Hello, MBAM and MSE identify that my PC (Vista 32) is infected by the above which, of course, they can't remove.
I've read a couple of the other posts on this topic and would be grateful if you could take me through the cleaning process.
First of all, here is my Farbar FRST file:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-08-2012 02
Ran by SYSTEM at 11-08-2012 09:17:41
Running from K:\
Windows Vista (TM) Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Default\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Default User\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Les_New\...\Policies\system: [LogonHoursAction] 2
HKU\Les_New\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
================================ Services (Whitelisted) ==================
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2006-11-07] ()
2 EPSON_PM_RPCV4_05; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE [130944 2012-02-02] (SEIKO EPSON CORPORATION)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-18] (Microsoft Corporation)
3 ExpressAccountsService; "C:\Program Files\NCH Software\ExpressAccounts\expressaccounts.exe" -service [2960900 2012-03-11] (NCH Software)
3 ExpressInvoiceService; "C:\Program Files\NCH Software\ExpressInvoice\expressinvoice.exe" -service [1987588 2012-03-11] (NCH Software)
2 gupdate1c90d02e9defad0; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2008-09-02] (Google Inc.)
2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [99936 2006-11-09] ()
2 M4-Service; C:\Users\Les_New\AppData\Roaming\Mikogo 4\M4-Service.exe [1008032 2012-06-08] ()
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 RapportMgmtService; "C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe" [931640 2011-11-01] (Trusteer Ltd.)
3 ServiceLayer; "C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe" [632832 2011-03-21] (Nokia)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-07-05] (Skype Technologies S.A.)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
3 Sony PC Companion; "C:\Program Files\Sony\Sony PC Companion\PCCService.exe" [155320 2012-01-18] (Avanquest Software)
2 STacSV; C:\Windows\system32\STacSV.exe [94208 2007-05-06] (SigmaTel, Inc.)
2 TeamViewer4; "C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe" -service [185640 2010-09-03] (TeamViewer GmbH)
2 Apache2.2; "c:\xampp\apache\bin\httpd.exe" -k runservice [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
2 mysql; c:\xampp\mysql\bin\mysqld.exe --defaults-file=c:\xampp\mysql\bin\my.ini mysql [x]
4 NetMsmqActivator; "c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [x]
4 NetPipeActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x]
4 NetTcpActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x]
4 NetTcpPortSharing; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [x]
========================== Drivers (Whitelisted) =============
3 BTUsbrXP(R); C:\Windows\System32\DRIVERS\btusbrxp.sys [93056 2003-01-21] (Askey Computer)
2 dsunidrv; \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys [7424 2006-08-17] (Gteko Ltd.)
3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2005-10-21] (HP)
3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-21] (HP)
3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2006-05-15] (HP)
3 libusb0; C:\Windows\System32\drivers\libusb0.sys [21504 2011-10-07] (http://libusb-win32.sourceforge.net)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-08] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
1 MpKsl14fb1d82; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8C72B1DA-0210-4465-B2AA-11C810408612}\MpKsl14fb1d82.sys [29904 2012-08-08] (Microsoft Corporation)
1 MpKsl8f54c53c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8C72B1DA-0210-4465-B2AA-11C810408612}\MpKsl8f54c53c.sys [29904 2012-08-08] ()
1 RapportCerberus_32301; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_32301.sys [227312 2011-11-01] ()
1 RapportEI; \??\C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [71440 2011-11-01] (Trusteer Ltd.)
3 RapportKELL; C:\Windows\System32\Drivers\RapportKELL.sys [64272 2011-11-01] (Trusteer Ltd.)
1 RapportPG; \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [164112 2011-11-01] (Trusteer Ltd.)
3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [100488 2007-04-24] (MCCI Corporation)
3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
3 Serial; C:\Windows\system32\drivers\serial.sys [63936 1998-01-05] (Brother Industries Ltd.)
3 STHDA; C:\Windows\System32\drivers\stwrt.sys [326656 2007-05-06] (SigmaTel, Inc.)
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerflt.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-11 09:17 - 2012-08-11 09:17 - 00000000 ____D C:\FRST
2012-08-08 11:56 - 2012-08-08 14:02 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-08 11:14 - 2012-08-08 11:14 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-08 11:09 - 2012-08-08 11:11 - 10288512 ____A (Microsoft Corporation) C:\Users\Les_New\Downloads\mseinstall.exe
2012-08-08 10:36 - 2012-08-08 10:38 - 00000000 ____D C:\Users\All Users\036E1912194FD0EDD9995CEE2F3B707C
2012-08-08 10:36 - 2012-08-08 10:36 - 00433664 ____A (Electronic Arts Inc.) C:\Users\Les_New\AppData\Roaming\ldxet.dll
2012-08-08 10:36 - 2012-08-08 10:36 - 00000000 ____D C:\Users\Les_New\AppData\Local\{F4A7B302-E187-11E1-8270-B8AC6F996F26}
2012-08-08 10:35 - 2012-08-08 10:35 - 00000000 ____D C:\Users\Les_New\AppData\Roaming\Ovis
2012-08-07 09:03 - 2012-08-08 11:00 - 00002660 ____A C:\Windows\PFRO.log
2012-08-04 06:04 - 2012-08-04 06:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\{9FC1C706-C763-49FE-B8A7-22D2B1B54B62}
2012-08-03 18:04 - 2012-08-03 18:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\{29BCABF9-0B12-4570-AD9D-2F0F2965AA3E}
2012-08-03 18:03 - 2012-08-04 06:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\{A6FA50C1-AF01-4A5C-9182-F20F58491991}
2012-08-03 06:03 - 2012-08-03 06:03 - 00000000 ____D C:\Users\Les_New\AppData\Local\{742FFC1C-46E5-41CC-95E3-542AC8F28867}
2012-08-03 06:03 - 2012-08-03 06:03 - 00000000 ____D C:\Users\Les_New\AppData\Local\{09D3C44B-1A8E-4473-A368-DD1527AC14B0}
2012-08-03 05:38 - 2012-03-08 09:32 - 00039272 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fssfltr.sys
2012-08-03 03:13 - 2012-08-03 03:13 - 00000000 ____D C:\Users\Les_New\AppData\Local\{22592C27-CBD1-42CC-928B-0D45EEE3818A}
2012-08-02 15:18 - 2012-08-02 15:18 - 00000000 ____D C:\Users\Les_New\AppData\Local\{C8CA92F8-0DAD-44F8-9E07-4DDDC71D4D46}
2012-08-02 12:04 - 2012-08-02 12:04 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26 (1).exe
2012-08-02 12:03 - 2012-08-02 12:04 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26.exe
2012-08-01 11:07 - 2012-08-01 11:07 - 00000000 ____D C:\Users\Les_New\AppData\Local\{8F50EFF1-658F-4BBE-A26A-F318092F8434}
2012-08-01 09:32 - 2012-08-04 06:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\Windows Live
2012-08-01 09:31 - 2012-08-01 09:32 - 00000000 ____D C:\Users\Les_New\AppData\Local\{30D5056D-FBA0-4AB2-9E68-7C5058D602CD}
2012-08-01 09:31 - 2012-08-01 09:31 - 00000000 ____D C:\Users\Les_New\AppData\Local\{C2DB3021-0D2D-4AE9-AA23-51BFBDD9F232}
2012-07-27 07:27 - 2012-07-27 07:27 - 00000000 ____D C:\Users\Les_New\AppData\Roaming\Nokia
2012-07-27 07:24 - 2012-07-27 07:24 - 00001880 ____A C:\Users\Public\Desktop\Nokia Music Player.lnk
2012-07-27 07:21 - 2008-08-26 01:26 - 00018816 ____A (Nokia) C:\Windows\System32\Drivers\pccsmcfd.sys
2012-07-20 11:09 - 2012-07-20 11:09 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-12 23:53 - 2012-07-12 23:53 - 00001026 ____A C:\Users\Les_New\Desktop\Update Service.lnk
2012-07-12 23:51 - 2012-07-12 23:51 - 00000000 ____D C:\Program Files\Sony Mobile
2012-07-12 23:45 - 2012-07-12 23:46 - 42259496 ____A C:\Users\Les_New\Downloads\Update_Service_Setup-2.12.8.23.exe
2012-07-12 07:23 - 2012-07-12 07:23 - 00001881 ____A C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2012-07-12 07:23 - 2012-07-12 07:23 - 00000000 ____D C:\Users\All Users\Sony
2012-07-12 07:23 - 2012-07-12 07:23 - 00000000 ____D C:\Program Files\Sony
2012-07-12 05:12 - 2012-07-12 05:12 - 27261120 ____A (Sony Mobile Communications ) C:\Users\Les_New\Downloads\Sony PC Companion_2.10.079_Web.exe
============ 3 Months Modified Files ========================
2012-08-08 14:27 - 2011-10-18 07:06 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-08-08 14:27 - 2006-11-02 05:01 - 00032602 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-08 14:27 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-08 14:26 - 2009-06-30 23:22 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-08 14:26 - 2006-11-02 04:47 - 00003696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-08 14:26 - 2006-11-02 04:47 - 00003696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-08 14:24 - 2009-09-29 07:56 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-08 14:03 - 2012-02-25 23:30 - 00001356 ____A C:\Users\Les_New\AppData\Local\d3d9caps.dat
2012-08-08 14:02 - 2012-08-08 11:56 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-08 11:55 - 2008-03-09 02:35 - 00000418 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{4410D2A5-866D-4E21-BE58-E2C137396A8C}.job
2012-08-08 11:55 - 2007-11-07 09:02 - 00000416 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{ED38B297-A111-4C4A-9A18-3554545F5267}.job
2012-08-08 11:49 - 2011-10-18 07:06 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-08-08 11:33 - 2009-06-30 23:22 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-08 11:15 - 2012-03-30 09:12 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-08 11:15 - 2011-10-05 00:32 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-08 11:15 - 2011-10-03 09:24 - 01537968 ____A C:\Windows\WindowsUpdate.log
2012-08-08 11:14 - 2006-11-02 02:33 - 00802910 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-08 11:11 - 2012-08-08 11:09 - 10288512 ____A (Microsoft Corporation) C:\Users\Les_New\Downloads\mseinstall.exe
2012-08-08 11:04 - 2011-07-11 13:54 - 00000930 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000UA.job
2012-08-08 11:00 - 2012-08-07 09:03 - 00002660 ____A C:\Windows\PFRO.log
2012-08-08 10:36 - 2012-08-08 10:36 - 00433664 ____A (Electronic Arts Inc.) C:\Users\Les_New\AppData\Roaming\ldxet.dll
2012-08-08 09:54 - 2009-06-30 09:32 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000UA.job
2012-08-07 20:04 - 2011-07-11 13:54 - 00000908 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000Core.job
2012-08-07 14:54 - 2009-06-30 09:32 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000Core.job
2012-08-05 12:44 - 2009-02-21 03:13 - 00057624 ____A C:\img2-001.raw
2012-08-03 03:21 - 2011-11-09 09:23 - 00077824 ____A C:\Users\Les_New\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-02 12:04 - 2012-08-02 12:04 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26 (1).exe
2012-08-02 12:04 - 2012-08-02 12:03 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26.exe
2012-08-01 23:37 - 2011-11-05 03:43 - 00001973 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-28 13:15 - 2012-03-30 09:15 - 09821896 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-07-28 13:15 - 2012-03-30 09:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-28 13:15 - 2011-10-25 10:31 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-27 07:24 - 2012-07-27 07:24 - 00001880 ____A C:\Users\Public\Desktop\Nokia Music Player.lnk
2012-07-20 12:38 - 2011-09-16 07:07 - 00000812 ____A C:\Users\Public\Desktop\Kobo.lnk
2012-07-20 11:09 - 2012-07-20 11:09 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-20 06:10 - 2012-07-06 04:49 - 00060304 ____A C:\Users\Les_New\g2mdlhlpx.exe
2012-07-12 23:53 - 2012-07-12 23:53 - 00001026 ____A C:\Users\Les_New\Desktop\Update Service.lnk
2012-07-12 23:46 - 2012-07-12 23:45 - 42259496 ____A C:\Users\Les_New\Downloads\Update_Service_Setup-2.12.8.23.exe
2012-07-12 07:23 - 2012-07-12 07:23 - 00001881 ____A C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2012-07-12 05:12 - 2012-07-12 05:12 - 27261120 ____A (Sony Mobile Communications ) C:\Users\Les_New\Downloads\Sony PC Companion_2.10.079_Web.exe
2012-07-11 18:35 - 2006-11-02 04:47 - 00570280 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 18:03 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-11 11:13 - 2012-07-11 11:13 - 00002487 ____A C:\Users\Les_New\Desktop\Apple Safari.lnk
2012-07-11 11:13 - 2012-07-11 11:13 - 00002463 ____A C:\Users\Public\Desktop\Safari.lnk
2012-07-06 05:02 - 2012-07-06 05:02 - 00002282 ____A C:\Users\Les_New\Desktop\GoToMeeting Quick Connect.lnk
2012-07-06 02:07 - 2011-11-07 02:52 - 00002583 ____A C:\Users\Les_New\Desktop\Microsoft Excel.lnk
2012-07-03 04:46 - 2011-10-04 05:39 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-25 06:13 - 2012-06-25 06:13 - 00000901 ____A C:\Users\Les_New\Desktop\Mikogo 4.lnk
2012-06-21 01:00 - 2012-06-21 01:00 - 00000957 ____A C:\Users\Public\Desktop\TeamViewer 4.lnk
2012-06-21 00:57 - 2012-06-21 00:57 - 02261392 ____A C:\Users\Les_New\Downloads\TeamViewer_Setup.exe
2012-06-13 05:40 - 2012-07-11 18:15 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 09:47 - 2012-07-10 22:48 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 08:47 - 2012-07-10 22:48 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-10 22:48 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 04:00 - 2011-11-05 06:37 - 00005292 ____A C:\Users\Les_New\Downloads\pspbrwse.jbf
2012-06-04 07:42 - 2012-06-04 07:42 - 00000907 ____A C:\Users\Les_New\AppData\Local\recently-used.xbel
2012-06-04 07:26 - 2012-07-10 22:48 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-21 02:32 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 02:32 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 02:32 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 02:31 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 02:31 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 02:32 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 02:31 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:54 - 2012-06-02 11:54 - 00000847 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-06-02 11:53 - 2012-03-23 00:05 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\System32\rmoc3260.dll
2012-06-02 11:53 - 2012-03-23 00:04 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5016.dll
2012-06-02 11:53 - 2012-03-23 00:04 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5032.dll
2012-06-02 11:53 - 2003-03-18 11:14 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\msvcp71.dll
2012-06-02 11:53 - 2003-02-20 19:42 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\msvcr71.dll
2012-06-02 06:19 - 2012-06-21 02:31 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-21 02:31 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 18:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 18:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 18:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 18:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 18:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 18:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 18:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 18:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 18:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 18:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 18:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 18:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 18:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 18:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 16:04 - 2012-07-10 22:48 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-10 22:48 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-27 00:55 - 2012-05-27 00:55 - 00000590 ____A C:\Users\Les_New\Desktop\lesharg1 - Shortcut.lnk
2012-05-26 00:37 - 2012-05-26 00:37 - 00000384 ____A C:\Users\Les_New\Desktop\xampp.lnk
2012-05-25 01:04 - 2012-05-25 01:04 - 00000560 ____A C:\Users\Les_New\Desktop\XAMPP Control Panel.lnk
2012-05-18 12:47 - 2012-05-18 12:47 - 00367360 ____A (Microsoft Corporation) C:\Windows\System32\vfprintpthelper.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00351248 ____A (Microsoft Corporation) C:\Windows\System32\vfbasics.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00306560 ____A (Microsoft Corporation) C:\Windows\System32\vfprint.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00242736 ____A (Microsoft Corporation) C:\Windows\System32\vfluapriv.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00173504 ____A (Microsoft Corporation) C:\Windows\System32\appverif.exe
2012-05-18 12:47 - 2012-05-18 12:47 - 00164168 ____A (Microsoft Corporation) C:\Windows\System32\vrfcore.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00087312 ____A (Microsoft Corporation) C:\Windows\System32\vfcompat.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00081560 ____A (Microsoft Corporation) C:\Windows\System32\vfnet.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00061352 ____A (Microsoft Corporation) C:\Windows\System32\vfnws.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00052016 ____A (Microsoft Corporation) C:\Windows\System32\vfcuzz.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00040120 ____A (Microsoft Corporation) C:\Windows\System32\vfntlmless.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00021432 ____A (Microsoft Corporation) C:\Windows\System32\cuzzapi.dll
ZeroAccess:
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\@
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\L
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\n
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U\00000001.@
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U\800000cb.@
ZeroAccess:
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\@
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\L
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\n
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 3005.88 MB
Available physical RAM: 2677.97 MB
Total Pagefile: 2908.54 MB
Available Pagefile: 2769.74 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.72 MB
======================= Partitions =========================
2 Drive c: (OS) (Fixed) (Total:138.97 GB) (Free:23.24 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
10 Drive k: (TESSA'S USB) (Removable) (Total:0.96 GB) (Free:0.95 GB) FAT
11 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:6.37 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 149 GB 1710 KB
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Disk 7 Online 980 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 32 KB
Partition 2 Primary 10 GB 40 MB
Partition 3 Primary 139 GB 10 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 10 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 C OS NTFS Partition 139 GB Healthy
==================================================================================
Partitions of Disk 7:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 979 MB 16 KB
==================================================================================
Disk: 7
Partition 1
Type : 0E
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 K TESSA'S USB FAT Removable 979 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 11:10
======================= End Of Log ==========================
Now the Search file:
Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 2012-08-11 09:19:22
Running from K:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009-09-29 07:56] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-09-24 02:28] - [2008-01-18 23:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 00:35] - [2006-11-02 01:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\Windows\System32\services.exe
[2009-09-29 07:56] - [2012-08-08 14:24] - 0279552 ____A (Microsoft Corporation) 8737764F4FD36D6808EE80578409C843
=== End Of Search ===
Many thanks in advance for your help.
Les
I've read a couple of the other posts on this topic and would be grateful if you could take me through the cleaning process.
First of all, here is my Farbar FRST file:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-08-2012 02
Ran by SYSTEM at 11-08-2012 09:17:41
Running from K:\
Windows Vista (TM) Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Default\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Default User\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Les_New\...\Policies\system: [LogonHoursAction] 2
HKU\Les_New\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
================================ Services (Whitelisted) ==================
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2006-11-07] ()
2 EPSON_PM_RPCV4_05; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE [130944 2012-02-02] (SEIKO EPSON CORPORATION)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-18] (Microsoft Corporation)
3 ExpressAccountsService; "C:\Program Files\NCH Software\ExpressAccounts\expressaccounts.exe" -service [2960900 2012-03-11] (NCH Software)
3 ExpressInvoiceService; "C:\Program Files\NCH Software\ExpressInvoice\expressinvoice.exe" -service [1987588 2012-03-11] (NCH Software)
2 gupdate1c90d02e9defad0; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2008-09-02] (Google Inc.)
2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [99936 2006-11-09] ()
2 M4-Service; C:\Users\Les_New\AppData\Roaming\Mikogo 4\M4-Service.exe [1008032 2012-06-08] ()
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 RapportMgmtService; "C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe" [931640 2011-11-01] (Trusteer Ltd.)
3 ServiceLayer; "C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe" [632832 2011-03-21] (Nokia)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-07-05] (Skype Technologies S.A.)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
3 Sony PC Companion; "C:\Program Files\Sony\Sony PC Companion\PCCService.exe" [155320 2012-01-18] (Avanquest Software)
2 STacSV; C:\Windows\system32\STacSV.exe [94208 2007-05-06] (SigmaTel, Inc.)
2 TeamViewer4; "C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe" -service [185640 2010-09-03] (TeamViewer GmbH)
2 Apache2.2; "c:\xampp\apache\bin\httpd.exe" -k runservice [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
2 mysql; c:\xampp\mysql\bin\mysqld.exe --defaults-file=c:\xampp\mysql\bin\my.ini mysql [x]
4 NetMsmqActivator; "c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [x]
4 NetPipeActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x]
4 NetTcpActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x]
4 NetTcpPortSharing; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [x]
========================== Drivers (Whitelisted) =============
3 BTUsbrXP(R); C:\Windows\System32\DRIVERS\btusbrxp.sys [93056 2003-01-21] (Askey Computer)
2 dsunidrv; \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys [7424 2006-08-17] (Gteko Ltd.)
3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2005-10-21] (HP)
3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-21] (HP)
3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2006-05-15] (HP)
3 libusb0; C:\Windows\System32\drivers\libusb0.sys [21504 2011-10-07] (http://libusb-win32.sourceforge.net)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-08] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
1 MpKsl14fb1d82; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8C72B1DA-0210-4465-B2AA-11C810408612}\MpKsl14fb1d82.sys [29904 2012-08-08] (Microsoft Corporation)
1 MpKsl8f54c53c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8C72B1DA-0210-4465-B2AA-11C810408612}\MpKsl8f54c53c.sys [29904 2012-08-08] ()
1 RapportCerberus_32301; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_32301.sys [227312 2011-11-01] ()
1 RapportEI; \??\C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [71440 2011-11-01] (Trusteer Ltd.)
3 RapportKELL; C:\Windows\System32\Drivers\RapportKELL.sys [64272 2011-11-01] (Trusteer Ltd.)
1 RapportPG; \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [164112 2011-11-01] (Trusteer Ltd.)
3 s125bus; C:\Windows\System32\DRIVERS\s125bus.sys [83336 2007-04-24] (MCCI Corporation)
3 s125mdfl; C:\Windows\System32\DRIVERS\s125mdfl.sys [15112 2007-04-24] (MCCI Corporation)
3 s125mdm; C:\Windows\System32\DRIVERS\s125mdm.sys [108680 2007-04-24] (MCCI Corporation)
3 s125mgmt; C:\Windows\System32\DRIVERS\s125mgmt.sys [100488 2007-04-24] (MCCI Corporation)
3 s125obex; C:\Windows\System32\DRIVERS\s125obex.sys [98696 2007-04-24] (MCCI Corporation)
3 Serial; C:\Windows\system32\drivers\serial.sys [63936 1998-01-05] (Brother Industries Ltd.)
3 STHDA; C:\Windows\System32\drivers\stwrt.sys [326656 2007-05-06] (SigmaTel, Inc.)
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerflt.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-11 09:17 - 2012-08-11 09:17 - 00000000 ____D C:\FRST
2012-08-08 11:56 - 2012-08-08 14:02 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-08 11:14 - 2012-08-08 11:14 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-08 11:09 - 2012-08-08 11:11 - 10288512 ____A (Microsoft Corporation) C:\Users\Les_New\Downloads\mseinstall.exe
2012-08-08 10:36 - 2012-08-08 10:38 - 00000000 ____D C:\Users\All Users\036E1912194FD0EDD9995CEE2F3B707C
2012-08-08 10:36 - 2012-08-08 10:36 - 00433664 ____A (Electronic Arts Inc.) C:\Users\Les_New\AppData\Roaming\ldxet.dll
2012-08-08 10:36 - 2012-08-08 10:36 - 00000000 ____D C:\Users\Les_New\AppData\Local\{F4A7B302-E187-11E1-8270-B8AC6F996F26}
2012-08-08 10:35 - 2012-08-08 10:35 - 00000000 ____D C:\Users\Les_New\AppData\Roaming\Ovis
2012-08-07 09:03 - 2012-08-08 11:00 - 00002660 ____A C:\Windows\PFRO.log
2012-08-04 06:04 - 2012-08-04 06:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\{9FC1C706-C763-49FE-B8A7-22D2B1B54B62}
2012-08-03 18:04 - 2012-08-03 18:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\{29BCABF9-0B12-4570-AD9D-2F0F2965AA3E}
2012-08-03 18:03 - 2012-08-04 06:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\{A6FA50C1-AF01-4A5C-9182-F20F58491991}
2012-08-03 06:03 - 2012-08-03 06:03 - 00000000 ____D C:\Users\Les_New\AppData\Local\{742FFC1C-46E5-41CC-95E3-542AC8F28867}
2012-08-03 06:03 - 2012-08-03 06:03 - 00000000 ____D C:\Users\Les_New\AppData\Local\{09D3C44B-1A8E-4473-A368-DD1527AC14B0}
2012-08-03 05:38 - 2012-03-08 09:32 - 00039272 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fssfltr.sys
2012-08-03 03:13 - 2012-08-03 03:13 - 00000000 ____D C:\Users\Les_New\AppData\Local\{22592C27-CBD1-42CC-928B-0D45EEE3818A}
2012-08-02 15:18 - 2012-08-02 15:18 - 00000000 ____D C:\Users\Les_New\AppData\Local\{C8CA92F8-0DAD-44F8-9E07-4DDDC71D4D46}
2012-08-02 12:04 - 2012-08-02 12:04 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26 (1).exe
2012-08-02 12:03 - 2012-08-02 12:04 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26.exe
2012-08-01 11:07 - 2012-08-01 11:07 - 00000000 ____D C:\Users\Les_New\AppData\Local\{8F50EFF1-658F-4BBE-A26A-F318092F8434}
2012-08-01 09:32 - 2012-08-04 06:04 - 00000000 ____D C:\Users\Les_New\AppData\Local\Windows Live
2012-08-01 09:31 - 2012-08-01 09:32 - 00000000 ____D C:\Users\Les_New\AppData\Local\{30D5056D-FBA0-4AB2-9E68-7C5058D602CD}
2012-08-01 09:31 - 2012-08-01 09:31 - 00000000 ____D C:\Users\Les_New\AppData\Local\{C2DB3021-0D2D-4AE9-AA23-51BFBDD9F232}
2012-07-27 07:27 - 2012-07-27 07:27 - 00000000 ____D C:\Users\Les_New\AppData\Roaming\Nokia
2012-07-27 07:24 - 2012-07-27 07:24 - 00001880 ____A C:\Users\Public\Desktop\Nokia Music Player.lnk
2012-07-27 07:21 - 2008-08-26 01:26 - 00018816 ____A (Nokia) C:\Windows\System32\Drivers\pccsmcfd.sys
2012-07-20 11:09 - 2012-07-20 11:09 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-12 23:53 - 2012-07-12 23:53 - 00001026 ____A C:\Users\Les_New\Desktop\Update Service.lnk
2012-07-12 23:51 - 2012-07-12 23:51 - 00000000 ____D C:\Program Files\Sony Mobile
2012-07-12 23:45 - 2012-07-12 23:46 - 42259496 ____A C:\Users\Les_New\Downloads\Update_Service_Setup-2.12.8.23.exe
2012-07-12 07:23 - 2012-07-12 07:23 - 00001881 ____A C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2012-07-12 07:23 - 2012-07-12 07:23 - 00000000 ____D C:\Users\All Users\Sony
2012-07-12 07:23 - 2012-07-12 07:23 - 00000000 ____D C:\Program Files\Sony
2012-07-12 05:12 - 2012-07-12 05:12 - 27261120 ____A (Sony Mobile Communications ) C:\Users\Les_New\Downloads\Sony PC Companion_2.10.079_Web.exe
============ 3 Months Modified Files ========================
2012-08-08 14:27 - 2011-10-18 07:06 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-08-08 14:27 - 2006-11-02 05:01 - 00032602 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-08 14:27 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-08 14:26 - 2009-06-30 23:22 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-08 14:26 - 2006-11-02 04:47 - 00003696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-08 14:26 - 2006-11-02 04:47 - 00003696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-08 14:24 - 2009-09-29 07:56 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-08 14:03 - 2012-02-25 23:30 - 00001356 ____A C:\Users\Les_New\AppData\Local\d3d9caps.dat
2012-08-08 14:02 - 2012-08-08 11:56 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-08 11:55 - 2008-03-09 02:35 - 00000418 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{4410D2A5-866D-4E21-BE58-E2C137396A8C}.job
2012-08-08 11:55 - 2007-11-07 09:02 - 00000416 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{ED38B297-A111-4C4A-9A18-3554545F5267}.job
2012-08-08 11:49 - 2011-10-18 07:06 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-08-08 11:33 - 2009-06-30 23:22 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-08 11:15 - 2012-03-30 09:12 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-08 11:15 - 2011-10-05 00:32 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-08 11:15 - 2011-10-03 09:24 - 01537968 ____A C:\Windows\WindowsUpdate.log
2012-08-08 11:14 - 2006-11-02 02:33 - 00802910 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-08 11:11 - 2012-08-08 11:09 - 10288512 ____A (Microsoft Corporation) C:\Users\Les_New\Downloads\mseinstall.exe
2012-08-08 11:04 - 2011-07-11 13:54 - 00000930 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000UA.job
2012-08-08 11:00 - 2012-08-07 09:03 - 00002660 ____A C:\Windows\PFRO.log
2012-08-08 10:36 - 2012-08-08 10:36 - 00433664 ____A (Electronic Arts Inc.) C:\Users\Les_New\AppData\Roaming\ldxet.dll
2012-08-08 09:54 - 2009-06-30 09:32 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000UA.job
2012-08-07 20:04 - 2011-07-11 13:54 - 00000908 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000Core.job
2012-08-07 14:54 - 2009-06-30 09:32 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2155982950-3057843811-3124903850-1000Core.job
2012-08-05 12:44 - 2009-02-21 03:13 - 00057624 ____A C:\img2-001.raw
2012-08-03 03:21 - 2011-11-09 09:23 - 00077824 ____A C:\Users\Les_New\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-02 12:04 - 2012-08-02 12:04 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26 (1).exe
2012-08-02 12:04 - 2012-08-02 12:03 - 32600440 ____A C:\Users\Les_New\Downloads\GraboidVideoSetup-3.26.exe
2012-08-01 23:37 - 2011-11-05 03:43 - 00001973 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-28 13:15 - 2012-03-30 09:15 - 09821896 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-07-28 13:15 - 2012-03-30 09:12 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-28 13:15 - 2011-10-25 10:31 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-27 07:24 - 2012-07-27 07:24 - 00001880 ____A C:\Users\Public\Desktop\Nokia Music Player.lnk
2012-07-20 12:38 - 2011-09-16 07:07 - 00000812 ____A C:\Users\Public\Desktop\Kobo.lnk
2012-07-20 11:09 - 2012-07-20 11:09 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-20 06:10 - 2012-07-06 04:49 - 00060304 ____A C:\Users\Les_New\g2mdlhlpx.exe
2012-07-12 23:53 - 2012-07-12 23:53 - 00001026 ____A C:\Users\Les_New\Desktop\Update Service.lnk
2012-07-12 23:46 - 2012-07-12 23:45 - 42259496 ____A C:\Users\Les_New\Downloads\Update_Service_Setup-2.12.8.23.exe
2012-07-12 07:23 - 2012-07-12 07:23 - 00001881 ____A C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2012-07-12 05:12 - 2012-07-12 05:12 - 27261120 ____A (Sony Mobile Communications ) C:\Users\Les_New\Downloads\Sony PC Companion_2.10.079_Web.exe
2012-07-11 18:35 - 2006-11-02 04:47 - 00570280 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 18:03 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-11 11:13 - 2012-07-11 11:13 - 00002487 ____A C:\Users\Les_New\Desktop\Apple Safari.lnk
2012-07-11 11:13 - 2012-07-11 11:13 - 00002463 ____A C:\Users\Public\Desktop\Safari.lnk
2012-07-06 05:02 - 2012-07-06 05:02 - 00002282 ____A C:\Users\Les_New\Desktop\GoToMeeting Quick Connect.lnk
2012-07-06 02:07 - 2011-11-07 02:52 - 00002583 ____A C:\Users\Les_New\Desktop\Microsoft Excel.lnk
2012-07-03 04:46 - 2011-10-04 05:39 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-25 06:13 - 2012-06-25 06:13 - 00000901 ____A C:\Users\Les_New\Desktop\Mikogo 4.lnk
2012-06-21 01:00 - 2012-06-21 01:00 - 00000957 ____A C:\Users\Public\Desktop\TeamViewer 4.lnk
2012-06-21 00:57 - 2012-06-21 00:57 - 02261392 ____A C:\Users\Les_New\Downloads\TeamViewer_Setup.exe
2012-06-13 05:40 - 2012-07-11 18:15 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 09:47 - 2012-07-10 22:48 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 08:47 - 2012-07-10 22:48 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-10 22:48 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 04:00 - 2011-11-05 06:37 - 00005292 ____A C:\Users\Les_New\Downloads\pspbrwse.jbf
2012-06-04 07:42 - 2012-06-04 07:42 - 00000907 ____A C:\Users\Les_New\AppData\Local\recently-used.xbel
2012-06-04 07:26 - 2012-07-10 22:48 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-21 02:32 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 02:32 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 02:32 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 02:31 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 02:31 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 02:32 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 02:31 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:54 - 2012-06-02 11:54 - 00000847 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-06-02 11:53 - 2012-03-23 00:05 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\System32\rmoc3260.dll
2012-06-02 11:53 - 2012-03-23 00:04 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5016.dll
2012-06-02 11:53 - 2012-03-23 00:04 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\System32\pndx5032.dll
2012-06-02 11:53 - 2003-03-18 11:14 - 00499712 ____A (Microsoft Corporation) C:\Windows\System32\msvcp71.dll
2012-06-02 11:53 - 2003-02-20 19:42 - 00348160 ____A (Microsoft Corporation) C:\Windows\System32\msvcr71.dll
2012-06-02 06:19 - 2012-06-21 02:31 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-21 02:31 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 18:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 18:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 18:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 18:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 18:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 18:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 18:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 18:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 18:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 18:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 18:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 18:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 18:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 18:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 16:04 - 2012-07-10 22:48 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-10 22:48 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-27 00:55 - 2012-05-27 00:55 - 00000590 ____A C:\Users\Les_New\Desktop\lesharg1 - Shortcut.lnk
2012-05-26 00:37 - 2012-05-26 00:37 - 00000384 ____A C:\Users\Les_New\Desktop\xampp.lnk
2012-05-25 01:04 - 2012-05-25 01:04 - 00000560 ____A C:\Users\Les_New\Desktop\XAMPP Control Panel.lnk
2012-05-18 12:47 - 2012-05-18 12:47 - 00367360 ____A (Microsoft Corporation) C:\Windows\System32\vfprintpthelper.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00351248 ____A (Microsoft Corporation) C:\Windows\System32\vfbasics.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00306560 ____A (Microsoft Corporation) C:\Windows\System32\vfprint.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00242736 ____A (Microsoft Corporation) C:\Windows\System32\vfluapriv.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00173504 ____A (Microsoft Corporation) C:\Windows\System32\appverif.exe
2012-05-18 12:47 - 2012-05-18 12:47 - 00164168 ____A (Microsoft Corporation) C:\Windows\System32\vrfcore.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00087312 ____A (Microsoft Corporation) C:\Windows\System32\vfcompat.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00081560 ____A (Microsoft Corporation) C:\Windows\System32\vfnet.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00061352 ____A (Microsoft Corporation) C:\Windows\System32\vfnws.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00052016 ____A (Microsoft Corporation) C:\Windows\System32\vfcuzz.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00040120 ____A (Microsoft Corporation) C:\Windows\System32\vfntlmless.dll
2012-05-18 12:47 - 2012-05-18 12:47 - 00021432 ____A (Microsoft Corporation) C:\Windows\System32\cuzzapi.dll
ZeroAccess:
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\@
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\L
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\n
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U\00000001.@
C:\Windows\Installer\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U\800000cb.@
ZeroAccess:
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\@
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\L
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\n
C:\Users\Les_New\AppData\Local\{c6c20914-49ac-17aa-db84-306d9719f7f3}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 3005.88 MB
Available physical RAM: 2677.97 MB
Total Pagefile: 2908.54 MB
Available Pagefile: 2769.74 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.72 MB
======================= Partitions =========================
2 Drive c: (OS) (Fixed) (Total:138.97 GB) (Free:23.24 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
10 Drive k: (TESSA'S USB) (Removable) (Total:0.96 GB) (Free:0.95 GB) FAT
11 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:6.37 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 149 GB 1710 KB
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Disk 7 Online 980 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 32 KB
Partition 2 Primary 10 GB 40 MB
Partition 3 Primary 139 GB 10 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 10 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 C OS NTFS Partition 139 GB Healthy
==================================================================================
Partitions of Disk 7:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 979 MB 16 KB
==================================================================================
Disk: 7
Partition 1
Type : 0E
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 K TESSA'S USB FAT Removable 979 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 11:10
======================= End Of Log ==========================
Now the Search file:
Farbar Recovery Scan Tool Version: 08-08-2012 02
Ran by SYSTEM at 2012-08-11 09:19:22
Running from K:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009-09-29 07:56] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-09-24 02:28] - [2008-01-18 23:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 00:35] - [2006-11-02 01:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\Windows\System32\services.exe
[2009-09-29 07:56] - [2012-08-08 14:24] - 0279552 ____A (Microsoft Corporation) 8737764F4FD36D6808EE80578409C843
=== End Of Search ===
Many thanks in advance for your help.
Les