256_GALIRDN.ttf
2012-07-26 06:31 - 2012-07-26 06:31 - 00041844 ____A C:\Users\AliciaSueYee\Downloads\square-slabserif-711-bold-bt.ttf
2012-07-25 15:35 - 2012-07-25 15:37 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\Firestorm
2012-07-25 15:35 - 2012-07-25 15:36 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Roaming\Firestorm
2012-07-25 10:45 - 2012-07-25 10:47 - 00000000 ____D C:\Users\AliciaSueYee\Desktop\SFP NewsRoom
2012-07-25 05:43 - 2012-07-25 05:46 - 00000000 ____D C:\Program Files (x86)\Firestorm-Release
2012-07-23 21:42 - 2012-07-23 21:42 - 00001994 ____A C:\Users\AliciaSueYee\Desktop\Kindle.lnk
2012-07-23 21:33 - 2012-07-23 21:45 - 00000000 ____D C:\Users\AliciaSueYee\Documents\Calibre Library
2012-07-23 21:33 - 2012-07-23 21:36 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Roaming\calibre
2012-07-23 21:33 - 2012-07-23 21:33 - 00000000 ____D C:\Program Files (x86)\Calibre2
2012-07-23 21:17 - 2012-07-23 21:17 - 00000000 ____D C:\Users\AliciaSueYee\Downloads\Neil Gaiman
2012-07-23 20:44 - 2012-07-23 20:45 - 09469165 ____A C:\Users\AliciaSueYee\Downloads\Neil Gaiman.rar
2012-07-18 15:37 - 2012-07-30 09:39 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\Mozilla
2012-07-18 15:37 - 2012-07-30 00:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\All Users\Desktop\Mozilla Firefox.lnk
2012-07-18 15:37 - 2012-07-18 15:37 - 00000000 ____D C:\Users\All Users\Mozilla
2012-07-18 15:37 - 2012-07-18 15:37 - 00000000 ____D C:\Users\All Users\Application Data\Mozilla
2012-07-18 15:37 - 2012-07-18 15:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-07-16 10:07 - 2009-05-18 09:17 - 00034152 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-07-16 10:07 - 2008-04-17 08:12 - 00126312 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi64.dll
2012-07-16 10:07 - 2008-04-17 08:12 - 00107368 ____A (GEAR Software Inc.) C:\Windows\SysWOW64\GEARAspi.dll
2012-07-16 10:06 - 2012-07-16 10:07 - 00000000 ____D C:\Program Files\iTunes
2012-07-16 10:06 - 2012-07-16 10:07 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-07-16 10:06 - 2012-07-16 10:06 - 00000000 ____D C:\Program Files\iPod
2012-07-11 12:22 - 2012-07-23 19:40 - 00000115 ____A C:\Users\AliciaSueYee\webct_upload_applet.properties
2012-07-10 16:46 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 16:42 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 16:42 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 16:42 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 16:42 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 16:42 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 16:42 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 16:42 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 16:42 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 16:42 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 16:42 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 16:42 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 16:42 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 16:42 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 16:42 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 16:42 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 16:42 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 16:42 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 16:42 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 16:42 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 16:42 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 16:42 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 16:42 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 16:42 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 16:42 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 16:42 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 16:42 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 16:42 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 16:42 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 16:35 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 16:35 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 16:35 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 16:35 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 16:35 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 16:35 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 16:35 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 16:35 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 16:35 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 16:35 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 16:35 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 16:35 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 16:35 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 16:35 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 16:35 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 16:35 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 16:35 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 16:35 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 16:35 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
============ 3 Months Modified Files ========================
2012-07-30 14:00 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-30 14:00 - 2009-07-13 20:51 - 00062364 ____A C:\Windows\setupact.log
2012-07-30 13:47 - 2009-07-13 21:13 - 00779526 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 13:28 - 2012-07-30 13:28 - 02322184 ____A (ESET) C:\Users\AliciaSueYee\Downloads\esetsmartinstaller_enu.exe
2012-07-30 13:28 - 2012-06-19 23:13 - 00002052 ____A C:\Windows\epplauncher.mif
2012-07-30 13:27 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:27 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:25 - 2012-07-30 13:24 - 12621696 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\mseinstall(1).exe
2012-07-30 13:20 - 2012-05-17 17:43 - 00264544 ____A C:\Windows\SysWOW64\debug.log
2012-07-30 13:19 - 2012-04-11 07:31 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-30 13:18 - 2012-07-30 13:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9FE2FAF2B94D1F6
2012-07-30 13:13 - 2012-07-30 13:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24A4F1AA4A338769
2012-07-30 13:12 - 2012-04-01 19:00 - 01526527 ____A C:\Windows\WindowsUpdate.log
2012-07-30 13:09 - 2012-07-30 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.646E8EFA69971057
2012-07-30 13:04 - 2012-07-30 13:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.257A8B78D33AFE34
2012-07-30 13:01 - 2012-07-30 13:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.65E703590D180112
2012-07-30 12:58 - 2012-07-30 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E96F3C519A57F521
2012-07-30 12:57 - 2009-07-13 21:08 - 00032638 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-30 12:55 - 2012-07-30 12:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD88C9432A0901BE
2012-07-30 12:52 - 2012-07-30 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.19FA7CD7D4577A2D
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.954A9076AC008D1F
2012-07-30 12:46 - 2012-07-30 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3180FB7F7C42E7D7
2012-07-30 12:46 - 2012-04-11 07:31 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-30 12:43 - 2012-06-05 18:38 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-30 12:33 - 2012-04-11 07:23 - 00000936 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001UA.job
2012-07-30 12:24 - 2012-07-30 12:24 - 00347424 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\MicrosoftFixit.WindowsFirewall.RNP.133267110647199226.1.1.Run.exe
2012-07-30 12:21 - 2012-04-11 07:38 - 00797112 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 11:21 - 2012-04-13 02:34 - 00000956 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001UA.job
2012-07-29 19:46 - 2012-04-11 07:23 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001Core.job
2012-07-29 14:21 - 2012-04-13 02:34 - 00000934 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001Core.job
2012-07-29 12:08 - 2012-07-29 12:08 - 00000012 ____A C:\Windows\srun.log
2012-07-27 22:28 - 2012-04-18 09:37 - 00000356 ____A C:\Windows\Tasks\HPCeeScheduleForALICIASUEYEE-HP$.job
2012-07-27 08:44 - 2012-05-23 08:48 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 08:44 - 2011-11-09 09:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-26 14:55 - 2012-07-26 14:55 - 00000425 ____A C:\Users\AliciaSueYee\Desktop\gaiman sandman.txt
2012-07-26 13:59 - 2009-07-13 20:45 - 05037360 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-26 13:58 - 2012-04-11 07:16 - 00000360 ____A C:\Windows\Tasks\HPCeeScheduleForAliciaSueYee.job
2012-07-26 10:23 - 2012-05-03 15:17 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-26 10:23 - 2012-04-12 11:00 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-07-26 07:22 - 2012-04-11 07:16 - 00111880 ____A C:\Users\AliciaSueYee\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-26 06:32 - 2012-07-26 06:32 - 00054544 ____A C:\Users\AliciaSueYee\Downloads\16256_GALIRDN.ttf
2012-07-26 06:31 - 2012-07-26 06:31 - 00041844 ____A C:\Users\AliciaSueYee\Downloads\square-slabserif-711-bold-bt.ttf
2012-07-23 21:42 - 2012-07-23 21:42 - 00001994 ____A C:\Users\AliciaSueYee\Desktop\Kindle.lnk
2012-07-23 21:41 - 2012-06-02 22:31 - 00000242 ____A C:\Windows\wininit.ini
2012-07-23 20:45 - 2012-07-23 20:44 - 09469165 ____A C:\Users\AliciaSueYee\Downloads\Neil Gaiman.rar
2012-07-23 19:40 - 2012-07-11 12:22 - 00000115 ____A C:\Users\AliciaSueYee\webct_upload_applet.properties
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\All Users\Desktop\Mozilla Firefox.lnk
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-07-11 12:29 - 2012-04-11 07:30 - 00002439 ____A C:\Users\AliciaSueYee\Desktop\Google Chrome.lnk
2012-07-10 16:43 - 2012-04-12 16:45 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-26 22:04 - 2012-06-26 22:04 - 00188768 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-06-20 05:58 - 2012-06-04 19:34 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-20 05:58 - 2012-06-04 19:34 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-19 23:13 - 2012-06-19 23:11 - 12621696 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\mseinstall.exe
2012-06-19 23:09 - 2012-06-19 23:09 - 00001762 ____A C:\Users\AliciaSueYee\Desktop\Skype.lnk
2012-06-19 22:52 - 2010-11-20 19:47 - 00669624 ____A C:\Windows\PFRO.log
2012-06-11 19:08 - 2012-07-10 16:46 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-10 16:35 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 16:35 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 16:35 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 16:35 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 16:35 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 16:35 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 16:35 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 16:35 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 18:14 - 2012-06-05 18:14 - 00001829 ____A C:\Users\Public\Desktop\Opera.lnk
2012-06-05 18:14 - 2012-06-05 18:14 - 00001829 ____A C:\Users\All Users\Desktop\Opera.lnk
2012-06-02 22:31 - 2012-04-11 07:52 - 00001045 ____A C:\Users\AliciaSueYee\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-22 08:52 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 08:52 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 08:52 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 08:52 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 08:52 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 08:52 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 08:52 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-22 08:52 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-22 08:52 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 16:42 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 16:42 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 16:42 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 16:42 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 16:42 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 16:42 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 16:42 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 16:42 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 16:42 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 16:42 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 16:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 16:42 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 16:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 16:42 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 16:42 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 16:42 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 16:42 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 16:42 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 16:42 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 16:42 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 16:42 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 16:42 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 16:42 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 16:42 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 16:42 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 16:42 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 16:42 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 16:42 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 16:35 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 16:35 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 16:35 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 16:35 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 16:35 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 16:35 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 16:35 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 16:35 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 16:35 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 08:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-28 08:33 - 2012-05-23 15:00 - 00006444 ____A C:\Windows\SysWOW64\AppLog.log
2012-05-25 16:30 - 2012-05-25 16:30 - 00031744 ____A C:\Users\AliciaSueYee\Downloads\Data_Set_4_-_Mothers_and_Daughters.xls
2012-05-04 03:06 - 2012-06-12 21:40 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 21:40 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 21:40 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 00:46 - 2012-05-04 00:46 - 00002418 ____A C:\Users\AliciaSueYee\Desktop\GA Fall.txt
ZeroAccess:
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\n
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L\00000004.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L\201d3dde
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\00000004.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\00000008.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\000000cb.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\80000000.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\80000032.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\80000064.@
ZeroAccess:
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\@
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 8139.6 MB
Available physical RAM: 7185.02 MB
Total Pagefile: 8137.75 MB
Available Pagefile: 7158.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:673.14 GB) (Free:552.73 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (Recovery) (Fixed) (Total:21.33 GB) (Free:2.3 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.07 GB) FAT32
5 Drive h: (ALICIA) (Removable) (Total:3.72 GB) (Free:2.83 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 3822 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 673 GB 200 MB
Partition 3 Primary 21 GB 673 GB
Partition 4 Primary 4062 MB 694 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 673 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recovery NTFS Partition 21 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 4062 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3818 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H ALICIA FAT32 Removable 3818 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-27 23:12
======================= End Of Log ==========================
I know I'm not meant to follow instructions given to others... I read through some other posts and realized that the FRST program should be run first, right? but that's as far as I went. I'm really not too sure about the rest of the process... I've posted the logs for the first FRST run, and the one where services.exe is searched for. Can someone please help me?
Thanks,
Alicia.
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 18:05:33
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-08-09] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-08-09] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-08-09] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-02] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2011-10-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe" [47616 2011-08-11] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-05-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\AliciaSueYee\...\Run: [Google Update] "C:\Users\AliciaSueYee\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-04-11] (Google Inc.)
HKU\AliciaSueYee\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3672384 2012-04-11] (DT Soft Ltd)
HKU\AliciaSueYee\...\Run: [Facebook Update] "C:\Users\AliciaSueYee\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-16] (Facebook Inc.)
HKU\AliciaSueYee\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-04-11] (Google Inc.)
HKU\AliciaSueYee\...\Run: [AdobeBridge] [x]
HKU\AliciaSueYee\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\AliciaSueYee\...\Run: [IBM] rundll32.exe "C:\Users\AliciaSueYee\AppData\Local\Mozilla\IBM\uctnh.dll",CreateInstance [425984 2012-07-30] (SEIKO EPSON CORPORATION)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\Facebook Messenger.lnk
ShortcutTarget: Facebook Messenger.lnk -> (No File)
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\AliciaSueYee\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Services (Whitelisted) ======
2 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [241648 2011-02-24] (CyberLink)
2 FPLService; "C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe" [260424 2011-08-26] (HP)
2 HPAuto; "C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe" [682040 2011-02-16] (Hewlett-Packard)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656536 2011-08-09] (Intel Corporation)
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [283200 2012-04-12] (DT Soft Ltd)
3 FLxHCIh; C:\Windows\System32\Drivers\FLxHCIh.sys [65536 2012-03-02] (Fresco Logic)
2 IDMWFP; C:\Windows\System32\Drivers\IDMWFP.sys [149640 2012-02-07] (Tonec Inc.)
1 bzauzhtw; \??\C:\Windows\system32\drivers\bzauzhtw.sys [x]
1 ybtsrbid; \??\C:\Windows\system32\drivers\ybtsrbid.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-30 13:28 - 2012-07-30 13:28 - 02322184 ____A (ESET) C:\Users\AliciaSueYee\Downloads\esetsmartinstaller_enu.exe
2012-07-30 13:24 - 2012-07-30 13:25 - 12621696 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\mseinstall(1).exe
2012-07-30 13:18 - 2012-07-30 13:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9FE2FAF2B94D1F6
2012-07-30 13:13 - 2012-07-30 13:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24A4F1AA4A338769
2012-07-30 13:09 - 2012-07-30 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.646E8EFA69971057
2012-07-30 13:04 - 2012-07-30 13:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.257A8B78D33AFE34
2012-07-30 13:01 - 2012-07-30 13:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.65E703590D180112
2012-07-30 12:58 - 2012-07-30 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E96F3C519A57F521
2012-07-30 12:55 - 2012-07-30 12:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD88C9432A0901BE
2012-07-30 12:52 - 2012-07-30 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.19FA7CD7D4577A2D
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.954A9076AC008D1F
2012-07-30 12:46 - 2012-07-30 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3180FB7F7C42E7D7
2012-07-30 12:24 - 2012-07-30 12:24 - 00347424 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\MicrosoftFixit.WindowsFirewall.RNP.133267110647199226.1.1.Run.exe
2012-07-29 12:15 - 2012-07-29 12:15 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-29 12:08 - 2012-07-29 12:08 - 00000012 ____A C:\Windows\srun.log
2012-07-28 08:54 - 2012-07-28 08:54 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\{1D823631-B05E-41E6-8A14-10CA591DB209}
2012-07-26 14:55 - 2012-07-26 14:55 - 00000425 ____A C:\Users\AliciaSueYee\Desktop\gaiman sandman.txt
2012-07-26 12:08 - 2012-07-26 12:08 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\HorizonWimba
2012-07-26 08:43 - 2012-07-26 08:43 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\Macromedia
2012-07-26 06:32 - 2012-07-26 06:32 - 00054544 ____A C:\Users\AliciaSueYee\Downloads\16256_GALIRDN.ttf
2012-07-26 06:31 - 2012-07-26 06:31 - 00041844 ____A C:\Users\AliciaSueYee\Downloads\square-slabserif-711-bold-bt.ttf
2012-07-25 15:35 - 2012-07-25 15:37 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\Firestorm
2012-07-25 15:35 - 2012-07-25 15:36 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Roaming\Firestorm
2012-07-25 10:45 - 2012-07-25 10:47 - 00000000 ____D C:\Users\AliciaSueYee\Desktop\SFP NewsRoom
2012-07-25 05:43 - 2012-07-25 05:46 - 00000000 ____D C:\Program Files (x86)\Firestorm-Release
2012-07-23 21:42 - 2012-07-23 21:42 - 00001994 ____A C:\Users\AliciaSueYee\Desktop\Kindle.lnk
2012-07-23 21:33 - 2012-07-23 21:45 - 00000000 ____D C:\Users\AliciaSueYee\Documents\Calibre Library
2012-07-23 21:33 - 2012-07-23 21:36 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Roaming\calibre
2012-07-23 21:33 - 2012-07-23 21:33 - 00000000 ____D C:\Program Files (x86)\Calibre2
2012-07-23 21:17 - 2012-07-23 21:17 - 00000000 ____D C:\Users\AliciaSueYee\Downloads\Neil Gaiman
2012-07-23 20:44 - 2012-07-23 20:45 - 09469165 ____A C:\Users\AliciaSueYee\Downloads\Neil Gaiman.rar
2012-07-18 15:37 - 2012-07-30 09:39 - 00000000 ____D C:\Users\AliciaSueYee\AppData\Local\Mozilla
2012-07-18 15:37 - 2012-07-30 00:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\All Users\Desktop\Mozilla Firefox.lnk
2012-07-18 15:37 - 2012-07-18 15:37 - 00000000 ____D C:\Users\All Users\Mozilla
2012-07-18 15:37 - 2012-07-18 15:37 - 00000000 ____D C:\Users\All Users\Application Data\Mozilla
2012-07-18 15:37 - 2012-07-18 15:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-07-16 10:07 - 2009-05-18 09:17 - 00034152 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-07-16 10:07 - 2008-04-17 08:12 - 00126312 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi64.dll
2012-07-16 10:07 - 2008-04-17 08:12 - 00107368 ____A (GEAR Software Inc.) C:\Windows\SysWOW64\GEARAspi.dll
2012-07-16 10:06 - 2012-07-16 10:07 - 00000000 ____D C:\Program Files\iTunes
2012-07-16 10:06 - 2012-07-16 10:07 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-07-16 10:06 - 2012-07-16 10:06 - 00000000 ____D C:\Program Files\iPod
2012-07-11 12:22 - 2012-07-23 19:40 - 00000115 ____A C:\Users\AliciaSueYee\webct_upload_applet.properties
2012-07-10 16:46 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 16:42 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 16:42 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 16:42 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 16:42 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 16:42 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 16:42 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 16:42 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 16:42 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 16:42 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 16:42 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 16:42 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 16:42 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 16:42 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 16:42 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 16:42 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 16:42 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 16:42 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 16:42 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 16:42 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 16:42 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 16:42 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 16:42 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 16:42 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 16:42 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 16:42 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 16:42 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 16:42 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 16:42 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 16:35 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 16:35 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 16:35 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 16:35 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 16:35 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 16:35 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 16:35 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 16:35 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 16:35 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 16:35 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 16:35 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 16:35 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 16:35 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 16:35 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 16:35 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 16:35 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 16:35 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 16:35 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 16:35 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
============ 3 Months Modified Files ========================
2012-07-30 14:00 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-30 14:00 - 2009-07-13 20:51 - 00062364 ____A C:\Windows\setupact.log
2012-07-30 13:47 - 2009-07-13 21:13 - 00779526 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 13:28 - 2012-07-30 13:28 - 02322184 ____A (ESET) C:\Users\AliciaSueYee\Downloads\esetsmartinstaller_enu.exe
2012-07-30 13:28 - 2012-06-19 23:13 - 00002052 ____A C:\Windows\epplauncher.mif
2012-07-30 13:27 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:27 - 2009-07-13 20:45 - 00032064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:25 - 2012-07-30 13:24 - 12621696 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\mseinstall(1).exe
2012-07-30 13:20 - 2012-05-17 17:43 - 00264544 ____A C:\Windows\SysWOW64\debug.log
2012-07-30 13:19 - 2012-04-11 07:31 - 00000906 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-30 13:18 - 2012-07-30 13:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9FE2FAF2B94D1F6
2012-07-30 13:13 - 2012-07-30 13:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24A4F1AA4A338769
2012-07-30 13:12 - 2012-04-01 19:00 - 01526527 ____A C:\Windows\WindowsUpdate.log
2012-07-30 13:09 - 2012-07-30 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.646E8EFA69971057
2012-07-30 13:04 - 2012-07-30 13:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.257A8B78D33AFE34
2012-07-30 13:01 - 2012-07-30 13:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.65E703590D180112
2012-07-30 12:58 - 2012-07-30 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E96F3C519A57F521
2012-07-30 12:57 - 2009-07-13 21:08 - 00032638 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-30 12:55 - 2012-07-30 12:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD88C9432A0901BE
2012-07-30 12:52 - 2012-07-30 12:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.19FA7CD7D4577A2D
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.954A9076AC008D1F
2012-07-30 12:46 - 2012-07-30 12:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3180FB7F7C42E7D7
2012-07-30 12:46 - 2012-04-11 07:31 - 00000910 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-30 12:43 - 2012-06-05 18:38 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-30 12:33 - 2012-04-11 07:23 - 00000936 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001UA.job
2012-07-30 12:24 - 2012-07-30 12:24 - 00347424 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\MicrosoftFixit.WindowsFirewall.RNP.133267110647199226.1.1.Run.exe
2012-07-30 12:21 - 2012-04-11 07:38 - 00797112 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 11:21 - 2012-04-13 02:34 - 00000956 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001UA.job
2012-07-29 19:46 - 2012-04-11 07:23 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001Core.job
2012-07-29 14:21 - 2012-04-13 02:34 - 00000934 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-946850208-3789892574-1044012170-1001Core.job
2012-07-29 12:08 - 2012-07-29 12:08 - 00000012 ____A C:\Windows\srun.log
2012-07-27 22:28 - 2012-04-18 09:37 - 00000356 ____A C:\Windows\Tasks\HPCeeScheduleForALICIASUEYEE-HP$.job
2012-07-27 08:44 - 2012-05-23 08:48 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 08:44 - 2011-11-09 09:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-26 14:55 - 2012-07-26 14:55 - 00000425 ____A C:\Users\AliciaSueYee\Desktop\gaiman sandman.txt
2012-07-26 13:59 - 2009-07-13 20:45 - 05037360 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-26 13:58 - 2012-04-11 07:16 - 00000360 ____A C:\Windows\Tasks\HPCeeScheduleForAliciaSueYee.job
2012-07-26 10:23 - 2012-05-03 15:17 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-07-26 10:23 - 2012-04-12 11:00 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-07-26 07:22 - 2012-04-11 07:16 - 00111880 ____A C:\Users\AliciaSueYee\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-26 06:32 - 2012-07-26 06:32 - 00054544 ____A C:\Users\AliciaSueYee\Downloads\16256_GALIRDN.ttf
2012-07-26 06:31 - 2012-07-26 06:31 - 00041844 ____A C:\Users\AliciaSueYee\Downloads\square-slabserif-711-bold-bt.ttf
2012-07-23 21:42 - 2012-07-23 21:42 - 00001994 ____A C:\Users\AliciaSueYee\Desktop\Kindle.lnk
2012-07-23 21:41 - 2012-06-02 22:31 - 00000242 ____A C:\Windows\wininit.ini
2012-07-23 20:45 - 2012-07-23 20:44 - 09469165 ____A C:\Users\AliciaSueYee\Downloads\Neil Gaiman.rar
2012-07-23 19:40 - 2012-07-11 12:22 - 00000115 ____A C:\Users\AliciaSueYee\webct_upload_applet.properties
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-07-18 15:37 - 2012-07-18 15:37 - 00001130 ____A C:\Users\All Users\Desktop\Mozilla Firefox.lnk
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-16 10:07 - 2012-07-16 10:07 - 00001783 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-07-11 12:29 - 2012-04-11 07:30 - 00002439 ____A C:\Users\AliciaSueYee\Desktop\Google Chrome.lnk
2012-07-10 16:43 - 2012-04-12 16:45 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-26 22:04 - 2012-06-26 22:04 - 00188768 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-06-20 05:58 - 2012-06-04 19:34 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-06-20 05:58 - 2012-06-04 19:34 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-06-19 23:13 - 2012-06-19 23:11 - 12621696 ____A (Microsoft Corporation) C:\Users\AliciaSueYee\Downloads\mseinstall.exe
2012-06-19 23:09 - 2012-06-19 23:09 - 00001762 ____A C:\Users\AliciaSueYee\Desktop\Skype.lnk
2012-06-19 22:52 - 2010-11-20 19:47 - 00669624 ____A C:\Windows\PFRO.log
2012-06-11 19:08 - 2012-07-10 16:46 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-10 16:35 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 16:35 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 16:35 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 16:35 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 16:35 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 16:35 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 16:35 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 16:35 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 18:14 - 2012-06-05 18:14 - 00001829 ____A C:\Users\Public\Desktop\Opera.lnk
2012-06-05 18:14 - 2012-06-05 18:14 - 00001829 ____A C:\Users\All Users\Desktop\Opera.lnk
2012-06-02 22:31 - 2012-04-11 07:52 - 00001045 ____A C:\Users\AliciaSueYee\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-22 08:52 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-22 08:52 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-22 08:52 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-22 08:52 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-22 08:52 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-22 08:52 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-22 08:52 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-22 08:52 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-22 08:52 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 16:42 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 16:42 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 16:42 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 16:42 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 16:42 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 16:42 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 16:42 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 16:42 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 16:42 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 16:42 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 16:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 16:42 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 16:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 16:42 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 16:42 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 16:42 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 16:42 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 16:42 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 16:42 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 16:42 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 16:42 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 16:42 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 16:42 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 16:42 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 16:42 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 16:42 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 16:42 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 16:42 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 16:35 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 16:35 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 16:35 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 16:35 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 16:35 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 16:35 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 16:35 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 16:35 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 16:35 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 08:25 - 2010-11-20 19:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-28 08:33 - 2012-05-23 15:00 - 00006444 ____A C:\Windows\SysWOW64\AppLog.log
2012-05-25 16:30 - 2012-05-25 16:30 - 00031744 ____A C:\Users\AliciaSueYee\Downloads\Data_Set_4_-_Mothers_and_Daughters.xls
2012-05-04 03:06 - 2012-06-12 21:40 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 21:40 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 21:40 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 00:46 - 2012-05-04 00:46 - 00002418 ____A C:\Users\AliciaSueYee\Desktop\GA Fall.txt
ZeroAccess:
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\n
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L\00000004.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L\201d3dde
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\00000004.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\00000008.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\000000cb.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\80000000.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\80000032.@
C:\Windows\Installer\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U\80000064.@
ZeroAccess:
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\@
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\L
C:\Users\AliciaSueYee\AppData\Local\{fe3ef9bd-ee77-7df8-f15b-3ef5e0bbf996}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 8139.6 MB
Available physical RAM: 7185.02 MB
Total Pagefile: 8137.75 MB
Available Pagefile: 7158.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:673.14 GB) (Free:552.73 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (Recovery) (Fixed) (Total:21.33 GB) (Free:2.3 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.07 GB) FAT32
5 Drive h: (ALICIA) (Removable) (Total:3.72 GB) (Free:2.83 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 3822 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 673 GB 200 MB
Partition 3 Primary 21 GB 673 GB
Partition 4 Primary 4062 MB 694 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 199 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 673 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Recovery NTFS Partition 21 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F HP_TOOLS FAT32 Partition 4062 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3818 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H ALICIA FAT32 Removable 3818 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-27 23:12
======================= End Of Log ==========================