Running, Windows 7 Home Premium 32bit.
Coming here because it looks like someone is actually able to help! I've followed a few threads and I've tried to do the first step that has been going around. Here are the FRST.txt log and the Search.txt log:
FRST:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-08-2012
Ran by SYSTEM at 09-08-2012 15:15:37
Running from J:\AV
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [7739936 2009-09-11] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [136216 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [171032 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [170520 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\RealTime Communications.lnk
ShortcutTarget: RealTime Communications.lnk -> C:\RT3\RTComm.exe (Sundial Time Systems, Inc.)
================================ Services (Whitelisted) ==================
2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
2 BPowMon; C:\Program Files\Broadcom\BPowMon\BPowMon.exe [79168 2009-08-17] (Broadcom Corp.)
3 dkab_device; C:\Windows\system32\DKabcoms.exe -service [508824 2006-10-21] ( )
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 k57nd60x; C:\Windows\System32\DRIVERS\k57nd60x.sys [273960 2009-08-21] (Broadcom Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [165376 2009-09-22] (Microsoft Corporation)
1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [55040 2009-09-22] (Microsoft Corporation)
3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2009-09-22] (Microsoft Corporation)
3 vpcuxd; C:\Windows\System32\DRIVERS\vpcuxd.sys [12800 2009-09-22] (Microsoft Corporation)
1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [294912 2009-09-22] (Microsoft Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 16:35 - 2012-08-09 16:35 - 00302592 ____A C:\Users\Thomas\Downloads\mgy59hk3.exe
2012-08-09 15:15 - 2012-08-09 15:15 - 00000000 ____D C:\FRST
2012-08-09 14:40 - 2012-08-09 14:43 - 07750160 ____A (SurfRight B.V.) C:\Users\Thomas\Downloads\HitmanPro36.exe
2012-08-09 14:40 - 2012-08-09 14:41 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix (1).exe
2012-08-09 14:37 - 2012-08-09 14:38 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix.exe
2012-08-09 14:37 - 2012-08-09 14:38 - 00001606 ____A C:\Users\Thomas\Desktop\Rkill.txt
2012-08-09 14:35 - 2012-08-09 14:35 - 04981254 ____A C:\Users\Thomas\Downloads\unconfirmed 57173.download
2012-08-09 14:34 - 2012-08-09 14:35 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\iExplore.exe
2012-08-09 14:34 - 2012-08-09 14:34 - 00001205 ____A C:\Users\Thomas\Downloads\registryfix.reg
2012-08-09 14:26 - 2012-08-09 14:26 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-09 14:23 - 2012-08-09 14:23 - 00407872 ____A C:\Users\Thomas\Downloads\pkiller.exe
2012-08-09 14:21 - 2012-08-09 14:23 - 10288512 ____A (Microsoft Corporation) C:\Users\Thomas\Downloads\mseinstall.exe
2012-08-09 14:17 - 2012-08-09 14:17 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Thomas\Downloads\SpyHunter-Installer.exe
2012-08-09 14:00 - 2012-08-09 14:00 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2012-08-09 14:00 - 2012-08-09 14:00 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-09 14:00 - 2012-08-09 14:00 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-09 14:00 - 2010-12-20 20:09 - 00038224 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-09 14:00 - 2010-12-20 20:08 - 00020952 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-09 13:55 - 2012-08-09 13:55 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\rkill.exe
2012-08-09 12:43 - 2012-08-09 12:43 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-09 12:41 - 2012-08-09 12:43 - 00000000 ____D C:\Users\All Users\036DFF85031355ACEEDADB1C4F147CE7
2012-08-09 12:40 - 2012-08-09 12:40 - 00057344 ___AH (AhnLab, Inc.) C:\Windows\System32\exe2host.dll
2012-08-07 16:20 - 2012-08-07 16:20 - 00012657 ____A C:\Users\Thomas\Documents\Ba-Le UH Order.xlsx
2012-08-07 12:34 - 2012-08-07 12:34 - 00013650 ____A C:\Users\Thomas\Documents\Baker Hours.xlsx
2012-08-06 08:42 - 2012-08-07 10:37 - 00062464 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 08-10-12 PAYROLL.xls
2012-08-03 17:23 - 2012-08-04 17:01 - 00275526 ____A C:\Users\Thomas\Documents\Tri1.xlsx
2012-07-29 10:38 - 2012-07-29 10:38 - 00000000 ____D C:\Users\Thomas\AppData\Local\Macromedia
2012-07-29 09:52 - 2012-08-09 16:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-29 09:52 - 2012-08-02 14:06 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-27 10:49 - 2012-07-27 11:57 - 00013225 ____A C:\Users\Thomas\Documents\Form for Rodney.xlsx
2012-07-23 11:10 - 2012-07-23 11:15 - 00060928 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-13-2012 PAYROLL.xls
2012-07-22 12:27 - 2012-07-29 13:22 - 00061440 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-27-2012 PAYROLL.xls
2012-07-22 11:19 - 2012-07-23 10:37 - 00000568 ____A C:\Windows\System32\LexFiles.usr
2012-07-19 13:58 - 2012-07-19 13:58 - 00012588 ____A C:\Users\Thomas\Documents\Puff On sales 6-12.xlsx
2012-07-15 15:05 - 2012-07-15 15:05 - 00012731 ____A C:\Users\Thomas\Documents\Rush Order Form.xlsx
2012-07-15 13:21 - 2012-07-15 13:21 - 00013003 ____A C:\Users\Thomas\Documents\production Form for Baker.xlsx
2012-07-10 15:40 - 2012-07-10 15:40 - 00013682 ____A C:\Users\Thomas\Windows Xp Mode.vmc.vpcbackup
2012-07-10 13:53 - 2012-07-10 16:52 - 00014801 ____A C:\Users\Thomas\Documents\Food Cost for Puff.xlsx
============ 3 Months Modified Files ========================
2012-08-09 17:11 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 17:11 - 2009-07-13 20:39 - 00032591 ____A C:\Windows\setupact.log
2012-08-09 17:08 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 16:35 - 2012-08-09 16:35 - 00302592 ____A C:\Users\Thomas\Downloads\mgy59hk3.exe
2012-08-09 16:04 - 2012-07-29 09:52 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 15:04 - 2009-07-13 20:55 - 01663835 ____A C:\Windows\WindowsUpdate.log
2012-08-09 14:57 - 2010-08-10 10:30 - 00733518 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 14:57 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 14:57 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 14:43 - 2012-08-09 14:40 - 07750160 ____A (SurfRight B.V.) C:\Users\Thomas\Downloads\HitmanPro36.exe
2012-08-09 14:41 - 2012-08-09 14:40 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix (1).exe
2012-08-09 14:38 - 2012-08-09 14:37 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix.exe
2012-08-09 14:38 - 2012-08-09 14:37 - 00001606 ____A C:\Users\Thomas\Desktop\Rkill.txt
2012-08-09 14:35 - 2012-08-09 14:35 - 04981254 ____A C:\Users\Thomas\Downloads\unconfirmed 57173.download
2012-08-09 14:35 - 2012-08-09 14:34 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\iExplore.exe
2012-08-09 14:34 - 2012-08-09 14:34 - 00001205 ____A C:\Users\Thomas\Downloads\registryfix.reg
2012-08-09 14:26 - 2012-01-04 14:43 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 14:23 - 2012-08-09 14:23 - 00407872 ____A C:\Users\Thomas\Downloads\pkiller.exe
2012-08-09 14:23 - 2012-08-09 14:21 - 10288512 ____A (Microsoft Corporation) C:\Users\Thomas\Downloads\mseinstall.exe
2012-08-09 14:17 - 2012-08-09 14:17 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Thomas\Downloads\SpyHunter-Installer.exe
2012-08-09 13:55 - 2012-08-09 13:55 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\rkill.exe
2012-08-09 13:53 - 2010-08-10 12:20 - 00034096 ____A C:\Windows\PFRO.log
2012-08-09 12:40 - 2012-08-09 12:40 - 00057344 ___AH (AhnLab, Inc.) C:\Windows\System32\exe2host.dll
2012-08-07 16:20 - 2012-08-07 16:20 - 00012657 ____A C:\Users\Thomas\Documents\Ba-Le UH Order.xlsx
2012-08-07 12:34 - 2012-08-07 12:34 - 00013650 ____A C:\Users\Thomas\Documents\Baker Hours.xlsx
2012-08-07 10:37 - 2012-08-06 08:42 - 00062464 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 08-10-12 PAYROLL.xls
2012-08-06 10:00 - 2010-09-18 12:49 - 00043382 ____A C:\Users\Thomas\Documents\LATOUR HOUR SUMMARY.xlsx
2012-08-05 11:53 - 2010-10-05 08:33 - 00014752 ____A C:\Users\Thomas\Documents\Do Xang.xlsx
2012-08-05 11:33 - 2012-02-03 15:16 - 00014326 ____A C:\Users\Thomas\Documents\Sales by Customer Summary.xlsx
2012-08-04 17:01 - 2012-08-03 17:23 - 00275526 ____A C:\Users\Thomas\Documents\Tri1.xlsx
2012-08-02 14:06 - 2012-07-29 09:52 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 14:06 - 2011-05-30 17:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 13:16 - 2012-06-29 10:40 - 00015179 ____A C:\Users\Thomas\Documents\Ba-Le Inc Sales Summary 2012.xlsx
2012-07-29 13:22 - 2012-07-22 12:27 - 00061440 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-27-2012 PAYROLL.xls
2012-07-27 11:57 - 2012-07-27 10:49 - 00013225 ____A C:\Users\Thomas\Documents\Form for Rodney.xlsx
2012-07-23 11:15 - 2012-07-23 11:10 - 00060928 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-13-2012 PAYROLL.xls
2012-07-23 10:37 - 2012-07-22 11:19 - 00000568 ____A C:\Windows\System32\LexFiles.usr
2012-07-19 13:58 - 2012-07-19 13:58 - 00012588 ____A C:\Users\Thomas\Documents\Puff On sales 6-12.xlsx
2012-07-15 15:05 - 2012-07-15 15:05 - 00012731 ____A C:\Users\Thomas\Documents\Rush Order Form.xlsx
2012-07-15 13:21 - 2012-07-15 13:21 - 00013003 ____A C:\Users\Thomas\Documents\production Form for Baker.xlsx
2012-07-13 18:17 - 2011-04-25 17:02 - 186166408 ____A C:\Users\Thomas\Windows Xp Mode.vsv
2012-07-13 18:17 - 2010-09-15 13:28 - 00014086 ____A C:\Users\Thomas\Windows Xp Mode.vmc
2012-07-10 16:52 - 2012-07-10 13:53 - 00014801 ____A C:\Users\Thomas\Documents\Food Cost for Puff.xlsx
2012-07-10 15:40 - 2012-07-10 15:40 - 00013682 ____A C:\Users\Thomas\Windows Xp Mode.vmc.vpcbackup
2012-07-09 10:09 - 2012-07-08 11:44 - 00060928 ____A C:\Users\Thomas\Documents\PAYROLL SHEET FOR 07-13-2012 PAYROLL.xls
2012-07-01 13:50 - 2010-10-04 12:17 - 00012899 ____A C:\Users\Thomas\Documents\Lunch Wagon.xlsx
2012-06-29 10:26 - 2010-10-29 14:38 - 00013102 ____A C:\Users\Thomas\Documents\Mr Lam Form.xlsx
2012-06-28 09:48 - 2010-09-27 17:25 - 00013430 ____A C:\Users\Thomas\Documents\Latour Vehicle.xlsx
2012-06-24 16:09 - 2012-06-24 16:09 - 00024144 ____A C:\Users\Thomas\Documents\daoduckinh.txt
2012-06-17 13:12 - 2012-06-15 16:13 - 00016577 ____A C:\Users\Thomas\Documents\Inventory 12312011.xlsx
2012-06-17 12:11 - 2012-06-15 15:19 - 00014762 ____A C:\Users\Thomas\Documents\Accoune Receivable12312011.xlsx
2012-06-15 15:10 - 2012-06-15 15:10 - 00014049 ____A C:\Users\Thomas\Documents\Accoune payable12312011.xlsx
2012-06-15 15:00 - 2012-06-15 15:00 - 00013994 ____A C:\Users\Thomas\Documents\Accoune payable12312012.xlsx
2012-06-11 11:52 - 2012-06-10 15:25 - 00030340 ____A C:\Users\Thomas\Documents\PAYROLL SHEET FOR 06-15-2012 PAYROLL.xlsx
2012-06-10 12:40 - 2012-06-10 12:40 - 00005632 ____A C:\TransactionList.xls
2012-06-07 11:50 - 2012-06-07 10:55 - 00015625 ____A C:\Users\Thomas\Documents\Sales At Ba-Le Inc1.xlsx
2012-06-07 10:54 - 2011-11-04 14:21 - 00014398 ____A C:\Users\Thomas\Documents\Ba-Le Inc Sales Summary.xlsx
2012-06-05 12:47 - 2012-06-05 12:29 - 00013412 ____A C:\Users\Thomas\Documents\Satnding Order for Market.xlsx
2012-06-02 17:19 - 2012-06-20 23:32 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 17:12 - 2012-06-20 23:32 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 14:19 - 2012-06-20 23:32 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 23:32 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 23:32 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 23:32 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 23:32 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 23:32 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 23:32 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-05-29 10:21 - 2011-04-14 10:57 - 00001817 ____A C:\Users\Thomas\Desktop\H264Real.lnk
2012-05-25 09:49 - 2011-03-15 09:31 - 00013141 ____A C:\Users\Thomas\Documents\Lavosh Sheet.xlsx
2012-05-24 14:13 - 2012-05-24 14:13 - 00019543 ____A C:\Users\Thomas\Documents\Foodland the orther island deliver to C&S.xlsx
2012-05-14 09:01 - 2012-05-13 11:24 - 00060928 ____A C:\Users\Thomas\Documents\PAYROLL SHEET FOR 05-18-2012 PAYROLL.xls
ZeroAccess:
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\@
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\L
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\n
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\U
ZeroAccess:
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\@
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\L
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\n
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3036.8 MB
Available physical RAM: 2584.11 MB
Total Pagefile: 3035.08 MB
Available Pagefile: 2587.63 MB
Total Virtual: 2047.88 MB
Available Virtual: 1956.7 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:139.58 GB) (Free:89.46 GB) NTFS
7 Drive j: (M-S325) (Removable) (Total:7.45 GB) (Free:6.29 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (RECOVERY) (Fixed) (Total:9.39 GB) (Free:5.24 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 7648 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 9 GB 40 MB
Partition 3 Primary 139 GB 9 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 9 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 139 GB Healthy
==================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7647 MB 40 KB
==================================================================================
Disk: 5
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J M-S325 FAT32 Removable 7647 MB Healthy
==================================================================================
Last Boot: 2012-08-07 02:39
======================= End Of Log ==========================
Search.txt:
Farbar Recovery Scan Tool Version: 09-08-2012
Ran by SYSTEM at 2012-08-09 15:16:40
Running from J:\AV
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-09 17:08] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
Please help! Thank you.
Coming here because it looks like someone is actually able to help! I've followed a few threads and I've tried to do the first step that has been going around. Here are the FRST.txt log and the Search.txt log:
FRST:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 09-08-2012
Ran by SYSTEM at 09-08-2012 15:15:37
Running from J:\AV
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [7739936 2009-09-11] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [136216 2010-08-25] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [171032 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [170520 2010-08-25] (Intel Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\RealTime Communications.lnk
ShortcutTarget: RealTime Communications.lnk -> C:\RT3\RTComm.exe (Sundial Time Systems, Inc.)
================================ Services (Whitelisted) ==================
2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
2 BPowMon; C:\Program Files\Broadcom\BPowMon\BPowMon.exe [79168 2009-08-17] (Broadcom Corp.)
3 dkab_device; C:\Windows\system32\DKabcoms.exe -service [508824 2006-10-21] ( )
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 k57nd60x; C:\Windows\System32\DRIVERS\k57nd60x.sys [273960 2009-08-21] (Broadcom Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [165376 2009-09-22] (Microsoft Corporation)
1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [55040 2009-09-22] (Microsoft Corporation)
3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2009-09-22] (Microsoft Corporation)
3 vpcuxd; C:\Windows\System32\DRIVERS\vpcuxd.sys [12800 2009-09-22] (Microsoft Corporation)
1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [294912 2009-09-22] (Microsoft Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 16:35 - 2012-08-09 16:35 - 00302592 ____A C:\Users\Thomas\Downloads\mgy59hk3.exe
2012-08-09 15:15 - 2012-08-09 15:15 - 00000000 ____D C:\FRST
2012-08-09 14:40 - 2012-08-09 14:43 - 07750160 ____A (SurfRight B.V.) C:\Users\Thomas\Downloads\HitmanPro36.exe
2012-08-09 14:40 - 2012-08-09 14:41 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix (1).exe
2012-08-09 14:37 - 2012-08-09 14:38 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix.exe
2012-08-09 14:37 - 2012-08-09 14:38 - 00001606 ____A C:\Users\Thomas\Desktop\Rkill.txt
2012-08-09 14:35 - 2012-08-09 14:35 - 04981254 ____A C:\Users\Thomas\Downloads\unconfirmed 57173.download
2012-08-09 14:34 - 2012-08-09 14:35 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\iExplore.exe
2012-08-09 14:34 - 2012-08-09 14:34 - 00001205 ____A C:\Users\Thomas\Downloads\registryfix.reg
2012-08-09 14:26 - 2012-08-09 14:26 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-09 14:23 - 2012-08-09 14:23 - 00407872 ____A C:\Users\Thomas\Downloads\pkiller.exe
2012-08-09 14:21 - 2012-08-09 14:23 - 10288512 ____A (Microsoft Corporation) C:\Users\Thomas\Downloads\mseinstall.exe
2012-08-09 14:17 - 2012-08-09 14:17 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Thomas\Downloads\SpyHunter-Installer.exe
2012-08-09 14:00 - 2012-08-09 14:00 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2012-08-09 14:00 - 2012-08-09 14:00 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-09 14:00 - 2012-08-09 14:00 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-09 14:00 - 2010-12-20 20:09 - 00038224 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-09 14:00 - 2010-12-20 20:08 - 00020952 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-09 13:55 - 2012-08-09 13:55 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\rkill.exe
2012-08-09 12:43 - 2012-08-09 12:43 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-09 12:41 - 2012-08-09 12:43 - 00000000 ____D C:\Users\All Users\036DFF85031355ACEEDADB1C4F147CE7
2012-08-09 12:40 - 2012-08-09 12:40 - 00057344 ___AH (AhnLab, Inc.) C:\Windows\System32\exe2host.dll
2012-08-07 16:20 - 2012-08-07 16:20 - 00012657 ____A C:\Users\Thomas\Documents\Ba-Le UH Order.xlsx
2012-08-07 12:34 - 2012-08-07 12:34 - 00013650 ____A C:\Users\Thomas\Documents\Baker Hours.xlsx
2012-08-06 08:42 - 2012-08-07 10:37 - 00062464 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 08-10-12 PAYROLL.xls
2012-08-03 17:23 - 2012-08-04 17:01 - 00275526 ____A C:\Users\Thomas\Documents\Tri1.xlsx
2012-07-29 10:38 - 2012-07-29 10:38 - 00000000 ____D C:\Users\Thomas\AppData\Local\Macromedia
2012-07-29 09:52 - 2012-08-09 16:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-29 09:52 - 2012-08-02 14:06 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-27 10:49 - 2012-07-27 11:57 - 00013225 ____A C:\Users\Thomas\Documents\Form for Rodney.xlsx
2012-07-23 11:10 - 2012-07-23 11:15 - 00060928 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-13-2012 PAYROLL.xls
2012-07-22 12:27 - 2012-07-29 13:22 - 00061440 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-27-2012 PAYROLL.xls
2012-07-22 11:19 - 2012-07-23 10:37 - 00000568 ____A C:\Windows\System32\LexFiles.usr
2012-07-19 13:58 - 2012-07-19 13:58 - 00012588 ____A C:\Users\Thomas\Documents\Puff On sales 6-12.xlsx
2012-07-15 15:05 - 2012-07-15 15:05 - 00012731 ____A C:\Users\Thomas\Documents\Rush Order Form.xlsx
2012-07-15 13:21 - 2012-07-15 13:21 - 00013003 ____A C:\Users\Thomas\Documents\production Form for Baker.xlsx
2012-07-10 15:40 - 2012-07-10 15:40 - 00013682 ____A C:\Users\Thomas\Windows Xp Mode.vmc.vpcbackup
2012-07-10 13:53 - 2012-07-10 16:52 - 00014801 ____A C:\Users\Thomas\Documents\Food Cost for Puff.xlsx
============ 3 Months Modified Files ========================
2012-08-09 17:11 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-09 17:11 - 2009-07-13 20:39 - 00032591 ____A C:\Windows\setupact.log
2012-08-09 17:08 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 16:35 - 2012-08-09 16:35 - 00302592 ____A C:\Users\Thomas\Downloads\mgy59hk3.exe
2012-08-09 16:04 - 2012-07-29 09:52 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-09 15:04 - 2009-07-13 20:55 - 01663835 ____A C:\Windows\WindowsUpdate.log
2012-08-09 14:57 - 2010-08-10 10:30 - 00733518 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-09 14:57 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-09 14:57 - 2009-07-13 20:34 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-09 14:43 - 2012-08-09 14:40 - 07750160 ____A (SurfRight B.V.) C:\Users\Thomas\Downloads\HitmanPro36.exe
2012-08-09 14:41 - 2012-08-09 14:40 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix (1).exe
2012-08-09 14:38 - 2012-08-09 14:37 - 04727110 ____A (Swearware) C:\Users\Thomas\Downloads\ComboFix.exe
2012-08-09 14:38 - 2012-08-09 14:37 - 00001606 ____A C:\Users\Thomas\Desktop\Rkill.txt
2012-08-09 14:35 - 2012-08-09 14:35 - 04981254 ____A C:\Users\Thomas\Downloads\unconfirmed 57173.download
2012-08-09 14:35 - 2012-08-09 14:34 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\iExplore.exe
2012-08-09 14:34 - 2012-08-09 14:34 - 00001205 ____A C:\Users\Thomas\Downloads\registryfix.reg
2012-08-09 14:26 - 2012-01-04 14:43 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 14:23 - 2012-08-09 14:23 - 00407872 ____A C:\Users\Thomas\Downloads\pkiller.exe
2012-08-09 14:23 - 2012-08-09 14:21 - 10288512 ____A (Microsoft Corporation) C:\Users\Thomas\Downloads\mseinstall.exe
2012-08-09 14:17 - 2012-08-09 14:17 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Thomas\Downloads\SpyHunter-Installer.exe
2012-08-09 13:55 - 2012-08-09 13:55 - 01051552 ____A (Bleeping Computer, LLC) C:\Users\Thomas\Downloads\rkill.exe
2012-08-09 13:53 - 2010-08-10 12:20 - 00034096 ____A C:\Windows\PFRO.log
2012-08-09 12:40 - 2012-08-09 12:40 - 00057344 ___AH (AhnLab, Inc.) C:\Windows\System32\exe2host.dll
2012-08-07 16:20 - 2012-08-07 16:20 - 00012657 ____A C:\Users\Thomas\Documents\Ba-Le UH Order.xlsx
2012-08-07 12:34 - 2012-08-07 12:34 - 00013650 ____A C:\Users\Thomas\Documents\Baker Hours.xlsx
2012-08-07 10:37 - 2012-08-06 08:42 - 00062464 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 08-10-12 PAYROLL.xls
2012-08-06 10:00 - 2010-09-18 12:49 - 00043382 ____A C:\Users\Thomas\Documents\LATOUR HOUR SUMMARY.xlsx
2012-08-05 11:53 - 2010-10-05 08:33 - 00014752 ____A C:\Users\Thomas\Documents\Do Xang.xlsx
2012-08-05 11:33 - 2012-02-03 15:16 - 00014326 ____A C:\Users\Thomas\Documents\Sales by Customer Summary.xlsx
2012-08-04 17:01 - 2012-08-03 17:23 - 00275526 ____A C:\Users\Thomas\Documents\Tri1.xlsx
2012-08-02 14:06 - 2012-07-29 09:52 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 14:06 - 2011-05-30 17:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 13:16 - 2012-06-29 10:40 - 00015179 ____A C:\Users\Thomas\Documents\Ba-Le Inc Sales Summary 2012.xlsx
2012-07-29 13:22 - 2012-07-22 12:27 - 00061440 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-27-2012 PAYROLL.xls
2012-07-27 11:57 - 2012-07-27 10:49 - 00013225 ____A C:\Users\Thomas\Documents\Form for Rodney.xlsx
2012-07-23 11:15 - 2012-07-23 11:10 - 00060928 ____A C:\Users\Thomas\Downloads\PAYROLL SHEET FOR 07-13-2012 PAYROLL.xls
2012-07-23 10:37 - 2012-07-22 11:19 - 00000568 ____A C:\Windows\System32\LexFiles.usr
2012-07-19 13:58 - 2012-07-19 13:58 - 00012588 ____A C:\Users\Thomas\Documents\Puff On sales 6-12.xlsx
2012-07-15 15:05 - 2012-07-15 15:05 - 00012731 ____A C:\Users\Thomas\Documents\Rush Order Form.xlsx
2012-07-15 13:21 - 2012-07-15 13:21 - 00013003 ____A C:\Users\Thomas\Documents\production Form for Baker.xlsx
2012-07-13 18:17 - 2011-04-25 17:02 - 186166408 ____A C:\Users\Thomas\Windows Xp Mode.vsv
2012-07-13 18:17 - 2010-09-15 13:28 - 00014086 ____A C:\Users\Thomas\Windows Xp Mode.vmc
2012-07-10 16:52 - 2012-07-10 13:53 - 00014801 ____A C:\Users\Thomas\Documents\Food Cost for Puff.xlsx
2012-07-10 15:40 - 2012-07-10 15:40 - 00013682 ____A C:\Users\Thomas\Windows Xp Mode.vmc.vpcbackup
2012-07-09 10:09 - 2012-07-08 11:44 - 00060928 ____A C:\Users\Thomas\Documents\PAYROLL SHEET FOR 07-13-2012 PAYROLL.xls
2012-07-01 13:50 - 2010-10-04 12:17 - 00012899 ____A C:\Users\Thomas\Documents\Lunch Wagon.xlsx
2012-06-29 10:26 - 2010-10-29 14:38 - 00013102 ____A C:\Users\Thomas\Documents\Mr Lam Form.xlsx
2012-06-28 09:48 - 2010-09-27 17:25 - 00013430 ____A C:\Users\Thomas\Documents\Latour Vehicle.xlsx
2012-06-24 16:09 - 2012-06-24 16:09 - 00024144 ____A C:\Users\Thomas\Documents\daoduckinh.txt
2012-06-17 13:12 - 2012-06-15 16:13 - 00016577 ____A C:\Users\Thomas\Documents\Inventory 12312011.xlsx
2012-06-17 12:11 - 2012-06-15 15:19 - 00014762 ____A C:\Users\Thomas\Documents\Accoune Receivable12312011.xlsx
2012-06-15 15:10 - 2012-06-15 15:10 - 00014049 ____A C:\Users\Thomas\Documents\Accoune payable12312011.xlsx
2012-06-15 15:00 - 2012-06-15 15:00 - 00013994 ____A C:\Users\Thomas\Documents\Accoune payable12312012.xlsx
2012-06-11 11:52 - 2012-06-10 15:25 - 00030340 ____A C:\Users\Thomas\Documents\PAYROLL SHEET FOR 06-15-2012 PAYROLL.xlsx
2012-06-10 12:40 - 2012-06-10 12:40 - 00005632 ____A C:\TransactionList.xls
2012-06-07 11:50 - 2012-06-07 10:55 - 00015625 ____A C:\Users\Thomas\Documents\Sales At Ba-Le Inc1.xlsx
2012-06-07 10:54 - 2011-11-04 14:21 - 00014398 ____A C:\Users\Thomas\Documents\Ba-Le Inc Sales Summary.xlsx
2012-06-05 12:47 - 2012-06-05 12:29 - 00013412 ____A C:\Users\Thomas\Documents\Satnding Order for Market.xlsx
2012-06-02 17:19 - 2012-06-20 23:32 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 17:12 - 2012-06-20 23:32 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 14:19 - 2012-06-20 23:32 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 23:32 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 23:32 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 23:32 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 23:32 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-20 23:32 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-20 23:32 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-05-29 10:21 - 2011-04-14 10:57 - 00001817 ____A C:\Users\Thomas\Desktop\H264Real.lnk
2012-05-25 09:49 - 2011-03-15 09:31 - 00013141 ____A C:\Users\Thomas\Documents\Lavosh Sheet.xlsx
2012-05-24 14:13 - 2012-05-24 14:13 - 00019543 ____A C:\Users\Thomas\Documents\Foodland the orther island deliver to C&S.xlsx
2012-05-14 09:01 - 2012-05-13 11:24 - 00060928 ____A C:\Users\Thomas\Documents\PAYROLL SHEET FOR 05-18-2012 PAYROLL.xls
ZeroAccess:
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\@
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\L
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\n
C:\Windows\Installer\{a86c0781-1163-a2ba-458a-60892fb0ddff}\U
ZeroAccess:
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\@
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\L
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\n
C:\Users\Thomas\AppData\Local\{a86c0781-1163-a2ba-458a-60892fb0ddff}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3036.8 MB
Available physical RAM: 2584.11 MB
Total Pagefile: 3035.08 MB
Available Pagefile: 2587.63 MB
Total Virtual: 2047.88 MB
Available Virtual: 1956.7 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:139.58 GB) (Free:89.46 GB) NTFS
7 Drive j: (M-S325) (Removable) (Total:7.45 GB) (Free:6.29 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (RECOVERY) (Fixed) (Total:9.39 GB) (Free:5.24 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 7648 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 9 GB 40 MB
Partition 3 Primary 139 GB 9 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 9 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 139 GB Healthy
==================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7647 MB 40 KB
==================================================================================
Disk: 5
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J M-S325 FAT32 Removable 7647 MB Healthy
==================================================================================
Last Boot: 2012-08-07 02:39
======================= End Of Log ==========================
Search.txt:
Farbar Recovery Scan Tool Version: 09-08-2012
Ran by SYSTEM at 2012-08-09 15:16:40
Running from J:\AV
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-09 17:08] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
Please help! Thank you.