It seems like this sirefef.y virus is making the round right now. I am having very similar problems as everyone else, and I think it might have stemmed from clicking a fake Adobe Flash Player update. This is my first post here, I've hit a wall with what I know how to do. I would like to be able to solve this problem without nuking the system and reinstalling, but I'm not opposed to doing that.
Up to this point I have UNinstalled Live Security Platinum which was part of the problem. I wasn't able to open executable files so I ran a fixexec program to resolve that. I've installed Microsoft Security Essentials, and I've run scans with Malwarebytes and two antivirus live CDs (Kaspersky and Bitdefender). None of these have resolved the problem.
Thanks in advance for any help anyone might provide.
Anywho, I'm including the logs for the Farbar Recovery Scan Tool, as well as the search for Services.exe since I see that requested every time.
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 31-07-2012 19:36:05
Running from D:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11046504 2010-07-13] (Realtek Semiconductor)
HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe [2922496 2011-06-16] (Eastman Kodak Company)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [102400 2010-05-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe [2095616 2010-07-20] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATORHL] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe [557056 2010-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [DT HPO] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -HPO [121456 2010-12-01] (Portrait Displays, Inc.)
HKLM-x32\...\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe [895512 2010-10-22] (PDF Complete Inc)
HKLM-x32\...\Run: [Conime] %windir%\system32\conime.exe [x]
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [296056 2012-06-02] (RealNetworks, Inc.)
HKLM-x32\...\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe [2922496 2011-06-16] (Eastman Kodak Company)
Tcpip\Parameters: [DhcpNameServer] 66.206.177.5
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Snapfish PictureMover.lnk
ShortcutTarget: Snapfish PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
Startup: C:\Users\Vicki\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 CalendarSynchService; "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe" [16384 2010-08-05] (Hewlett-Packard)
2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe [129648 2010-12-01] (Portrait Displays, Inc.)
2 Kodak AiO Status Monitor Service; "C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe" [777728 2012-06-19] (Eastman Kodak Company)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PdiService; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [109168 2010-04-16] (Portrait Displays, Inc.)
========================== Drivers (Whitelisted) =============
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-31 03:41 - 2012-07-31 05:26 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0BB16474FEE69EBC
2012-07-30 12:44 - 2012-07-30 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B915A3201113FDD
2012-07-30 12:41 - 2012-07-30 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2A1CED08850EABB2
2012-07-30 12:39 - 2012-07-30 12:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30B2584A3C97A320
2012-07-30 12:36 - 2012-07-30 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.70EE7353E0288A8E
2012-07-30 12:33 - 2012-07-30 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DFABFE50CF50686C
2012-07-30 12:30 - 2012-07-30 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1F8B5425F0D4ECE
2012-07-30 12:26 - 2012-07-30 12:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B75DF3A30CBDBC7E
2012-07-30 12:24 - 2012-01-31 01:59 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-07-30 12:22 - 2012-07-30 12:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-30 12:21 - 2012-07-30 12:22 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-30 11:25 - 2012-07-30 09:50 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-30 10:45 - 2012-07-30 10:45 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 10:45 - 2012-07-30 10:45 - 00000000 ____D C:\Users\Vicki\AppData\Roaming\Malwarebytes
2012-07-30 10:45 - 2012-07-30 10:45 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-30 10:45 - 2012-07-30 10:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-30 10:45 - 2012-07-03 09:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-30 10:38 - 2012-07-30 12:23 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 08:57 - 2012-07-30 08:57 - 00000000 ____D C:\Users\Vicki\AppData\Roaming\Tific
2012-07-29 14:23 - 2012-07-29 14:23 - 00000000 ____D C:\Users\Vicki\AppData\Local\Symantec
2012-07-29 14:07 - 2012-07-29 14:07 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-28 16:48 - 2012-07-28 16:48 - 03421869 ____A C:\Users\Vicki\Downloads\Greatest Love.wma
2012-07-28 15:00 - 2012-07-28 15:00 - 01275649 ____A C:\Users\Vicki\Downloads\These are my People.wma
2012-07-28 09:27 - 2012-07-28 09:27 - 01105024 ____A C:\Users\Vicki\Downloads\up_sonneries_stevie-wonder-happy-birthday_downloader.exe
2012-07-21 07:03 - 2012-07-21 07:03 - 00002158 ____A C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
2012-07-21 07:03 - 2012-07-21 07:03 - 00002077 ____A C:\Users\Public\Desktop\Get CleanPrint.lnk
2012-07-21 07:00 - 2012-07-21 07:00 - 00000000 ____D C:\Users\Default\AppData\Roaming\KODAK AiO Home Center429929630
2012-07-21 07:00 - 2012-07-21 07:00 - 00000000 ____D C:\Users\Default User\AppData\Roaming\KODAK AiO Home Center429929630
2012-07-19 19:56 - 2012-07-19 19:56 - 00037577 ____A C:\Users\Vicki\Desktop\O'Connor article.htm
2012-07-19 19:56 - 2012-07-19 19:56 - 00000000 ____D C:\Users\Vicki\Desktop\O'Connor article_files
2012-07-19 17:55 - 2012-07-19 17:55 - 00010430 ____A C:\Users\Vicki\Documents\Wiki Class Grades.xlsx
2012-07-11 23:05 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 23:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 23:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 23:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 23:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 23:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 23:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 23:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 23:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 23:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 23:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 23:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 23:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 23:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 23:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 23:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 23:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 23:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 23:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 23:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 23:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 23:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 23:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 17:57 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 17:57 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 17:57 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 17:57 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 17:57 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 17:57 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 17:57 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-11 17:56 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 17:56 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 17:56 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 17:56 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 17:56 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 17:56 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 17:56 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 17:56 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 17:56 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 17:56 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 17:56 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 17:56 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-04 17:08 - 2012-07-04 17:10 - 00000000 ____D C:\Miscellaneous Work
2012-07-04 17:05 - 2012-07-04 17:07 - 00000000 ____D C:\CEC Club
============ 3 Months Modified Files ========================
2012-07-31 15:21 - 2009-07-13 21:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-31 15:21 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-31 15:21 - 2009-07-13 20:51 - 00040387 ____A C:\Windows\setupact.log
2012-07-31 05:31 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0BB16474FEE69EBC
2012-07-30 12:44 - 2012-07-30 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B915A3201113FDD
2012-07-30 12:41 - 2012-07-30 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2A1CED08850EABB2
2012-07-30 12:39 - 2012-07-30 12:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30B2584A3C97A320
2012-07-30 12:39 - 2012-04-09 18:51 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-30 12:36 - 2012-07-30 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.70EE7353E0288A8E
2012-07-30 12:33 - 2012-07-30 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DFABFE50CF50686C
2012-07-30 12:30 - 2012-07-30 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1F8B5425F0D4ECE
2012-07-30 12:26 - 2012-07-30 12:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B75DF3A30CBDBC7E
2012-07-30 12:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 12:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 12:24 - 2009-07-13 21:13 - 00782528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 12:23 - 2012-07-30 10:38 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 12:23 - 2011-04-07 10:05 - 01817799 ____A C:\Windows\WindowsUpdate.log
2012-07-30 12:22 - 2011-04-07 10:12 - 00796186 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 11:33 - 2011-04-07 13:00 - 00302354 ____A C:\Windows\PFRO.log
2012-07-30 10:45 - 2012-07-30 10:45 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 09:50 - 2012-07-30 11:25 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-28 16:48 - 2012-07-28 16:48 - 03421869 ____A C:\Users\Vicki\Downloads\Greatest Love.wma
2012-07-28 15:00 - 2012-07-28 15:00 - 01275649 ____A C:\Users\Vicki\Downloads\These are my People.wma
2012-07-28 09:27 - 2012-07-28 09:27 - 01105024 ____A C:\Users\Vicki\Downloads\up_sonneries_stevie-wonder-happy-birthday_downloader.exe
2012-07-27 05:39 - 2012-04-09 18:50 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 05:39 - 2011-06-09 16:01 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-21 07:03 - 2012-07-21 07:03 - 00002158 ____A C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
2012-07-21 07:03 - 2012-07-21 07:03 - 00002077 ____A C:\Users\Public\Desktop\Get CleanPrint.lnk
2012-07-21 07:00 - 2011-09-28 11:11 - 00800824 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\DPInst.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00800824 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\DPInst.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00106496 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\gacutil.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00106496 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\gacutil.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00036352 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\PnPutil.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00036352 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\PnPutil.exe
2012-07-21 06:24 - 2011-11-29 10:52 - 00000332 ____A C:\Windows\Tasks\HPCeeScheduleForVicki.job
2012-07-19 19:56 - 2012-07-19 19:56 - 00037577 ____A C:\Users\Vicki\Desktop\O'Connor article.htm
2012-07-19 17:55 - 2012-07-19 17:55 - 00010430 ____A C:\Users\Vicki\Documents\Wiki Class Grades.xlsx
2012-07-14 06:34 - 2011-07-11 18:32 - 00000342 ____A C:\Windows\Tasks\HPCeeScheduleForDONNE-HP$.job
2012-07-11 23:22 - 2009-07-13 20:45 - 00425784 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 23:02 - 2011-06-09 09:26 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 09:46 - 2012-07-30 10:45 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-11 19:08 - 2012-07-11 23:05 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 17:57 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 17:56 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-11 17:57 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 17:57 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 17:56 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 17:57 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 17:57 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 17:56 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-26 22:31 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-26 22:31 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-26 22:31 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-26 22:30 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-26 22:30 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-26 22:31 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-26 22:30 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-26 22:30 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-26 22:30 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 07:06 - 2012-06-02 07:06 - 00001042 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-06-02 07:05 - 2011-12-01 03:49 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2012-06-02 04:49 - 2012-07-11 23:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 23:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 23:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 23:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 23:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 23:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 23:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 23:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 23:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 23:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 23:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 23:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 23:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 23:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 23:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 23:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 23:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 23:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 23:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 23:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 23:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 23:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 23:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 23:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 23:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 23:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 17:56 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 17:56 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 17:56 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 17:56 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 17:56 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 17:56 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 17:56 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 17:56 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 17:56 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-26 07:27 - 2012-05-26 07:27 - 39483256 ____A (Apple Inc.) C:\Users\Vicki\Downloads\QuickTimeInstaller(2).exe
2012-05-04 03:06 - 2012-06-14 06:37 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-14 06:37 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-14 06:37 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
ZeroAccess:
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}\@
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}\L
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}\U
ZeroAccess:
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}\@
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}\L
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe FCB084FA3DCB7449F3BAA13312A215B4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 21%
Total physical RAM: 3839.3 MB
Available physical RAM: 3026.91 MB
Total Pagefile: 3837.45 MB
Available Pagefile: 3003.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:682.32 GB) (Free:624.32 GB) NTFS
2 Drive d: (PENDRIVE) (Removable) (Total:7.2 GB) (Free:4.52 GB) FAT32
3 Drive f: (HP_RECOVERY) (Fixed) (Total:16.21 GB) (Free:2.01 GB) NTFS ==>[System with boot components (obtained from reading drive)]
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 7385 MB 0 B
Disk 2 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 682 GB 101 MB
Partition 3 Primary 16 GB 682 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 682 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F HP_RECOVERY NTFS Partition 16 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7381 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D PENDRIVE FAT32 Removable 7381 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-17 20:15
======================= End Of Log ==========================
And the services.exe search:
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-31 19:38:30
Running from D:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-31 05:31] - 0328704 ____A (Microsoft Corporation) FCB084FA3DCB7449F3BAA13312A215B4
====== End Of Search ======
Up to this point I have UNinstalled Live Security Platinum which was part of the problem. I wasn't able to open executable files so I ran a fixexec program to resolve that. I've installed Microsoft Security Essentials, and I've run scans with Malwarebytes and two antivirus live CDs (Kaspersky and Bitdefender). None of these have resolved the problem.
Thanks in advance for any help anyone might provide.
Anywho, I'm including the logs for the Farbar Recovery Scan Tool, as well as the search for Services.exe since I see that requested every time.
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 31-07-2012 19:36:05
Running from D:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11046504 2010-07-13] (Realtek Semiconductor)
HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe [2922496 2011-06-16] (Eastman Kodak Company)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [102400 2010-05-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe [2095616 2010-07-20] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATORHL] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR_HIDList.exe [557056 2010-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [DT HPO] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -HPO [121456 2010-12-01] (Portrait Displays, Inc.)
HKLM-x32\...\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe [895512 2010-10-22] (PDF Complete Inc)
HKLM-x32\...\Run: [Conime] %windir%\system32\conime.exe [x]
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [296056 2012-06-02] (RealNetworks, Inc.)
HKLM-x32\...\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe [2922496 2011-06-16] (Eastman Kodak Company)
Tcpip\Parameters: [DhcpNameServer] 66.206.177.5
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Snapfish PictureMover.lnk
ShortcutTarget: Snapfish PictureMover.lnk -> C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
Startup: C:\Users\Vicki\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 CalendarSynchService; "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe" [16384 2010-08-05] (Hewlett-Packard)
2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe [129648 2010-12-01] (Portrait Displays, Inc.)
2 Kodak AiO Status Monitor Service; "C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe" [777728 2012-06-19] (Eastman Kodak Company)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PdiService; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [109168 2010-04-16] (Portrait Displays, Inc.)
========================== Drivers (Whitelisted) =============
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-31 03:41 - 2012-07-31 05:26 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0BB16474FEE69EBC
2012-07-30 12:44 - 2012-07-30 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B915A3201113FDD
2012-07-30 12:41 - 2012-07-30 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2A1CED08850EABB2
2012-07-30 12:39 - 2012-07-30 12:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30B2584A3C97A320
2012-07-30 12:36 - 2012-07-30 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.70EE7353E0288A8E
2012-07-30 12:33 - 2012-07-30 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DFABFE50CF50686C
2012-07-30 12:30 - 2012-07-30 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1F8B5425F0D4ECE
2012-07-30 12:26 - 2012-07-30 12:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B75DF3A30CBDBC7E
2012-07-30 12:24 - 2012-01-31 01:59 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-07-30 12:22 - 2012-07-30 12:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-30 12:21 - 2012-07-30 12:22 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-30 11:25 - 2012-07-30 09:50 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-30 10:45 - 2012-07-30 10:45 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 10:45 - 2012-07-30 10:45 - 00000000 ____D C:\Users\Vicki\AppData\Roaming\Malwarebytes
2012-07-30 10:45 - 2012-07-30 10:45 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-30 10:45 - 2012-07-30 10:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-30 10:45 - 2012-07-03 09:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-30 10:38 - 2012-07-30 12:23 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 08:57 - 2012-07-30 08:57 - 00000000 ____D C:\Users\Vicki\AppData\Roaming\Tific
2012-07-29 14:23 - 2012-07-29 14:23 - 00000000 ____D C:\Users\Vicki\AppData\Local\Symantec
2012-07-29 14:07 - 2012-07-29 14:07 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-28 16:48 - 2012-07-28 16:48 - 03421869 ____A C:\Users\Vicki\Downloads\Greatest Love.wma
2012-07-28 15:00 - 2012-07-28 15:00 - 01275649 ____A C:\Users\Vicki\Downloads\These are my People.wma
2012-07-28 09:27 - 2012-07-28 09:27 - 01105024 ____A C:\Users\Vicki\Downloads\up_sonneries_stevie-wonder-happy-birthday_downloader.exe
2012-07-21 07:03 - 2012-07-21 07:03 - 00002158 ____A C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
2012-07-21 07:03 - 2012-07-21 07:03 - 00002077 ____A C:\Users\Public\Desktop\Get CleanPrint.lnk
2012-07-21 07:00 - 2012-07-21 07:00 - 00000000 ____D C:\Users\Default\AppData\Roaming\KODAK AiO Home Center429929630
2012-07-21 07:00 - 2012-07-21 07:00 - 00000000 ____D C:\Users\Default User\AppData\Roaming\KODAK AiO Home Center429929630
2012-07-19 19:56 - 2012-07-19 19:56 - 00037577 ____A C:\Users\Vicki\Desktop\O'Connor article.htm
2012-07-19 19:56 - 2012-07-19 19:56 - 00000000 ____D C:\Users\Vicki\Desktop\O'Connor article_files
2012-07-19 17:55 - 2012-07-19 17:55 - 00010430 ____A C:\Users\Vicki\Documents\Wiki Class Grades.xlsx
2012-07-11 23:05 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 23:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 23:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 23:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 23:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 23:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 23:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 23:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 23:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 23:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 23:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 23:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 23:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 23:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 23:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 23:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 23:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 23:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 23:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 23:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 23:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 23:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 23:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 23:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 23:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 23:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 17:57 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 17:57 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 17:57 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 17:57 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 17:57 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 17:57 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 17:57 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-11 17:56 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 17:56 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 17:56 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 17:56 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 17:56 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 17:56 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 17:56 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 17:56 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 17:56 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 17:56 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 17:56 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 17:56 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-04 17:08 - 2012-07-04 17:10 - 00000000 ____D C:\Miscellaneous Work
2012-07-04 17:05 - 2012-07-04 17:07 - 00000000 ____D C:\CEC Club
============ 3 Months Modified Files ========================
2012-07-31 15:21 - 2009-07-13 21:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-31 15:21 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-31 15:21 - 2009-07-13 20:51 - 00040387 ____A C:\Windows\setupact.log
2012-07-31 05:31 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-30 12:49 - 2012-07-30 12:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0BB16474FEE69EBC
2012-07-30 12:44 - 2012-07-30 12:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B915A3201113FDD
2012-07-30 12:41 - 2012-07-30 12:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2A1CED08850EABB2
2012-07-30 12:39 - 2012-07-30 12:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30B2584A3C97A320
2012-07-30 12:39 - 2012-04-09 18:51 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-30 12:36 - 2012-07-30 12:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.70EE7353E0288A8E
2012-07-30 12:33 - 2012-07-30 12:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DFABFE50CF50686C
2012-07-30 12:30 - 2012-07-30 12:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1F8B5425F0D4ECE
2012-07-30 12:26 - 2012-07-30 12:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B75DF3A30CBDBC7E
2012-07-30 12:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-30 12:26 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-30 12:24 - 2009-07-13 21:13 - 00782528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-30 12:23 - 2012-07-30 10:38 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-30 12:23 - 2011-04-07 10:05 - 01817799 ____A C:\Windows\WindowsUpdate.log
2012-07-30 12:22 - 2011-04-07 10:12 - 00796186 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-30 11:33 - 2011-04-07 13:00 - 00302354 ____A C:\Windows\PFRO.log
2012-07-30 10:45 - 2012-07-30 10:45 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 09:50 - 2012-07-30 11:25 - 00457632 ____A (Bleeping Computer, LLC) C:\FixExec.com
2012-07-28 16:48 - 2012-07-28 16:48 - 03421869 ____A C:\Users\Vicki\Downloads\Greatest Love.wma
2012-07-28 15:00 - 2012-07-28 15:00 - 01275649 ____A C:\Users\Vicki\Downloads\These are my People.wma
2012-07-28 09:27 - 2012-07-28 09:27 - 01105024 ____A C:\Users\Vicki\Downloads\up_sonneries_stevie-wonder-happy-birthday_downloader.exe
2012-07-27 05:39 - 2012-04-09 18:50 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 05:39 - 2011-06-09 16:01 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-21 07:03 - 2012-07-21 07:03 - 00002158 ____A C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
2012-07-21 07:03 - 2012-07-21 07:03 - 00002077 ____A C:\Users\Public\Desktop\Get CleanPrint.lnk
2012-07-21 07:00 - 2011-09-28 11:11 - 00800824 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\DPInst.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00800824 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\DPInst.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00106496 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\gacutil.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00106496 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\gacutil.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00036352 ____A (Microsoft Corporation) C:\Users\Default\AppData\Roaming\PnPutil.exe
2012-07-21 07:00 - 2011-09-28 11:11 - 00036352 ____A (Microsoft Corporation) C:\Users\Default User\AppData\Roaming\PnPutil.exe
2012-07-21 06:24 - 2011-11-29 10:52 - 00000332 ____A C:\Windows\Tasks\HPCeeScheduleForVicki.job
2012-07-19 19:56 - 2012-07-19 19:56 - 00037577 ____A C:\Users\Vicki\Desktop\O'Connor article.htm
2012-07-19 17:55 - 2012-07-19 17:55 - 00010430 ____A C:\Users\Vicki\Documents\Wiki Class Grades.xlsx
2012-07-14 06:34 - 2011-07-11 18:32 - 00000342 ____A C:\Windows\Tasks\HPCeeScheduleForDONNE-HP$.job
2012-07-11 23:22 - 2009-07-13 20:45 - 00425784 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 23:02 - 2011-06-09 09:26 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 09:46 - 2012-07-30 10:45 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-11 19:08 - 2012-07-11 23:05 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 17:57 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 17:56 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-11 17:57 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 17:57 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 17:56 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 17:57 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 17:57 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 17:56 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-26 22:31 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-26 22:31 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-26 22:31 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-26 22:30 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-26 22:30 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-26 22:31 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-26 22:30 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-26 22:30 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-26 22:30 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 07:06 - 2012-06-02 07:06 - 00001042 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2012-06-02 07:05 - 2011-12-01 03:49 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2012-06-02 07:05 - 2011-12-01 03:49 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2012-06-02 04:49 - 2012-07-11 23:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 23:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 23:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 23:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 23:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 23:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 23:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 23:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 23:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 23:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 23:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 23:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 23:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 23:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 23:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 23:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 23:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 23:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 23:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 23:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 23:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 23:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 23:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 23:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 23:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 23:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 23:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 17:56 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 17:56 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 17:56 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 17:56 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 17:56 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 17:56 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 17:56 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 17:56 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 17:56 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-26 07:27 - 2012-05-26 07:27 - 39483256 ____A (Apple Inc.) C:\Users\Vicki\Downloads\QuickTimeInstaller(2).exe
2012-05-04 03:06 - 2012-06-14 06:37 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-14 06:37 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-14 06:37 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
ZeroAccess:
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}\@
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}\L
C:\Windows\Installer\{915de5e1-789c-15c9-f94d-45adb15a200a}\U
ZeroAccess:
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}\@
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}\L
C:\Users\Vicki\AppData\Local\{915de5e1-789c-15c9-f94d-45adb15a200a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe FCB084FA3DCB7449F3BAA13312A215B4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 21%
Total physical RAM: 3839.3 MB
Available physical RAM: 3026.91 MB
Total Pagefile: 3837.45 MB
Available Pagefile: 3003.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:682.32 GB) (Free:624.32 GB) NTFS
2 Drive d: (PENDRIVE) (Removable) (Total:7.2 GB) (Free:4.52 GB) FAT32
3 Drive f: (HP_RECOVERY) (Fixed) (Total:16.21 GB) (Free:2.01 GB) NTFS ==>[System with boot components (obtained from reading drive)]
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 7385 MB 0 B
Disk 2 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 682 GB 101 MB
Partition 3 Primary 16 GB 682 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 682 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F HP_RECOVERY NTFS Partition 16 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7381 MB 4032 KB
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 D PENDRIVE FAT32 Removable 7381 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-17 20:15
======================= End Of Log ==========================
And the services.exe search:
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-07-31 19:38:30
Running from D:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-31 05:31] - 0328704 ____A (Microsoft Corporation) FCB084FA3DCB7449F3BAA13312A215B4
====== End Of Search ======