OscarZ
Posts: 48 +0
Hello,
Each time I start my Windows, Essentials detects a trojan and it restarts after a minute, it says that is Sirefef.w and Sirefef.ab
I read the instructions to somebody with a similar problem and downloaded the Farbar Recovery Scan Tool.
Thank you very much for your help.
Here the FRST Log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-10-2012
Ran by SYSTEM at 07-10-2012 20:42:51
Running from G:\
Windows 7 Professional N (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [309248 2009-02-27] (Alps Electric Co., Ltd.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [85160 2009-06-17] (Elaborate Bytes AG)
HKLM-x32\...\Run: [vmware-tray] "D:\ProgramFiles\VMWare\vmware-tray.exe" [x]
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKU\Oscar\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\Oscar\...\Run: [Google Update] "C:\Users\Oscar\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-05-10] (Google Inc.)
HKU\Oscar\...\Run: [] [x]
HKU\Oscar\...\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [1084840 2012-05-16] (Nokia)
HKU\Oscar\...\Run: [Windows Time] rundll32.exe "C:\ProgramData\OvvifwenYafz.dll",EntryPoint [31232 2012-08-08] (G-view)
Tcpip\Parameters: [DhcpNameServer] 200.118.2.91 190.157.2.140
Startup: C:\Users\Oscar\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Oscar\Start Menu\Programs\Startup\Recorte de pantalla y Selector de OneNote 2010.lnk
ShortcutTarget: Recorte de pantalla y Selector de OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ===================
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2003-04-18] ()
2 LogWatch; C:\Windows\LogWatNT.exe [50176 2000-06-08] ()
2 MKSAUTH; C:\Windows\SysWOW64\mksauth.exe [94168 2007-07-25] (Mortice Kern Systems Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
2 nsverctl; "C:\Program Files\Citrix\Secure Access Client\nsverctl.exe" [154776 2011-01-19] (Citrix Systems, Inc)
2 NuTCRACKERService; C:\Windows\system32\nutsrv4.exe [423896 2007-07-20] (MKS Software Inc.)
2 RetroExp Helper; "C:\Program Files (x86)\Retrospect\Retrospect Express HD 2.5\rthlpsvc.exe" [128280 2008-07-16] (EMC Corporation)
2 RetroExpLauncher; "C:\Program Files (x86)\Retrospect\Retrospect Express HD 2.5\retrorun.exe" [107800 2008-07-16] (EMC Corporation)
2 rpcnetp; C:\Windows\System32\rpcnetp.exe [17920 2012-10-07] ()
2 rpcnetp; C:\Windows\SysWow64\rpcnetp.exe [17920 2012-10-07] ()
2 VMUSBArbService; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [563760 2009-10-22] (VMware, Inc.)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
2 ASCLCSSrv; C:\IBM\InformationServer\MCM\ClientSwitcherService.exe /start [x]
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
2 TeamViewer7; C:\ProgramFiles\Version7\TeamViewer_Service.exe [x]
3 ufad-ws60; C:\ProgramFiles\VMWare\vmware-ufad.exe -d "C:\ProgramFiles\VMWare\\" -s ufad-p2v.xml [x]
2 VMAuthdService; "C:\ProgramFiles\VMWare\vmware-authd.exe" [x]
==================== Drivers (Whitelisted) =====================
2 cag; \??\C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys [96384 2010-08-04] (Citrix Systems, Inc.)
3 ctxva51; C:\Windows\System32\Drivers\ctxva51.sys [45720 2011-01-19] (Citrix Systems, Inc.)
2 DLABMFSE; C:\Windows\System32\Drivers\DLABMFSE.sys [46448 2007-07-23] (Roxio)
2 DLABOIOE; C:\Windows\System32\Drivers\DLABOIOE.sys [42352 2007-07-23] (Roxio)
0 DLACDBHE; C:\Windows\System32\Drivers\DLACDBHE.sys [17776 2007-07-23] (Roxio)
2 DLADResE; C:\Windows\System32\Drivers\DLADResE.sys [9968 2007-07-23] (Roxio)
2 DLAIFS_E; C:\Windows\System32\Drivers\DLAIFS_E.sys [146672 2007-07-23] (Roxio)
2 DLAOPIOE; C:\Windows\System32\Drivers\DLAOPIOE.sys [35056 2007-07-23] (Roxio)
2 DLAPoolE; C:\Windows\System32\Drivers\DLAPoolE.sys [19824 2007-07-23] (Roxio)
1 DLARTL_E; C:\Windows\System32\Drivers\DLARTL_E.sys [41072 2007-07-23] (Roxio)
2 DLAUDFAE; C:\Windows\System32\Drivers\DLAUDFAE.sys [135152 2007-07-23] (Roxio)
2 DLAUDF_E; C:\Windows\System32\Drivers\DLAUDF_E.sys [144112 2007-07-23] (Roxio)
0 DRVECDB; C:\Windows\System32\Drivers\DRVECDB.sys [124112 2007-07-23] (Sonic Solutions)
2 DRVEDDM; C:\Windows\System32\Drivers\DRVEDDM.sys [63984 2007-07-23] (Roxio)
3 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [32768 2010-01-18] (Huawei Tech. Co., Ltd.)
3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-11] (Huawei Technologies Co., Ltd.)
3 msloop; C:\Windows\System32\DRIVERS\loop.sys [7680 2009-07-13] (Microsoft Corporation)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [47632 2009-10-20] (CACE Technologies, Inc.)
3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [48800 2009-05-07] (O2Micro )
3 OEM13Vfx; C:\Windows\System32\Drivers\OEM13Vfx.sys [12288 2007-03-05] (EyePower Games Pte. Ltd.)
3 OEM13Vid; C:\Windows\System32\Drivers\OEM13Vid.sys [267296 2008-05-28] (Creative Technology Ltd.)
0 pavboot; C:\Windows\System32\drivers\pavboot64.sys [33800 2009-06-30] (Panda Security, S.L.)
3 s125bus; C:\Windows\System32\Drivers\s125bus.sys [108296 2007-04-24] (MCCI Corporation)
3 s125mdfl; C:\Windows\System32\Drivers\s125mdfl.sys [19720 2007-04-24] (MCCI Corporation)
3 s125mdm; C:\Windows\System32\Drivers\s125mdm.sys [144648 2007-04-24] (MCCI Corporation)
3 s125mgmt; C:\Windows\System32\Drivers\s125mgmt.sys [126216 2007-04-24] (MCCI Corporation)
3 s125obex; C:\Windows\System32\Drivers\s125obex.sys [123656 2007-04-24] (MCCI Corporation)
2 vstor2-ws60; \??\D:\ProgramFiles\VMWare\vstor2-ws60.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-10-07 20:42 - 2012-10-07 20:42 - 00000000 ____D C:\FRST
2012-10-07 16:41 - 2012-10-07 16:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB2E2F2256B466F3
2012-10-07 16:31 - 2012-10-07 16:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E21C948CC2A0677A
2012-10-07 16:22 - 2012-10-07 16:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17B677EA6C7C465A
2012-10-07 16:14 - 2012-10-07 16:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89104D6F9D9BB4A1
2012-10-07 16:07 - 2012-10-07 16:09 - 13540328 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall(1).exe
2012-10-07 16:02 - 2012-10-07 16:04 - 13529576 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall.exe
2012-10-07 11:13 - 2012-10-07 11:13 - 00000000 ____D C:\Users\Oscar\AppData\Roaming\Rational
2012-10-07 11:07 - 2012-10-07 11:17 - 00000105 ____A C:\Users\All Users\.sdplic
2012-10-07 10:42 - 2012-10-07 10:42 - 00000000 ____D C:\Users\Oscar\AppData\Local\{70A8234C-ECD8-43BD-ACCD-EFDAE1D67234}
2012-10-07 10:35 - 2012-10-07 10:35 - 00000000 ____D C:\Users\Oscar\AppData\Local\{09551C6C-DEC1-41B1-83C1-33EB53E78DB4}
2012-10-07 09:39 - 2012-10-07 09:39 - 00000000 ____D C:\Users\Oscar\AppData\Local\javasharedresources
2012-10-07 09:28 - 2012-10-07 09:28 - 00000000 ____D C:\Users\Oscar\AppData\Roaming\IBM
2012-10-07 09:28 - 2012-10-07 09:28 - 00000000 ____D C:\Users\All Users\IBM
2012-10-07 09:24 - 2012-10-07 09:24 - 00000000 ____D C:\Users\Oscar\AppData\Local\{9DFA4BAE-95DC-4DEC-96EC-13BAF28BC294}
2012-10-06 08:09 - 2012-10-06 08:10 - 00000000 ____D C:\Users\Oscar\AppData\Local\{0465A75F-5699-4213-A3EF-D711A56261D4}
2012-10-05 18:01 - 2012-10-05 18:01 - 00000000 ____D C:\Users\Oscar\Downloads\fwdcasamodeloproyectoterraocre
2012-10-05 18:00 - 2012-10-05 18:00 - 00581069 ____A C:\Users\Oscar\Downloads\fwdcasamodeloproyectoterraocre.zip
2012-10-05 14:05 - 2012-10-05 14:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{D4768795-1147-4A55-96BC-084691A115CB}
2012-10-04 12:27 - 2012-10-04 12:28 - 00000000 ____D C:\Users\Oscar\AppData\Local\{12A3830E-E764-4E85-ACDF-CCD8BEF3674A}
2012-10-03 14:04 - 2012-10-03 14:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{3A13BFC4-95D8-469C-B780-B567E825371A}
2012-10-02 13:01 - 2012-10-02 13:01 - 00000000 ____D C:\Users\Oscar\AppData\Local\{A05A0ECA-8C7C-4AFE-9A65-589BF46EE8C7}
2012-10-01 15:17 - 2012-10-01 15:17 - 00000000 ____D C:\Users\Oscar\AppData\Local\{899BF719-8DE7-4845-8A29-81BE3534B388}
2012-10-01 13:10 - 2012-09-04 10:30 - 00038912 ____A (Absolute Software Corporation) C:\Windows\SysWOW64\identprv.dll
2012-09-30 06:23 - 2012-09-30 06:23 - 00000000 ____D C:\Users\Oscar\AppData\Local\{7845DACA-8CB2-40BA-86F6-D841F67CCC46}
2012-09-29 04:04 - 2012-09-29 04:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{0D6ACF0F-A93D-43E3-910F-A683DBAC7690}
2012-09-27 12:09 - 2012-09-27 12:10 - 00000000 ____D C:\Users\Oscar\AppData\Local\{83C1E754-AF8D-418E-9DF8-08E00B671C20}
2012-09-26 15:37 - 2012-09-26 15:37 - 00000000 ____D C:\Users\Oscar\AppData\Local\{E680FD49-273E-47D2-B24D-2FEFBB59C8A6}
2012-09-25 16:09 - 2012-09-25 16:09 - 00000000 ____D C:\Users\Oscar\AppData\Local\{A3CD9CC7-4912-419E-81C3-81AA16D60B44}
2012-09-24 14:21 - 2012-09-24 14:22 - 00000000 ____D C:\Users\Oscar\AppData\Local\{3BD60750-A904-4FFA-A8C7-85D450363123}
2012-09-23 17:38 - 2012-09-23 17:38 - 00000000 ____D C:\Users\Oscar\AppData\Local\{F098413E-E56C-4E3B-B384-DFE2F9CFC646}
2012-09-22 16:06 - 2012-09-22 16:06 - 00000000 ____D C:\Users\Oscar\AppData\Local\{F34C45D1-AC7B-457C-A53D-14DAE1669BC2}
2012-09-21 14:45 - 2012-09-21 14:45 - 00000000 ____D C:\Users\Oscar\AppData\Local\{52F8F118-0E7C-44C3-96C8-A5FDBA5FF281}
2012-09-20 13:33 - 2012-09-20 13:34 - 00000000 ____D C:\Users\Oscar\AppData\Local\{774E50B8-99C4-4694-9A93-E4124D9F85E0}
2012-09-19 13:43 - 2012-09-19 13:44 - 00000000 ____D C:\Users\Oscar\AppData\Local\{22E0198D-E899-4329-A9E6-EC5C0B3FD851}
2012-09-18 13:36 - 2012-09-18 13:36 - 00000000 ____D C:\Users\Oscar\AppData\Local\{E41BC32C-DB30-4CDB-9414-537F7050271D}
2012-09-17 12:13 - 2012-09-17 12:13 - 00000000 ____D C:\Users\Oscar\AppData\Local\{FF7BDED2-30D5-479E-BEC0-93B69BB821A7}
2012-09-16 15:17 - 2012-09-16 15:17 - 00000000 ____D C:\Users\Oscar\AppData\Local\{6FA8EE90-94FF-4A83-B8F1-AE6094663A00}
2012-09-15 06:38 - 2012-09-15 06:38 - 00000000 ____D C:\Users\Oscar\AppData\Local\{EDE2D357-DFE7-4167-885F-2CC4891AA4FC}
2012-09-14 16:05 - 2012-09-14 16:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{FC7D132C-2B7A-4B40-BE9B-48343F30948F}
2012-09-13 12:13 - 2012-09-13 12:13 - 00000000 ____D C:\Users\Oscar\AppData\Local\{2AC906E7-952F-471E-BB65-FDBE77E71ACB}
2012-09-12 13:01 - 2012-09-12 13:02 - 00000000 ____D C:\Users\Oscar\AppData\Local\{9F614F6F-8A70-4E74-BD0A-7F4193FAC31A}
2012-09-09 13:39 - 2012-09-09 13:40 - 00000000 ____D C:\Users\Oscar\AppData\Local\{1AB49357-EA84-437F-82F2-A9C953D9FC43}
2012-09-08 08:11 - 2012-09-08 08:11 - 00000000 ____D C:\Users\Oscar\AppData\Local\{FCC26B3C-8204-4600-899D-1FC048E7B6C3}
2012-09-07 15:14 - 2012-09-29 10:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-09-07 14:10 - 2012-09-07 14:10 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-09-07 13:38 - 2012-09-07 13:39 - 00000000 ____D C:\Users\Oscar\AppData\Local\{36074283-52D7-470B-A8E2-897386CC71ED}
==================== 3 Months Modified Files ==================
2012-10-07 17:38 - 2012-04-28 18:57 - 00058288 ____A (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll
2012-10-07 17:38 - 2011-01-25 17:53 - 00001030 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-10-07 17:38 - 2010-03-09 09:21 - 00017920 ____A C:\Windows\SysWOW64\rpcnetp.dll
2012-10-07 17:38 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-07 17:37 - 2011-06-27 09:40 - 00072260 ____A C:\Windows\setupact.log
2012-10-07 17:37 - 2010-03-09 10:16 - 01773571 ____A C:\Windows\WindowsUpdate.log
2012-10-07 17:36 - 2010-03-09 09:20 - 00017920 ____A C:\Windows\SysWOW64\rpcnetp.exe
2012-10-07 17:36 - 2010-03-09 09:20 - 00017920 ____A C:\Windows\System32\rpcnetp.exe
2012-10-07 17:26 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-10-07 16:41 - 2012-10-07 16:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB2E2F2256B466F3
2012-10-07 16:31 - 2012-10-07 16:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E21C948CC2A0677A
2012-10-07 16:22 - 2012-10-07 16:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17B677EA6C7C465A
2012-10-07 16:14 - 2012-10-07 16:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89104D6F9D9BB4A1
2012-10-07 16:12 - 2011-01-28 22:15 - 00002155 ____A C:\Windows\epplauncher.mif
2012-10-07 16:09 - 2012-10-07 16:07 - 13540328 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall(1).exe
2012-10-07 16:08 - 2012-04-02 06:08 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-10-07 16:04 - 2012-10-07 16:02 - 13529576 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall.exe
2012-10-07 15:32 - 2011-01-25 17:54 - 00001034 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-10-07 15:24 - 2010-05-10 19:10 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3223265864-3949170350-323350453-1000UA.job
2012-10-07 12:24 - 2010-05-10 19:10 - 00000994 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3223265864-3949170350-323350453-1000Core.job
2012-10-07 11:17 - 2012-10-07 11:07 - 00000105 ____A C:\Users\All Users\.sdplic
2012-10-07 10:47 - 2009-07-13 20:50 - 00015200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-10-07 10:47 - 2009-07-13 20:50 - 00015200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-10-07 09:36 - 2010-03-10 06:42 - 00007620 ____A C:\Users\Oscar\AppData\Local\resmon.resmoncfg
2012-10-07 09:26 - 2009-07-13 21:12 - 00936528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-10-05 18:00 - 2012-10-05 18:00 - 00581069 ____A C:\Users\Oscar\Downloads\fwdcasamodeloproyectoterraocre.zip
2012-09-29 10:38 - 2011-04-15 13:47 - 00001130 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-09-21 15:09 - 2012-04-02 06:08 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-21 15:09 - 2011-06-07 17:16 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-04 14:11 - 2010-03-10 09:33 - 00058288 ____N (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe
2012-09-04 14:11 - 2010-03-10 09:33 - 00013160 ____A (Absolute Software Corp.) C:\Windows\SysWOW64\Upgrd.exe
2012-09-04 10:30 - 2012-10-01 13:10 - 00038912 ____A (Absolute Software Corporation) C:\Windows\SysWOW64\identprv.dll
2012-09-02 18:33 - 2012-09-02 18:33 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
2012-08-30 19:03 - 2012-08-30 19:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 19:03 - 2010-10-24 18:25 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-20 17:47 - 2012-01-21 09:10 - 00002014 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-08-20 12:47 - 2012-08-20 12:47 - 00507302 ____A C:\Users\Oscar\Downloads\gmc_setup_v1.exe
2012-08-11 05:23 - 2009-07-13 21:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-08 16:25 - 2012-08-08 16:25 - 00031232 ____A (G-view) C:\Users\All Users\OvvifwenYafz.dll
2012-08-04 20:49 - 2012-08-04 20:49 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-04 20:49 - 2012-08-04 20:46 - 19198344 ____A (Panda Security ) C:\Users\Oscar\Downloads\PandaCloudCleaner.exe
2012-08-04 20:42 - 2011-07-06 09:31 - 00028516 ____A C:\Windows\PFRO.log
2012-08-04 18:27 - 2012-08-04 18:26 - 04533848 ____A (www.orbitdownloader.com ) C:\Users\Oscar\Downloads\OrbitDownloaderSetup.exe
2012-07-29 17:24 - 2012-07-29 17:24 - 00001176 ____A C:\Users\Public\Desktop\Paint.NET.lnk
2012-07-29 17:22 - 2012-07-29 17:22 - 03730109 ____A C:\Users\Oscar\Downloads\Paint.NET.3.5.10.Install.zip
2012-07-15 10:23 - 2012-07-15 10:23 - 03623673 ____A C:\Users\Oscar\Downloads\documentosdelreacienciasnaturales.zip
2012-07-13 16:13 - 2009-07-13 20:50 - 04965224 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 18:52 - 2010-03-12 05:12 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
ZeroAccess:
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\@
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\L
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\n
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\00000001.@
ZeroAccess:
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\@
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\L
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\n.vir
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\00000001.@
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\80000000.@
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\800000cb.@
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 16%
Total physical RAM: 4056.88 MB
Available physical RAM: 3385.59 MB
Total Pagefile: 4055.03 MB
Available Pagefile: 3387.52 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:50 GB) (Free:4.08 GB) NTFS
2 Drive e: () (Fixed) (Total:182.79 GB) (Free:42.79 GB) NTFS
4 Drive g: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 Online 3835 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 50 GB 101 MB
Partition 3 Primary 182 GB 50 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 50 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 182 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3827 MB Healthy
=========================================================
Last Boot: 2012-09-27 12:04
==================== End Of Log =============================
Each time I start my Windows, Essentials detects a trojan and it restarts after a minute, it says that is Sirefef.w and Sirefef.ab
I read the instructions to somebody with a similar problem and downloaded the Farbar Recovery Scan Tool.
Thank you very much for your help.
Here the FRST Log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-10-2012
Ran by SYSTEM at 07-10-2012 20:42:51
Running from G:\
Windows 7 Professional N (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [309248 2009-02-27] (Alps Electric Co., Ltd.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s [85160 2009-06-17] (Elaborate Bytes AG)
HKLM-x32\...\Run: [vmware-tray] "D:\ProgramFiles\VMWare\vmware-tray.exe" [x]
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKU\Oscar\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\Oscar\...\Run: [Google Update] "C:\Users\Oscar\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-05-10] (Google Inc.)
HKU\Oscar\...\Run: [] [x]
HKU\Oscar\...\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [1084840 2012-05-16] (Nokia)
HKU\Oscar\...\Run: [Windows Time] rundll32.exe "C:\ProgramData\OvvifwenYafz.dll",EntryPoint [31232 2012-08-08] (G-view)
Tcpip\Parameters: [DhcpNameServer] 200.118.2.91 190.157.2.140
Startup: C:\Users\Oscar\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Oscar\Start Menu\Programs\Startup\Recorte de pantalla y Selector de OneNote 2010.lnk
ShortcutTarget: Recorte de pantalla y Selector de OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ===================
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2003-04-18] ()
2 LogWatch; C:\Windows\LogWatNT.exe [50176 2000-06-08] ()
2 MKSAUTH; C:\Windows\SysWOW64\mksauth.exe [94168 2007-07-25] (Mortice Kern Systems Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
2 nsverctl; "C:\Program Files\Citrix\Secure Access Client\nsverctl.exe" [154776 2011-01-19] (Citrix Systems, Inc)
2 NuTCRACKERService; C:\Windows\system32\nutsrv4.exe [423896 2007-07-20] (MKS Software Inc.)
2 RetroExp Helper; "C:\Program Files (x86)\Retrospect\Retrospect Express HD 2.5\rthlpsvc.exe" [128280 2008-07-16] (EMC Corporation)
2 RetroExpLauncher; "C:\Program Files (x86)\Retrospect\Retrospect Express HD 2.5\retrorun.exe" [107800 2008-07-16] (EMC Corporation)
2 rpcnetp; C:\Windows\System32\rpcnetp.exe [17920 2012-10-07] ()
2 rpcnetp; C:\Windows\SysWow64\rpcnetp.exe [17920 2012-10-07] ()
2 VMUSBArbService; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [563760 2009-10-22] (VMware, Inc.)
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
2 ASCLCSSrv; C:\IBM\InformationServer\MCM\ClientSwitcherService.exe /start [x]
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
2 TeamViewer7; C:\ProgramFiles\Version7\TeamViewer_Service.exe [x]
3 ufad-ws60; C:\ProgramFiles\VMWare\vmware-ufad.exe -d "C:\ProgramFiles\VMWare\\" -s ufad-p2v.xml [x]
2 VMAuthdService; "C:\ProgramFiles\VMWare\vmware-authd.exe" [x]
==================== Drivers (Whitelisted) =====================
2 cag; \??\C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys [96384 2010-08-04] (Citrix Systems, Inc.)
3 ctxva51; C:\Windows\System32\Drivers\ctxva51.sys [45720 2011-01-19] (Citrix Systems, Inc.)
2 DLABMFSE; C:\Windows\System32\Drivers\DLABMFSE.sys [46448 2007-07-23] (Roxio)
2 DLABOIOE; C:\Windows\System32\Drivers\DLABOIOE.sys [42352 2007-07-23] (Roxio)
0 DLACDBHE; C:\Windows\System32\Drivers\DLACDBHE.sys [17776 2007-07-23] (Roxio)
2 DLADResE; C:\Windows\System32\Drivers\DLADResE.sys [9968 2007-07-23] (Roxio)
2 DLAIFS_E; C:\Windows\System32\Drivers\DLAIFS_E.sys [146672 2007-07-23] (Roxio)
2 DLAOPIOE; C:\Windows\System32\Drivers\DLAOPIOE.sys [35056 2007-07-23] (Roxio)
2 DLAPoolE; C:\Windows\System32\Drivers\DLAPoolE.sys [19824 2007-07-23] (Roxio)
1 DLARTL_E; C:\Windows\System32\Drivers\DLARTL_E.sys [41072 2007-07-23] (Roxio)
2 DLAUDFAE; C:\Windows\System32\Drivers\DLAUDFAE.sys [135152 2007-07-23] (Roxio)
2 DLAUDF_E; C:\Windows\System32\Drivers\DLAUDF_E.sys [144112 2007-07-23] (Roxio)
0 DRVECDB; C:\Windows\System32\Drivers\DRVECDB.sys [124112 2007-07-23] (Sonic Solutions)
2 DRVEDDM; C:\Windows\System32\Drivers\DRVEDDM.sys [63984 2007-07-23] (Roxio)
3 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [32768 2010-01-18] (Huawei Tech. Co., Ltd.)
3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-11] (Huawei Technologies Co., Ltd.)
3 msloop; C:\Windows\System32\DRIVERS\loop.sys [7680 2009-07-13] (Microsoft Corporation)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [47632 2009-10-20] (CACE Technologies, Inc.)
3 O2SDGRDR; C:\Windows\System32\DRIVERS\o2sdgx64.sys [48800 2009-05-07] (O2Micro )
3 OEM13Vfx; C:\Windows\System32\Drivers\OEM13Vfx.sys [12288 2007-03-05] (EyePower Games Pte. Ltd.)
3 OEM13Vid; C:\Windows\System32\Drivers\OEM13Vid.sys [267296 2008-05-28] (Creative Technology Ltd.)
0 pavboot; C:\Windows\System32\drivers\pavboot64.sys [33800 2009-06-30] (Panda Security, S.L.)
3 s125bus; C:\Windows\System32\Drivers\s125bus.sys [108296 2007-04-24] (MCCI Corporation)
3 s125mdfl; C:\Windows\System32\Drivers\s125mdfl.sys [19720 2007-04-24] (MCCI Corporation)
3 s125mdm; C:\Windows\System32\Drivers\s125mdm.sys [144648 2007-04-24] (MCCI Corporation)
3 s125mgmt; C:\Windows\System32\Drivers\s125mgmt.sys [126216 2007-04-24] (MCCI Corporation)
3 s125obex; C:\Windows\System32\Drivers\s125obex.sys [123656 2007-04-24] (MCCI Corporation)
2 vstor2-ws60; \??\D:\ProgramFiles\VMWare\vstor2-ws60.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-10-07 20:42 - 2012-10-07 20:42 - 00000000 ____D C:\FRST
2012-10-07 16:41 - 2012-10-07 16:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB2E2F2256B466F3
2012-10-07 16:31 - 2012-10-07 16:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E21C948CC2A0677A
2012-10-07 16:22 - 2012-10-07 16:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17B677EA6C7C465A
2012-10-07 16:14 - 2012-10-07 16:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89104D6F9D9BB4A1
2012-10-07 16:07 - 2012-10-07 16:09 - 13540328 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall(1).exe
2012-10-07 16:02 - 2012-10-07 16:04 - 13529576 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall.exe
2012-10-07 11:13 - 2012-10-07 11:13 - 00000000 ____D C:\Users\Oscar\AppData\Roaming\Rational
2012-10-07 11:07 - 2012-10-07 11:17 - 00000105 ____A C:\Users\All Users\.sdplic
2012-10-07 10:42 - 2012-10-07 10:42 - 00000000 ____D C:\Users\Oscar\AppData\Local\{70A8234C-ECD8-43BD-ACCD-EFDAE1D67234}
2012-10-07 10:35 - 2012-10-07 10:35 - 00000000 ____D C:\Users\Oscar\AppData\Local\{09551C6C-DEC1-41B1-83C1-33EB53E78DB4}
2012-10-07 09:39 - 2012-10-07 09:39 - 00000000 ____D C:\Users\Oscar\AppData\Local\javasharedresources
2012-10-07 09:28 - 2012-10-07 09:28 - 00000000 ____D C:\Users\Oscar\AppData\Roaming\IBM
2012-10-07 09:28 - 2012-10-07 09:28 - 00000000 ____D C:\Users\All Users\IBM
2012-10-07 09:24 - 2012-10-07 09:24 - 00000000 ____D C:\Users\Oscar\AppData\Local\{9DFA4BAE-95DC-4DEC-96EC-13BAF28BC294}
2012-10-06 08:09 - 2012-10-06 08:10 - 00000000 ____D C:\Users\Oscar\AppData\Local\{0465A75F-5699-4213-A3EF-D711A56261D4}
2012-10-05 18:01 - 2012-10-05 18:01 - 00000000 ____D C:\Users\Oscar\Downloads\fwdcasamodeloproyectoterraocre
2012-10-05 18:00 - 2012-10-05 18:00 - 00581069 ____A C:\Users\Oscar\Downloads\fwdcasamodeloproyectoterraocre.zip
2012-10-05 14:05 - 2012-10-05 14:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{D4768795-1147-4A55-96BC-084691A115CB}
2012-10-04 12:27 - 2012-10-04 12:28 - 00000000 ____D C:\Users\Oscar\AppData\Local\{12A3830E-E764-4E85-ACDF-CCD8BEF3674A}
2012-10-03 14:04 - 2012-10-03 14:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{3A13BFC4-95D8-469C-B780-B567E825371A}
2012-10-02 13:01 - 2012-10-02 13:01 - 00000000 ____D C:\Users\Oscar\AppData\Local\{A05A0ECA-8C7C-4AFE-9A65-589BF46EE8C7}
2012-10-01 15:17 - 2012-10-01 15:17 - 00000000 ____D C:\Users\Oscar\AppData\Local\{899BF719-8DE7-4845-8A29-81BE3534B388}
2012-10-01 13:10 - 2012-09-04 10:30 - 00038912 ____A (Absolute Software Corporation) C:\Windows\SysWOW64\identprv.dll
2012-09-30 06:23 - 2012-09-30 06:23 - 00000000 ____D C:\Users\Oscar\AppData\Local\{7845DACA-8CB2-40BA-86F6-D841F67CCC46}
2012-09-29 04:04 - 2012-09-29 04:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{0D6ACF0F-A93D-43E3-910F-A683DBAC7690}
2012-09-27 12:09 - 2012-09-27 12:10 - 00000000 ____D C:\Users\Oscar\AppData\Local\{83C1E754-AF8D-418E-9DF8-08E00B671C20}
2012-09-26 15:37 - 2012-09-26 15:37 - 00000000 ____D C:\Users\Oscar\AppData\Local\{E680FD49-273E-47D2-B24D-2FEFBB59C8A6}
2012-09-25 16:09 - 2012-09-25 16:09 - 00000000 ____D C:\Users\Oscar\AppData\Local\{A3CD9CC7-4912-419E-81C3-81AA16D60B44}
2012-09-24 14:21 - 2012-09-24 14:22 - 00000000 ____D C:\Users\Oscar\AppData\Local\{3BD60750-A904-4FFA-A8C7-85D450363123}
2012-09-23 17:38 - 2012-09-23 17:38 - 00000000 ____D C:\Users\Oscar\AppData\Local\{F098413E-E56C-4E3B-B384-DFE2F9CFC646}
2012-09-22 16:06 - 2012-09-22 16:06 - 00000000 ____D C:\Users\Oscar\AppData\Local\{F34C45D1-AC7B-457C-A53D-14DAE1669BC2}
2012-09-21 14:45 - 2012-09-21 14:45 - 00000000 ____D C:\Users\Oscar\AppData\Local\{52F8F118-0E7C-44C3-96C8-A5FDBA5FF281}
2012-09-20 13:33 - 2012-09-20 13:34 - 00000000 ____D C:\Users\Oscar\AppData\Local\{774E50B8-99C4-4694-9A93-E4124D9F85E0}
2012-09-19 13:43 - 2012-09-19 13:44 - 00000000 ____D C:\Users\Oscar\AppData\Local\{22E0198D-E899-4329-A9E6-EC5C0B3FD851}
2012-09-18 13:36 - 2012-09-18 13:36 - 00000000 ____D C:\Users\Oscar\AppData\Local\{E41BC32C-DB30-4CDB-9414-537F7050271D}
2012-09-17 12:13 - 2012-09-17 12:13 - 00000000 ____D C:\Users\Oscar\AppData\Local\{FF7BDED2-30D5-479E-BEC0-93B69BB821A7}
2012-09-16 15:17 - 2012-09-16 15:17 - 00000000 ____D C:\Users\Oscar\AppData\Local\{6FA8EE90-94FF-4A83-B8F1-AE6094663A00}
2012-09-15 06:38 - 2012-09-15 06:38 - 00000000 ____D C:\Users\Oscar\AppData\Local\{EDE2D357-DFE7-4167-885F-2CC4891AA4FC}
2012-09-14 16:05 - 2012-09-14 16:05 - 00000000 ____D C:\Users\Oscar\AppData\Local\{FC7D132C-2B7A-4B40-BE9B-48343F30948F}
2012-09-13 12:13 - 2012-09-13 12:13 - 00000000 ____D C:\Users\Oscar\AppData\Local\{2AC906E7-952F-471E-BB65-FDBE77E71ACB}
2012-09-12 13:01 - 2012-09-12 13:02 - 00000000 ____D C:\Users\Oscar\AppData\Local\{9F614F6F-8A70-4E74-BD0A-7F4193FAC31A}
2012-09-09 13:39 - 2012-09-09 13:40 - 00000000 ____D C:\Users\Oscar\AppData\Local\{1AB49357-EA84-437F-82F2-A9C953D9FC43}
2012-09-08 08:11 - 2012-09-08 08:11 - 00000000 ____D C:\Users\Oscar\AppData\Local\{FCC26B3C-8204-4600-899D-1FC048E7B6C3}
2012-09-07 15:14 - 2012-09-29 10:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-09-07 14:10 - 2012-09-07 14:10 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-09-07 13:38 - 2012-09-07 13:39 - 00000000 ____D C:\Users\Oscar\AppData\Local\{36074283-52D7-470B-A8E2-897386CC71ED}
==================== 3 Months Modified Files ==================
2012-10-07 17:38 - 2012-04-28 18:57 - 00058288 ____A (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll
2012-10-07 17:38 - 2011-01-25 17:53 - 00001030 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-10-07 17:38 - 2010-03-09 09:21 - 00017920 ____A C:\Windows\SysWOW64\rpcnetp.dll
2012-10-07 17:38 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-10-07 17:37 - 2011-06-27 09:40 - 00072260 ____A C:\Windows\setupact.log
2012-10-07 17:37 - 2010-03-09 10:16 - 01773571 ____A C:\Windows\WindowsUpdate.log
2012-10-07 17:36 - 2010-03-09 09:20 - 00017920 ____A C:\Windows\SysWOW64\rpcnetp.exe
2012-10-07 17:36 - 2010-03-09 09:20 - 00017920 ____A C:\Windows\System32\rpcnetp.exe
2012-10-07 17:26 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-10-07 16:41 - 2012-10-07 16:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB2E2F2256B466F3
2012-10-07 16:31 - 2012-10-07 16:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E21C948CC2A0677A
2012-10-07 16:22 - 2012-10-07 16:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17B677EA6C7C465A
2012-10-07 16:14 - 2012-10-07 16:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89104D6F9D9BB4A1
2012-10-07 16:12 - 2011-01-28 22:15 - 00002155 ____A C:\Windows\epplauncher.mif
2012-10-07 16:09 - 2012-10-07 16:07 - 13540328 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall(1).exe
2012-10-07 16:08 - 2012-04-02 06:08 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-10-07 16:04 - 2012-10-07 16:02 - 13529576 ____A (Microsoft Corporation) C:\Users\Oscar\Downloads\mseinstall.exe
2012-10-07 15:32 - 2011-01-25 17:54 - 00001034 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-10-07 15:24 - 2010-05-10 19:10 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3223265864-3949170350-323350453-1000UA.job
2012-10-07 12:24 - 2010-05-10 19:10 - 00000994 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3223265864-3949170350-323350453-1000Core.job
2012-10-07 11:17 - 2012-10-07 11:07 - 00000105 ____A C:\Users\All Users\.sdplic
2012-10-07 10:47 - 2009-07-13 20:50 - 00015200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-10-07 10:47 - 2009-07-13 20:50 - 00015200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-10-07 09:36 - 2010-03-10 06:42 - 00007620 ____A C:\Users\Oscar\AppData\Local\resmon.resmoncfg
2012-10-07 09:26 - 2009-07-13 21:12 - 00936528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-10-05 18:00 - 2012-10-05 18:00 - 00581069 ____A C:\Users\Oscar\Downloads\fwdcasamodeloproyectoterraocre.zip
2012-09-29 10:38 - 2011-04-15 13:47 - 00001130 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-09-21 15:09 - 2012-04-02 06:08 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-21 15:09 - 2011-06-07 17:16 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-04 14:11 - 2010-03-10 09:33 - 00058288 ____N (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe
2012-09-04 14:11 - 2010-03-10 09:33 - 00013160 ____A (Absolute Software Corp.) C:\Windows\SysWOW64\Upgrd.exe
2012-09-04 10:30 - 2012-10-01 13:10 - 00038912 ____A (Absolute Software Corporation) C:\Windows\SysWOW64\identprv.dll
2012-09-02 18:33 - 2012-09-02 18:33 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
2012-08-30 19:03 - 2012-08-30 19:03 - 00228768 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-08-30 19:03 - 2010-10-24 18:25 - 00128456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-08-20 17:47 - 2012-01-21 09:10 - 00002014 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-08-20 12:47 - 2012-08-20 12:47 - 00507302 ____A C:\Users\Oscar\Downloads\gmc_setup_v1.exe
2012-08-11 05:23 - 2009-07-13 21:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-08 16:25 - 2012-08-08 16:25 - 00031232 ____A (G-view) C:\Users\All Users\OvvifwenYafz.dll
2012-08-04 20:49 - 2012-08-04 20:49 - 00001282 ____A C:\Users\Public\Desktop\Panda Cloud Cleaner.lnk
2012-08-04 20:49 - 2012-08-04 20:46 - 19198344 ____A (Panda Security ) C:\Users\Oscar\Downloads\PandaCloudCleaner.exe
2012-08-04 20:42 - 2011-07-06 09:31 - 00028516 ____A C:\Windows\PFRO.log
2012-08-04 18:27 - 2012-08-04 18:26 - 04533848 ____A (www.orbitdownloader.com ) C:\Users\Oscar\Downloads\OrbitDownloaderSetup.exe
2012-07-29 17:24 - 2012-07-29 17:24 - 00001176 ____A C:\Users\Public\Desktop\Paint.NET.lnk
2012-07-29 17:22 - 2012-07-29 17:22 - 03730109 ____A C:\Users\Oscar\Downloads\Paint.NET.3.5.10.Install.zip
2012-07-15 10:23 - 2012-07-15 10:23 - 03623673 ____A C:\Users\Oscar\Downloads\documentosdelreacienciasnaturales.zip
2012-07-13 16:13 - 2009-07-13 20:50 - 04965224 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 18:52 - 2010-03-12 05:12 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
ZeroAccess:
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\@
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\L
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\n
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U
C:\Windows\Installer\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\00000001.@
ZeroAccess:
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\@
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\L
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\n.vir
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\00000001.@
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\80000000.@
C:\Users\Oscar\AppData\Local\{4a97ea77-0bb0-3f60-6279-0682757e39c6}\U\800000cb.@
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 16%
Total physical RAM: 4056.88 MB
Available physical RAM: 3385.59 MB
Total Pagefile: 4055.03 MB
Available Pagefile: 3387.52 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:50 GB) (Free:4.08 GB) NTFS
2 Drive e: () (Fixed) (Total:182.79 GB) (Free:42.79 GB) NTFS
4 Drive g: () (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 Online 3835 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 50 GB 101 MB
Partition 3 Primary 182 GB 50 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 50 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 182 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3827 MB 19 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3827 MB Healthy
=========================================================
Last Boot: 2012-09-27 12:04
==================== End Of Log =============================