MTshortstuff
Posts: 8 +0
Hey guys. Like many others, my home computer got infected with Win64/sirefef.y today. I've browsed the threads you have made for other users, and I have followed the instructions up to the point where I can get the initial report from the Farbar Recovery Scan Tool. It seems like the action to take from here is unique to each infected computer, so I was wondering if I could get the 411 on my situation.
Here is the report. Thanks in advance guys
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 19:26:15
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k [244480 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Gateway Photo Frame] "C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe" -A [124416 2009-07-20] (IOI)
HKLM-x32\...\Run: [Qwest Personal Digital Vault] "C:\Program Files (x86)\Qwest Personal Digital Vault\QwestPersonalDigitalVault.exe" /m [1064808 2009-12-18] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421160 2011-04-14] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-04-08] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [x]
HKLM-x32\...\Run: [Philips Device Listener] "C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe" [380416 2012-03-16] ()
HKLM-x32\...\Run: [BYR_AGENT] C:\ProgramData\LGMOBILEAX\BYR_Client\VZWNotiAgent.exe [392280 2012-03-14] (LG Electronics)
HKU\Betsy\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2009-08-27] (Google Inc.)
HKU\Betsy\...\Run: [Ihotushi] C:\Users\Betsy\AppData\Roaming\Avatbo\myco.exe [307200 2010-09-28] (IconFX Software)
HKU\Betsy\...\Policies\system: [LogonHoursAction] 2
HKU\Betsy\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Brandon\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4240760 2010-11-10] (Microsoft Corporation)
HKU\Brandon\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2009-08-27] (Google Inc.)
HKU\Brandon\...\Run: [winupd] C:\Users\Brandon\AppData\Local\Temp:winupd.exe [x]
HKU\Brandon\...\Policies\system: [LogonHoursAction] 2
HKU\Brandon\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
==================== Services (Whitelisted) ======
3 FirebirdServerMAGIXInstance; "C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe" [3276800 2008-08-07] (MAGIXÆ)
4 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [62208 2009-08-12] (NewTech Infosystems, Inc.)
2 uvnc_service_gs; "C:\Program Files (x86)\Gbridge LLC\Gbridge\gbwinvnc.exe" -service [1587536 2010-06-11] (UltraVNC)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
3 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
2 RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe /service [x]
========================== Drivers (Whitelisted) =============
3 gbridge; C:\Windows\System32\DRIVERS\gbridge64.sys [48192 2009-10-12] (Gbridge LLC)
3 GEARAspiWDM; C:\Windows\SysWow64\Drivers\GEARAspiWDM.sys [15664 2011-03-02] (GEAR Software Inc.)
3 OV550I; C:\Windows\System32\Drivers\FilmScan.sys [196992 2008-02-21] (Omnivision Technologies, Inc.)
3 UBHelper; C:\Windows\System32\Drivers\UBHelper.sys [16896 2009-05-05] (NewTech Infosystems Corporation)
1 jzagqzbv; \??\C:\Windows\system32\drivers\jzagqzbv.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-30 19:26 - 2012-07-30 19:26 - 00000000 ____D C:\FRST
2012-07-30 16:48 - 2012-07-30 16:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14A7F2C64F543E3B
2012-07-30 16:44 - 2012-07-30 16:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E640E03D67A50D59
2012-07-30 14:55 - 2012-07-30 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5EC784F0D89CA26
2012-07-30 14:49 - 2012-07-30 14:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E2F1680CCAE39D33
2012-07-30 14:46 - 2012-07-30 14:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4B44364F8E12FF01
2012-07-30 14:39 - 2012-07-30 14:40 - 00001273 ____A C:\Users\Betsy\Desktop\shutdown.lnk
2012-07-30 14:23 - 2012-07-30 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5303699A6A8B0AC
2012-07-30 14:16 - 2012-07-30 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16E1673C7590AEC7
2012-07-30 14:10 - 2012-07-30 14:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.895625ADFD36B12C
2012-07-30 14:06 - 2012-07-30 14:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-30 14:04 - 2012-07-30 14:05 - 12621696 ____A (Microsoft Corporation) C:\Users\Betsy\Downloads\mseinstall.exe
2012-07-30 14:02 - 2012-07-30 14:02 - 07866472 ____A (Microsoft Corporation) C:\Users\Betsy\Desktop\mseinstall.exe
2012-07-30 14:01 - 2012-07-30 14:01 - 00352976 ____A (Softonic) C:\Users\Betsy\Downloads\SoftonicDownloader_for_microsoft-security-essentials.exe
2012-07-30 13:44 - 2012-07-30 13:45 - 00000000 ___SD C:\32788R22FWJFW
2012-07-30 13:44 - 2012-07-30 13:45 - 00000000 ____D C:\Qoobox
2012-07-30 13:43 - 2012-07-30 13:44 - 04722436 ____R (Swearware) C:\Users\Betsy\Downloads\ComboFix.exe
2012-07-29 19:26 - 2012-07-29 20:04 - 00000480 ____A C:\Windows\Tasks\PC Utility Kit Registration3.job
2012-07-29 19:26 - 2012-07-29 20:04 - 00000446 ____A C:\Windows\Tasks\PC Utility Kit Update3.job
2012-07-29 19:26 - 2012-07-29 20:04 - 00000444 ____A C:\Windows\Tasks\PC Utility Kit.job
2012-07-29 19:26 - 2012-07-29 19:26 - 00001199 ____A C:\Users\Betsy\Desktop\PC Utility Kit.lnk
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Users\Betsy\AppData\Roaming\PC Utility Kit
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Users\Betsy\AppData\Roaming\DriverCure
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Users\All Users\PC Utility Kit
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Program Files (x86)\PC Utility Kit
2012-07-18 07:01 - 2012-07-18 07:01 - 00226816 ____A C:\Users\Betsy\Documents\2012-13 MOA Registration Word Template.dot
2012-07-17 03:15 - 2012-07-17 16:17 - 00000761 ____A C:\Windows\System32\Drivers\etc\hosts.txt
2012-07-11 09:41 - 2012-07-11 09:41 - 00104674 ____A C:\Users\Betsy\Downloads\decibel.zip
2012-07-11 09:41 - 2012-07-11 09:41 - 00000000 ____D C:\Users\Betsy\Downloads\decibel
============ 3 Months Modified Files ========================
2012-07-30 16:54 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-30 16:54 - 2009-07-13 20:51 - 00088478 ____A C:\Windows\setupact.log
2012-07-30 16:48 - 2012-07-30 16:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14A7F2C64F543E3B
2012-07-30 16:44 - 2012-07-30 16:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E640E03D67A50D59
2012-07-30 14:58 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-30 14:57 - 2010-01-31 18:32 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-30 14:55 - 2012-07-30 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5EC784F0D89CA26
2012-07-30 14:49 - 2012-07-30 14:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E2F1680CCAE39D33
2012-07-30 14:46 - 2012-07-30 14:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4B44364F8E12FF01
2012-07-30 14:40 - 2012-07-30 14:39 - 00001273 ____A C:\Users\Betsy\Desktop\shutdown.lnk
2012-07-30 14:23 - 2012-07-30 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5303699A6A8B0AC
2012-07-30 14:23 - 2009-07-13 21:13 - 00005202 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 14:16 - 2012-07-30 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16E1673C7590AEC7
2012-07-30 14:16 - 2009-10-22 15:33 - 01377972 ___AH C:\Windows\WindowsUpdate.log
2012-07-30 14:11 - 2009-08-27 12:54 - 00235476 ____A C:\Windows\PFRO.log
2012-07-30 14:10 - 2012-07-30 14:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.895625ADFD36B12C
2012-07-30 14:06 - 2011-01-29 16:57 - 00005168 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 14:05 - 2012-07-30 14:04 - 12621696 ____A (Microsoft Corporation) C:\Users\Betsy\Downloads\mseinstall.exe
2012-07-30 14:02 - 2012-07-30 14:02 - 07866472 ____A (Microsoft Corporation) C:\Users\Betsy\Desktop\mseinstall.exe
2012-07-30 14:01 - 2012-07-30 14:01 - 00352976 ____A (Softonic) C:\Users\Betsy\Downloads\SoftonicDownloader_for_microsoft-security-essentials.exe
2012-07-30 13:55 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:55 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:49 - 2010-01-31 18:32 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-30 13:44 - 2012-07-30 13:43 - 04722436 ____R (Swearware) C:\Users\Betsy\Downloads\ComboFix.exe
2012-07-29 20:04 - 2012-07-29 19:26 - 00000480 ____A C:\Windows\Tasks\PC Utility Kit Registration3.job
2012-07-29 20:04 - 2012-07-29 19:26 - 00000446 ____A C:\Windows\Tasks\PC Utility Kit Update3.job
2012-07-29 20:04 - 2012-07-29 19:26 - 00000444 ____A C:\Windows\Tasks\PC Utility Kit.job
2012-07-29 20:04 - 2012-04-18 17:41 - 00002427 ____A C:\Windows\SysWOW64\lgAxconfig.ini
2012-07-29 19:53 - 2012-01-23 19:20 - 00001076 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-29 19:30 - 2011-12-22 16:46 - 00002257 ___AH C:\Users\Brandon\Desktop\Jodix Free WMA to MP3 Converter.lnk
2012-07-29 19:30 - 2010-01-24 08:04 - 00002186 ___AH C:\Users\Brandon\Desktop\Magic DVD Ripper.lnk
2012-07-29 19:26 - 2012-07-29 19:26 - 00001199 ____A C:\Users\Betsy\Desktop\PC Utility Kit.lnk
2012-07-25 18:04 - 2009-12-07 13:32 - 00119912 ____A C:\Users\Betsy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-25 18:04 - 2009-07-13 20:45 - 00433080 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 07:01 - 2012-07-18 07:01 - 00226816 ____A C:\Users\Betsy\Documents\2012-13 MOA Registration Word Template.dot
2012-07-17 16:17 - 2012-07-17 03:15 - 00000761 ____A C:\Windows\System32\Drivers\etc\hosts.txt
2012-07-12 11:08 - 2011-08-09 12:40 - 00002307 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-11 09:41 - 2012-07-11 09:41 - 00104674 ____A C:\Users\Betsy\Downloads\decibel.zip
2012-07-03 11:46 - 2011-12-19 19:40 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
ZeroAccess:
C:\Windows\Installer\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}
C:\Windows\Installer\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\L
C:\Windows\Installer\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\U
ZeroAccess:
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\@
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\L
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\n
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 6109.14 MB
Available physical RAM: 5398.61 MB
Total Pagefile: 6107.29 MB
Available Pagefile: 5392.24 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Gateway) (Fixed) (Total:916.41 GB) (Free:816.55 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:15 GB) (Free:5.43 GB) NTFS
4 Drive g: (GROBELS) (Fixed) (Total:931.09 GB) (Free:927.67 GB) FAT32
5 Drive h: (BRENT HEIST) (Removable) (Total:0.95 GB) (Free:0.95 GB) FAT
9 Drive l: () (Removable) (Total:0.95 GB) (Free:0.05 GB) FAT
11 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
12 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 931 GB 0 B
Disk 2 Online 974 MB 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 Online 968 MB 0 B
Disk 7 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 15 GB 1024 KB
Partition 2 Primary 100 MB 15 GB
Partition 3 Primary 916 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 15 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Gateway NTFS Partition 916 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 200 MB 512 B
Partition 2 Primary 931 GB 201 MB
==================================================================================
Disk: 1
Partition 1
Type : EE
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Disk: 1
Partition 2
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G GROBELS FAT32 Partition 931 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 974 MB 0 B
==================================================================================
Disk: 2
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
Partitions of Disk 6:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 968 MB 124 KB
==================================================================================
Disk: 6
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 9 L FAT Removable 968 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-25 20:58
======================= End Of Log ==========================
Here is the report. Thanks in advance guys
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 19:26:15
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162328 2011-02-11] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417304 2011-02-11] (Intel Corporation)
HKLM\...\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k [244480 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Gateway Photo Frame] "C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe" -A [124416 2009-07-20] (IOI)
HKLM-x32\...\Run: [Qwest Personal Digital Vault] "C:\Program Files (x86)\Qwest Personal Digital Vault\QwestPersonalDigitalVault.exe" /m [1064808 2009-12-18] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421160 2011-04-14] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-04-08] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [x]
HKLM-x32\...\Run: [Philips Device Listener] "C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe" [380416 2012-03-16] ()
HKLM-x32\...\Run: [BYR_AGENT] C:\ProgramData\LGMOBILEAX\BYR_Client\VZWNotiAgent.exe [392280 2012-03-14] (LG Electronics)
HKU\Betsy\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2009-08-27] (Google Inc.)
HKU\Betsy\...\Run: [Ihotushi] C:\Users\Betsy\AppData\Roaming\Avatbo\myco.exe [307200 2010-09-28] (IconFX Software)
HKU\Betsy\...\Policies\system: [LogonHoursAction] 2
HKU\Betsy\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Brandon\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4240760 2010-11-10] (Microsoft Corporation)
HKU\Brandon\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2009-08-27] (Google Inc.)
HKU\Brandon\...\Run: [winupd] C:\Users\Brandon\AppData\Local\Temp:winupd.exe [x]
HKU\Brandon\...\Policies\system: [LogonHoursAction] 2
HKU\Brandon\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
==================== Services (Whitelisted) ======
3 FirebirdServerMAGIXInstance; "C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe" [3276800 2008-08-07] (MAGIXÆ)
4 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [62208 2009-08-12] (NewTech Infosystems, Inc.)
2 uvnc_service_gs; "C:\Program Files (x86)\Gbridge LLC\Gbridge\gbwinvnc.exe" -service [1587536 2010-06-11] (UltraVNC)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
3 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
2 RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe /service [x]
========================== Drivers (Whitelisted) =============
3 gbridge; C:\Windows\System32\DRIVERS\gbridge64.sys [48192 2009-10-12] (Gbridge LLC)
3 GEARAspiWDM; C:\Windows\SysWow64\Drivers\GEARAspiWDM.sys [15664 2011-03-02] (GEAR Software Inc.)
3 OV550I; C:\Windows\System32\Drivers\FilmScan.sys [196992 2008-02-21] (Omnivision Technologies, Inc.)
3 UBHelper; C:\Windows\System32\Drivers\UBHelper.sys [16896 2009-05-05] (NewTech Infosystems Corporation)
1 jzagqzbv; \??\C:\Windows\system32\drivers\jzagqzbv.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-30 19:26 - 2012-07-30 19:26 - 00000000 ____D C:\FRST
2012-07-30 16:48 - 2012-07-30 16:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14A7F2C64F543E3B
2012-07-30 16:44 - 2012-07-30 16:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E640E03D67A50D59
2012-07-30 14:55 - 2012-07-30 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5EC784F0D89CA26
2012-07-30 14:49 - 2012-07-30 14:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E2F1680CCAE39D33
2012-07-30 14:46 - 2012-07-30 14:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4B44364F8E12FF01
2012-07-30 14:39 - 2012-07-30 14:40 - 00001273 ____A C:\Users\Betsy\Desktop\shutdown.lnk
2012-07-30 14:23 - 2012-07-30 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5303699A6A8B0AC
2012-07-30 14:16 - 2012-07-30 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16E1673C7590AEC7
2012-07-30 14:10 - 2012-07-30 14:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.895625ADFD36B12C
2012-07-30 14:06 - 2012-07-30 14:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-30 14:04 - 2012-07-30 14:05 - 12621696 ____A (Microsoft Corporation) C:\Users\Betsy\Downloads\mseinstall.exe
2012-07-30 14:02 - 2012-07-30 14:02 - 07866472 ____A (Microsoft Corporation) C:\Users\Betsy\Desktop\mseinstall.exe
2012-07-30 14:01 - 2012-07-30 14:01 - 00352976 ____A (Softonic) C:\Users\Betsy\Downloads\SoftonicDownloader_for_microsoft-security-essentials.exe
2012-07-30 13:44 - 2012-07-30 13:45 - 00000000 ___SD C:\32788R22FWJFW
2012-07-30 13:44 - 2012-07-30 13:45 - 00000000 ____D C:\Qoobox
2012-07-30 13:43 - 2012-07-30 13:44 - 04722436 ____R (Swearware) C:\Users\Betsy\Downloads\ComboFix.exe
2012-07-29 19:26 - 2012-07-29 20:04 - 00000480 ____A C:\Windows\Tasks\PC Utility Kit Registration3.job
2012-07-29 19:26 - 2012-07-29 20:04 - 00000446 ____A C:\Windows\Tasks\PC Utility Kit Update3.job
2012-07-29 19:26 - 2012-07-29 20:04 - 00000444 ____A C:\Windows\Tasks\PC Utility Kit.job
2012-07-29 19:26 - 2012-07-29 19:26 - 00001199 ____A C:\Users\Betsy\Desktop\PC Utility Kit.lnk
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Users\Betsy\AppData\Roaming\PC Utility Kit
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Users\Betsy\AppData\Roaming\DriverCure
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Users\All Users\PC Utility Kit
2012-07-29 19:26 - 2012-07-29 19:26 - 00000000 ____D C:\Program Files (x86)\PC Utility Kit
2012-07-18 07:01 - 2012-07-18 07:01 - 00226816 ____A C:\Users\Betsy\Documents\2012-13 MOA Registration Word Template.dot
2012-07-17 03:15 - 2012-07-17 16:17 - 00000761 ____A C:\Windows\System32\Drivers\etc\hosts.txt
2012-07-11 09:41 - 2012-07-11 09:41 - 00104674 ____A C:\Users\Betsy\Downloads\decibel.zip
2012-07-11 09:41 - 2012-07-11 09:41 - 00000000 ____D C:\Users\Betsy\Downloads\decibel
============ 3 Months Modified Files ========================
2012-07-30 16:54 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-30 16:54 - 2009-07-13 20:51 - 00088478 ____A C:\Windows\setupact.log
2012-07-30 16:48 - 2012-07-30 16:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14A7F2C64F543E3B
2012-07-30 16:44 - 2012-07-30 16:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E640E03D67A50D59
2012-07-30 14:58 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-30 14:57 - 2010-01-31 18:32 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-30 14:55 - 2012-07-30 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5EC784F0D89CA26
2012-07-30 14:49 - 2012-07-30 14:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E2F1680CCAE39D33
2012-07-30 14:46 - 2012-07-30 14:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4B44364F8E12FF01
2012-07-30 14:40 - 2012-07-30 14:39 - 00001273 ____A C:\Users\Betsy\Desktop\shutdown.lnk
2012-07-30 14:23 - 2012-07-30 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5303699A6A8B0AC
2012-07-30 14:23 - 2009-07-13 21:13 - 00005202 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 14:16 - 2012-07-30 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16E1673C7590AEC7
2012-07-30 14:16 - 2009-10-22 15:33 - 01377972 ___AH C:\Windows\WindowsUpdate.log
2012-07-30 14:11 - 2009-08-27 12:54 - 00235476 ____A C:\Windows\PFRO.log
2012-07-30 14:10 - 2012-07-30 14:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.895625ADFD36B12C
2012-07-30 14:06 - 2011-01-29 16:57 - 00005168 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 14:05 - 2012-07-30 14:04 - 12621696 ____A (Microsoft Corporation) C:\Users\Betsy\Downloads\mseinstall.exe
2012-07-30 14:02 - 2012-07-30 14:02 - 07866472 ____A (Microsoft Corporation) C:\Users\Betsy\Desktop\mseinstall.exe
2012-07-30 14:01 - 2012-07-30 14:01 - 00352976 ____A (Softonic) C:\Users\Betsy\Downloads\SoftonicDownloader_for_microsoft-security-essentials.exe
2012-07-30 13:55 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:55 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 13:49 - 2010-01-31 18:32 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-30 13:44 - 2012-07-30 13:43 - 04722436 ____R (Swearware) C:\Users\Betsy\Downloads\ComboFix.exe
2012-07-29 20:04 - 2012-07-29 19:26 - 00000480 ____A C:\Windows\Tasks\PC Utility Kit Registration3.job
2012-07-29 20:04 - 2012-07-29 19:26 - 00000446 ____A C:\Windows\Tasks\PC Utility Kit Update3.job
2012-07-29 20:04 - 2012-07-29 19:26 - 00000444 ____A C:\Windows\Tasks\PC Utility Kit.job
2012-07-29 20:04 - 2012-04-18 17:41 - 00002427 ____A C:\Windows\SysWOW64\lgAxconfig.ini
2012-07-29 19:53 - 2012-01-23 19:20 - 00001076 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-29 19:30 - 2011-12-22 16:46 - 00002257 ___AH C:\Users\Brandon\Desktop\Jodix Free WMA to MP3 Converter.lnk
2012-07-29 19:30 - 2010-01-24 08:04 - 00002186 ___AH C:\Users\Brandon\Desktop\Magic DVD Ripper.lnk
2012-07-29 19:26 - 2012-07-29 19:26 - 00001199 ____A C:\Users\Betsy\Desktop\PC Utility Kit.lnk
2012-07-25 18:04 - 2009-12-07 13:32 - 00119912 ____A C:\Users\Betsy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-25 18:04 - 2009-07-13 20:45 - 00433080 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 07:01 - 2012-07-18 07:01 - 00226816 ____A C:\Users\Betsy\Documents\2012-13 MOA Registration Word Template.dot
2012-07-17 16:17 - 2012-07-17 03:15 - 00000761 ____A C:\Windows\System32\Drivers\etc\hosts.txt
2012-07-12 11:08 - 2011-08-09 12:40 - 00002307 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-11 09:41 - 2012-07-11 09:41 - 00104674 ____A C:\Users\Betsy\Downloads\decibel.zip
2012-07-03 11:46 - 2011-12-19 19:40 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
ZeroAccess:
C:\Windows\Installer\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}
C:\Windows\Installer\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\L
C:\Windows\Installer\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\U
ZeroAccess:
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\@
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\L
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\n
C:\Users\Betsy\AppData\Local\{31fb4b83-073c-0c52-27fd-c725bde1cb8f}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 6109.14 MB
Available physical RAM: 5398.61 MB
Total Pagefile: 6107.29 MB
Available Pagefile: 5392.24 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (Gateway) (Fixed) (Total:916.41 GB) (Free:816.55 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:15 GB) (Free:5.43 GB) NTFS
4 Drive g: (GROBELS) (Fixed) (Total:931.09 GB) (Free:927.67 GB) FAT32
5 Drive h: (BRENT HEIST) (Removable) (Total:0.95 GB) (Free:0.95 GB) FAT
9 Drive l: () (Removable) (Total:0.95 GB) (Free:0.05 GB) FAT
11 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
12 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 931 GB 0 B
Disk 2 Online 974 MB 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 Online 968 MB 0 B
Disk 7 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 15 GB 1024 KB
Partition 2 Primary 100 MB 15 GB
Partition 3 Primary 916 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E PQSERVICE NTFS Partition 15 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Gateway NTFS Partition 916 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 200 MB 512 B
Partition 2 Primary 931 GB 201 MB
==================================================================================
Disk: 1
Partition 1
Type : EE
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Disk: 1
Partition 2
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G GROBELS FAT32 Partition 931 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 974 MB 0 B
==================================================================================
Disk: 2
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
Partitions of Disk 6:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 968 MB 124 KB
==================================================================================
Disk: 6
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 9 L FAT Removable 968 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-25 20:58
======================= End Of Log ==========================