dougefresh1
Posts: 11 +0
My deskop is running on Windows 7 64-Bit
I believe that my laptop may have contracted the malware when I downloaded a "new" update for Adobe Flash Player, but im not sure
Live security was installed on my computer and I was able to remove it after using malwarebytes in safe mode. Now when I boot up my computer microsoft security essentials says I have a system failure and I have to restart, this happens everytime I boot up even in safe mode.
This is my log
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 31-07-2012 10:32:20
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5712896 2011-07-21] (Dell Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [166936 2010-10-07] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2010-10-07] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416792 2010-10-07] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252136 2011-05-04] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [HPHUPD05] C:\Program Files (x86)\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe [49152 2003-05-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Component Manager] "C:\Program Files (x86)\HP\hpcoretech\hpcmpmgr.exe" [233472 2003-10-23] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Software Update] "C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [49152 2003-06-25] (Hewlett-Packard)
HKLM-x32\...\Run: [HPHmon05] C:\Windows\SysWOW64\hphmon05.exe [483328 2003-05-22] (Hewlett-Packard)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-10-09] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [887976 2011-08-23] (Ask)
HKLM-x32\...\Run: [RoxioNowMediaManagerApp] C:\Program Files (x86)\Roxio\RoxioNow Player\RNowShell.exe -start [2785776 2011-08-02] (Rovi Corporation)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKU\XPS\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [4910912 2011-08-01] (DT Soft Ltd)
HKU\XPS\...\Run: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED [6077848 2012-07-30] (BitTorrent, Inc.)
HKU\XPS\...\Run: [Google Update] "C:\Users\XPS\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-08-23] (Google Inc.)
HKU\XPS\...\Run: [Facebook Update] "C:\Users\XPS\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\XPS\...\Run: [AdobeBridge] [x]
HKU\XPS\...\Run: [chromium] C:\Users\XPS\AppData\Local\Google\Chrome\Application\chrome.exe --no-startup-window [1250328 2012-07-09] (Google Inc.)
HKU\XPS\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17417392 2012-07-03] (Skype Technologies S.A.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) ======
2 BrcmMgmtAgent; "C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe" -service [158720 2010-06-29] (Broadcom Corporation)
2 HPSLPSVC; C:\Users\XPS\AppData\Local\Temp\7zS7B52\hpslpsvc64.dll [1039360 2011-08-22] (Hewlett-Packard Co.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RoxioNow Service; C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [400368 2011-08-02] (Rovi Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2655768 2010-10-06] (Intel Corporation)
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [270912 2011-08-06] (DT Soft Ltd)
3 hitmanpro36; C:\Windows\System32\Drivers\hitmanpro36.sys [30496 2012-07-30] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-31 10:32 - 2012-07-31 10:32 - 00000000 ____D C:\FRST
2012-07-31 09:02 - 2012-07-31 09:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BE66D4CF17418B8
2012-07-31 09:02 - 2012-07-31 09:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kvabrxjg.sys
2012-07-31 09:00 - 2012-07-31 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214AB0B4EF43C99D
2012-07-31 08:55 - 2012-07-31 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C82168ED7D567B4E
2012-07-31 08:48 - 2012-07-31 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8E387F9EDE0101CA
2012-07-31 08:45 - 2012-07-31 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.750FD8E45FB33FFA
2012-07-31 08:42 - 2012-07-31 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0A3142AB22760D0
2012-07-31 08:38 - 2012-07-31 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BB6970BB31AD5F4
2012-07-30 15:59 - 2012-07-30 15:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF09CA2AB00A0FE
2012-07-30 15:53 - 2012-07-30 15:53 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-30 15:53 - 2012-07-30 15:53 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-30 15:50 - 2012-07-30 15:51 - 12621696 ____A (Microsoft Corporation) C:\Users\XPS\Downloads\mseinstall(1).exe
2012-07-30 15:40 - 2012-07-30 15:40 - 00002166 ____A C:\Windows\System32\.crusader
2012-07-30 15:37 - 2012-07-30 15:41 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-30 15:36 - 2012-07-30 15:40 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-07-30 15:36 - 2012-07-30 15:36 - 08854904 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36_x64.exe
2012-07-30 15:35 - 2012-07-30 15:36 - 07750160 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36.exe
2012-07-30 15:04 - 2012-07-30 15:04 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 12:34 - 2012-07-30 12:34 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-30 12:33 - 2012-07-30 12:34 - 01012656 ____A C:\Users\XPS\Downloads\iExplore.exe
2012-07-30 12:33 - 2012-07-30 12:33 - 00001205 ____A C:\Users\XPS\Downloads\registryfix.reg
2012-07-30 12:27 - 2012-07-30 15:40 - 00000000 ____D C:\Users\All Users\7531CCA9000116D300584A13F875F002
2012-07-30 12:26 - 2012-07-30 15:27 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Exwy
2012-07-30 12:26 - 2012-07-30 14:53 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Xyhyi
2012-07-30 12:26 - 2012-07-30 12:26 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Fyicqo
2012-07-29 08:19 - 2012-07-29 08:19 - 09821896 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-20 20:48 - 2012-07-20 20:48 - 00000000 ____D C:\Users\XPS\Documents\Amazon MP3
2012-07-20 20:47 - 2012-07-20 20:47 - 01637016 ____A C:\Users\XPS\Downloads\AmazonMP3DownloaderInstall(1).exe
2012-07-20 14:09 - 2012-07-20 14:43 - 390765945 ____A C:\Users\XPS\Downloads\glSod.mp4
2012-07-20 10:28 - 2012-07-20 10:28 - 00211037 ____A C:\Users\XPS\Documents\holdmail.xps
2012-07-19 15:13 - 2012-07-19 15:13 - 00000000 ____D C:\Users\XPS\AppData\Roaming\GameTuts
2012-07-19 15:13 - 2012-07-19 15:13 - 00000000 ____D C:\Users\XPS\AppData\Local\GameTuts
2012-07-19 15:08 - 2012-07-19 15:08 - 00000000 ____D C:\Users\XPS\Downloads\NFL 2K13 - Version 1
2012-07-18 16:21 - 2012-07-18 17:01 - 72043540 ____A C:\Users\XPS\Downloads\snmndxsyjxsp.avi.part
2012-07-11 14:41 - 2012-07-11 14:41 - 08666333 ____A C:\Users\XPS\Downloads\meebo-chatlogs.zip
2012-07-09 15:21 - 2012-07-31 08:57 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Skype
2012-07-09 15:21 - 2012-07-09 15:21 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-07-09 15:21 - 2012-07-09 15:21 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-07-09 15:20 - 2012-07-17 15:05 - 00000000 ____D C:\Users\All Users\Skype
2012-07-09 15:20 - 2012-07-09 15:20 - 00946352 ____A (Skype Technologies S.A.) C:\Users\XPS\Downloads\SkypeSetup.exe
2012-07-08 17:56 - 2012-07-08 17:56 - 00000000 ____D C:\Users\XPS\AppData\Roaming\LolClient
2012-07-08 17:40 - 2012-07-08 17:40 - 00001720 ____A C:\Users\Public\Desktop\Play League of Legends.lnk
2012-07-08 17:40 - 2008-07-12 07:18 - 03851784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2012-07-08 17:40 - 2008-07-12 07:18 - 01493528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2012-07-08 17:40 - 2008-07-12 07:18 - 00467984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2012-07-08 17:34 - 2012-07-08 17:34 - 00000000 ____D C:\Riot Games
2012-07-08 16:51 - 2012-07-08 17:33 - 00000000 ____D C:\Users\XPS\Desktop\League of legends
2012-07-08 16:50 - 2012-07-11 16:23 - 00000000 ____D C:\Users\XPS\AppData\Local\PMB Files
2012-07-08 16:50 - 2012-07-11 16:23 - 00000000 ____D C:\Users\All Users\PMB Files
2012-07-08 16:50 - 2012-07-08 16:50 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2012-07-08 16:48 - 2012-07-08 16:48 - 02353512 ____A C:\Users\XPS\Downloads\LeagueofLegends.exe
2012-07-04 08:15 - 2012-07-04 08:15 - 00000000 ____D C:\Users\XPS\Downloads\THAI_-_FROM_WHERE_I_BEGAN_(454LIFE)
============ 3 Months Modified Files ========================
2012-07-31 09:02 - 2012-07-31 09:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BE66D4CF17418B8
2012-07-31 09:02 - 2012-07-31 09:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kvabrxjg.sys
2012-07-31 09:01 - 2012-05-20 09:19 - 00001816 ____A C:\Windows\setupact.log
2012-07-31 09:01 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-31 09:00 - 2012-07-31 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214AB0B4EF43C99D
2012-07-31 08:55 - 2012-07-31 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C82168ED7D567B4E
2012-07-31 08:54 - 2009-07-13 21:13 - 00795812 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-31 08:48 - 2012-07-31 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8E387F9EDE0101CA
2012-07-31 08:45 - 2012-07-31 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.750FD8E45FB33FFA
2012-07-31 08:42 - 2012-07-31 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0A3142AB22760D0
2012-07-31 08:38 - 2012-07-31 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BB6970BB31AD5F4
2012-07-31 08:36 - 2012-04-11 16:43 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-31 08:36 - 2011-08-31 16:21 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000UA.job
2012-07-31 08:36 - 2011-08-23 15:01 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000UA.job
2012-07-30 15:59 - 2012-07-30 15:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF09CA2AB00A0FE
2012-07-30 15:54 - 2011-07-21 20:07 - 01907904 ____A C:\Windows\WindowsUpdate.log
2012-07-30 15:53 - 2011-07-21 20:52 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 15:53 - 2011-07-21 20:51 - 00809470 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 15:52 - 2009-07-13 20:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 15:52 - 2009-07-13 20:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 15:51 - 2012-07-30 15:50 - 12621696 ____A (Microsoft Corporation) C:\Users\XPS\Downloads\mseinstall(1).exe
2012-07-30 15:49 - 2011-07-30 21:02 - 00000963 ____A C:\Users\Public\Desktop\BitTorrent.lnk
2012-07-30 15:41 - 2012-07-30 15:37 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-30 15:40 - 2012-07-30 15:40 - 00002166 ____A C:\Windows\System32\.crusader
2012-07-30 15:36 - 2012-07-30 15:36 - 08854904 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36_x64.exe
2012-07-30 15:36 - 2012-07-30 15:35 - 07750160 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36.exe
2012-07-30 15:29 - 2012-05-22 15:53 - 00005196 ____A C:\Windows\PFRO.log
2012-07-30 15:04 - 2012-07-30 15:04 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 12:34 - 2012-07-30 12:33 - 01012656 ____A C:\Users\XPS\Downloads\iExplore.exe
2012-07-30 12:34 - 2012-05-22 17:33 - 00000361 ____A C:\rkill.log
2012-07-30 12:33 - 2012-07-30 12:33 - 00001205 ____A C:\Users\XPS\Downloads\registryfix.reg
2012-07-29 14:01 - 2011-08-31 16:21 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000Core.job
2012-07-29 13:59 - 2011-08-23 15:01 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000Core.job
2012-07-29 08:19 - 2012-07-29 08:19 - 09821896 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-29 08:18 - 2012-04-11 16:42 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-29 08:18 - 2011-07-30 20:28 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-20 20:48 - 2011-09-28 15:38 - 00002211 ____A C:\Users\Public\Desktop\Amazon Cloud Player.lnk
2012-07-20 20:47 - 2012-07-20 20:47 - 01637016 ____A C:\Users\XPS\Downloads\AmazonMP3DownloaderInstall(1).exe
2012-07-20 14:43 - 2012-07-20 14:09 - 390765945 ____A C:\Users\XPS\Downloads\glSod.mp4
2012-07-20 10:28 - 2012-07-20 10:28 - 00211037 ____A C:\Users\XPS\Documents\holdmail.xps
2012-07-18 17:01 - 2012-07-18 16:21 - 72043540 ____A C:\Users\XPS\Downloads\snmndxsyjxsp.avi.part
2012-07-12 13:45 - 2011-08-23 15:02 - 00002385 ____A C:\Users\XPS\Desktop\Google Chrome.lnk
2012-07-11 14:41 - 2012-07-11 14:41 - 08666333 ____A C:\Users\XPS\Downloads\meebo-chatlogs.zip
2012-07-09 15:21 - 2012-07-09 15:21 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-07-09 15:20 - 2012-07-09 15:20 - 00946352 ____A (Skype Technologies S.A.) C:\Users\XPS\Downloads\SkypeSetup.exe
2012-07-08 17:40 - 2012-07-08 17:40 - 00001720 ____A C:\Users\Public\Desktop\Play League of Legends.lnk
2012-07-08 16:48 - 2012-07-08 16:48 - 02353512 ____A C:\Users\XPS\Downloads\LeagueofLegends.exe
2012-07-03 12:46 - 2011-08-23 13:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 14:45 - 2012-06-26 14:45 - 08884725 ____A C:\Users\XPS\Downloads\Crossed-Over, fully furnished.Sims3Pack
2012-06-26 14:43 - 2012-06-26 14:43 - 26085955 ____A C:\Users\XPS\Downloads\Baseline-Apartment.Sims3Pack
2012-06-25 15:29 - 2012-06-25 15:29 - 02647730 ____A C:\Users\XPS\Downloads\952737.zip
2012-06-25 15:28 - 2012-06-25 15:28 - 00432837 ____A C:\Users\XPS\Downloads\CinemaSet_Projector.sims3pack
2012-06-25 15:28 - 2012-06-25 15:28 - 00089408 ____A C:\Users\XPS\Downloads\CinemaSet_screen.sims3pack
2012-06-25 15:28 - 2012-06-25 15:27 - 04938339 ____A C:\Users\XPS\Downloads\2009 Audi TT Roadster.sims3pack
2012-06-25 15:26 - 2012-06-25 15:26 - 00478011 ____A C:\Users\XPS\Downloads\Urban Dream Collection2 by Devirose.sims3pack
2012-06-25 15:04 - 2012-06-25 15:04 - 00001401 ____A C:\Users\XPS\Downloads\FrameworkSetup.zip
2012-06-17 12:02 - 2012-06-17 12:01 - 94358167 ____A C:\Users\XPS\Downloads\Pages-v1.5-uygarozdemir.ipa
2012-06-17 09:49 - 2012-06-17 09:49 - 00196452 ____A C:\Users\XPS\Documents\rewards.xps
2012-06-15 14:35 - 2012-03-27 18:55 - 00000059 ____A C:\Users\XPS\Desktop\vm.txt
2012-06-11 20:49 - 2012-06-11 20:49 - 00551810 ____A C:\Users\XPS\Documents\psychfinal1.pptx
2012-06-05 06:22 - 2012-06-05 06:20 - 01022966 ____A C:\Users\XPS\Downloads\The Bill That Made Every Student Happy.ppt (1).pptx
2012-05-22 17:34 - 2012-05-22 17:34 - 12621696 ____A (Microsoft Corporation) C:\Users\XPS\Downloads\mseinstall.exe
2012-05-22 17:32 - 2012-05-22 17:32 - 01012656 ____A C:\Users\XPS\Downloads\rkill.exe
2012-05-20 09:19 - 2012-05-20 09:19 - 00000000 ____A C:\Windows\setuperr.log
2012-05-18 20:57 - 2011-08-26 08:59 - 00000335 ____A C:\Users\XPS\Desktop\text.txt
2012-05-17 18:58 - 2012-05-17 16:48 - 04270288 ____A C:\Users\XPS\Documents\Dream Photo.pptx
2012-05-16 14:27 - 2009-07-13 20:45 - 04979672 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-16 14:07 - 2011-07-22 19:37 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-15 16:57 - 2012-05-15 16:57 - 00258931 ____A C:\Users\XPS\Documents\transcript.xps
2012-05-15 16:52 - 2012-05-08 20:29 - 00632811 ____A C:\Users\XPS\Documents\Jamba.xps
2012-05-13 14:51 - 2012-05-13 14:51 - 03542732 ____A () C:\Users\XPS\Downloads\Launcher_Setup.exe
2012-05-13 12:53 - 2012-05-13 12:53 - 00019456 ____A C:\Users\XPS\Downloads\May 2012.xls
2012-05-11 15:37 - 2012-05-11 15:37 - 00001941 ____A C:\Users\Public\Desktop\CDBurnerXP.lnk
2012-05-11 15:36 - 2012-05-11 15:35 - 05307840 ____A (Canneverbe Limited ) C:\Users\XPS\Downloads\cdbxp_setup_4.4.1.3099.exe
2012-05-04 17:09 - 2012-05-04 19:25 - 36830151 ____A C:\Users\XPS\Desktop\VID_20120504_180748.m4v
ZeroAccess:
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\@
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\L
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U\00000001.@
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U\80000000.@
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U\800000cb.@
ZeroAccess:
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\@
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\L
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 5992.44 MB
Available physical RAM: 5057.63 MB
Total Pagefile: 5990.59 MB
Available Pagefile: 5050.21 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:244.04 GB) (Free:7.47 GB) NTFS
2 Drive d: () (Fixed) (Total:465.76 GB) (Free:69.74 GB) NTFS
3 Drive f: () (Fixed) (Total:687.37 GB) (Free:612.83 GB) NTFS
5 Drive h: (KINGSTON) (Removable) (Total:7.45 GB) (Free:7.43 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 465 GB 1024 KB
Disk 2 Online 7636 MB 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 244 GB 101 MB
Partition 3 Primary 687 GB 244 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 244 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F NTFS Partition 687 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7632 MB 4032 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT32 Removable 7632 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-29 16:14
======================= End Of Log ==========================
I believe that my laptop may have contracted the malware when I downloaded a "new" update for Adobe Flash Player, but im not sure
Live security was installed on my computer and I was able to remove it after using malwarebytes in safe mode. Now when I boot up my computer microsoft security essentials says I have a system failure and I have to restart, this happens everytime I boot up even in safe mode.
This is my log
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 31-07-2012 10:32:20
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5712896 2011-07-21] (Dell Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [166936 2010-10-07] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2010-10-07] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416792 2010-10-07] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252136 2011-05-04] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [HPHUPD05] C:\Program Files (x86)\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe [49152 2003-05-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Component Manager] "C:\Program Files (x86)\HP\hpcoretech\hpcmpmgr.exe" [233472 2003-10-23] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Software Update] "C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [49152 2003-06-25] (Hewlett-Packard)
HKLM-x32\...\Run: [HPHmon05] C:\Windows\SysWOW64\hphmon05.exe [483328 2003-05-22] (Hewlett-Packard)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-10-09] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [887976 2011-08-23] (Ask)
HKLM-x32\...\Run: [RoxioNowMediaManagerApp] C:\Program Files (x86)\Roxio\RoxioNow Player\RNowShell.exe -start [2785776 2011-08-02] (Rovi Corporation)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [406992 2010-02-22] (Adobe Systems Incorporated)
HKU\XPS\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [4910912 2011-08-01] (DT Soft Ltd)
HKU\XPS\...\Run: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED [6077848 2012-07-30] (BitTorrent, Inc.)
HKU\XPS\...\Run: [Google Update] "C:\Users\XPS\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-08-23] (Google Inc.)
HKU\XPS\...\Run: [Facebook Update] "C:\Users\XPS\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\XPS\...\Run: [AdobeBridge] [x]
HKU\XPS\...\Run: [chromium] C:\Users\XPS\AppData\Local\Google\Chrome\Application\chrome.exe --no-startup-window [1250328 2012-07-09] (Google Inc.)
HKU\XPS\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17417392 2012-07-03] (Skype Technologies S.A.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) ======
2 BrcmMgmtAgent; "C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe" -service [158720 2010-06-29] (Broadcom Corporation)
2 HPSLPSVC; C:\Users\XPS\AppData\Local\Temp\7zS7B52\hpslpsvc64.dll [1039360 2011-08-22] (Hewlett-Packard Co.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RoxioNow Service; C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [400368 2011-08-02] (Rovi Corporation)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2655768 2010-10-06] (Intel Corporation)
========================== Drivers (Whitelisted) =============
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [270912 2011-08-06] (DT Soft Ltd)
3 hitmanpro36; C:\Windows\System32\Drivers\hitmanpro36.sys [30496 2012-07-30] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-31 10:32 - 2012-07-31 10:32 - 00000000 ____D C:\FRST
2012-07-31 09:02 - 2012-07-31 09:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BE66D4CF17418B8
2012-07-31 09:02 - 2012-07-31 09:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kvabrxjg.sys
2012-07-31 09:00 - 2012-07-31 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214AB0B4EF43C99D
2012-07-31 08:55 - 2012-07-31 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C82168ED7D567B4E
2012-07-31 08:48 - 2012-07-31 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8E387F9EDE0101CA
2012-07-31 08:45 - 2012-07-31 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.750FD8E45FB33FFA
2012-07-31 08:42 - 2012-07-31 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0A3142AB22760D0
2012-07-31 08:38 - 2012-07-31 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BB6970BB31AD5F4
2012-07-30 15:59 - 2012-07-30 15:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF09CA2AB00A0FE
2012-07-30 15:53 - 2012-07-30 15:53 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-30 15:53 - 2012-07-30 15:53 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-30 15:50 - 2012-07-30 15:51 - 12621696 ____A (Microsoft Corporation) C:\Users\XPS\Downloads\mseinstall(1).exe
2012-07-30 15:40 - 2012-07-30 15:40 - 00002166 ____A C:\Windows\System32\.crusader
2012-07-30 15:37 - 2012-07-30 15:41 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-30 15:36 - 2012-07-30 15:40 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-07-30 15:36 - 2012-07-30 15:36 - 08854904 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36_x64.exe
2012-07-30 15:35 - 2012-07-30 15:36 - 07750160 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36.exe
2012-07-30 15:04 - 2012-07-30 15:04 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 12:34 - 2012-07-30 12:34 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-30 12:33 - 2012-07-30 12:34 - 01012656 ____A C:\Users\XPS\Downloads\iExplore.exe
2012-07-30 12:33 - 2012-07-30 12:33 - 00001205 ____A C:\Users\XPS\Downloads\registryfix.reg
2012-07-30 12:27 - 2012-07-30 15:40 - 00000000 ____D C:\Users\All Users\7531CCA9000116D300584A13F875F002
2012-07-30 12:26 - 2012-07-30 15:27 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Exwy
2012-07-30 12:26 - 2012-07-30 14:53 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Xyhyi
2012-07-30 12:26 - 2012-07-30 12:26 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Fyicqo
2012-07-29 08:19 - 2012-07-29 08:19 - 09821896 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-20 20:48 - 2012-07-20 20:48 - 00000000 ____D C:\Users\XPS\Documents\Amazon MP3
2012-07-20 20:47 - 2012-07-20 20:47 - 01637016 ____A C:\Users\XPS\Downloads\AmazonMP3DownloaderInstall(1).exe
2012-07-20 14:09 - 2012-07-20 14:43 - 390765945 ____A C:\Users\XPS\Downloads\glSod.mp4
2012-07-20 10:28 - 2012-07-20 10:28 - 00211037 ____A C:\Users\XPS\Documents\holdmail.xps
2012-07-19 15:13 - 2012-07-19 15:13 - 00000000 ____D C:\Users\XPS\AppData\Roaming\GameTuts
2012-07-19 15:13 - 2012-07-19 15:13 - 00000000 ____D C:\Users\XPS\AppData\Local\GameTuts
2012-07-19 15:08 - 2012-07-19 15:08 - 00000000 ____D C:\Users\XPS\Downloads\NFL 2K13 - Version 1
2012-07-18 16:21 - 2012-07-18 17:01 - 72043540 ____A C:\Users\XPS\Downloads\snmndxsyjxsp.avi.part
2012-07-11 14:41 - 2012-07-11 14:41 - 08666333 ____A C:\Users\XPS\Downloads\meebo-chatlogs.zip
2012-07-09 15:21 - 2012-07-31 08:57 - 00000000 ____D C:\Users\XPS\AppData\Roaming\Skype
2012-07-09 15:21 - 2012-07-09 15:21 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-07-09 15:21 - 2012-07-09 15:21 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-07-09 15:20 - 2012-07-17 15:05 - 00000000 ____D C:\Users\All Users\Skype
2012-07-09 15:20 - 2012-07-09 15:20 - 00946352 ____A (Skype Technologies S.A.) C:\Users\XPS\Downloads\SkypeSetup.exe
2012-07-08 17:56 - 2012-07-08 17:56 - 00000000 ____D C:\Users\XPS\AppData\Roaming\LolClient
2012-07-08 17:40 - 2012-07-08 17:40 - 00001720 ____A C:\Users\Public\Desktop\Play League of Legends.lnk
2012-07-08 17:40 - 2008-07-12 07:18 - 03851784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2012-07-08 17:40 - 2008-07-12 07:18 - 01493528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2012-07-08 17:40 - 2008-07-12 07:18 - 00467984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2012-07-08 17:34 - 2012-07-08 17:34 - 00000000 ____D C:\Riot Games
2012-07-08 16:51 - 2012-07-08 17:33 - 00000000 ____D C:\Users\XPS\Desktop\League of legends
2012-07-08 16:50 - 2012-07-11 16:23 - 00000000 ____D C:\Users\XPS\AppData\Local\PMB Files
2012-07-08 16:50 - 2012-07-11 16:23 - 00000000 ____D C:\Users\All Users\PMB Files
2012-07-08 16:50 - 2012-07-08 16:50 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2012-07-08 16:48 - 2012-07-08 16:48 - 02353512 ____A C:\Users\XPS\Downloads\LeagueofLegends.exe
2012-07-04 08:15 - 2012-07-04 08:15 - 00000000 ____D C:\Users\XPS\Downloads\THAI_-_FROM_WHERE_I_BEGAN_(454LIFE)
============ 3 Months Modified Files ========================
2012-07-31 09:02 - 2012-07-31 09:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8BE66D4CF17418B8
2012-07-31 09:02 - 2012-07-31 09:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kvabrxjg.sys
2012-07-31 09:01 - 2012-05-20 09:19 - 00001816 ____A C:\Windows\setupact.log
2012-07-31 09:01 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-31 09:00 - 2012-07-31 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.214AB0B4EF43C99D
2012-07-31 08:55 - 2012-07-31 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C82168ED7D567B4E
2012-07-31 08:54 - 2009-07-13 21:13 - 00795812 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-31 08:48 - 2012-07-31 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8E387F9EDE0101CA
2012-07-31 08:45 - 2012-07-31 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.750FD8E45FB33FFA
2012-07-31 08:42 - 2012-07-31 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0A3142AB22760D0
2012-07-31 08:38 - 2012-07-31 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BB6970BB31AD5F4
2012-07-31 08:36 - 2012-04-11 16:43 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-31 08:36 - 2011-08-31 16:21 - 00000920 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000UA.job
2012-07-31 08:36 - 2011-08-23 15:01 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000UA.job
2012-07-30 15:59 - 2012-07-30 15:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF09CA2AB00A0FE
2012-07-30 15:54 - 2011-07-21 20:07 - 01907904 ____A C:\Windows\WindowsUpdate.log
2012-07-30 15:53 - 2011-07-21 20:52 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 15:53 - 2011-07-21 20:51 - 00809470 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 15:52 - 2009-07-13 20:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 15:52 - 2009-07-13 20:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 15:51 - 2012-07-30 15:50 - 12621696 ____A (Microsoft Corporation) C:\Users\XPS\Downloads\mseinstall(1).exe
2012-07-30 15:49 - 2011-07-30 21:02 - 00000963 ____A C:\Users\Public\Desktop\BitTorrent.lnk
2012-07-30 15:41 - 2012-07-30 15:37 - 00030496 ____A C:\Windows\System32\Drivers\hitmanpro36.sys
2012-07-30 15:40 - 2012-07-30 15:40 - 00002166 ____A C:\Windows\System32\.crusader
2012-07-30 15:36 - 2012-07-30 15:36 - 08854904 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36_x64.exe
2012-07-30 15:36 - 2012-07-30 15:35 - 07750160 ____A (SurfRight B.V.) C:\Users\XPS\Downloads\HitmanPro36.exe
2012-07-30 15:29 - 2012-05-22 15:53 - 00005196 ____A C:\Windows\PFRO.log
2012-07-30 15:04 - 2012-07-30 15:04 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 12:34 - 2012-07-30 12:33 - 01012656 ____A C:\Users\XPS\Downloads\iExplore.exe
2012-07-30 12:34 - 2012-05-22 17:33 - 00000361 ____A C:\rkill.log
2012-07-30 12:33 - 2012-07-30 12:33 - 00001205 ____A C:\Users\XPS\Downloads\registryfix.reg
2012-07-29 14:01 - 2011-08-31 16:21 - 00000898 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000Core.job
2012-07-29 13:59 - 2011-08-23 15:01 - 00000848 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1116915572-4048967381-267455803-1000Core.job
2012-07-29 08:19 - 2012-07-29 08:19 - 09821896 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-29 08:18 - 2012-04-11 16:42 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-29 08:18 - 2011-07-30 20:28 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-20 20:48 - 2011-09-28 15:38 - 00002211 ____A C:\Users\Public\Desktop\Amazon Cloud Player.lnk
2012-07-20 20:47 - 2012-07-20 20:47 - 01637016 ____A C:\Users\XPS\Downloads\AmazonMP3DownloaderInstall(1).exe
2012-07-20 14:43 - 2012-07-20 14:09 - 390765945 ____A C:\Users\XPS\Downloads\glSod.mp4
2012-07-20 10:28 - 2012-07-20 10:28 - 00211037 ____A C:\Users\XPS\Documents\holdmail.xps
2012-07-18 17:01 - 2012-07-18 16:21 - 72043540 ____A C:\Users\XPS\Downloads\snmndxsyjxsp.avi.part
2012-07-12 13:45 - 2011-08-23 15:02 - 00002385 ____A C:\Users\XPS\Desktop\Google Chrome.lnk
2012-07-11 14:41 - 2012-07-11 14:41 - 08666333 ____A C:\Users\XPS\Downloads\meebo-chatlogs.zip
2012-07-09 15:21 - 2012-07-09 15:21 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-07-09 15:20 - 2012-07-09 15:20 - 00946352 ____A (Skype Technologies S.A.) C:\Users\XPS\Downloads\SkypeSetup.exe
2012-07-08 17:40 - 2012-07-08 17:40 - 00001720 ____A C:\Users\Public\Desktop\Play League of Legends.lnk
2012-07-08 16:48 - 2012-07-08 16:48 - 02353512 ____A C:\Users\XPS\Downloads\LeagueofLegends.exe
2012-07-03 12:46 - 2011-08-23 13:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-26 14:45 - 2012-06-26 14:45 - 08884725 ____A C:\Users\XPS\Downloads\Crossed-Over, fully furnished.Sims3Pack
2012-06-26 14:43 - 2012-06-26 14:43 - 26085955 ____A C:\Users\XPS\Downloads\Baseline-Apartment.Sims3Pack
2012-06-25 15:29 - 2012-06-25 15:29 - 02647730 ____A C:\Users\XPS\Downloads\952737.zip
2012-06-25 15:28 - 2012-06-25 15:28 - 00432837 ____A C:\Users\XPS\Downloads\CinemaSet_Projector.sims3pack
2012-06-25 15:28 - 2012-06-25 15:28 - 00089408 ____A C:\Users\XPS\Downloads\CinemaSet_screen.sims3pack
2012-06-25 15:28 - 2012-06-25 15:27 - 04938339 ____A C:\Users\XPS\Downloads\2009 Audi TT Roadster.sims3pack
2012-06-25 15:26 - 2012-06-25 15:26 - 00478011 ____A C:\Users\XPS\Downloads\Urban Dream Collection2 by Devirose.sims3pack
2012-06-25 15:04 - 2012-06-25 15:04 - 00001401 ____A C:\Users\XPS\Downloads\FrameworkSetup.zip
2012-06-17 12:02 - 2012-06-17 12:01 - 94358167 ____A C:\Users\XPS\Downloads\Pages-v1.5-uygarozdemir.ipa
2012-06-17 09:49 - 2012-06-17 09:49 - 00196452 ____A C:\Users\XPS\Documents\rewards.xps
2012-06-15 14:35 - 2012-03-27 18:55 - 00000059 ____A C:\Users\XPS\Desktop\vm.txt
2012-06-11 20:49 - 2012-06-11 20:49 - 00551810 ____A C:\Users\XPS\Documents\psychfinal1.pptx
2012-06-05 06:22 - 2012-06-05 06:20 - 01022966 ____A C:\Users\XPS\Downloads\The Bill That Made Every Student Happy.ppt (1).pptx
2012-05-22 17:34 - 2012-05-22 17:34 - 12621696 ____A (Microsoft Corporation) C:\Users\XPS\Downloads\mseinstall.exe
2012-05-22 17:32 - 2012-05-22 17:32 - 01012656 ____A C:\Users\XPS\Downloads\rkill.exe
2012-05-20 09:19 - 2012-05-20 09:19 - 00000000 ____A C:\Windows\setuperr.log
2012-05-18 20:57 - 2011-08-26 08:59 - 00000335 ____A C:\Users\XPS\Desktop\text.txt
2012-05-17 18:58 - 2012-05-17 16:48 - 04270288 ____A C:\Users\XPS\Documents\Dream Photo.pptx
2012-05-16 14:27 - 2009-07-13 20:45 - 04979672 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-16 14:07 - 2011-07-22 19:37 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-15 16:57 - 2012-05-15 16:57 - 00258931 ____A C:\Users\XPS\Documents\transcript.xps
2012-05-15 16:52 - 2012-05-08 20:29 - 00632811 ____A C:\Users\XPS\Documents\Jamba.xps
2012-05-13 14:51 - 2012-05-13 14:51 - 03542732 ____A () C:\Users\XPS\Downloads\Launcher_Setup.exe
2012-05-13 12:53 - 2012-05-13 12:53 - 00019456 ____A C:\Users\XPS\Downloads\May 2012.xls
2012-05-11 15:37 - 2012-05-11 15:37 - 00001941 ____A C:\Users\Public\Desktop\CDBurnerXP.lnk
2012-05-11 15:36 - 2012-05-11 15:35 - 05307840 ____A (Canneverbe Limited ) C:\Users\XPS\Downloads\cdbxp_setup_4.4.1.3099.exe
2012-05-04 17:09 - 2012-05-04 19:25 - 36830151 ____A C:\Users\XPS\Desktop\VID_20120504_180748.m4v
ZeroAccess:
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\@
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\L
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U\00000001.@
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U\80000000.@
C:\Windows\Installer\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U\800000cb.@
ZeroAccess:
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\@
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\L
C:\Users\XPS\AppData\Local\{6475f421-1d12-9cbe-7bbe-25d6199403bc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 5992.44 MB
Available physical RAM: 5057.63 MB
Total Pagefile: 5990.59 MB
Available Pagefile: 5050.21 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:244.04 GB) (Free:7.47 GB) NTFS
2 Drive d: () (Fixed) (Total:465.76 GB) (Free:69.74 GB) NTFS
3 Drive f: () (Fixed) (Total:687.37 GB) (Free:612.83 GB) NTFS
5 Drive h: (KINGSTON) (Removable) (Total:7.45 GB) (Free:7.43 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 465 GB 1024 KB
Disk 2 Online 7636 MB 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 244 GB 101 MB
Partition 3 Primary 687 GB 244 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 244 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F NTFS Partition 687 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7632 MB 4032 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H KINGSTON FAT32 Removable 7632 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-29 16:14
======================= End Of Log ==========================