jamiefairlie
Posts: 6 +0
Hi, it seems I'm another Sirefef victim. I've followed the instructions (Boot to System Recovery Options and run FRST then Search for Services.exe) and have pasted the output below . Thanks for your help.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2012
Ran by SYSTEM at 12-09-2012 22:33:34
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" [74752 2010-07-12] (Nullsoft, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [VX3000] C:\Windows\vVX3000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-29] (Sun Microsystems, Inc.)
HKLM\...\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe" [291496 2009-04-27] ()
HKLM\...\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe" [25256 2009-04-27] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Ed\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-17] (Google Inc.)
HKU\Ed\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 64.59.144.19 64.59.150.135
Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{270FE6A0-E893-421C-809E-5B9111C2D4EC}\Icon3E5562ED7.ico ()
==================== Services ================================
2 CVPND; "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" [1504304 2006-10-06] (Cisco Systems, Inc.)
2 lxddCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [99248 2007-05-25] (Lexmark International, Inc.)
2 lxdd_device; C:\Windows\system32\lxddcoms.exe -service [537520 2007-05-25] ( )
2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2253120 2011-10-15] (NVIDIA Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
==================== Drivers =================================
3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5315 2005-05-17] (Cisco Systems, Inc.)
2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [305787 2006-10-06] (Cisco Systems, Inc.)
3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [126864 2006-10-02] (Deterministic Networks, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-09-12 22:33 - 2012-09-12 22:33 - 00000000 ____D C:\FRST
2012-09-12 21:25 - 2012-09-12 20:29 - 04749988 ___RA (Swearware) C:\Users\Ed\Desktop\ComboFix.exe
2012-09-12 21:25 - 2012-09-12 19:54 - 01632160 ____A (Bleeping Computer, LLC) C:\Users\Ed\Desktop\rkill.exe
2012-09-12 21:25 - 2012-09-12 19:17 - 00903834 ____A (Farbar) C:\Users\Ed\Desktop\FRST.exe
2012-09-12 21:24 - 2012-09-12 21:24 - 00000621 ____A C:\Users\Ed\Desktop\ComboFix - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000596 ____A C:\Users\Ed\Desktop\rkill - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000589 ____A C:\Users\Ed\Desktop\FRST - Shortcut.lnk
2012-09-12 20:51 - 2012-09-12 20:51 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-12 20:45 - 2012-09-12 20:45 - 00000332 ____A C:\Start_.cmd
2012-09-12 20:45 - 2012-09-12 20:45 - 00000000 ____D C:\ComboFix
2012-09-12 20:44 - 2012-09-12 21:10 - 00000000 ____D C:\Qoobox
2012-09-12 20:43 - 2012-09-12 21:10 - 00000000 ___SD C:\32788R22FWJFW
2012-09-12 20:43 - 2012-09-12 21:09 - 00000000 ____D C:\Windows\erdnt
2012-09-12 20:41 - 2012-09-12 20:41 - 00139104 ____A C:\Windows\Minidump\091212-20779-01.dmp
2012-09-12 20:41 - 2012-09-12 20:41 - 00000000 ____D C:\Windows\Minidump
2012-09-12 19:59 - 2012-09-12 21:10 - 00002836 ____A C:\Users\Ed\Desktop\Rkill.txt
2012-09-11 20:24 - 2012-09-11 20:25 - 00000000 ____D C:\Users\Ed\AppData\Local\{C87B86D2-1D73-4658-96D6-7D0B49FF49E2}
2012-09-11 08:23 - 2012-09-11 08:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{12C0C3B2-B167-4347-B64E-E10D7C3D6193}
2012-09-11 07:01 - 2012-09-11 07:01 - 00000249 ____A C:\Users\Ed\Desktop\Reset_and_Clear_Print_Spooler_Queue.bat
2012-09-10 20:21 - 2012-09-10 20:23 - 00000000 ____D C:\Users\Ed\AppData\Local\{60DECF96-9876-437C-A454-FC106DDE610B}
2012-09-10 08:20 - 2012-09-10 08:21 - 00000000 ____D C:\Users\Ed\AppData\Local\{49265433-F11A-446D-A626-9D2B0DBA5C65}
2012-09-09 20:54 - 2012-09-12 06:22 - 00000000 ____D C:\Users\Ed\Desktop\stick dump
2012-09-09 20:18 - 2012-09-09 20:20 - 00000000 ____D C:\Users\Ed\AppData\Local\{4BAD108A-9D06-407C-AB01-AB07E91F6CA0}
2012-09-09 16:21 - 2012-09-09 16:21 - 00002262 ____A C:\Users\Ed\Desktop\ripped cds - Shortcut.lnk
2012-09-09 16:21 - 2012-09-09 16:21 - 00000000 ____D C:\Users\Ed\Desktop\ripped cds
2012-09-09 08:16 - 2012-09-09 08:18 - 00000000 ____D C:\Users\Ed\AppData\Local\{19BE1D50-1A09-43AA-AB70-29ED87C7D728}
2012-09-08 08:13 - 2012-09-08 20:16 - 00000000 ____D C:\Users\Ed\AppData\Local\{55710E8B-7731-4DFE-BAC7-41CBEF6121C2}
2012-08-19 11:52 - 2012-08-19 11:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-18 11:25 - 2012-08-18 11:25 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-18 10:01 - 2012-08-18 10:02 - 00000000 ____D C:\Users\Ed\AppData\Local\{71A085F3-455E-40FE-8138-53577C326D02}
2012-08-17 22:00 - 2012-08-17 22:00 - 00000000 ____D C:\Users\Ed\AppData\Local\{9250A0FF-BF06-4A2D-9839-2FA071B18256}
2012-08-17 09:59 - 2012-08-17 10:00 - 00000000 ____D C:\Users\Ed\AppData\Local\{8EDD5CEB-6190-4D49-A2CB-FDE10791D076}
2012-08-16 21:58 - 2012-08-16 21:58 - 00000000 ____D C:\Users\Ed\AppData\Local\{8445152D-8BE0-4816-8BD0-E12870A221C1}
2012-08-16 09:56 - 2012-08-16 09:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{84038A28-1D02-40E3-9858-13F4085691DB}
2012-08-16 09:55 - 2012-08-18 22:03 - 00000000 ____D C:\Users\Ed\AppData\Local\{DE771767-9528-4D82-9385-BA1658674E74}
2012-08-16 02:06 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-16 02:06 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-16 02:06 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-16 02:06 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-16 02:06 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-16 02:06 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-16 02:06 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-16 02:06 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-16 02:06 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-16 02:06 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-16 02:06 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-16 02:06 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-16 02:06 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-16 02:06 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-15 21:54 - 2012-08-15 21:55 - 00000000 ____D C:\Users\Ed\AppData\Local\{554D9C41-45D5-4274-A7D6-C834DC440A15}
2012-08-15 21:54 - 2012-08-15 21:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{C4A930C1-A7C6-46E0-B8AB-BAEB9BDE3A02}
2012-08-15 09:53 - 2012-08-15 09:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{BB8C3B84-2F1F-42CC-9FB0-959FB059DFAF}
2012-08-15 09:51 - 2012-08-15 09:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{19CD7B34-313B-474E-B5C6-995CAC5AAF9A}
2012-08-15 04:09 - 2012-07-18 09:47 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-15 04:09 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-15 04:09 - 2012-07-04 13:14 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-15 04:09 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-15 04:09 - 2012-05-13 20:33 - 00769024 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-15 04:09 - 2012-05-04 23:46 - 00400896 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-15 04:09 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-15 04:09 - 2012-02-10 21:37 - 00317440 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-14 21:51 - 2012-08-14 21:51 - 00000000 ____D C:\Users\Ed\AppData\Local\{9AE428ED-B3B0-4BCD-B143-03AFD51599D6}
2012-08-14 21:51 - 2012-08-14 21:51 - 00000000 ____D C:\Users\Ed\AppData\Local\{1A604F21-A22C-4666-ADA8-D2E14C6DC4EE}
2012-08-14 09:49 - 2012-08-14 09:50 - 00000000 ____D C:\Users\Ed\AppData\Local\{4BF539D8-3749-4905-9E55-8C1A2D5F83C7}
2012-08-14 09:48 - 2012-08-14 09:49 - 00000000 ____D C:\Users\Ed\AppData\Local\{92F5D29E-4B5C-479F-A964-4EDF855093A5}
2012-08-13 21:47 - 2012-08-13 21:48 - 00000000 ____D C:\Users\Ed\AppData\Local\{491ECC7E-A6A7-4A5A-A72E-B5055EB7D39D}
2012-08-13 21:46 - 2012-08-13 21:47 - 00000000 ____D C:\Users\Ed\AppData\Local\{B846F75B-F08D-4C6E-97C6-D2760C98AC36}
2012-08-13 18:39 - 2012-08-13 18:40 - 00000000 ____D C:\Users\Ed\Desktop\behaviours
2012-08-13 09:45 - 2012-08-13 09:46 - 00000000 ____D C:\Users\Ed\AppData\Local\{29F7AC6D-B43B-4C2A-B644-7D134770BA57}
2012-08-13 09:43 - 2012-08-13 09:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{7725E018-75D2-479F-99BA-5AA6E929B7F2}
============ 3 Months Modified Files ========================
2012-09-12 21:24 - 2012-09-12 21:24 - 00000621 ____A C:\Users\Ed\Desktop\ComboFix - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000596 ____A C:\Users\Ed\Desktop\rkill - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000589 ____A C:\Users\Ed\Desktop\FRST - Shortcut.lnk
2012-09-12 21:24 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-09-12 21:23 - 2010-10-17 09:19 - 00000874 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-12 21:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-12 21:22 - 2009-07-13 20:39 - 00033305 ____A C:\Windows\setupact.log
2012-09-12 21:10 - 2012-09-12 19:59 - 00002836 ____A C:\Users\Ed\Desktop\Rkill.txt
2012-09-12 20:52 - 2012-07-11 21:07 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-12 20:52 - 2010-08-16 16:03 - 02013417 ____A C:\Windows\WindowsUpdate.log
2012-09-12 20:51 - 2011-01-30 12:51 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-12 20:51 - 2010-08-16 22:38 - 00738640 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-12 20:49 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-12 20:49 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-12 20:45 - 2012-09-12 20:45 - 00000332 ____A C:\Start_.cmd
2012-09-12 20:41 - 2012-09-12 20:41 - 00139104 ____A C:\Windows\Minidump\091212-20779-01.dmp
2012-09-12 20:29 - 2012-09-12 21:25 - 04749988 ___RA (Swearware) C:\Users\Ed\Desktop\ComboFix.exe
2012-09-12 19:54 - 2012-09-12 21:25 - 01632160 ____A (Bleeping Computer, LLC) C:\Users\Ed\Desktop\rkill.exe
2012-09-12 19:17 - 2012-09-12 21:25 - 00903834 ____A (Farbar) C:\Users\Ed\Desktop\FRST.exe
2012-09-12 08:16 - 2010-10-17 09:19 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-11 07:01 - 2012-09-11 07:01 - 00000249 ____A C:\Users\Ed\Desktop\Reset_and_Clear_Print_Spooler_Queue.bat
2012-09-09 16:21 - 2012-09-09 16:21 - 00002262 ____A C:\Users\Ed\Desktop\ripped cds - Shortcut.lnk
2012-08-19 11:48 - 2012-07-11 21:07 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-19 11:48 - 2011-10-30 15:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-18 11:25 - 2012-08-18 11:25 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-16 02:38 - 2009-07-13 20:33 - 00409752 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 02:37 - 2010-08-16 21:31 - 00097580 ____A C:\Windows\PFRO.log
2012-08-16 02:12 - 2010-08-16 20:13 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-12 10:28 - 2012-08-12 10:27 - 00013191 ____A C:\M1319.log
2012-08-08 15:49 - 2012-08-08 15:47 - 00001594 ____A C:\Windows\VPNInstall.MIF
2012-08-08 15:32 - 2012-03-12 21:25 - 00010046 ____A C:\Users\Ed\Desktop\Rental Property Transactions.xlsx
2012-07-24 20:22 - 2012-07-24 20:22 - 00001823 ____A C:\Users\Ed\Desktop\ed cd drive (ED-MAIN) - Shortcut.lnk
2012-07-24 20:06 - 2010-08-16 21:40 - 00001802 ____A C:\Users\Public\Desktop\Vuze.lnk
2012-07-23 20:12 - 2012-07-23 20:12 - 00001811 ____A C:\Users\Ed\Desktop\dvd drive (ED-MAIN) - Shortcut.lnk
2012-07-22 21:50 - 2012-07-22 21:50 - 00002006 ____A C:\Users\Ed\Desktop\accomodata silver 500g (MEDIA) - Shortcut.lnk
2012-07-22 21:50 - 2012-07-22 21:50 - 00001876 ____A C:\Users\Ed\Desktop\h (Media) - Shortcut.lnk
2012-07-22 21:50 - 2012-07-22 21:50 - 00001780 ____A C:\Users\Ed\Desktop\g (Media) - Shortcut.lnk
2012-07-18 09:47 - 2012-08-15 04:09 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 02:17 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-04 13:16 - 2012-08-15 04:09 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 13:14 - 2012-08-15 04:09 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 13:14 - 2012-08-15 04:09 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-06-28 16:52 - 2012-08-16 02:06 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 16:27 - 2012-08-16 02:06 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 16:16 - 2012-08-16 02:06 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 16:09 - 2012-08-16 02:06 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 16:09 - 2012-08-16 02:06 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 16:08 - 2012-08-16 02:06 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 16:07 - 2012-08-16 02:06 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 16:06 - 2012-08-16 02:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 16:04 - 2012-08-16 02:06 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 16:04 - 2012-08-16 02:06 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 16:01 - 2012-08-16 02:06 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 16:01 - 2012-08-16 02:06 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 16:00 - 2012-08-16 02:06 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 15:57 - 2012-08-16 02:06 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-17 20:52 - 2012-04-05 21:03 - 00002357 ____A C:\Users\Ed\Desktop\000 new arrivals - Shortcut.lnk
2012-06-17 20:52 - 2012-02-25 10:19 - 00002319 ____A C:\Users\Ed\Desktop\000 radio to keep - Shortcut (2).lnk
2012-06-17 20:52 - 2012-02-25 10:03 - 00002256 ____A C:\Users\Ed\Desktop\000 Live - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 18:26 - 00001762 ____A C:\Users\Ed\Desktop\yoga - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 17:05 - 00002172 ____A C:\Users\Ed\Desktop\Music to store - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 17:05 - 00002166 ____A C:\Users\Ed\Desktop\Public Videos - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 17:05 - 00002129 ____A C:\Users\Ed\Desktop\Public Music - Shortcut.lnk
ZeroAccess:
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\L
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\n
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\L\00000004.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\L\201d3dde
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\00000004.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\00000008.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\000000cb.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\80000000.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\80000032.@
ZeroAccess:
C:\Users\Ed\AppData\Local\{9838b74c-83bf-812d-73dc-c532d0013103}
C:\Users\Ed\AppData\Local\{9838b74c-83bf-812d-73dc-c532d0013103}\L
C:\Users\Ed\AppData\Local\{9838b74c-83bf-812d-73dc-c532d0013103}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-12 09:09:31
==================== Memory info ===========================
Percentage of memory in use: 22%
Total physical RAM: 1791.18 MB
Available physical RAM: 1384.85 MB
Total Pagefile: 1791.18 MB
Available Pagefile: 1393.85 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.73 MB
==================== Partitions ============================
1 Drive c: (Acer) (Fixed) (Total:131.95 GB) (Free:22.04 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:17 GB) (Free:7.34 GB) NTFS
3 Drive f: (Lexar) (Removable) (Total:14.91 GB) (Free:14.86 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 17 GB 1024 KB
Partition 2 Primary 100 MB 17 GB
Partition 3 Primary 131 GB 17 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E PQSERVICE NTFS Partition 17 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Acer NTFS Partition 131 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 64 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Lexar FAT32 Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-09-07 16:30
==================== End Of Log =============================
-----------------------------------------------------------------------------------------
Farbar Recovery Scan Tool (x86) Version: 12-09-2012
Ran by SYSTEM at 2012-09-12 22:36:15
Running from F:\
================== Search: "services.exe" ===================
C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows.old\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-09-12 21:24] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2012
Ran by SYSTEM at 12-09-2012 22:33:34
Running from F:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" [74752 2010-07-12] (Nullsoft, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [VX3000] C:\Windows\vVX3000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-29] (Sun Microsystems, Inc.)
HKLM\...\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe" [291496 2009-04-27] ()
HKLM\...\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe" [25256 2009-04-27] ()
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Ed\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-17] (Google Inc.)
HKU\Ed\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 64.59.144.19 64.59.150.135
Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{270FE6A0-E893-421C-809E-5B9111C2D4EC}\Icon3E5562ED7.ico ()
==================== Services ================================
2 CVPND; "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" [1504304 2006-10-06] (Cisco Systems, Inc.)
2 lxddCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [99248 2007-05-25] (Lexmark International, Inc.)
2 lxdd_device; C:\Windows\system32\lxddcoms.exe -service [537520 2007-05-25] ( )
2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2253120 2011-10-15] (NVIDIA Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
==================== Drivers =================================
3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5315 2005-05-17] (Cisco Systems, Inc.)
2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [305787 2006-10-06] (Cisco Systems, Inc.)
3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [126864 2006-10-02] (Deterministic Networks, Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) =================
============ One Month Created Files and Folders ==============
2012-09-12 22:33 - 2012-09-12 22:33 - 00000000 ____D C:\FRST
2012-09-12 21:25 - 2012-09-12 20:29 - 04749988 ___RA (Swearware) C:\Users\Ed\Desktop\ComboFix.exe
2012-09-12 21:25 - 2012-09-12 19:54 - 01632160 ____A (Bleeping Computer, LLC) C:\Users\Ed\Desktop\rkill.exe
2012-09-12 21:25 - 2012-09-12 19:17 - 00903834 ____A (Farbar) C:\Users\Ed\Desktop\FRST.exe
2012-09-12 21:24 - 2012-09-12 21:24 - 00000621 ____A C:\Users\Ed\Desktop\ComboFix - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000596 ____A C:\Users\Ed\Desktop\rkill - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000589 ____A C:\Users\Ed\Desktop\FRST - Shortcut.lnk
2012-09-12 20:51 - 2012-09-12 20:51 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-09-12 20:45 - 2012-09-12 20:45 - 00000332 ____A C:\Start_.cmd
2012-09-12 20:45 - 2012-09-12 20:45 - 00000000 ____D C:\ComboFix
2012-09-12 20:44 - 2012-09-12 21:10 - 00000000 ____D C:\Qoobox
2012-09-12 20:43 - 2012-09-12 21:10 - 00000000 ___SD C:\32788R22FWJFW
2012-09-12 20:43 - 2012-09-12 21:09 - 00000000 ____D C:\Windows\erdnt
2012-09-12 20:41 - 2012-09-12 20:41 - 00139104 ____A C:\Windows\Minidump\091212-20779-01.dmp
2012-09-12 20:41 - 2012-09-12 20:41 - 00000000 ____D C:\Windows\Minidump
2012-09-12 19:59 - 2012-09-12 21:10 - 00002836 ____A C:\Users\Ed\Desktop\Rkill.txt
2012-09-11 20:24 - 2012-09-11 20:25 - 00000000 ____D C:\Users\Ed\AppData\Local\{C87B86D2-1D73-4658-96D6-7D0B49FF49E2}
2012-09-11 08:23 - 2012-09-11 08:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{12C0C3B2-B167-4347-B64E-E10D7C3D6193}
2012-09-11 07:01 - 2012-09-11 07:01 - 00000249 ____A C:\Users\Ed\Desktop\Reset_and_Clear_Print_Spooler_Queue.bat
2012-09-10 20:21 - 2012-09-10 20:23 - 00000000 ____D C:\Users\Ed\AppData\Local\{60DECF96-9876-437C-A454-FC106DDE610B}
2012-09-10 08:20 - 2012-09-10 08:21 - 00000000 ____D C:\Users\Ed\AppData\Local\{49265433-F11A-446D-A626-9D2B0DBA5C65}
2012-09-09 20:54 - 2012-09-12 06:22 - 00000000 ____D C:\Users\Ed\Desktop\stick dump
2012-09-09 20:18 - 2012-09-09 20:20 - 00000000 ____D C:\Users\Ed\AppData\Local\{4BAD108A-9D06-407C-AB01-AB07E91F6CA0}
2012-09-09 16:21 - 2012-09-09 16:21 - 00002262 ____A C:\Users\Ed\Desktop\ripped cds - Shortcut.lnk
2012-09-09 16:21 - 2012-09-09 16:21 - 00000000 ____D C:\Users\Ed\Desktop\ripped cds
2012-09-09 08:16 - 2012-09-09 08:18 - 00000000 ____D C:\Users\Ed\AppData\Local\{19BE1D50-1A09-43AA-AB70-29ED87C7D728}
2012-09-08 08:13 - 2012-09-08 20:16 - 00000000 ____D C:\Users\Ed\AppData\Local\{55710E8B-7731-4DFE-BAC7-41CBEF6121C2}
2012-08-19 11:52 - 2012-08-19 11:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-18 11:25 - 2012-08-18 11:25 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-18 10:01 - 2012-08-18 10:02 - 00000000 ____D C:\Users\Ed\AppData\Local\{71A085F3-455E-40FE-8138-53577C326D02}
2012-08-17 22:00 - 2012-08-17 22:00 - 00000000 ____D C:\Users\Ed\AppData\Local\{9250A0FF-BF06-4A2D-9839-2FA071B18256}
2012-08-17 09:59 - 2012-08-17 10:00 - 00000000 ____D C:\Users\Ed\AppData\Local\{8EDD5CEB-6190-4D49-A2CB-FDE10791D076}
2012-08-16 21:58 - 2012-08-16 21:58 - 00000000 ____D C:\Users\Ed\AppData\Local\{8445152D-8BE0-4816-8BD0-E12870A221C1}
2012-08-16 09:56 - 2012-08-16 09:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{84038A28-1D02-40E3-9858-13F4085691DB}
2012-08-16 09:55 - 2012-08-18 22:03 - 00000000 ____D C:\Users\Ed\AppData\Local\{DE771767-9528-4D82-9385-BA1658674E74}
2012-08-16 02:06 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-16 02:06 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-16 02:06 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-16 02:06 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-16 02:06 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-16 02:06 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-16 02:06 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-16 02:06 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-16 02:06 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-16 02:06 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-16 02:06 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-16 02:06 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-16 02:06 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-16 02:06 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-15 21:54 - 2012-08-15 21:55 - 00000000 ____D C:\Users\Ed\AppData\Local\{554D9C41-45D5-4274-A7D6-C834DC440A15}
2012-08-15 21:54 - 2012-08-15 21:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{C4A930C1-A7C6-46E0-B8AB-BAEB9BDE3A02}
2012-08-15 09:53 - 2012-08-15 09:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{BB8C3B84-2F1F-42CC-9FB0-959FB059DFAF}
2012-08-15 09:51 - 2012-08-15 09:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{19CD7B34-313B-474E-B5C6-995CAC5AAF9A}
2012-08-15 04:09 - 2012-07-18 09:47 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-15 04:09 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-15 04:09 - 2012-07-04 13:14 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-15 04:09 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-15 04:09 - 2012-05-13 20:33 - 00769024 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-15 04:09 - 2012-05-04 23:46 - 00400896 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-15 04:09 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-15 04:09 - 2012-02-10 21:37 - 00317440 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-14 21:51 - 2012-08-14 21:51 - 00000000 ____D C:\Users\Ed\AppData\Local\{9AE428ED-B3B0-4BCD-B143-03AFD51599D6}
2012-08-14 21:51 - 2012-08-14 21:51 - 00000000 ____D C:\Users\Ed\AppData\Local\{1A604F21-A22C-4666-ADA8-D2E14C6DC4EE}
2012-08-14 09:49 - 2012-08-14 09:50 - 00000000 ____D C:\Users\Ed\AppData\Local\{4BF539D8-3749-4905-9E55-8C1A2D5F83C7}
2012-08-14 09:48 - 2012-08-14 09:49 - 00000000 ____D C:\Users\Ed\AppData\Local\{92F5D29E-4B5C-479F-A964-4EDF855093A5}
2012-08-13 21:47 - 2012-08-13 21:48 - 00000000 ____D C:\Users\Ed\AppData\Local\{491ECC7E-A6A7-4A5A-A72E-B5055EB7D39D}
2012-08-13 21:46 - 2012-08-13 21:47 - 00000000 ____D C:\Users\Ed\AppData\Local\{B846F75B-F08D-4C6E-97C6-D2760C98AC36}
2012-08-13 18:39 - 2012-08-13 18:40 - 00000000 ____D C:\Users\Ed\Desktop\behaviours
2012-08-13 09:45 - 2012-08-13 09:46 - 00000000 ____D C:\Users\Ed\AppData\Local\{29F7AC6D-B43B-4C2A-B644-7D134770BA57}
2012-08-13 09:43 - 2012-08-13 09:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{7725E018-75D2-479F-99BA-5AA6E929B7F2}
============ 3 Months Modified Files ========================
2012-09-12 21:24 - 2012-09-12 21:24 - 00000621 ____A C:\Users\Ed\Desktop\ComboFix - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000596 ____A C:\Users\Ed\Desktop\rkill - Shortcut.lnk
2012-09-12 21:24 - 2012-09-12 21:24 - 00000589 ____A C:\Users\Ed\Desktop\FRST - Shortcut.lnk
2012-09-12 21:24 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-09-12 21:23 - 2010-10-17 09:19 - 00000874 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-12 21:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-12 21:22 - 2009-07-13 20:39 - 00033305 ____A C:\Windows\setupact.log
2012-09-12 21:10 - 2012-09-12 19:59 - 00002836 ____A C:\Users\Ed\Desktop\Rkill.txt
2012-09-12 20:52 - 2012-07-11 21:07 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-12 20:52 - 2010-08-16 16:03 - 02013417 ____A C:\Windows\WindowsUpdate.log
2012-09-12 20:51 - 2011-01-30 12:51 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-12 20:51 - 2010-08-16 22:38 - 00738640 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-12 20:49 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-12 20:49 - 2009-07-13 20:34 - 00017168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-12 20:45 - 2012-09-12 20:45 - 00000332 ____A C:\Start_.cmd
2012-09-12 20:41 - 2012-09-12 20:41 - 00139104 ____A C:\Windows\Minidump\091212-20779-01.dmp
2012-09-12 20:29 - 2012-09-12 21:25 - 04749988 ___RA (Swearware) C:\Users\Ed\Desktop\ComboFix.exe
2012-09-12 19:54 - 2012-09-12 21:25 - 01632160 ____A (Bleeping Computer, LLC) C:\Users\Ed\Desktop\rkill.exe
2012-09-12 19:17 - 2012-09-12 21:25 - 00903834 ____A (Farbar) C:\Users\Ed\Desktop\FRST.exe
2012-09-12 08:16 - 2010-10-17 09:19 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-11 07:01 - 2012-09-11 07:01 - 00000249 ____A C:\Users\Ed\Desktop\Reset_and_Clear_Print_Spooler_Queue.bat
2012-09-09 16:21 - 2012-09-09 16:21 - 00002262 ____A C:\Users\Ed\Desktop\ripped cds - Shortcut.lnk
2012-08-19 11:48 - 2012-07-11 21:07 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-19 11:48 - 2011-10-30 15:23 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-18 11:25 - 2012-08-18 11:25 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-08-16 02:38 - 2009-07-13 20:33 - 00409752 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-16 02:37 - 2010-08-16 21:31 - 00097580 ____A C:\Windows\PFRO.log
2012-08-16 02:12 - 2010-08-16 20:13 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-12 10:28 - 2012-08-12 10:27 - 00013191 ____A C:\M1319.log
2012-08-08 15:49 - 2012-08-08 15:47 - 00001594 ____A C:\Windows\VPNInstall.MIF
2012-08-08 15:32 - 2012-03-12 21:25 - 00010046 ____A C:\Users\Ed\Desktop\Rental Property Transactions.xlsx
2012-07-24 20:22 - 2012-07-24 20:22 - 00001823 ____A C:\Users\Ed\Desktop\ed cd drive (ED-MAIN) - Shortcut.lnk
2012-07-24 20:06 - 2010-08-16 21:40 - 00001802 ____A C:\Users\Public\Desktop\Vuze.lnk
2012-07-23 20:12 - 2012-07-23 20:12 - 00001811 ____A C:\Users\Ed\Desktop\dvd drive (ED-MAIN) - Shortcut.lnk
2012-07-22 21:50 - 2012-07-22 21:50 - 00002006 ____A C:\Users\Ed\Desktop\accomodata silver 500g (MEDIA) - Shortcut.lnk
2012-07-22 21:50 - 2012-07-22 21:50 - 00001876 ____A C:\Users\Ed\Desktop\h (Media) - Shortcut.lnk
2012-07-22 21:50 - 2012-07-22 21:50 - 00001780 ____A C:\Users\Ed\Desktop\g (Media) - Shortcut.lnk
2012-07-18 09:47 - 2012-08-15 04:09 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 02:17 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-04 13:16 - 2012-08-15 04:09 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 13:14 - 2012-08-15 04:09 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 13:14 - 2012-08-15 04:09 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-06-28 16:52 - 2012-08-16 02:06 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 16:27 - 2012-08-16 02:06 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 16:16 - 2012-08-16 02:06 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 16:09 - 2012-08-16 02:06 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 16:09 - 2012-08-16 02:06 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 16:08 - 2012-08-16 02:06 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 16:07 - 2012-08-16 02:06 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 16:06 - 2012-08-16 02:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 16:04 - 2012-08-16 02:06 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 16:04 - 2012-08-16 02:06 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 16:01 - 2012-08-16 02:06 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 16:01 - 2012-08-16 02:06 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 16:00 - 2012-08-16 02:06 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 15:57 - 2012-08-16 02:06 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-17 20:52 - 2012-04-05 21:03 - 00002357 ____A C:\Users\Ed\Desktop\000 new arrivals - Shortcut.lnk
2012-06-17 20:52 - 2012-02-25 10:19 - 00002319 ____A C:\Users\Ed\Desktop\000 radio to keep - Shortcut (2).lnk
2012-06-17 20:52 - 2012-02-25 10:03 - 00002256 ____A C:\Users\Ed\Desktop\000 Live - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 18:26 - 00001762 ____A C:\Users\Ed\Desktop\yoga - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 17:05 - 00002172 ____A C:\Users\Ed\Desktop\Music to store - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 17:05 - 00002166 ____A C:\Users\Ed\Desktop\Public Videos - Shortcut.lnk
2012-06-17 20:52 - 2011-06-05 17:05 - 00002129 ____A C:\Users\Ed\Desktop\Public Music - Shortcut.lnk
ZeroAccess:
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\L
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\n
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\L\00000004.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\L\201d3dde
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\00000004.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\00000008.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\000000cb.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\80000000.@
C:\Windows\Installer\{9838b74c-83bf-812d-73dc-c532d0013103}\U\80000032.@
ZeroAccess:
C:\Users\Ed\AppData\Local\{9838b74c-83bf-812d-73dc-c532d0013103}
C:\Users\Ed\AppData\Local\{9838b74c-83bf-812d-73dc-c532d0013103}\L
C:\Users\Ed\AppData\Local\{9838b74c-83bf-812d-73dc-c532d0013103}\U
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-12 09:09:31
==================== Memory info ===========================
Percentage of memory in use: 22%
Total physical RAM: 1791.18 MB
Available physical RAM: 1384.85 MB
Total Pagefile: 1791.18 MB
Available Pagefile: 1393.85 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.73 MB
==================== Partitions ============================
1 Drive c: (Acer) (Fixed) (Total:131.95 GB) (Free:22.04 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:17 GB) (Free:7.34 GB) NTFS
3 Drive f: (Lexar) (Removable) (Total:14.91 GB) (Free:14.86 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 17 GB 1024 KB
Partition 2 Primary 100 MB 17 GB
Partition 3 Primary 131 GB 17 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E PQSERVICE NTFS Partition 17 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM RESE NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Acer NTFS Partition 131 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 64 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Lexar FAT32 Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-09-07 16:30
==================== End Of Log =============================
-----------------------------------------------------------------------------------------
Farbar Recovery Scan Tool (x86) Version: 12-09-2012
Ran by SYSTEM at 2012-09-12 22:36:15
Running from F:\
================== Search: "services.exe" ===================
C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows.old\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-09-12 21:24] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===