Here are the logs...
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 10-08-2012
Ran by SYSTEM at 13-08-2012 11:59:42
Running from G:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [8120864 2009-11-24] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Kathy Kobe\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Kathy Kobe\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-04-17] (Google Inc.)
HKU\Kathy Kobe\...\Run: [{D4572255-EE12-AD7F-0E53-1D5C07133E41}] "C:\Users\Kathy Kobe\AppData\Roaming\Janita\orse.exe" [x]
Tcpip\..\Interfaces\{82FCC858-7ED9-4063-946E-E056C3CBA2B1}: [NameServer]12.127.1.3,12.127.17.72
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-13] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys [14080 2012-08-13] ()
3 catchme; \??\C:\Users\KATHYK~1\AppData\Local\Temp\catchme.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 11:59 - 2012-08-13 11:59 - 00000000 ____D C:\FRST
2012-08-13 07:18 - 2012-08-13 07:23 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-13 07:12 - 2012-08-14 07:10 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Kathy Kobe\Desktop\mbam-setup-1.62.0.1300.exe
2012-08-13 07:12 - 2012-08-13 07:12 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-13 07:12 - 2012-08-13 07:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-13 07:12 - 2012-07-03 09:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-13 07:02 - 2012-08-13 07:02 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-13 07:01 - 2012-08-14 06:59 - 01558528 ____A C:\Users\Kathy Kobe\Desktop\RogueKiller.exe
2012-08-13 07:00 - 2012-08-13 07:00 - 00000000 ____D C:\Users\Kathy Kobe\Desktop\RK_Quarantine
2012-08-13 06:59 - 2012-08-13 06:59 - 00139896 ____A C:\Windows\Minidump\081312-18080-01.dmp
2012-08-13 04:05 - 2012-08-13 04:05 - 00139896 ____A C:\Windows\Minidump\081312-15958-01.dmp
2012-08-13 03:18 - 2012-08-13 03:18 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-13 03:16 - 2012-08-13 03:16 - 10288512 ____A (Microsoft Corporation) C:\Users\Kathy Kobe\Downloads\mseinstall.exe
2012-08-13 02:55 - 2012-08-13 03:14 - 00000000 ___SD C:\32788R22FWJFW
2012-08-10 12:13 - 2012-08-10 12:13 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-10 12:07 - 2012-08-10 12:07 - 00475136 ____A C:\Users\Kathy Kobe\AppData\Local\zcumgtf.exe
2012-07-16 09:46 - 2012-05-14 19:08 - 00981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-16 09:46 - 2012-05-14 19:06 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-16 09:46 - 2012-04-27 19:19 - 00177152 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-07-16 09:46 - 2012-04-25 20:48 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-07-16 09:46 - 2012-04-25 20:48 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-07-16 09:46 - 2012-04-25 20:43 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-07-16 09:46 - 2012-04-19 21:07 - 01230336 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-16 09:46 - 2012-04-19 21:07 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 06028288 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00627200 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00606208 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00067584 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 11019776 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 02072576 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00381440 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00185856 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00044544 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-07-16 09:46 - 2012-04-19 21:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-07-16 09:46 - 2012-04-19 19:58 - 00386048 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-07-16 09:46 - 2012-04-19 19:24 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-16 09:27 - 2012-06-11 18:44 - 02344448 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
============ 3 Months Modified Files ========================
2012-08-14 07:10 - 2012-08-13 07:12 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Kathy Kobe\Desktop\mbam-setup-1.62.0.1300.exe
2012-08-14 06:59 - 2012-08-13 07:01 - 01558528 ____A C:\Users\Kathy Kobe\Desktop\RogueKiller.exe
2012-08-13 07:23 - 2012-08-13 07:18 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-13 07:22 - 2012-04-17 04:24 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-13 07:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 07:22 - 2009-07-13 20:39 - 00028613 ____A C:\Windows\setupact.log
2012-08-13 07:14 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-13 07:12 - 2012-08-13 07:12 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-13 07:02 - 2012-08-13 07:02 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-13 06:59 - 2012-08-13 06:59 - 00139896 ____A C:\Windows\Minidump\081312-18080-01.dmp
2012-08-13 06:59 - 2010-09-14 08:25 - 137761396 ____A C:\Windows\MEMORY.DMP
2012-08-13 06:42 - 2012-04-17 04:24 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-13 04:05 - 2012-08-13 04:05 - 00139896 ____A C:\Windows\Minidump\081312-15958-01.dmp
2012-08-13 03:34 - 2012-04-17 04:24 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-13 03:24 - 2009-07-13 20:34 - 00015168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-13 03:24 - 2009-07-13 20:34 - 00015168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-13 03:21 - 2010-09-08 08:47 - 00717086 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-13 03:19 - 2012-05-11 04:59 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-13 03:19 - 2010-09-08 08:36 - 01572994 ____A C:\Windows\WindowsUpdate.log
2012-08-13 03:16 - 2012-08-13 03:16 - 10288512 ____A (Microsoft Corporation) C:\Users\Kathy Kobe\Downloads\mseinstall.exe
2012-08-13 03:14 - 2011-12-15 11:32 - 00022279 ____A C:\Users\Kathy Kobe\Desktop\~ESETUninstaller.log
2012-08-10 12:07 - 2012-08-10 12:07 - 00475136 ____A C:\Users\Kathy Kobe\AppData\Local\zcumgtf.exe
2012-08-03 07:35 - 2012-04-17 04:24 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 07:35 - 2011-08-30 03:04 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-16 09:41 - 2009-07-13 20:33 - 00303096 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-03 09:46 - 2012-08-13 07:12 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 23:13 - 2010-09-08 08:48 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-22 03:59 - 2012-04-16 02:56 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-06-22 03:36 - 2010-09-09 04:34 - 00001434 ____A C:\users\Kathy
2012-06-11 18:44 - 2012-07-16 09:27 - 02344448 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:46 - 2012-07-11 02:48 - 12868608 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 21:09 - 2012-07-11 02:48 - 01389568 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:09 - 2012-07-11 02:48 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 02:56 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 02:56 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 02:56 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-19 02:56 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-19 02:56 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:51 - 2012-07-11 02:48 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:51 - 2012-07-11 02:48 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:50 - 2012-07-11 02:48 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:48 - 2012-07-11 02:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:47 - 2012-07-11 02:48 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-22 10:15 - 2012-05-22 10:15 - 00795360 ____A (Solid State Networks) C:\Users\Kathy Kobe\Downloads\install_flashplayer11x32ax_gtbp_chra_aih.exe
ZeroAccess:
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\@
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\L
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\n
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\U
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\U\80000000.@
ZeroAccess:
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\@
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\L
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 22%
Total physical RAM: 1791.37 MB
Available physical RAM: 1393.85 MB
Total Pagefile: 1791.37 MB
Available Pagefile: 1394.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:465.66 GB) (Free:437.58 GB) NTFS
2 Drive d: () (Fixed) (Total:37.3 GB) (Free:27.68 GB) FAT32
4 Drive g: (My Passport) (Fixed) (Total:232.88 GB) (Free:232.79 GB) NTFS
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 37 GB 1024 KB
Disk 2 Online 232 GB 1024 KB
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 465 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 37 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D FAT32 Partition 37 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 232 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G My Passport NTFS Partition 232 GB Healthy
==================================================================================
Last Boot: 2012-08-09 12:39
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 10-08-2012
Ran by SYSTEM at 2012-08-13 12:01:07
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-13 07:14] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
C:\Windows\ERDNT\cache\services.exe
[2011-12-15 10:36] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 10-08-2012
Ran by SYSTEM at 13-08-2012 11:59:42
Running from G:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [8120864 2009-11-24] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Kathy Kobe\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Kathy Kobe\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-04-17] (Google Inc.)
HKU\Kathy Kobe\...\Run: [{D4572255-EE12-AD7F-0E53-1D5C07133E41}] "C:\Users\Kathy Kobe\AppData\Roaming\Janita\orse.exe" [x]
Tcpip\..\Interfaces\{82FCC858-7ED9-4063-946E-E056C3CBA2B1}: [NameServer]12.127.1.3,12.127.17.72
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-07] (Skype Technologies)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-13] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys [14080 2012-08-13] ()
3 catchme; \??\C:\Users\KATHYK~1\AppData\Local\Temp\catchme.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 11:59 - 2012-08-13 11:59 - 00000000 ____D C:\FRST
2012-08-13 07:18 - 2012-08-13 07:23 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-13 07:12 - 2012-08-14 07:10 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Kathy Kobe\Desktop\mbam-setup-1.62.0.1300.exe
2012-08-13 07:12 - 2012-08-13 07:12 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-13 07:12 - 2012-08-13 07:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-13 07:12 - 2012-07-03 09:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-13 07:02 - 2012-08-13 07:02 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-13 07:01 - 2012-08-14 06:59 - 01558528 ____A C:\Users\Kathy Kobe\Desktop\RogueKiller.exe
2012-08-13 07:00 - 2012-08-13 07:00 - 00000000 ____D C:\Users\Kathy Kobe\Desktop\RK_Quarantine
2012-08-13 06:59 - 2012-08-13 06:59 - 00139896 ____A C:\Windows\Minidump\081312-18080-01.dmp
2012-08-13 04:05 - 2012-08-13 04:05 - 00139896 ____A C:\Windows\Minidump\081312-15958-01.dmp
2012-08-13 03:18 - 2012-08-13 03:18 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-13 03:16 - 2012-08-13 03:16 - 10288512 ____A (Microsoft Corporation) C:\Users\Kathy Kobe\Downloads\mseinstall.exe
2012-08-13 02:55 - 2012-08-13 03:14 - 00000000 ___SD C:\32788R22FWJFW
2012-08-10 12:13 - 2012-08-10 12:13 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-10 12:07 - 2012-08-10 12:07 - 00475136 ____A C:\Users\Kathy Kobe\AppData\Local\zcumgtf.exe
2012-07-16 09:46 - 2012-05-14 19:08 - 00981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-16 09:46 - 2012-05-14 19:06 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-16 09:46 - 2012-04-27 19:19 - 00177152 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-07-16 09:46 - 2012-04-25 20:48 - 00129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-07-16 09:46 - 2012-04-25 20:48 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-07-16 09:46 - 2012-04-25 20:43 - 00008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-07-16 09:46 - 2012-04-19 21:07 - 01230336 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-16 09:46 - 2012-04-19 21:07 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 06028288 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00627200 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00606208 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00067584 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-16 09:46 - 2012-04-19 21:06 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 11019776 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 02072576 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00381440 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00185856 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-16 09:46 - 2012-04-19 21:05 - 00044544 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-07-16 09:46 - 2012-04-19 21:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-07-16 09:46 - 2012-04-19 19:58 - 00386048 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-07-16 09:46 - 2012-04-19 19:24 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-16 09:27 - 2012-06-11 18:44 - 02344448 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
============ 3 Months Modified Files ========================
2012-08-14 07:10 - 2012-08-13 07:12 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Kathy Kobe\Desktop\mbam-setup-1.62.0.1300.exe
2012-08-14 06:59 - 2012-08-13 07:01 - 01558528 ____A C:\Users\Kathy Kobe\Desktop\RogueKiller.exe
2012-08-13 07:23 - 2012-08-13 07:18 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-13 07:22 - 2012-04-17 04:24 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-13 07:22 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 07:22 - 2009-07-13 20:39 - 00028613 ____A C:\Windows\setupact.log
2012-08-13 07:14 - 2009-07-13 15:11 - 00259072 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-13 07:12 - 2012-08-13 07:12 - 00001067 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-13 07:02 - 2012-08-13 07:02 - 00014080 ____A C:\Windows\System32\Drivers\TrueSight.sys
2012-08-13 06:59 - 2012-08-13 06:59 - 00139896 ____A C:\Windows\Minidump\081312-18080-01.dmp
2012-08-13 06:59 - 2010-09-14 08:25 - 137761396 ____A C:\Windows\MEMORY.DMP
2012-08-13 06:42 - 2012-04-17 04:24 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-13 04:05 - 2012-08-13 04:05 - 00139896 ____A C:\Windows\Minidump\081312-15958-01.dmp
2012-08-13 03:34 - 2012-04-17 04:24 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-13 03:24 - 2009-07-13 20:34 - 00015168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-13 03:24 - 2009-07-13 20:34 - 00015168 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-13 03:21 - 2010-09-08 08:47 - 00717086 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-13 03:19 - 2012-05-11 04:59 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-13 03:19 - 2010-09-08 08:36 - 01572994 ____A C:\Windows\WindowsUpdate.log
2012-08-13 03:16 - 2012-08-13 03:16 - 10288512 ____A (Microsoft Corporation) C:\Users\Kathy Kobe\Downloads\mseinstall.exe
2012-08-13 03:14 - 2011-12-15 11:32 - 00022279 ____A C:\Users\Kathy Kobe\Desktop\~ESETUninstaller.log
2012-08-10 12:07 - 2012-08-10 12:07 - 00475136 ____A C:\Users\Kathy Kobe\AppData\Local\zcumgtf.exe
2012-08-03 07:35 - 2012-04-17 04:24 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 07:35 - 2011-08-30 03:04 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-16 09:41 - 2009-07-13 20:33 - 00303096 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-03 09:46 - 2012-08-13 07:12 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 23:13 - 2010-09-08 08:48 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-22 03:59 - 2012-04-16 02:56 - 00001984 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-06-22 03:36 - 2010-09-09 04:34 - 00001434 ____A C:\users\Kathy
2012-06-11 18:44 - 2012-07-16 09:27 - 02344448 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:46 - 2012-07-11 02:48 - 12868608 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 21:09 - 2012-07-11 02:48 - 01389568 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:09 - 2012-07-11 02:48 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 02:56 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 02:56 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 02:56 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 02:56 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-19 02:56 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:12 - 2012-06-19 02:56 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 20:51 - 2012-07-11 02:48 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:51 - 2012-07-11 02:48 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:50 - 2012-07-11 02:48 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:48 - 2012-07-11 02:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:47 - 2012-07-11 02:48 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-22 10:15 - 2012-05-22 10:15 - 00795360 ____A (Solid State Networks) C:\Users\Kathy Kobe\Downloads\install_flashplayer11x32ax_gtbp_chra_aih.exe
ZeroAccess:
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\@
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\L
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\n
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\U
C:\Windows\Installer\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\U\80000000.@
ZeroAccess:
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\@
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\L
C:\Users\Kathy Kobe\AppData\Local\{8d9458ec-69f2-7e02-1c1a-6480b16c1adc}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 22%
Total physical RAM: 1791.37 MB
Available physical RAM: 1393.85 MB
Total Pagefile: 1791.37 MB
Available Pagefile: 1394.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.7 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:465.66 GB) (Free:437.58 GB) NTFS
2 Drive d: () (Fixed) (Total:37.3 GB) (Free:27.68 GB) FAT32
4 Drive g: (My Passport) (Fixed) (Total:232.88 GB) (Free:232.79 GB) NTFS
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 37 GB 1024 KB
Disk 2 Online 232 GB 1024 KB
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 465 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 37 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D FAT32 Partition 37 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 232 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G My Passport NTFS Partition 232 GB Healthy
==================================================================================
Last Boot: 2012-08-09 12:39
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 10-08-2012
Ran by SYSTEM at 2012-08-13 12:01:07
Running from G:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2012-08-13 07:14] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
C:\Windows\ERDNT\cache\services.exe
[2011-12-15 10:36] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===