First I want to say thanks for helping in advance.
I don't mean to seem ungrateful, because that is NOT the case whatsoever, but I have to ask something. I see a lot of sirefef posts, and of course lots of posts in general. Each offered help by stand up community members who I know sacrifice their time to help others, which is awesome. In every case I've read with sirefef at least, every person who assists makes the statement "this script is specifically for the original poster... (etc).". I'm no dummy to getting around the computer and have used tools in the past to help out friends/family. I'm reminded of the old proverb/saying "if you bring fish to a man he eats for a day, if you teach him how to fish, you feed him for life." I'm wondering why no one seems to be offering up what to look for in the logs, and how each (I'm assuming) non-corrupted services.exe or related infected file should be used from the winsxs folder. or better put, why there is no guide/tutorial/info on looking at the result logs and 'teaching' us, the world, what to look for, how to figure out the proper version(?), if that's the difference in the winsxs folder, etc.. Maybe I'm wrong, is there a learning area to teach us this stuff, because I'd be really interested in it!
I was also curious about why the majority of posts regarding sirefef use this tool frst as opposed to the traditionally used hijackthis which was always used in the past. Again, no offense, just trying to get a grip on what's the latest and why in the anti-mal/virus world..
So, like the rest of the folk here, I've got a PC with this nasty bug. Having no idea which file(s) to replace, I turn to the valued community here, and present my log files:
MY FRSTLOG: (Search log below that)
Search.txt for services.exe:
I don't mean to seem ungrateful, because that is NOT the case whatsoever, but I have to ask something. I see a lot of sirefef posts, and of course lots of posts in general. Each offered help by stand up community members who I know sacrifice their time to help others, which is awesome. In every case I've read with sirefef at least, every person who assists makes the statement "this script is specifically for the original poster... (etc).". I'm no dummy to getting around the computer and have used tools in the past to help out friends/family. I'm reminded of the old proverb/saying "if you bring fish to a man he eats for a day, if you teach him how to fish, you feed him for life." I'm wondering why no one seems to be offering up what to look for in the logs, and how each (I'm assuming) non-corrupted services.exe or related infected file should be used from the winsxs folder. or better put, why there is no guide/tutorial/info on looking at the result logs and 'teaching' us, the world, what to look for, how to figure out the proper version(?), if that's the difference in the winsxs folder, etc.. Maybe I'm wrong, is there a learning area to teach us this stuff, because I'd be really interested in it!
I was also curious about why the majority of posts regarding sirefef use this tool frst as opposed to the traditionally used hijackthis which was always used in the past. Again, no offense, just trying to get a grip on what's the latest and why in the anti-mal/virus world..
So, like the rest of the folk here, I've got a PC with this nasty bug. Having no idea which file(s) to replace, I turn to the valued community here, and present my log files:
MY FRSTLOG: (Search log below that)
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 20-07-2012 01
Ran by SYSTEM at 24-07-2012 10:29:15
Running from E:\
Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet003
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1721640 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [554320 2007-09-04] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" [468264 2007-12-19] (CyberLink Corp.)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13601312 2009-06-24] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2009-06-24] (NVIDIA Corporation)
HKLM\...\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN [622592 2007-02-06] (Brother Industries, Ltd.)
HKLM\...\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun [65536 2006-07-19] (Brother Industries, Ltd.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [997920 2011-06-15] (Microsoft Corporation)
HKU\Rachel\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
================================ Services (Whitelisted) ==================
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-18] (Microsoft Corporation)
2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe" [335872 2006-10-26] (Microsoft Corporation)
2 QPCapSvc; "C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe" [271760 2007-12-19] ()
2 QPSched; "C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe" [112016 2007-12-19] ()
2 RichVideo; "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" [272024 2007-01-09] ()
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [176640 2007-09-09] (Conexant Systems Inc.)
3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-11] (Hewlett-Packard Development Company, L.P.)
1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
1 MpKsl79804453; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EBB9D24C-6EA7-46BD-B93E-821A150A0501}\MpKsl79804453.sys [29904 2012-07-22] (Microsoft Corporation)
3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-04-18] (Microsoft Corporation)
3 nvsmu; C:\Windows\System32\DRIVERS\nvsmu.sys [12032 2007-02-16] (NVIDIA Corporation)
4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x]
3 catchme; \??\C:\Users\Rachel\AppData\Local\Temp\catchme.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-23 23:58 - 2012-07-24 10:14 - 00000000 ____D C:\FRST
2012-07-23 22:03 - 2012-07-23 22:03 - 00000000 ___SD C:\ComboFix
2012-07-22 23:37 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-07-22 23:37 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-07-22 23:37 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-07-22 23:37 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-07-22 23:37 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-07-22 23:37 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-07-22 23:37 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-07-22 23:37 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-07-22 23:36 - 2012-07-22 23:37 - 00000000 ____D C:\Qoobox
2012-07-22 23:36 - 2012-07-22 23:36 - 00000000 ____D C:\Windows\erdnt
2012-07-22 23:33 - 2012-07-22 23:34 - 04582474 ____R (Swearware) C:\Users\Rachel\Desktop\ComboFix.exe
2012-07-21 10:50 - 2012-07-21 19:16 - 00000000 ____D C:\Windows\Microsoft Antimalware
2012-07-17 23:48 - 2012-07-17 23:48 - 00000000 ____D C:\Users\Rachel\Desktop\7dc84bcd3da8a1dd351bf50cdd0d
2012-07-17 23:35 - 2012-07-17 23:35 - 00000000 ____D C:\Users\Rachel\Desktop\installer folder
2012-07-17 00:06 - 2012-07-17 00:06 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-16 23:33 - 2012-07-16 23:33 - 00000000 ____D C:\Users\Rachel\AppData\Local\{AB020816-CFE1-11E1-8270-B8AC6F996F26}
2012-07-16 23:05 - 2012-07-16 23:05 - 00000000 ____D C:\Users\Rachel\AppData\Roaming\SignagePlayer.86EE3EEE54D7DB049D16E358CDC443F088917621.1
2012-07-16 23:04 - 2012-07-16 23:04 - 00000852 ____A C:\Users\Public\Desktop\SignagePlayer.lnk
2012-07-16 21:52 - 2012-07-16 21:52 - 00000000 ____D C:\Users\Rachel\AppData\Roaming\SignageStudio.86EE3EEE54D7DB049D16E358CDC443F088917621.1
2012-07-16 21:51 - 2012-07-16 21:51 - 00000718 ____A C:\Users\Public\Desktop\SignageStudio.lnk
2012-07-16 21:50 - 2012-07-16 23:03 - 00000000 ____D C:\Signagestudio
2012-07-16 15:20 - 2012-07-16 15:21 - 12051521 ____A C:\Users\Rachel\Downloads\MangosWeb_3.0.3.zip
2012-07-16 14:59 - 2012-07-16 15:01 - 07872678 ____A C:\Users\Rachel\Downloads\Joomla_2.5.6-Stable-Full_Package.zip
2012-07-15 20:36 - 2012-07-15 20:36 - 00000000 ____D C:\Users\Public\CyberLink
2012-07-14 00:50 - 2012-07-14 00:50 - 00000237 ____A C:\Users\Rachel\Desktop\casino bank notes.txt
2012-07-13 22:38 - 2012-07-13 22:38 - 00002108 ____A C:\Users\Rachel\.recently-used.xbel
2012-07-13 19:13 - 2012-07-13 22:06 - 00000000 ____D C:\Users\Rachel\AppData\Roaming\Notepad++
2012-07-13 19:12 - 2012-07-13 19:13 - 00000000 ____D C:\Program Files\Notepad++
2012-07-13 19:07 - 2012-07-13 19:10 - 05811050 ____A C:\Users\Rachel\Downloads\npp.6.1.5.Installer.exe
2012-07-07 21:18 - 2012-07-07 21:18 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-05 16:36 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-05 16:36 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-05 16:36 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-05 16:36 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-05 16:36 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-05 16:36 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-05 16:36 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-05 16:36 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-05 16:36 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-05 16:36 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-05 16:36 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-05 16:36 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-05 16:36 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-05 16:36 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-05 16:33 - 2012-05-15 11:51 - 02045440 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-05 16:33 - 2012-05-01 06:03 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-07-05 16:28 - 2012-07-05 16:28 - 00000105 ____A C:\Users\Rachel\Desktop\Gambling-Addict_Poker-Hand-Cards.pdf (applicationpdf Object).URL
2012-06-24 08:40 - 2012-06-02 14:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-24 08:40 - 2012-06-02 14:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-24 08:40 - 2012-06-02 14:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-24 08:40 - 2012-06-02 14:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-24 08:39 - 2012-06-02 14:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-24 08:39 - 2012-06-02 14:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-24 08:39 - 2012-06-02 14:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-24 08:39 - 2012-06-02 14:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-24 08:39 - 2012-06-02 14:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
============ 3 Months Modified Files ========================
2012-07-23 22:00 - 2006-11-02 02:33 - 00706586 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-23 21:49 - 2012-01-29 20:08 - 00067536 ____A C:\Windows\PFRO.log
2012-07-23 00:29 - 2006-11-02 04:52 - 01910797 ____A C:\Windows\WindowsUpdate.log
2012-07-23 00:13 - 2006-11-02 02:23 - 00000215 ____A C:\Windows\system.ini
2012-07-22 23:47 - 2012-01-29 20:34 - 00000258 ____A C:\Users\Public\Documents\hpqp.ini
2012-07-22 23:46 - 2012-01-29 20:15 - 00031966 ____A C:\Users\All Users\nvModes.001
2012-07-22 23:45 - 2012-01-29 20:10 - 00031966 ____A C:\Users\All Users\nvModes.dat
2012-07-22 23:44 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-22 23:44 - 2006-11-02 04:47 - 00003664 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-22 23:44 - 2006-11-02 04:47 - 00003664 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-22 23:34 - 2012-07-22 23:33 - 04582474 ____R (Swearware) C:\Users\Rachel\Desktop\ComboFix.exe
2012-07-21 19:36 - 2012-02-07 19:29 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-19 09:01 - 2006-11-02 05:01 - 00016558 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-17 23:49 - 2012-02-01 13:58 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-17 23:00 - 2012-01-29 17:59 - 00000680 ____A C:\Users\Rachel\AppData\Local\d3d9caps.dat
2012-07-16 23:04 - 2012-07-16 23:04 - 00000852 ____A C:\Users\Public\Desktop\SignagePlayer.lnk
2012-07-16 21:51 - 2012-07-16 21:51 - 00000718 ____A C:\Users\Public\Desktop\SignageStudio.lnk
2012-07-16 15:21 - 2012-07-16 15:20 - 12051521 ____A C:\Users\Rachel\Downloads\MangosWeb_3.0.3.zip
2012-07-16 15:01 - 2012-07-16 14:59 - 07872678 ____A C:\Users\Rachel\Downloads\Joomla_2.5.6-Stable-Full_Package.zip
2012-07-15 20:37 - 2012-01-29 20:35 - 00000021 ____A C:\Users\Public\Documents\hpqp.txt
2012-07-14 14:30 - 2012-02-07 20:23 - 00000426 ____A C:\Windows\BRWMARK.INI
2012-07-14 00:50 - 2012-07-14 00:50 - 00000237 ____A C:\Users\Rachel\Desktop\casino bank notes.txt
2012-07-13 22:38 - 2012-07-13 22:38 - 00002108 ____A C:\Users\Rachel\.recently-used.xbel
2012-07-13 19:10 - 2012-07-13 19:07 - 05811050 ____A C:\Users\Rachel\Downloads\npp.6.1.5.Installer.exe
2012-07-12 05:59 - 2012-02-02 00:12 - 00010269 ____A C:\Users\Rachel\Documents\Reminders.xlsx
2012-07-09 09:14 - 2012-02-01 23:45 - 00018944 ____A C:\Users\Rachel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-07 21:18 - 2012-07-07 21:18 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-07 21:18 - 2012-02-06 18:49 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-07 21:16 - 2006-11-02 04:47 - 00385328 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-05 16:43 - 2006-11-02 02:24 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-05 16:28 - 2012-07-05 16:28 - 00000105 ____A C:\Users\Rachel\Desktop\Gambling-Addict_Poker-Hand-Cards.pdf (applicationpdf Object).URL
2012-06-25 15:05 - 2012-02-01 20:02 - 00002234 ____N C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
2012-06-21 21:18 - 2012-06-21 21:06 - 174044000 ____A C:\Users\Rachel\Downloads\PS_AIO_06_C309g-m_USW_Full_Win_enu_140_175.exe
2012-06-15 20:55 - 2012-06-03 17:32 - 00001184 ____A C:\Users\Rachel\Desktop\post office candidate number.txt
2012-06-13 18:29 - 2012-06-13 18:28 - 01519697 ____A C:\Users\Rachel\Downloads\wrar42b3.exe
2012-06-13 18:27 - 2012-06-13 18:19 - 13358556 ____A C:\Users\Rachel\Downloads\k_emulator.rar
2012-06-13 18:13 - 2012-06-13 18:14 - 00174024 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-06-13 18:13 - 2012-06-13 18:14 - 00174024 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-06-13 18:05 - 2012-06-13 18:03 - 00893936 ____A (Oracle Corporation) C:\Users\Rachel\Downloads\jxpiinstall(1).exe
2012-06-13 17:32 - 2006-11-02 04:52 - 00027911 ____A C:\Windows\setupact.log
2012-06-13 10:35 - 2012-06-13 10:35 - 00714939 ____A C:\Users\Rachel\Downloads\Supermodel_0.2a_Win32.zip
2012-06-02 14:19 - 2012-06-24 08:40 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-24 08:40 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-24 08:40 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-24 08:39 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-24 08:39 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-24 08:39 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-24 08:40 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-24 08:39 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-24 08:39 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-25 12:55 - 2012-05-25 12:54 - 07266635 ____A C:\Users\Rachel\Downloads\sqlitebrowser_200_b1_win.zip
2012-05-21 16:49 - 2012-05-21 16:48 - 00892360 ____A (Oracle Corporation) C:\Users\Rachel\Downloads\jxpiinstall.exe
2012-05-19 10:46 - 2012-05-19 10:46 - 00026624 ____A C:\Users\Rachel\Documents\Ironpigs.db
2012-05-17 15:11 - 2012-07-05 16:36 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 14:48 - 2012-07-05 16:36 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 14:45 - 2012-07-05 16:36 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 14:36 - 2012-07-05 16:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 14:35 - 2012-07-05 16:36 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 14:35 - 2012-07-05 16:36 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 14:33 - 2012-07-05 16:36 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 14:31 - 2012-07-05 16:36 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 14:29 - 2012-07-05 16:36 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 14:29 - 2012-07-05 16:36 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 14:27 - 2012-07-05 16:36 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 14:25 - 2012-07-05 16:36 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 14:24 - 2012-07-05 16:36 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 14:20 - 2012-07-05 16:36 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-15 11:51 - 2012-07-05 16:33 - 02045440 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-04 15:04 - 2012-05-04 15:04 - 00000585 ____A C:\Users\Rachel\Desktop\SoulBringers Sorrow.lnk
2012-05-02 22:27 - 2012-05-02 22:26 - 15414390 ____A (Webyog Inc.) C:\Users\Rachel\Downloads\SQLyog-9.6.3-0Community.exe
2012-05-01 07:57 - 2012-05-01 07:57 - 00013650 ____A C:\Users\Rachel\Documents\TS0102627271.xlsx
2012-05-01 07:52 - 2012-05-01 07:52 - 00033811 ____A C:\Users\Rachel\Downloads\TS010262727.xltx
2012-05-01 06:03 - 2012-07-05 16:33 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 14:59 - 2012-04-27 14:59 - 00000934 ____A C:\Users\Public\Desktop\Paint.NET.lnk
2012-04-27 14:55 - 2012-04-27 14:54 - 03730109 ____A C:\Users\Rachel\Downloads\Paint.NET.3.5.10.Install.zip
ZeroAccess:
C:\Users\Rachel\AppData\Local\{19a45f3e-7070-ea89-cb23-efe32dc81e8c}
C:\Users\Rachel\AppData\Local\{19a45f3e-7070-ea89-cb23-efe32dc81e8c}\@
C:\Users\Rachel\AppData\Local\{19a45f3e-7070-ea89-cb23-efe32dc81e8c}\L
C:\Users\Rachel\AppData\Local\{19a45f3e-7070-ea89-cb23-efe32dc81e8c}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 18%
Total physical RAM: 2942.18 MB
Available physical RAM: 2399.48 MB
Total Pagefile: 2722.84 MB
Available Pagefile: 2532.86 MB
Total Virtual: 2047.88 MB
Available Virtual: 1972.95 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.79 GB) (Free:18.48 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (FRMCFRE_EN_DVD) (CDROM) (Total:2.87 GB) (Free:0 GB) UDF
3 Drive e: () (Removable) (Total:0.96 GB) (Free:0 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 112 GB 0 B
Disk 1 Online 984 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 112 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 112 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 984 MB 0 B
==================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
==================================================================================
==========================================================
Last Boot: 2012-07-22 23:53
======================= End Of Log ==========================
Search.txt for services.exe:
Farbar Recovery Scan Tool Version: 20-07-2012 01
Thanks again for taking the time!
Like many others (does it target this a/v software??) I run the Microsoft Security Essentials.. I did try running combofix previous to this (2 days ago) but the system does that forced "in one minute" reboot crap and combofix won't run. Additionally, combofix would not run in the PE environment, which I'm not entirely sure if that's normal or not, throwing it in for good measure. Anxiously awaiting instructionsTy!
exit151