Hello! Thanks in advance for everything you guys are doing. I have a standard Sirefef infection, first sign was limited access to Windows Firewall and inability to change Windows Update settings. Now it just won't stay on for more than a minute after logging in, even in safe mode.
So far I've run scans with MSE and Malwarebytes. MSE ID'd the virus and tried to remove, but wasn't fast enough. I haven't touched the registry, and I haven't tried deleting individual files.
FRST scan results are below:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 10-08-2012
Ran by SYSTEM at 10-08-2012 13:45:39
Running from G:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" [264040 2009-09-28] (Microsoft Corporation)
HKLM\...\Run: [WindowsLiveDeviceIntegrator] C:\Program Files\Windows Live\Device Integrator\wldi.exe [245544 2010-09-24] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [PrintDisp] C:\Windows\system32\PrintDisp.exe [871936 2009-04-07] (ActMask Co.,Ltd)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Jim\...\Run: [Retriever] C:\Program Files\Redtail Technology\Retriever for the Desktop\Retriever.exe [2045440 2011-04-29] (Redtail Technology)
HKU\Jim\...\Run: [WebEx] RUNDLL32.EXE C:\Users\Jim\AppData\Local\WebEx\xtefdfkf.dll,DllGetClassObject [746496 2012-08-10] ()
HKU\Jim\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-10-19] (Google Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.10.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Windows Home Server.lnk
ShortcutTarget: Windows Home Server.lnk -> C:\Windows\Installer\{21E49794-7C13-4E84-8659-55BD378267D5}\WHSTrayApp.exe (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
2 arXfrSvc; "C:\Program Files\Windows Home Server\Microsoft.HomeServer.Archive.TransferService.exe" [239472 2011-01-10] (Microsoft Corporation)
2 esClient; "C:\Program Files\Windows Home Server\esClient.exe" [97136 2011-01-10] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 M4-Service; C:\Users\Jim\AppData\Local\Mikogo4\Viewer\Service\M4-Service.exe [1008032 2012-07-16] ()
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2011-08-12] ()
2 Printer Control; C:\Windows\system32\PrintCtrl.exe [73728 2008-10-11] ()
2 WHSConnector; "C:\Program Files\Windows Home Server\WHSConnector.exe" [376688 2011-01-10] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
0 amacpi; C:\Windows\System32\DRIVERS\null.sys [4608 2009-07-13] (Microsoft Corporation)
3 htcnprot; C:\Windows\System32\DRIVERS\htcnprot.sys [23040 2010-06-23] (Windows (R) Win 7 DDK provider)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-10] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 usbaudio; C:\Windows\System32\drivers\usbaudio.sys [80768 2010-11-20] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-10 13:45 - 2012-08-10 13:45 - 00000000 ____D C:\FRST
2012-08-10 12:17 - 2012-08-10 12:17 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-10 12:01 - 2012-08-10 12:02 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (3).exe
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (2).exe
2012-08-09 10:53 - 2012-08-09 11:28 - 00000000 ____D C:\Users\Jim\Desktop\S&A Update
2012-08-09 10:38 - 2012-08-09 11:28 - 00000000 ____D C:\Users\Jim\Desktop\S&A!
2012-08-09 10:37 - 2012-08-09 10:54 - 00000000 ____D C:\Users\Jim\Desktop\S&A
2012-07-27 14:29 - 2012-08-10 12:28 - 00000000 ____D C:\Users\Jim\AppData\Local\WebEx
2012-07-25 06:44 - 2012-07-25 06:44 - 09601577 ____A C:\Users\Jim\Desktop\Sully Seminar Story.mp4
2012-07-24 06:34 - 2012-07-24 06:34 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-23 08:51 - 2012-07-23 08:54 - 00000000 ____D C:\Users\Jim\Desktop\Photo
2012-07-23 07:30 - 2012-08-09 17:00 - 00000440 ____A C:\Windows\Tasks\ParetoLogic Registration3.job
2012-07-23 07:29 - 2012-08-10 12:27 - 00000466 ____A C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2012-07-20 12:30 - 2012-07-20 12:30 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2012-07-16 12:42 - 2012-07-16 12:42 - 00000000 ____D C:\Program Files\LSI SoftModem
2012-07-16 12:41 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-07-16 12:33 - 2012-07-16 12:33 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (1).exe
2012-07-16 12:32 - 2012-07-16 12:32 - 12621696 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall.exe
2012-07-16 12:19 - 2012-07-16 12:19 - 00000000 ____D C:\Users\Jim\AppData\Roaming\Malwarebytes
2012-07-16 12:19 - 2012-07-16 12:19 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-16 12:19 - 2012-07-16 12:19 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-07-16 12:19 - 2012-07-03 12:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-16 12:18 - 2012-07-16 12:19 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Jim\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-16 09:21 - 2012-07-16 09:21 - 00000130 ____A C:\Users\Jim\Desktop\Mikogo.url
2012-07-16 09:03 - 2012-07-16 09:03 - 00000000 ____D C:\Users\Jim\Documents\Mikogo4
2012-07-16 09:03 - 2012-07-16 09:03 - 00000000 ____D C:\Users\Jim\AppData\Local\Mikogo4
2012-07-11 05:18 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 05:18 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 05:18 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 05:18 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 05:18 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 05:18 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 05:18 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 05:18 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 05:18 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 05:18 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 05:18 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 05:18 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 05:18 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 05:18 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 03:24 - 2012-07-11 03:24 - 00258422 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-11 03:24 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
============ 3 Months Modified Files ========================
2012-08-10 12:39 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-10 12:39 - 2009-07-13 20:39 - 00053167 ____A C:\Windows\setupact.log
2012-08-10 12:27 - 2012-07-23 07:29 - 00000466 ____A C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2012-08-10 12:27 - 2011-10-19 09:46 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-10 12:17 - 2012-08-10 12:17 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-10 12:06 - 2009-07-13 20:34 - 00016416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-10 12:06 - 2009-07-13 20:34 - 00016416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-10 12:05 - 2011-10-31 14:07 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (3).exe
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (2).exe
2012-08-10 12:01 - 2011-10-19 08:05 - 00795754 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-10 11:22 - 2011-10-19 09:46 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-10 11:21 - 2012-04-09 08:29 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-10 06:25 - 2011-11-17 09:28 - 00000372 ____A C:\Windows\Tasks\PC Health Advisor Defrag.job
2012-08-09 17:00 - 2012-07-23 07:30 - 00000440 ____A C:\Windows\Tasks\ParetoLogic Registration3.job
2012-08-09 15:20 - 2011-10-20 10:15 - 03827726 ____A C:\Windows\PFRO.log
2012-08-08 00:10 - 2011-11-17 09:28 - 00000354 ____A C:\Windows\Tasks\PC Health Advisor.job
2012-08-07 06:03 - 2011-11-17 14:57 - 00002570 ____A C:\0.bak
2012-08-02 17:21 - 2012-04-09 08:29 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 17:21 - 2011-10-19 13:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-28 18:46 - 2009-10-13 15:02 - 00000169 ____A C:\0
2012-07-25 06:44 - 2012-07-25 06:44 - 09601577 ____A C:\Users\Jim\Desktop\Sully Seminar Story.mp4
2012-07-24 06:25 - 2011-10-19 07:43 - 01940013 ____A C:\Windows\WindowsUpdate.log
2012-07-23 07:29 - 2011-11-17 09:28 - 00000414 ____A C:\Windows\Tasks\ParetoLogic Update Version3.job
2012-07-20 12:38 - 2011-10-19 10:11 - 00108824 ____A C:\Users\Jim\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-20 12:38 - 2009-07-13 20:33 - 00406272 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-20 12:25 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-16 12:33 - 2012-07-16 12:33 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (1).exe
2012-07-16 12:32 - 2012-07-16 12:32 - 12621696 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall.exe
2012-07-16 12:19 - 2012-07-16 12:18 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Jim\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-16 09:21 - 2012-07-16 09:21 - 00000130 ____A C:\Users\Jim\Desktop\Mikogo.url
2012-07-11 04:50 - 2011-10-24 08:34 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 03:24 - 2012-07-11 03:24 - 00258422 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-09 20:46 - 2012-07-09 20:46 - 00262016 ____A C:\Windows\Minidump\070912-17144-01.dmp
2012-07-07 12:38 - 2012-07-07 12:25 - 00029536 ____A C:\Users\Jim\Desktop\AAA Money Map (5 years to retire).xlsx
2012-07-07 12:23 - 2012-07-07 12:07 - 00027433 ____A C:\Users\Jim\Desktop\AAA Money Map.xlsx
2012-07-03 12:46 - 2012-07-16 12:19 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-25 15:04 - 2012-06-25 15:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-15 08:34 - 2012-06-15 08:34 - 00001791 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 18:40 - 2012-07-11 03:24 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-10 21:52 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-07 08:08 - 2012-06-07 08:08 - 01577160 ____A (Nefsis ) C:\Users\Jim\Downloads\Launcher.exe
2012-06-07 08:08 - 2012-06-07 08:08 - 01577160 ____A (Nefsis ) C:\Users\Jim\Downloads\Launcher (1).exe
2012-06-05 21:05 - 2012-07-10 21:52 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 21:52 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 21:52 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-18 20:25 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 20:25 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 20:25 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 20:24 - 00577048 ____A C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 20:24 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-18 20:24 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 20:25 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 20:24 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-18 20:24 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 05:18 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 05:18 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 05:18 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 05:18 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 05:18 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 05:18 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 05:18 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 05:18 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 05:18 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 05:18 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 05:18 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 05:18 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 05:18 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 05:18 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:45 - 2012-07-10 21:52 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 21:52 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 21:52 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 21:52 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 21:52 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:49 - 2012-06-01 16:49 - 04395874 ___AT C:\Users\Jim\Desktop\SNL.wmv
2012-05-18 14:32 - 2011-11-02 06:48 - 00060304 ____A C:\Users\Jim\g2mdlhlpx.exe
ZeroAccess:
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\@
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\L
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\n
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U\00000001.@
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U\80000000.@
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U\800000cb.@
ZeroAccess:
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\@
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\L
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 2549.51 MB
Available physical RAM: 2144.2 MB
Total Pagefile: 2547.79 MB
Available Pagefile: 2148.22 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.73 MB
======================= Partitions =========================
1 Drive c: (Gateway) (Fixed) (Total:186.3 GB) (Free:15.54 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
5 Drive g: (16GB) (Removable) (Total:14.92 GB) (Free:14.83 GB) NTFS
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 186 GB 9 MB
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 Online 14 GB 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Disk 7 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 186 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Gateway NTFS Partition 186 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 1024 KB
==================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G 16GB NTFS Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-08-06 23:34
======================= End Of Log ==========================
So far I've run scans with MSE and Malwarebytes. MSE ID'd the virus and tried to remove, but wasn't fast enough. I haven't touched the registry, and I haven't tried deleting individual files.
FRST scan results are below:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 10-08-2012
Ran by SYSTEM at 10-08-2012 13:45:39
Running from G:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [LifeChat] "C:\Program Files\Microsoft LifeChat\LifeChat.exe" [264040 2009-09-28] (Microsoft Corporation)
HKLM\...\Run: [WindowsLiveDeviceIntegrator] C:\Program Files\Windows Live\Device Integrator\wldi.exe [245544 2010-09-24] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [PrintDisp] C:\Windows\system32\PrintDisp.exe [871936 2009-04-07] (ActMask Co.,Ltd)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Jim\...\Run: [Retriever] C:\Program Files\Redtail Technology\Retriever for the Desktop\Retriever.exe [2045440 2011-04-29] (Redtail Technology)
HKU\Jim\...\Run: [WebEx] RUNDLL32.EXE C:\Users\Jim\AppData\Local\WebEx\xtefdfkf.dll,DllGetClassObject [746496 2012-08-10] ()
HKU\Jim\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-10-19] (Google Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.10.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Windows Home Server.lnk
ShortcutTarget: Windows Home Server.lnk -> C:\Windows\Installer\{21E49794-7C13-4E84-8659-55BD378267D5}\WHSTrayApp.exe (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
2 arXfrSvc; "C:\Program Files\Windows Home Server\Microsoft.HomeServer.Archive.TransferService.exe" [239472 2011-01-10] (Microsoft Corporation)
2 esClient; "C:\Program Files\Windows Home Server\esClient.exe" [97136 2011-01-10] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 M4-Service; C:\Users\Jim\AppData\Local\Mikogo4\Viewer\Service\M4-Service.exe [1008032 2012-07-16] ()
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2011-08-12] ()
2 Printer Control; C:\Windows\system32\PrintCtrl.exe [73728 2008-10-11] ()
2 WHSConnector; "C:\Program Files\Windows Home Server\WHSConnector.exe" [376688 2011-01-10] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
0 amacpi; C:\Windows\System32\DRIVERS\null.sys [4608 2009-07-13] (Microsoft Corporation)
3 htcnprot; C:\Windows\System32\DRIVERS\htcnprot.sys [23040 2010-06-23] (Windows (R) Win 7 DDK provider)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-10] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 usbaudio; C:\Windows\System32\drivers\usbaudio.sys [80768 2010-11-20] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-10 13:45 - 2012-08-10 13:45 - 00000000 ____D C:\FRST
2012-08-10 12:17 - 2012-08-10 12:17 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-10 12:01 - 2012-08-10 12:02 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (3).exe
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (2).exe
2012-08-09 10:53 - 2012-08-09 11:28 - 00000000 ____D C:\Users\Jim\Desktop\S&A Update
2012-08-09 10:38 - 2012-08-09 11:28 - 00000000 ____D C:\Users\Jim\Desktop\S&A!
2012-08-09 10:37 - 2012-08-09 10:54 - 00000000 ____D C:\Users\Jim\Desktop\S&A
2012-07-27 14:29 - 2012-08-10 12:28 - 00000000 ____D C:\Users\Jim\AppData\Local\WebEx
2012-07-25 06:44 - 2012-07-25 06:44 - 09601577 ____A C:\Users\Jim\Desktop\Sully Seminar Story.mp4
2012-07-24 06:34 - 2012-07-24 06:34 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-23 08:51 - 2012-07-23 08:54 - 00000000 ____D C:\Users\Jim\Desktop\Photo
2012-07-23 07:30 - 2012-08-09 17:00 - 00000440 ____A C:\Windows\Tasks\ParetoLogic Registration3.job
2012-07-23 07:29 - 2012-08-10 12:27 - 00000466 ____A C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2012-07-20 12:30 - 2012-07-20 12:30 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2012-07-16 12:42 - 2012-07-16 12:42 - 00000000 ____D C:\Program Files\LSI SoftModem
2012-07-16 12:41 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-07-16 12:33 - 2012-07-16 12:33 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (1).exe
2012-07-16 12:32 - 2012-07-16 12:32 - 12621696 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall.exe
2012-07-16 12:19 - 2012-07-16 12:19 - 00000000 ____D C:\Users\Jim\AppData\Roaming\Malwarebytes
2012-07-16 12:19 - 2012-07-16 12:19 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-16 12:19 - 2012-07-16 12:19 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-07-16 12:19 - 2012-07-03 12:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-16 12:18 - 2012-07-16 12:19 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Jim\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-16 09:21 - 2012-07-16 09:21 - 00000130 ____A C:\Users\Jim\Desktop\Mikogo.url
2012-07-16 09:03 - 2012-07-16 09:03 - 00000000 ____D C:\Users\Jim\Documents\Mikogo4
2012-07-16 09:03 - 2012-07-16 09:03 - 00000000 ____D C:\Users\Jim\AppData\Local\Mikogo4
2012-07-11 05:18 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 05:18 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 05:18 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 05:18 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 05:18 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 05:18 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 05:18 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 05:18 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 05:18 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 05:18 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 05:18 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 05:18 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 05:18 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 05:18 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 03:24 - 2012-07-11 03:24 - 00258422 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-11 03:24 - 2012-06-11 18:40 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
============ 3 Months Modified Files ========================
2012-08-10 12:39 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-10 12:39 - 2009-07-13 20:39 - 00053167 ____A C:\Windows\setupact.log
2012-08-10 12:27 - 2012-07-23 07:29 - 00000466 ____A C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2012-08-10 12:27 - 2011-10-19 09:46 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-10 12:17 - 2012-08-10 12:17 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-10 12:06 - 2009-07-13 20:34 - 00016416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-10 12:06 - 2009-07-13 20:34 - 00016416 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-10 12:05 - 2011-10-31 14:07 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (3).exe
2012-08-10 12:01 - 2012-08-10 12:01 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (2).exe
2012-08-10 12:01 - 2011-10-19 08:05 - 00795754 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-10 11:22 - 2011-10-19 09:46 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-10 11:21 - 2012-04-09 08:29 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-10 06:25 - 2011-11-17 09:28 - 00000372 ____A C:\Windows\Tasks\PC Health Advisor Defrag.job
2012-08-09 17:00 - 2012-07-23 07:30 - 00000440 ____A C:\Windows\Tasks\ParetoLogic Registration3.job
2012-08-09 15:20 - 2011-10-20 10:15 - 03827726 ____A C:\Windows\PFRO.log
2012-08-08 00:10 - 2011-11-17 09:28 - 00000354 ____A C:\Windows\Tasks\PC Health Advisor.job
2012-08-07 06:03 - 2011-11-17 14:57 - 00002570 ____A C:\0.bak
2012-08-02 17:21 - 2012-04-09 08:29 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-02 17:21 - 2011-10-19 13:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-28 18:46 - 2009-10-13 15:02 - 00000169 ____A C:\0
2012-07-25 06:44 - 2012-07-25 06:44 - 09601577 ____A C:\Users\Jim\Desktop\Sully Seminar Story.mp4
2012-07-24 06:25 - 2011-10-19 07:43 - 01940013 ____A C:\Windows\WindowsUpdate.log
2012-07-23 07:29 - 2011-11-17 09:28 - 00000414 ____A C:\Windows\Tasks\ParetoLogic Update Version3.job
2012-07-20 12:38 - 2011-10-19 10:11 - 00108824 ____A C:\Users\Jim\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-20 12:38 - 2009-07-13 20:33 - 00406272 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-20 12:25 - 2009-07-13 18:04 - 00000478 ____A C:\Windows\win.ini
2012-07-16 12:33 - 2012-07-16 12:33 - 10288512 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall (1).exe
2012-07-16 12:32 - 2012-07-16 12:32 - 12621696 ____A (Microsoft Corporation) C:\Users\Jim\Downloads\mseinstall.exe
2012-07-16 12:19 - 2012-07-16 12:18 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Jim\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-16 09:21 - 2012-07-16 09:21 - 00000130 ____A C:\Users\Jim\Desktop\Mikogo.url
2012-07-11 04:50 - 2011-10-24 08:34 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 03:24 - 2012-07-11 03:24 - 00258422 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-07-09 20:46 - 2012-07-09 20:46 - 00262016 ____A C:\Windows\Minidump\070912-17144-01.dmp
2012-07-07 12:38 - 2012-07-07 12:25 - 00029536 ____A C:\Users\Jim\Desktop\AAA Money Map (5 years to retire).xlsx
2012-07-07 12:23 - 2012-07-07 12:07 - 00027433 ____A C:\Users\Jim\Desktop\AAA Money Map.xlsx
2012-07-03 12:46 - 2012-07-16 12:19 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-25 15:04 - 2012-06-25 15:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\System32\msxml4.dll
2012-06-15 08:34 - 2012-06-15 08:34 - 00001791 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-11 18:40 - 2012-07-11 03:24 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 20:41 - 2012-07-10 21:52 - 12873728 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-07 08:08 - 2012-06-07 08:08 - 01577160 ____A (Nefsis ) C:\Users\Jim\Downloads\Launcher.exe
2012-06-07 08:08 - 2012-06-07 08:08 - 01577160 ____A (Nefsis ) C:\Users\Jim\Downloads\Launcher (1).exe
2012-06-05 21:05 - 2012-07-10 21:52 - 01390080 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 21:05 - 2012-07-10 21:52 - 01236992 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:03 - 2012-07-10 21:52 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-02 14:19 - 2012-06-18 20:25 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 20:25 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 20:25 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 20:24 - 00577048 ____A C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 20:24 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-18 20:24 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 20:25 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 20:24 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-18 20:24 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 05:18 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 05:18 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 05:18 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 05:18 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 05:18 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 05:18 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 05:18 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 05:18 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 05:18 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 05:18 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 05:18 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 05:18 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 05:18 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 05:18 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:45 - 2012-07-10 21:52 - 00134000 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 20:45 - 2012-07-10 21:52 - 00067440 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 20:40 - 2012-07-10 21:52 - 00369336 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 20:40 - 2012-07-10 21:52 - 00225280 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:39 - 2012-07-10 21:52 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:49 - 2012-06-01 16:49 - 04395874 ___AT C:\Users\Jim\Desktop\SNL.wmv
2012-05-18 14:32 - 2011-11-02 06:48 - 00060304 ____A C:\Users\Jim\g2mdlhlpx.exe
ZeroAccess:
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\@
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\L
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\n
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U\00000001.@
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U\80000000.@
C:\Windows\Installer\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U\800000cb.@
ZeroAccess:
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\@
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\L
C:\Users\Jim\AppData\Local\{de3bd9f3-4cee-e571-16b7-643d7eb9e770}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 2549.51 MB
Available physical RAM: 2144.2 MB
Total Pagefile: 2547.79 MB
Available Pagefile: 2148.22 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.73 MB
======================= Partitions =========================
1 Drive c: (Gateway) (Fixed) (Total:186.3 GB) (Free:15.54 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
5 Drive g: (16GB) (Removable) (Total:14.92 GB) (Free:14.83 GB) NTFS
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 186 GB 9 MB
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 Online 14 GB 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Disk 7 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 186 GB 31 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Gateway NTFS Partition 186 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 1024 KB
==================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G 16GB NTFS Removable 14 GB Healthy
==================================================================================
Last Boot: 2012-08-06 23:34
======================= End Of Log ==========================