Mothy101218
Posts: 7 +0
Hi I am not very good with computers and was wondering if someone could help me remove these problems....
I have read a couple of other threads but each result seems to be tailor made to that person's computer :-|
So lets see if I have got this right to start here is my FRST log. I have tried to do the search for services.exe but the computer restarts before completing
....
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by User at 26-07-2012 18:18:35
Running from C:\Users\User\Desktop
Service Pack 2 (X86) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-26 17:41 - 2012-07-26 13:00 - 76366752 ____A (Sophos Limited) C:\Users\User\Desktop\Sophos Virus Removal Tool.exe
2012-07-26 17:27 - 2012-07-26 17:42 - 00019773 ____A C:\Windows\Partizan.log
2012-07-26 17:26 - 2012-07-26 18:16 - 00000372 ____A C:\Windows\System32\PARTIZAN.TXT
2012-07-26 17:24 - 2012-07-26 17:45 - 00000000 ____D C:\Users\Public\Documents\regruninfo
2012-07-26 17:24 - 2012-07-26 17:40 - 00000000 ____D C:\Users\User\Documents\RegRun2
2012-07-26 17:24 - 2012-07-26 17:24 - 00039184 ____A (Greatis Software) C:\Windows\System32\Partizan.exe
2012-07-26 17:24 - 2012-07-26 17:24 - 00035816 ____A (Greatis Software) C:\Windows\System32\Drivers\Partizan.sys
2012-07-26 17:24 - 2012-07-26 17:24 - 00000406 ____A C:\Windows\Tasks\UnHackMe Task Scheduler.job
2012-07-26 17:24 - 2012-07-26 17:24 - 00000002 RASHOT C:\Windows\winstart.bat
2012-07-26 17:24 - 2012-07-26 17:24 - 00000000 ____D C:\Program Files\UnHackMe
2012-07-26 17:24 - 2012-01-23 17:01 - 00012800 ____A (Greatis Software, LLC.) C:\Windows\System32\Drivers\UnHackMeDrv.sys
2012-07-26 17:09 - 2012-07-26 17:20 - 00000321 ____A C:\rkill.log
2012-07-26 16:58 - 2012-07-26 18:18 - 00000000 ____D C:\FRST
2012-07-26 16:57 - 2012-07-25 01:07 - 00892822 ____A (Farbar) C:\Users\User\Desktop\FRST.exe
2012-07-26 16:04 - 2012-07-26 16:07 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-07-26 15:45 - 2012-07-26 15:55 - 00027424 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-26 15:43 - 2012-07-26 18:11 - 00000000 ____D C:\Users\User\Desktop\Virus stuff
2012-07-26 15:43 - 2012-07-26 15:54 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-07-26 15:43 - 2012-07-26 15:43 - 00000000 ____D C:\Program Files\HitmanPro
2012-07-26 14:29 - 2012-07-26 14:29 - 00450352 ____A (Microsoft Corporation) C:\Users\User\Downloads\FixitCenter_Run.exe
2012-07-26 13:54 - 2012-07-26 13:54 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2012-07-26 13:54 - 2012-07-26 13:54 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-26 13:54 - 2012-07-26 13:54 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-07-26 13:54 - 2012-07-03 13:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-26 12:44 - 2012-07-26 12:44 - 00000297 ____A C:\Users\User\Desktop\ACER (C) - Shortcut.lnk
2012-07-26 12:21 - 2012-07-26 12:21 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-07-26 12:03 - 2012-07-26 12:05 - 00000000 ____D C:\Windows\pss
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT42BB.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT3820.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 00000000 ____D C:\Program Files\GUM42AA.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 00000000 ____D C:\Program Files\GUM3800.tmp
2012-06-30 11:24 - 2012-06-30 11:24 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-30 10:49 - 2012-06-30 10:49 - 10288512 ____A (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
2012-06-28 16:23 - 2012-06-28 16:23 - 00000000 ____D C:\Program Files\DailyBibleGuideEI
============ 3 Months Modified Files ========================
2012-07-26 18:16 - 2012-07-26 17:26 - 00000372 ____A C:\Windows\System32\PARTIZAN.TXT
2012-07-26 18:14 - 2011-11-06 17:03 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-26 18:14 - 2006-11-02 13:47 - 00004240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-26 18:14 - 2006-11-02 13:47 - 00004240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-26 18:13 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-26 18:02 - 2006-11-02 14:01 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-26 17:42 - 2012-07-26 17:27 - 00019773 ____A C:\Windows\Partizan.log
2012-07-26 17:24 - 2012-07-26 17:24 - 00039184 ____A (Greatis Software) C:\Windows\System32\Partizan.exe
2012-07-26 17:24 - 2012-07-26 17:24 - 00035816 ____A (Greatis Software) C:\Windows\System32\Drivers\Partizan.sys
2012-07-26 17:24 - 2012-07-26 17:24 - 00000406 ____A C:\Windows\Tasks\UnHackMe Task Scheduler.job
2012-07-26 17:24 - 2012-07-26 17:24 - 00000002 RASHOT C:\Windows\winstart.bat
2012-07-26 17:24 - 2006-11-02 11:23 - 00002577 ____A C:\Windows\System32\config.nt
2012-07-26 17:24 - 2006-11-02 11:23 - 00001688 ____A C:\Windows\System32\autoexec.nt
2012-07-26 17:20 - 2012-07-26 17:09 - 00000321 ____A C:\rkill.log
2012-07-26 16:39 - 2009-04-11 13:37 - 01056236 ____A C:\Windows\WindowsUpdate.log
2012-07-26 16:28 - 2011-11-08 17:31 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-110114514-3210166799-939169939-1000UA.job
2012-07-26 16:27 - 2009-04-11 14:18 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-26 16:23 - 2011-11-06 17:03 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-26 15:55 - 2012-07-26 15:45 - 00027424 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-26 15:24 - 2011-11-03 17:33 - 00004133 ____A C:\Windows\setupact.log
2012-07-26 14:57 - 2006-11-02 11:33 - 00710764 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-26 14:29 - 2012-07-26 14:29 - 00450352 ____A (Microsoft Corporation) C:\Users\User\Downloads\FixitCenter_Run.exe
2012-07-26 14:26 - 2011-11-04 18:37 - 00009056 ____A C:\Windows\PFRO.log
2012-07-26 13:00 - 2012-07-26 17:41 - 76366752 ____A (Sophos Limited) C:\Users\User\Desktop\Sophos Virus Removal Tool.exe
2012-07-26 12:44 - 2012-07-26 12:44 - 00000297 ____A C:\Users\User\Desktop\ACER (C) - Shortcut.lnk
2012-07-26 12:33 - 2011-11-03 10:08 - 00001356 ____A C:\Users\User\AppData\Local\d3d9caps.dat
2012-07-26 11:28 - 2011-11-08 17:31 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-110114514-3210166799-939169939-1000Core.job
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT42BB.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT3820.tmp
2012-07-25 01:07 - 2012-07-26 16:57 - 00892822 ____A (Farbar) C:\Users\User\Desktop\FRST.exe
2012-07-03 13:46 - 2012-07-26 13:54 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-30 11:25 - 2011-11-03 10:17 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-30 10:49 - 2012-06-30 10:49 - 10288512 ____A (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
2012-06-15 03:26 - 2006-11-02 13:47 - 00396320 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-15 03:05 - 2006-11-02 11:24 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-02 23:19 - 2012-06-19 11:46 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-19 11:46 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-19 11:46 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-19 11:46 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-19 11:46 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:12 - 2012-06-19 11:46 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:12 - 2012-06-19 11:46 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-19 11:46 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:12 - 2012-06-19 11:46 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-18 00:11 - 2012-06-15 03:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 23:48 - 2012-06-15 03:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 23:45 - 2012-06-15 03:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 23:36 - 2012-06-15 03:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 23:35 - 2012-06-15 03:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 23:35 - 2012-06-15 03:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 23:33 - 2012-06-15 03:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 23:31 - 2012-06-15 03:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 23:29 - 2012-06-15 03:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 23:29 - 2012-06-15 03:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 23:27 - 2012-06-15 03:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 23:25 - 2012-06-15 03:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 23:24 - 2012-06-15 03:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 23:20 - 2012-06-15 03:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 19:43 - 2012-05-17 19:43 - 00000104 ____A C:\Users\User\Desktop\Recycle Bin - Shortcut - Copy.lnk
2012-05-17 16:50 - 2012-05-17 16:50 - 00001668 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-05-15 20:51 - 2012-06-14 09:11 - 02045440 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-07 13:19 - 2012-05-07 13:19 - 01107336 ____A C:\Users\User\Downloads\MusicConverterSetup.exe
2012-05-07 13:19 - 2012-05-07 13:19 - 01107336 ____A C:\Users\User\Downloads\MusicConverterSetup (1).exe
2012-05-01 15:03 - 2012-06-14 09:11 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-28 14:38 - 2012-04-28 14:38 - 00000050 ____A C:\user.js
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 3061.57 MB
Available physical RAM: 2541.46 MB
Total Pagefile: 6323.55 MB
Available Pagefile: 5974.29 MB
Total Virtual: 2047.88 MB
Available Virtual: 1978.66 MB
======================= Partitions =========================
1 Drive c: (ACER) (Fixed) (Total:70.05 GB) (Free:23.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (DATA) (Fixed) (Total:69 GB) (Free:68.88 GB) NTFS
4 Drive f: () (Removable) (Total:3.74 GB) (Free:2.85 GB) FAT32
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 3836 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
DiskPart encountered an unexpected error.
Check the system event log for more information on the failure.
==================================================================================
Partitions of Disk 1:
===============
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==================================================================================
==========================================================
Last Boot: 2012-06-30 11:08
======================= End Of Log ==========================
Many thanks
I have read a couple of other threads but each result seems to be tailor made to that person's computer :-|
So lets see if I have got this right to start here is my FRST log. I have tried to do the search for services.exe but the computer restarts before completing
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by User at 26-07-2012 18:18:35
Running from C:\Users\User\Desktop
Service Pack 2 (X86) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-26 17:41 - 2012-07-26 13:00 - 76366752 ____A (Sophos Limited) C:\Users\User\Desktop\Sophos Virus Removal Tool.exe
2012-07-26 17:27 - 2012-07-26 17:42 - 00019773 ____A C:\Windows\Partizan.log
2012-07-26 17:26 - 2012-07-26 18:16 - 00000372 ____A C:\Windows\System32\PARTIZAN.TXT
2012-07-26 17:24 - 2012-07-26 17:45 - 00000000 ____D C:\Users\Public\Documents\regruninfo
2012-07-26 17:24 - 2012-07-26 17:40 - 00000000 ____D C:\Users\User\Documents\RegRun2
2012-07-26 17:24 - 2012-07-26 17:24 - 00039184 ____A (Greatis Software) C:\Windows\System32\Partizan.exe
2012-07-26 17:24 - 2012-07-26 17:24 - 00035816 ____A (Greatis Software) C:\Windows\System32\Drivers\Partizan.sys
2012-07-26 17:24 - 2012-07-26 17:24 - 00000406 ____A C:\Windows\Tasks\UnHackMe Task Scheduler.job
2012-07-26 17:24 - 2012-07-26 17:24 - 00000002 RASHOT C:\Windows\winstart.bat
2012-07-26 17:24 - 2012-07-26 17:24 - 00000000 ____D C:\Program Files\UnHackMe
2012-07-26 17:24 - 2012-01-23 17:01 - 00012800 ____A (Greatis Software, LLC.) C:\Windows\System32\Drivers\UnHackMeDrv.sys
2012-07-26 17:09 - 2012-07-26 17:20 - 00000321 ____A C:\rkill.log
2012-07-26 16:58 - 2012-07-26 18:18 - 00000000 ____D C:\FRST
2012-07-26 16:57 - 2012-07-25 01:07 - 00892822 ____A (Farbar) C:\Users\User\Desktop\FRST.exe
2012-07-26 16:04 - 2012-07-26 16:07 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-07-26 15:45 - 2012-07-26 15:55 - 00027424 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-26 15:43 - 2012-07-26 18:11 - 00000000 ____D C:\Users\User\Desktop\Virus stuff
2012-07-26 15:43 - 2012-07-26 15:54 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-07-26 15:43 - 2012-07-26 15:43 - 00000000 ____D C:\Program Files\HitmanPro
2012-07-26 14:29 - 2012-07-26 14:29 - 00450352 ____A (Microsoft Corporation) C:\Users\User\Downloads\FixitCenter_Run.exe
2012-07-26 13:54 - 2012-07-26 13:54 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2012-07-26 13:54 - 2012-07-26 13:54 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-26 13:54 - 2012-07-26 13:54 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-07-26 13:54 - 2012-07-03 13:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-26 12:44 - 2012-07-26 12:44 - 00000297 ____A C:\Users\User\Desktop\ACER (C) - Shortcut.lnk
2012-07-26 12:21 - 2012-07-26 12:21 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-07-26 12:03 - 2012-07-26 12:05 - 00000000 ____D C:\Windows\pss
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT42BB.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT3820.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 00000000 ____D C:\Program Files\GUM42AA.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 00000000 ____D C:\Program Files\GUM3800.tmp
2012-06-30 11:24 - 2012-06-30 11:24 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-30 10:49 - 2012-06-30 10:49 - 10288512 ____A (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
2012-06-28 16:23 - 2012-06-28 16:23 - 00000000 ____D C:\Program Files\DailyBibleGuideEI
============ 3 Months Modified Files ========================
2012-07-26 18:16 - 2012-07-26 17:26 - 00000372 ____A C:\Windows\System32\PARTIZAN.TXT
2012-07-26 18:14 - 2011-11-06 17:03 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-26 18:14 - 2006-11-02 13:47 - 00004240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-26 18:14 - 2006-11-02 13:47 - 00004240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-26 18:13 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-26 18:02 - 2006-11-02 14:01 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-26 17:42 - 2012-07-26 17:27 - 00019773 ____A C:\Windows\Partizan.log
2012-07-26 17:24 - 2012-07-26 17:24 - 00039184 ____A (Greatis Software) C:\Windows\System32\Partizan.exe
2012-07-26 17:24 - 2012-07-26 17:24 - 00035816 ____A (Greatis Software) C:\Windows\System32\Drivers\Partizan.sys
2012-07-26 17:24 - 2012-07-26 17:24 - 00000406 ____A C:\Windows\Tasks\UnHackMe Task Scheduler.job
2012-07-26 17:24 - 2012-07-26 17:24 - 00000002 RASHOT C:\Windows\winstart.bat
2012-07-26 17:24 - 2006-11-02 11:23 - 00002577 ____A C:\Windows\System32\config.nt
2012-07-26 17:24 - 2006-11-02 11:23 - 00001688 ____A C:\Windows\System32\autoexec.nt
2012-07-26 17:20 - 2012-07-26 17:09 - 00000321 ____A C:\rkill.log
2012-07-26 16:39 - 2009-04-11 13:37 - 01056236 ____A C:\Windows\WindowsUpdate.log
2012-07-26 16:28 - 2011-11-08 17:31 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-110114514-3210166799-939169939-1000UA.job
2012-07-26 16:27 - 2009-04-11 14:18 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-26 16:23 - 2011-11-06 17:03 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-26 15:55 - 2012-07-26 15:45 - 00027424 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-26 15:24 - 2011-11-03 17:33 - 00004133 ____A C:\Windows\setupact.log
2012-07-26 14:57 - 2006-11-02 11:33 - 00710764 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-26 14:29 - 2012-07-26 14:29 - 00450352 ____A (Microsoft Corporation) C:\Users\User\Downloads\FixitCenter_Run.exe
2012-07-26 14:26 - 2011-11-04 18:37 - 00009056 ____A C:\Windows\PFRO.log
2012-07-26 13:00 - 2012-07-26 17:41 - 76366752 ____A (Sophos Limited) C:\Users\User\Desktop\Sophos Virus Removal Tool.exe
2012-07-26 12:44 - 2012-07-26 12:44 - 00000297 ____A C:\Users\User\Desktop\ACER (C) - Shortcut.lnk
2012-07-26 12:33 - 2011-11-03 10:08 - 00001356 ____A C:\Users\User\AppData\Local\d3d9caps.dat
2012-07-26 11:28 - 2011-11-08 17:31 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-110114514-3210166799-939169939-1000Core.job
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT42BB.tmp
2012-07-26 11:22 - 2012-07-26 11:22 - 04024320 ____A C:\Program Files\GUT3820.tmp
2012-07-25 01:07 - 2012-07-26 16:57 - 00892822 ____A (Farbar) C:\Users\User\Desktop\FRST.exe
2012-07-03 13:46 - 2012-07-26 13:54 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-30 11:25 - 2011-11-03 10:17 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-30 10:49 - 2012-06-30 10:49 - 10288512 ____A (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
2012-06-15 03:26 - 2006-11-02 13:47 - 00396320 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-15 03:05 - 2006-11-02 11:24 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-02 23:19 - 2012-06-19 11:46 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 23:19 - 2012-06-19 11:46 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 23:19 - 2012-06-19 11:46 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 23:19 - 2012-06-19 11:46 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 23:19 - 2012-06-19 11:46 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 23:12 - 2012-06-19 11:46 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 23:12 - 2012-06-19 11:46 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-19 11:46 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:12 - 2012-06-19 11:46 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-18 00:11 - 2012-06-15 03:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 23:48 - 2012-06-15 03:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 23:45 - 2012-06-15 03:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 23:36 - 2012-06-15 03:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 23:35 - 2012-06-15 03:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 23:35 - 2012-06-15 03:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 23:33 - 2012-06-15 03:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 23:31 - 2012-06-15 03:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 23:29 - 2012-06-15 03:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 23:29 - 2012-06-15 03:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 23:27 - 2012-06-15 03:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 23:25 - 2012-06-15 03:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 23:24 - 2012-06-15 03:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 23:20 - 2012-06-15 03:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 19:43 - 2012-05-17 19:43 - 00000104 ____A C:\Users\User\Desktop\Recycle Bin - Shortcut - Copy.lnk
2012-05-17 16:50 - 2012-05-17 16:50 - 00001668 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-05-15 20:51 - 2012-06-14 09:11 - 02045440 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-07 13:19 - 2012-05-07 13:19 - 01107336 ____A C:\Users\User\Downloads\MusicConverterSetup.exe
2012-05-07 13:19 - 2012-05-07 13:19 - 01107336 ____A C:\Users\User\Downloads\MusicConverterSetup (1).exe
2012-05-01 15:03 - 2012-06-14 09:11 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-28 14:38 - 2012-04-28 14:38 - 00000050 ____A C:\user.js
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 3061.57 MB
Available physical RAM: 2541.46 MB
Total Pagefile: 6323.55 MB
Available Pagefile: 5974.29 MB
Total Virtual: 2047.88 MB
Available Virtual: 1978.66 MB
======================= Partitions =========================
1 Drive c: (ACER) (Fixed) (Total:70.05 GB) (Free:23.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (DATA) (Fixed) (Total:69 GB) (Free:68.88 GB) NTFS
4 Drive f: () (Removable) (Total:3.74 GB) (Free:2.85 GB) FAT32
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 3836 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
DiskPart encountered an unexpected error.
Check the system event log for more information on the failure.
==================================================================================
Partitions of Disk 1:
===============
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==================================================================================
==========================================================
Last Boot: 2012-06-30 11:08
======================= End Of Log ==========================
Many thanks