Judy Miller
Posts: 18 +0
I have read other solutions and all said clean up is specific to only that pc. AVG finds one threat in "service.exe" file but cannot remove or isolate it. My son needs this HP laptop for work and we need help ASAP. Thank you so much for any assistance you can give us. I followed the instructions to run the Farbar scan and following are the results:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-09-2012
Ran by SYSTEM at 29-09-2012 13:22:42
Running from I:\Downloads\Dave-0912
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2281256 2012-03-04] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6489704 2012-03-24] (Realtek Semiconductor)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-06-18] (Hewlett-Packard Company)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-06-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-31] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1107552 2012-07-10] ()
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [928096 2012-01-29] ()
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\d\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Default\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Guest\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] ()
Tcpip\Parameters: [DhcpNameServer] 66.102.144.5 66.102.145.5
==================== Services (Whitelisted) ===================
2 avgfws; "C:\Program Files (x86)\AVG\AVG2012\avgfws.exe" [2321560 2012-06-13] (AVG Technologies CZ, s.r.o.)
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-13] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
2 vToolbarUpdater11.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [935008 2012-07-10] ()
==================== Drivers (Whitelisted) =====================
1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [48992 2011-05-23] (AVG Technologies CZ, s.r.o.)
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-26] (AVG Technologies CZ, s.r.o.)
1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.)
2 mrtRate; C:\Windows\SysWow64\Drivers\mrtRate.sys [34916 1999-08-10] (Marimba, Inc.)
3 NWUSBModem; C:\Windows\System32\DRIVERS\nwusbmdm.sys [213376 2009-02-23] (Novatel Wireless Inc.)
3 NWUSBPort; C:\Windows\System32\DRIVERS\nwusbser.sys [213376 2009-02-23] (Novatel Wireless Inc.)
3 NWUSBPort2; C:\Windows\System32\DRIVERS\nwusbser2.sys [213376 2009-02-23] (Novatel Wireless Inc.)
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-09-28 16:52 - 2012-09-28 17:20 - 00054105 ____A C:\Users\d\Desktop\result.7z
2012-09-28 13:43 - 2012-09-28 13:43 - 00000000 ____D C:\Users\d\AppData\Roaming\U3
2012-09-22 18:54 - 2012-09-22 18:54 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2012-09-15 13:51 - 2012-09-28 16:35 - 00000000 ____D C:\Program Files (x86)\Java
2012-09-15 13:51 - 2012-09-15 13:51 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-09-15 13:51 - 2012-09-15 13:51 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-09-14 11:34 - 2012-09-14 11:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-09-11 11:32 - 2012-09-11 11:32 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-09-01 08:05 - 2012-09-01 08:06 - 01001264 ____A (Solid State Networks) C:\Users\d\Downloads\install_flashplayer11x32ax_mssd_au_aih.exe
==================== 3 Months Modified Files ==================
2012-09-29 12:03 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-29 12:03 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-29 11:56 - 2012-06-23 12:04 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-29 11:56 - 2012-01-29 12:14 - 00016672 ____A C:\Windows\setupact.log
2012-09-29 11:56 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-29 11:54 - 2012-06-23 12:04 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-29 11:54 - 2012-04-18 07:53 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-29 11:54 - 2012-03-31 15:03 - 00000334 ____A C:\Windows\Tasks\HPCeeScheduleForD-HP$.job
2012-09-28 18:08 - 2009-07-13 21:13 - 00726142 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-28 17:20 - 2012-09-28 16:52 - 00054105 ____A C:\Users\d\Desktop\result.7z
2012-09-28 15:41 - 2012-06-30 18:45 - 00000316 ____A C:\Windows\Tasks\HPCeeScheduleFord.job
2012-09-28 07:57 - 2009-07-13 21:08 - 00032642 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-22 08:23 - 2012-04-18 07:53 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-22 08:23 - 2012-01-27 12:14 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-15 17:22 - 2012-01-29 12:14 - 00174648 ____A C:\Windows\PFRO.log
2012-09-15 13:51 - 2012-09-15 13:51 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-09-15 13:51 - 2012-09-15 13:51 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-09-15 13:51 - 2010-07-10 21:29 - 00473072 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-09-11 11:46 - 2012-01-27 02:21 - 00000967 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-09-10 05:26 - 2010-12-01 00:05 - 01348275 ____A C:\Windows\WindowsUpdate.log
2012-09-05 09:20 - 2012-06-23 12:16 - 00002346 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-09-01 08:06 - 2012-09-01 08:05 - 01001264 ____A (Solid State Networks) C:\Users\d\Downloads\install_flashplayer11x32ax_mssd_au_aih.exe
2012-08-24 16:06 - 2012-08-15 14:21 - 00057627 ____A C:\alotserviceruntime.log
2012-08-24 16:06 - 2012-08-15 14:21 - 00023016 ____A C:\INSTALLHELPER.LOG
2012-08-24 14:43 - 2012-08-24 14:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys
2012-08-22 18:39 - 2009-07-13 20:45 - 00434608 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-22 04:38 - 2012-02-20 15:48 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-19 10:02 - 2012-08-19 10:02 - 00000000 ____A C:\Windows\SysWOW64\?w?xlotserviceruntime.log
2012-08-13 11:11 - 2012-08-13 11:11 - 00116472 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-13 11:08 - 2012-08-13 11:08 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2012-08-05 19:14 - 2012-08-05 19:14 - 00000692 ____A C:\Users\d\Downloads\pibiview.js
2012-07-26 02:21 - 2012-07-26 02:21 - 00291680 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgldx64.sys
2012-07-18 10:15 - 2012-08-19 15:57 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-08 11:44 - 2012-07-08 11:49 - 00143626 ____A C:\Users\d\Desktop\prescription-drug-card.jpeg
2012-07-08 11:44 - 2012-07-08 11:44 - 00143626 ____A C:\Users\d\Downloads\prescription-drug-card.jpeg
2012-07-06 19:16 - 2012-07-06 19:16 - 01272776 ____A C:\Users\d\Downloads\ArcadeCandyGames.exe
2012-07-04 14:16 - 2012-08-19 15:57 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 14:13 - 2012-08-19 15:57 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 14:13 - 2012-08-19 15:57 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 13:16 - 2012-08-19 15:57 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 13:14 - 2012-08-19 15:57 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
ZeroAccess:
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\L
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\L\00000004.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\L\201d3dde
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\00000004.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\00000008.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\000000cb.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\80000000.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\80000032.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-01 09:51:53
Restore point made on: 2012-09-15 13:50:39
Restore point made on: 2012-09-15 18:10:23
Restore point made on: 2012-09-15 18:32:35
Restore point made on: 2012-09-15 20:03:41
Restore point made on: 2012-09-15 20:05:28
Restore point made on: 2012-09-23 20:45:15
Restore point made on: 2012-09-28 08:08:15
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 3834.9 MB
Available physical RAM: 3114.25 MB
Total Pagefile: 3833.05 MB
Available Pagefile: 3110.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:280.47 GB) (Free:228.43 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:17.33 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
6 Drive I: (NEW VOLUME) (Removable) (Total:1.87 GB) (Free:1.03 GB) FAT
7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
8 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.15 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 1916 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 280 GB 200 MB
Partition 3 Primary 17 GB 280 GB
Partition 4 Primary 103 MB 297 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 Y SYSTEM NTFS Partition 199 MB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 280 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E RECOVERY NTFS Partition 17 GB Healthy
=========================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 F HP_TOOLS FAT32 Partition 103 MB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1913 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 I NEW VOLUME FAT Removable 1913 MB Healthy
=========================================================
Last Boot: 2012-09-25 03:04
==================== End Of Log =============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-09-2012
Ran by SYSTEM at 29-09-2012 13:22:42
Running from I:\Downloads\Dave-0912
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2281256 2012-03-04] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6489704 2012-03-24] (Realtek Semiconductor)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-06-18] (Hewlett-Packard Company)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-06-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2596984 2012-07-31] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1107552 2012-07-10] ()
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [928096 2012-01-29] ()
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKU\d\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Default\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Guest\...\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] ()
Tcpip\Parameters: [DhcpNameServer] 66.102.144.5 66.102.145.5
==================== Services (Whitelisted) ===================
2 avgfws; "C:\Program Files (x86)\AVG\AVG2012\avgfws.exe" [2321560 2012-06-13] (AVG Technologies CZ, s.r.o.)
2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe" [5167736 2012-08-13] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
2 vToolbarUpdater11.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [935008 2012-07-10] ()
==================== Drivers (Whitelisted) =====================
1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [48992 2011-05-23] (AVG Technologies CZ, s.r.o.)
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [291680 2012-07-26] (AVG Technologies CZ, s.r.o.)
1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [384352 2012-08-24] (AVG Technologies CZ, s.r.o.)
2 mrtRate; C:\Windows\SysWow64\Drivers\mrtRate.sys [34916 1999-08-10] (Marimba, Inc.)
3 NWUSBModem; C:\Windows\System32\DRIVERS\nwusbmdm.sys [213376 2009-02-23] (Novatel Wireless Inc.)
3 NWUSBPort; C:\Windows\System32\DRIVERS\nwusbser.sys [213376 2009-02-23] (Novatel Wireless Inc.)
3 NWUSBPort2; C:\Windows\System32\DRIVERS\nwusbser2.sys [213376 2009-02-23] (Novatel Wireless Inc.)
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2012-09-28 16:52 - 2012-09-28 17:20 - 00054105 ____A C:\Users\d\Desktop\result.7z
2012-09-28 13:43 - 2012-09-28 13:43 - 00000000 ____D C:\Users\d\AppData\Roaming\U3
2012-09-22 18:54 - 2012-09-22 18:54 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2012-09-15 13:51 - 2012-09-28 16:35 - 00000000 ____D C:\Program Files (x86)\Java
2012-09-15 13:51 - 2012-09-15 13:51 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-09-15 13:51 - 2012-09-15 13:51 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-09-14 11:34 - 2012-09-14 11:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-09-11 11:32 - 2012-09-11 11:32 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-09-01 08:05 - 2012-09-01 08:06 - 01001264 ____A (Solid State Networks) C:\Users\d\Downloads\install_flashplayer11x32ax_mssd_au_aih.exe
==================== 3 Months Modified Files ==================
2012-09-29 12:03 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-29 12:03 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-29 11:56 - 2012-06-23 12:04 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-29 11:56 - 2012-01-29 12:14 - 00016672 ____A C:\Windows\setupact.log
2012-09-29 11:56 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-29 11:54 - 2012-06-23 12:04 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-29 11:54 - 2012-04-18 07:53 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-29 11:54 - 2012-03-31 15:03 - 00000334 ____A C:\Windows\Tasks\HPCeeScheduleForD-HP$.job
2012-09-28 18:08 - 2009-07-13 21:13 - 00726142 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-28 17:20 - 2012-09-28 16:52 - 00054105 ____A C:\Users\d\Desktop\result.7z
2012-09-28 15:41 - 2012-06-30 18:45 - 00000316 ____A C:\Windows\Tasks\HPCeeScheduleFord.job
2012-09-28 07:57 - 2009-07-13 21:08 - 00032642 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-22 08:23 - 2012-04-18 07:53 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-09-22 08:23 - 2012-01-27 12:14 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-09-15 17:22 - 2012-01-29 12:14 - 00174648 ____A C:\Windows\PFRO.log
2012-09-15 13:51 - 2012-09-15 13:51 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll
2012-09-15 13:51 - 2012-09-15 13:51 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-09-15 13:51 - 2012-09-15 13:51 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-09-15 13:51 - 2010-07-10 21:29 - 00473072 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-09-11 11:46 - 2012-01-27 02:21 - 00000967 ____A C:\Users\Public\Desktop\AVG 2012.lnk
2012-09-10 05:26 - 2010-12-01 00:05 - 01348275 ____A C:\Windows\WindowsUpdate.log
2012-09-05 09:20 - 2012-06-23 12:16 - 00002346 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-09-01 08:06 - 2012-09-01 08:05 - 01001264 ____A (Solid State Networks) C:\Users\d\Downloads\install_flashplayer11x32ax_mssd_au_aih.exe
2012-08-24 16:06 - 2012-08-15 14:21 - 00057627 ____A C:\alotserviceruntime.log
2012-08-24 16:06 - 2012-08-15 14:21 - 00023016 ____A C:\INSTALLHELPER.LOG
2012-08-24 14:43 - 2012-08-24 14:43 - 00384352 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgtdia.sys
2012-08-22 18:39 - 2009-07-13 20:45 - 00434608 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-22 04:38 - 2012-02-20 15:48 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-19 10:02 - 2012-08-19 10:02 - 00000000 ____A C:\Windows\SysWOW64\?w?xlotserviceruntime.log
2012-08-13 11:11 - 2012-08-13 11:11 - 00116472 ____A C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2012-08-13 11:08 - 2012-08-13 11:08 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2012-08-05 19:14 - 2012-08-05 19:14 - 00000692 ____A C:\Users\d\Downloads\pibiview.js
2012-07-26 02:21 - 2012-07-26 02:21 - 00291680 ____A (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgldx64.sys
2012-07-18 10:15 - 2012-08-19 15:57 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-08 11:44 - 2012-07-08 11:49 - 00143626 ____A C:\Users\d\Desktop\prescription-drug-card.jpeg
2012-07-08 11:44 - 2012-07-08 11:44 - 00143626 ____A C:\Users\d\Downloads\prescription-drug-card.jpeg
2012-07-06 19:16 - 2012-07-06 19:16 - 01272776 ____A C:\Users\d\Downloads\ArcadeCandyGames.exe
2012-07-04 14:16 - 2012-08-19 15:57 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 14:13 - 2012-08-19 15:57 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 14:13 - 2012-08-19 15:57 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 13:16 - 2012-08-19 15:57 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 13:14 - 2012-08-19 15:57 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
ZeroAccess:
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\L
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\L\00000004.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\L\201d3dde
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\00000004.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\00000008.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\000000cb.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\80000000.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\80000032.@
C:\Windows\Installer\{d5fa697f-768e-713f-59b3-04c039cb0df2}\U\80000064.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-01 09:51:53
Restore point made on: 2012-09-15 13:50:39
Restore point made on: 2012-09-15 18:10:23
Restore point made on: 2012-09-15 18:32:35
Restore point made on: 2012-09-15 20:03:41
Restore point made on: 2012-09-15 20:05:28
Restore point made on: 2012-09-23 20:45:15
Restore point made on: 2012-09-28 08:08:15
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 3834.9 MB
Available physical RAM: 3114.25 MB
Total Pagefile: 3833.05 MB
Available Pagefile: 3110.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:280.47 GB) (Free:228.43 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:17.33 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
5 Drive h: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
6 Drive I: (NEW VOLUME) (Removable) (Total:1.87 GB) (Free:1.03 GB) FAT
7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
8 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.15 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 1916 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 280 GB 200 MB
Partition 3 Primary 17 GB 280 GB
Partition 4 Primary 103 MB 297 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 Y SYSTEM NTFS Partition 199 MB Healthy
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 280 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E RECOVERY NTFS Partition 17 GB Healthy
=========================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 F HP_TOOLS FAT32 Partition 103 MB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1913 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 I NEW VOLUME FAT Removable 1913 MB Healthy
=========================================================
Last Boot: 2012-09-25 03:04
==================== End Of Log =============================