Hi. I'm another victim of a Sirefef trojan horse. Two computers on my home network, both running Windows Vista 32-bit, are infected. Could you please assist me in cleaning these machines? I'm assuming the cleaning process will be different for each computer and so they will need to be treated one at a time. Below are the FRST logs for the first computer. Thank you.
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 26-07-2012 11:47:56
Running from G:\FRST
Windows Vista (TM) Business (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2006-10-02] (Macrovision Corporation)
HKLM\...\Run: [] [x]
HKLM\...\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [1116920 2006-08-16] (Roxio)
HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [118784 2006-10-20] (CyberLink Corp.)
HKLM\...\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [30192 2010-07-31] (Google)
HKLM\...\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe [17920 2006-11-17] ( )
HKLM\...\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [221184 2006-10-02] (Macrovision Corporation)
HKLM\...\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [16384 2007-11-14] ( )
HKLM\...\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe [x]
HKLM\...\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [118784 2005-01-30] ()
HKLM\...\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [39792 2008-10-14] (Adobe Systems Incorporated)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13687328 2009-04-13] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2009-04-13] (NVIDIA Corporation)
HKLM\...\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe [53248 2003-08-18] (Fellowes, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] sttray.exe [x]
HKLM\...\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [73728 2011-11-03] ()
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-23] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-26] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-28] (Sun Microsystems, Inc.)
HKLM\...\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [129304 2012-07-25] (Trend Micro Inc.)
HKU\Admin\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Default\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Default User\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Kids\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Rach\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Steve\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Steve\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 61.9.226.33 61.9.194.49
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
HKLM\...\InprocServer32: [Default-wbem] \\.\globalroot\systemroot\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\n. ATTENTION! ====> ZeroAccess
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\D-Link\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check(2).lnk
ShortcutTarget: EPSON Status Monitor 3 Environment Check(2).lnk -> C:\Windows\System32\spool\drivers\w32x86\3\E_SRCV02.EXE (SEIKO EPSON CORPORATION)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\PHOTOfunSTUDIO -viewer-.lnk
ShortcutTarget: PHOTOfunSTUDIO -viewer-.lnk -> C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
================================ Services (Whitelisted) ==================
2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-17] (ArcSoft Inc.)
2 btwdins; C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe [440872 2007-08-13] (Broadcom Corporation.)
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2006-11-06] ()
2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [90112 2004-11-16] (SEIKO EPSON CORPORATION)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-18] (Microsoft Corporation)
3 GoogleDesktopManager-051210-111108; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2010-07-31] (Google)
2 gupdate1c9c245f6bd23e3; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2009-04-20] (Google Inc.)
2 SeagateDashboardService; C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [8704 2011-11-03] (Memeo)
2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-03-12] (Ulead Systems, Inc.)
2 wscsvc; "C:\Windows\system32\wscsvc.dll" [61440 2009-04-10] (Microsoft Corporation)
2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad [x]
3 MSSQL$MSSMLBIZ; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
2 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
========================== Drivers (Whitelisted) =============
3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-22] (Arcsoft, Inc.)
2 dsunidrv; \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys [7424 2006-08-16] (Gteko Ltd.)
3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [7296 2003-09-23] (GARMIN Corp.)
3 PAC7311; C:\Windows\System32\DRIVERS\PA707UCM.SYS [530304 2006-11-07] (PixArt Imaging Inc.)
3 STHDA; C:\Windows\System32\drivers\stwrt.sys [647680 2006-11-22] (SigmaTel, Inc.)
1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [81168 2012-07-25] (Trend Micro Inc.)
1 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [205072 2012-07-25] (Trend Micro Inc.)
2 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [55056 2012-07-25] (Trend Micro Inc.)
1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [68368 2012-07-25] (Trend Micro Inc.)
2 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [171280 2012-07-25] (Trend Micro Inc.)
1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [92432 2012-07-25] (Trend Micro Inc.)
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [15872 2009-04-10] (Microsoft Corporation)
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Users\Steve\AppData\Roaming\Adobe
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Users\Steve\AppData\Local\Adobe
2012-07-25 15:28 - 2012-07-25 15:23 - 00205072 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00171280 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmnciesc.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00092432 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmtdi.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00081168 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmactmon.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00068368 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmevtmgr.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00055056 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmeevw.sys
2012-07-25 15:19 - 2012-07-25 15:19 - 00000500 ____A C:\Windows\PFRO.log
2012-07-25 15:15 - 2012-07-25 15:15 - 00000000 ____D C:\Users\Steve\AppData\Roaming\Apple Computer
2012-07-25 15:15 - 2012-07-25 15:15 - 00000000 ____D C:\Users\Steve\AppData\Local\ArcSoft
2012-07-25 15:14 - 2012-07-25 15:15 - 00000000 ____D C:\Users\Steve\AppData\Roaming\ArcSoft
2012-07-25 15:14 - 2012-07-25 15:14 - 00000000 ____D C:\Users\Steve\AppData\Roaming\Seagate
2012-07-25 15:14 - 2012-07-25 15:14 - 00000000 ____D C:\Users\Steve\AppData\Roaming\EPSON
2012-07-24 16:24 - 2012-07-24 16:41 - 00000000 ____D C:\Users\Admin\AppData\Roaming\EurekaLog
2012-07-02 05:51 - 2012-07-02 05:51 - 00156168 ____A C:\Windows\Minidump\Mini070212-01.dmp
2012-07-02 05:47 - 2012-07-02 05:47 - 00000036 ____A C:\Users\Admin\AppData\Local\housecall.guid.cache
============ 3 Months Modified Files ========================
2012-07-25 18:11 - 2012-06-03 16:42 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-07-25 18:11 - 2006-11-02 05:01 - 00032544 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-25 18:11 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 18:11 - 2006-11-02 04:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:11 - 2006-11-02 04:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:06 - 2006-11-02 02:33 - 00786166 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-25 18:04 - 2006-11-02 04:52 - 00109128 ____A C:\Windows\setupact.log
2012-07-25 17:17 - 2009-06-30 20:03 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-25 15:41 - 2009-06-30 20:03 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 15:23 - 2012-07-25 15:28 - 00205072 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00171280 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmnciesc.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00092432 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmtdi.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00081168 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmactmon.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00068368 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmevtmgr.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00055056 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmeevw.sys
2012-07-25 15:19 - 2012-07-25 15:19 - 00000500 ____A C:\Windows\PFRO.log
2012-07-25 15:14 - 2007-02-23 05:36 - 00170712 ____A C:\Users\Steve\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-24 21:20 - 2009-04-20 21:54 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job
2012-07-12 14:15 - 2009-04-20 21:58 - 00001973 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-02 05:51 - 2012-07-02 05:51 - 00156168 ____A C:\Windows\Minidump\Mini070212-01.dmp
2012-07-02 05:50 - 2007-07-26 01:06 - 199205342 ____A C:\Windows\MEMORY.DMP
2012-07-02 05:47 - 2012-07-02 05:47 - 00000036 ____A C:\Users\Admin\AppData\Local\housecall.guid.cache
2012-06-30 05:50 - 2007-02-13 05:43 - 01858454 ____A C:\Windows\WindowsUpdate.log
2012-06-19 16:29 - 2008-09-05 17:02 - 00000000 ____A C:\Windows\DCEBOOT.LOG
2012-06-19 16:14 - 2008-09-05 03:08 - 00022032 ____A C:\Windows\DCEBoot.exe
2012-06-13 14:39 - 2006-11-02 04:47 - 00521656 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 14:26 - 2006-11-02 02:24 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-07 02:13 - 2012-06-07 02:13 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-06-07 02:13 - 2007-02-13 05:50 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-06-07 02:13 - 2007-02-13 05:50 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-06-07 02:13 - 2007-02-13 05:50 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-06-07 02:11 - 2012-06-07 02:11 - 00001543 ____A C:\Users\Public\Desktop\JMP Pro 10.lnk
2012-06-03 16:42 - 2012-06-03 16:39 - 00005114 ____A C:\Windows\DPINST.LOG
2012-06-02 14:19 - 2012-06-18 13:28 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 13:28 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 13:28 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 13:28 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 13:28 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 13:28 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 13:28 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-01 21:49 - 2012-06-18 13:28 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 21:42 - 2012-06-18 13:28 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-24 17:16 - 2012-05-24 03:06 - 00108048 ____A C:\Windows\RegBootClean.exe
2012-05-24 03:30 - 2007-03-07 21:55 - 00196608 ____A C:\Windows\System32\Ikeext.etl
2012-05-22 20:01 - 2007-02-24 17:56 - 00000848 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-17 15:11 - 2012-06-13 14:20 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-06-13 14:20 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-06-13 14:20 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-06-13 14:20 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-06-13 14:20 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 14:20 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-06-13 14:20 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-06-13 14:20 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 14:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:29 - 2012-06-13 14:20 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:27 - 2012-06-13 14:21 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-06-13 14:21 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 14:21 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 14:21 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-15 11:51 - 2012-06-13 00:18 - 02045440 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-01 06:03 - 2012-06-13 00:18 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
ZeroAccess:
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\@
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\L
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\n
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U\00000001.@
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U\80000000.@
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U\800000cb.@
ZeroAccess:
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}\@
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}\L
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 2045.88 MB
Available physical RAM: 1737.94 MB
Total Pagefile: 1977.55 MB
Available Pagefile: 1834.03 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.72 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:125.11 GB) (Free:22.4 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Data) (Fixed) (Total:105.67 GB) (Free:3.92 GB) NTFS
4 Drive f: (Elements) (Fixed) (Total:596.02 GB) (Free:337.6 GB) FAT32
5 Drive g: () (Removable) (Total:7.47 GB) (Free:5.31 GB) FAT32
6 Drive x: (RECOVERY) (Fixed) (Total:2 GB) (Free:1.11 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 233 GB 1024 KB
Disk 1 Online 596 GB 1528 KB
Disk 2 Online 7664 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 32 KB
Partition 2 Primary 2048 MB 48 MB
Partition 3 Primary 125 GB 2096 MB
Partition 0 Extended 106 GB 127 GB
Partition 4 Logical 106 GB 127 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 X RECOVERY NTFS Partition 2048 MB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 125 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Data NTFS Partition 106 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 F Elements FAT32 Partition 596 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7656 MB 22 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7656 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-25 15:25
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-26 11:49:37
Running from G:\FRST
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009-09-23 14:42] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-09-23 13:54] - [2008-01-18 23:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 00:35] - [2006-11-02 01:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\Windows\System32\services.exe
[2009-09-23 14:42] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
=== End Of Search ========================== End Of Log ==========================
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 26-07-2012 11:47:56
Running from G:\FRST
Windows Vista (TM) Business (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2006-10-02] (Macrovision Corporation)
HKLM\...\Run: [] [x]
HKLM\...\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [1116920 2006-08-16] (Roxio)
HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [118784 2006-10-20] (CyberLink Corp.)
HKLM\...\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [30192 2010-07-31] (Google)
HKLM\...\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe [17920 2006-11-17] ( )
HKLM\...\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [221184 2006-10-02] (Macrovision Corporation)
HKLM\...\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [16384 2007-11-14] ( )
HKLM\...\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe [x]
HKLM\...\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [118784 2005-01-30] ()
HKLM\...\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [39792 2008-10-14] (Adobe Systems Incorporated)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13687328 2009-04-13] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2009-04-13] (NVIDIA Corporation)
HKLM\...\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe [53248 2003-08-18] (Fellowes, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] sttray.exe [x]
HKLM\...\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [73728 2011-11-03] ()
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-23] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-26] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-28] (Sun Microsystems, Inc.)
HKLM\...\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [129304 2012-07-25] (Trend Micro Inc.)
HKU\Admin\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Default\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Default User\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Kids\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Rach\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Steve\...\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [446976 2006-11-11] (Gteko Ltd.)
HKU\Steve\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 61.9.226.33 61.9.194.49
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
HKLM\...\InprocServer32: [Default-wbem] \\.\globalroot\systemroot\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\n. ATTENTION! ====> ZeroAccess
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\D-Link\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check(2).lnk
ShortcutTarget: EPSON Status Monitor 3 Environment Check(2).lnk -> C:\Windows\System32\spool\drivers\w32x86\3\E_SRCV02.EXE (SEIKO EPSON CORPORATION)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\PHOTOfunSTUDIO -viewer-.lnk
ShortcutTarget: PHOTOfunSTUDIO -viewer-.lnk -> C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
================================ Services (Whitelisted) ==================
2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-17] (ArcSoft Inc.)
2 btwdins; C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe [440872 2007-08-13] (Broadcom Corporation.)
3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2006-11-06] ()
2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [90112 2004-11-16] (SEIKO EPSON CORPORATION)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-18] (Microsoft Corporation)
3 GoogleDesktopManager-051210-111108; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2010-07-31] (Google)
2 gupdate1c9c245f6bd23e3; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2009-04-20] (Google Inc.)
2 SeagateDashboardService; C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [8704 2011-11-03] (Memeo)
2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-03-12] (Ulead Systems, Inc.)
2 wscsvc; "C:\Windows\system32\wscsvc.dll" [61440 2009-04-10] (Microsoft Corporation)
2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad [x]
3 MSSQL$MSSMLBIZ; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [x]
4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x]
2 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x]
2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x]
========================== Drivers (Whitelisted) =============
3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-22] (Arcsoft, Inc.)
2 dsunidrv; \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys [7424 2006-08-16] (Gteko Ltd.)
3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [7296 2003-09-23] (GARMIN Corp.)
3 PAC7311; C:\Windows\System32\DRIVERS\PA707UCM.SYS [530304 2006-11-07] (PixArt Imaging Inc.)
3 STHDA; C:\Windows\System32\drivers\stwrt.sys [647680 2006-11-22] (SigmaTel, Inc.)
1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [81168 2012-07-25] (Trend Micro Inc.)
1 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [205072 2012-07-25] (Trend Micro Inc.)
2 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [55056 2012-07-25] (Trend Micro Inc.)
1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [68368 2012-07-25] (Trend Micro Inc.)
2 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [171280 2012-07-25] (Trend Micro Inc.)
1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [92432 2012-07-25] (Trend Micro Inc.)
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [15872 2009-04-10] (Microsoft Corporation)
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Users\Steve\AppData\Roaming\Adobe
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Users\Steve\AppData\Local\Adobe
2012-07-25 15:28 - 2012-07-25 15:23 - 00205072 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00171280 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmnciesc.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00092432 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmtdi.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00081168 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmactmon.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00068368 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmevtmgr.sys
2012-07-25 15:28 - 2012-07-25 15:23 - 00055056 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmeevw.sys
2012-07-25 15:19 - 2012-07-25 15:19 - 00000500 ____A C:\Windows\PFRO.log
2012-07-25 15:15 - 2012-07-25 15:15 - 00000000 ____D C:\Users\Steve\AppData\Roaming\Apple Computer
2012-07-25 15:15 - 2012-07-25 15:15 - 00000000 ____D C:\Users\Steve\AppData\Local\ArcSoft
2012-07-25 15:14 - 2012-07-25 15:15 - 00000000 ____D C:\Users\Steve\AppData\Roaming\ArcSoft
2012-07-25 15:14 - 2012-07-25 15:14 - 00000000 ____D C:\Users\Steve\AppData\Roaming\Seagate
2012-07-25 15:14 - 2012-07-25 15:14 - 00000000 ____D C:\Users\Steve\AppData\Roaming\EPSON
2012-07-24 16:24 - 2012-07-24 16:41 - 00000000 ____D C:\Users\Admin\AppData\Roaming\EurekaLog
2012-07-02 05:51 - 2012-07-02 05:51 - 00156168 ____A C:\Windows\Minidump\Mini070212-01.dmp
2012-07-02 05:47 - 2012-07-02 05:47 - 00000036 ____A C:\Users\Admin\AppData\Local\housecall.guid.cache
============ 3 Months Modified Files ========================
2012-07-25 18:11 - 2012-06-03 16:42 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-07-25 18:11 - 2006-11-02 05:01 - 00032544 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-25 18:11 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 18:11 - 2006-11-02 04:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:11 - 2006-11-02 04:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:06 - 2006-11-02 02:33 - 00786166 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-25 18:04 - 2006-11-02 04:52 - 00109128 ____A C:\Windows\setupact.log
2012-07-25 17:17 - 2009-06-30 20:03 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-25 15:41 - 2009-06-30 20:03 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 15:23 - 2012-07-25 15:28 - 00205072 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmcomm.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00171280 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmnciesc.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00092432 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmtdi.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00081168 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmactmon.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00068368 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmevtmgr.sys
2012-07-25 15:23 - 2012-07-25 15:28 - 00055056 ____A (Trend Micro Inc.) C:\Windows\System32\Drivers\tmeevw.sys
2012-07-25 15:19 - 2012-07-25 15:19 - 00000500 ____A C:\Windows\PFRO.log
2012-07-25 15:14 - 2007-02-23 05:36 - 00170712 ____A C:\Users\Steve\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-24 21:20 - 2009-04-20 21:54 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job
2012-07-12 14:15 - 2009-04-20 21:58 - 00001973 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-02 05:51 - 2012-07-02 05:51 - 00156168 ____A C:\Windows\Minidump\Mini070212-01.dmp
2012-07-02 05:50 - 2007-07-26 01:06 - 199205342 ____A C:\Windows\MEMORY.DMP
2012-07-02 05:47 - 2012-07-02 05:47 - 00000036 ____A C:\Users\Admin\AppData\Local\housecall.guid.cache
2012-06-30 05:50 - 2007-02-13 05:43 - 01858454 ____A C:\Windows\WindowsUpdate.log
2012-06-19 16:29 - 2008-09-05 17:02 - 00000000 ____A C:\Windows\DCEBOOT.LOG
2012-06-19 16:14 - 2008-09-05 03:08 - 00022032 ____A C:\Windows\DCEBoot.exe
2012-06-13 14:39 - 2006-11-02 04:47 - 00521656 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 14:26 - 2006-11-02 02:24 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-07 02:13 - 2012-06-07 02:13 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-06-07 02:13 - 2007-02-13 05:50 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-06-07 02:13 - 2007-02-13 05:50 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-06-07 02:13 - 2007-02-13 05:50 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2012-06-07 02:11 - 2012-06-07 02:11 - 00001543 ____A C:\Users\Public\Desktop\JMP Pro 10.lnk
2012-06-03 16:42 - 2012-06-03 16:39 - 00005114 ____A C:\Windows\DPINST.LOG
2012-06-02 14:19 - 2012-06-18 13:28 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 13:28 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 13:28 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 13:28 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 13:28 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 13:28 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 13:28 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-01 21:49 - 2012-06-18 13:28 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 21:42 - 2012-06-18 13:28 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-24 17:16 - 2012-05-24 03:06 - 00108048 ____A C:\Windows\RegBootClean.exe
2012-05-24 03:30 - 2007-03-07 21:55 - 00196608 ____A C:\Windows\System32\Ikeext.etl
2012-05-22 20:01 - 2007-02-24 17:56 - 00000848 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-17 15:11 - 2012-06-13 14:20 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-06-13 14:20 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-06-13 14:20 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-06-13 14:20 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-06-13 14:20 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 14:20 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-06-13 14:20 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-06-13 14:20 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 14:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:29 - 2012-06-13 14:20 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:27 - 2012-06-13 14:21 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-06-13 14:21 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 14:21 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 14:21 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-15 11:51 - 2012-06-13 00:18 - 02045440 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-01 06:03 - 2012-06-13 00:18 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
ZeroAccess:
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\@
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\L
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\n
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U\00000001.@
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U\80000000.@
C:\Windows\Installer\{bd9395c0-202e-6b41-e67f-7528330a338f}\U\800000cb.@
ZeroAccess:
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}\@
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}\L
C:\Users\Admin\AppData\Local\{bd9395c0-202e-6b41-e67f-7528330a338f}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 2045.88 MB
Available physical RAM: 1737.94 MB
Total Pagefile: 1977.55 MB
Available Pagefile: 1834.03 MB
Total Virtual: 2047.88 MB
Available Virtual: 1983.72 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:125.11 GB) (Free:22.4 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (Data) (Fixed) (Total:105.67 GB) (Free:3.92 GB) NTFS
4 Drive f: (Elements) (Fixed) (Total:596.02 GB) (Free:337.6 GB) FAT32
5 Drive g: () (Removable) (Total:7.47 GB) (Free:5.31 GB) FAT32
6 Drive x: (RECOVERY) (Fixed) (Total:2 GB) (Free:1.11 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 233 GB 1024 KB
Disk 1 Online 596 GB 1528 KB
Disk 2 Online 7664 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 47 MB 32 KB
Partition 2 Primary 2048 MB 48 MB
Partition 3 Primary 125 GB 2096 MB
Partition 0 Extended 106 GB 127 GB
Partition 4 Logical 106 GB 127 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 FAT Partition 47 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 X RECOVERY NTFS Partition 2048 MB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 125 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Data NTFS Partition 106 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 596 GB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 F Elements FAT32 Partition 596 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7656 MB 22 KB
==================================================================================
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7656 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-25 15:25
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-26 11:49:37
Running from G:\FRST
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2009-09-23 14:42] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-09-23 13:54] - [2008-01-18 23:33] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2006-11-02 00:35] - [2006-11-02 01:45] - 0279552 ____A (Microsoft Corporation) 329CF3C97CE4C19375C8ABCABAE258B0
C:\Windows\System32\services.exe
[2009-09-23 14:42] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
=== End Of Search ========================== End Of Log ==========================