I was using my grandmother's computer tonight and somehow infected by Live Security Platinum. I used Malwarebytes to remove it by following the directions here.
It appeared to work, but after restarting my computer, I keep getting the error, "Windows has encountered a critical problem and will restart automatically in one minute." I open up Microsoft Security Essentials to see what is causing the problem, and the two programs "Win64/Sirefef.Y" and "Win64/Sirefef.B" are labeled as dangerous. MSE cannot scan the computer quickly enough to remove those programs before the computer is restarted.
Details provided by MSE shows that "file:C:\Windows\system32\services"
I have seen other questions about this problem, but I wasn't able to find anything for Vista, only Windows 7. I ran FRST64 and posted the FRST.txt below, but it took multiple posts to get it all.
===================================================
====================== FRST.txt =====================
===================================================
Scan result of Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 16-08-2012 12:22:34
Running from F:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2215768 2011-09-30] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\Pat Coe\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\PatriciaCoe\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-02-15] (Google Inc.)
HKU\PatriciaCoe\...\Run: [rfwime] rundll32.exe "C:\Users\PatriciaCoe\AppData\Roaming\rfwime.dll",HrVerifyCertEnhKeyUsage [159744 2012-08-15] ()
HKU\PatriciaCoe\...\Run: [asefr] "C:\Users\PatriciaCoe\AppData\Roaming\asefr.dll",MemoryError [466944 2012-08-15] (EFD Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) ======
3 GameConsoleService; "C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe" [165416 2008-05-05] (WildTangent, Inc.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [366640 2011-07-06] (Malwarebytes Corporation)
2 McciCMService64; "C:\Program Files\Common Files\Motive\McciCMService.exe" [517632 2009-10-21] (Alcatel-Lucent)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RapportMgmtService; "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" [976728 2012-07-29] (Trusteer Ltd.)
========================== Drivers (Whitelisted) =============
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [25912 2011-07-06] (Malwarebytes Corporation)
3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [43008 2009-09-15] (Printing Communications Assoc., Inc. (PCAUSA))
3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [40960 2009-09-15] (Printing Communications Assoc., Inc. (PCAUSA))
1 RapportCerberus_42020; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys [397720 2012-08-15] ()
1 RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [55096 2012-07-29] (Trusteer Ltd.)
0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [101688 2012-07-29] (Trusteer Ltd.)
1 RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [297240 2012-07-29] (Trusteer Ltd.)
2 {55662437-DA8C-40c0-AADA-2C816A897A49}; \??\C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-10-21] (CyberLink Corp.)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 PCD5SRVC{8AAF211B-043E02A9-05040000}; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC_x64.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-16 12:22 - 2012-08-16 12:22 - 00000000 ____D C:\FRST
2012-08-16 08:06 - 2012-08-16 08:06 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BBAD32CDCD2E5BD
2012-08-15 19:33 - 2012-08-15 19:33 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7A694262B2C0D112
2012-08-15 19:26 - 2012-08-15 19:26 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BA211D3C753A4C1
2012-08-15 19:21 - 2012-08-15 19:21 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-15 19:21 - 2012-08-15 19:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-15 18:23 - 2012-08-15 18:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-15 18:21 - 2012-08-15 19:10 - 00000000 ____D C:\Users\All Users\Application Data\0C1CFB130094D364E329D4D42F3B707C
2012-08-15 18:21 - 2012-08-15 19:10 - 00000000 ____D C:\Users\All Users\0C1CFB130094D364E329D4D42F3B707C
2012-08-15 18:21 - 2012-08-15 18:21 - 00466944 ____A (EFD Software) C:\Users\PatriciaCoe\Application Data\asefr.dll
2012-08-15 18:21 - 2012-08-15 18:21 - 00466944 ____A (EFD Software) C:\Users\PatriciaCoe\AppData\Roaming\asefr.dll
2012-08-15 18:20 - 2012-08-15 18:20 - 00159744 __ASH C:\Users\PatriciaCoe\Application Data\rfwime.dll
2012-08-15 18:20 - 2012-08-15 18:20 - 00159744 __ASH C:\Users\PatriciaCoe\AppData\Roaming\rfwime.dll
2012-08-15 00:05 - 2012-07-04 06:33 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-14 14:33 - 2012-06-29 08:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-14 14:33 - 2012-06-29 08:01 - 00467968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-14 14:33 - 2012-06-28 03:37 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-14 14:33 - 2012-06-28 03:37 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-14 14:33 - 2012-06-28 03:37 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-14 14:33 - 2012-06-28 03:35 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-08-14 14:33 - 2012-06-28 03:33 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 06008320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-14 14:33 - 2012-06-28 03:31 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-14 14:33 - 2012-06-28 01:59 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-08-14 14:33 - 2012-06-28 00:19 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-08-14 14:33 - 2012-06-28 00:19 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-14 14:33 - 2012-06-28 00:18 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-08-14 14:33 - 2012-06-28 00:17 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-14 14:33 - 2012-06-27 22:53 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-14 14:33 - 2012-06-27 22:53 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-14 14:33 - 2012-06-27 22:53 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-14 14:33 - 2012-06-27 22:51 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-08-14 14:33 - 2012-06-27 22:48 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-14 14:33 - 2012-06-27 22:48 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-08-14 14:33 - 2012-06-27 22:48 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-08-14 14:33 - 2012-06-27 21:54 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-08-14 14:33 - 2012-06-27 21:11 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-14 14:33 - 2012-06-27 21:11 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-08-14 14:33 - 2012-06-27 21:10 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-14 14:33 - 2012-06-27 21:10 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-08-14 14:33 - 2012-06-16 03:19 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-08-14 14:33 - 2012-06-16 03:14 - 00727040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-14 14:33 - 2012-06-15 23:02 - 00610816 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-14 14:33 - 2012-06-15 22:58 - 00818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-14 14:33 - 2012-05-11 08:34 - 00788480 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-14 14:33 - 2012-05-11 07:57 - 00623616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\localspl.dll
2012-08-12 15:23 - 2012-08-12 15:23 - 00000000 ____A C:\Windows\iPlayer.INI
2012-08-12 15:20 - 2012-08-12 15:20 - 00000877 ____A C:\Users\Public\Desktop\InterActual Player.lnk
2012-08-12 15:20 - 2012-08-12 15:20 - 00000877 ____A C:\Users\All Users\Desktop\InterActual Player.lnk
2012-08-12 15:20 - 2012-08-12 15:20 - 00000000 ____D C:\Program Files\InterActual
2012-08-03 15:35 - 2012-08-03 15:35 - 00038395 ____A C:\Users\PatriciaCoe\My Documents\Senior Discounts... PASS IT ON.htm
2012-08-03 15:35 - 2012-08-03 15:35 - 00038395 ____A C:\Users\PatriciaCoe\Documents\Senior Discounts... PASS IT ON.htm
2012-08-03 15:35 - 2012-08-03 15:35 - 00000000 ____D C:\Users\PatriciaCoe\My Documents\Senior Discounts... PASS IT ON_files
2012-08-03 15:35 - 2012-08-03 15:35 - 00000000 ____D C:\Users\PatriciaCoe\Documents\Senior Discounts... PASS IT ON_files
2012-07-21 13:40 - 2012-07-21 13:41 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-21 13:40 - 2012-07-21 13:40 - 00001758 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-21 13:40 - 2012-07-21 13:40 - 00001758 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk
2012-07-21 13:40 - 2012-07-21 13:40 - 00000000 ____D C:\Users\All Users\Application Data\Apple Computer
2012-07-21 13:40 - 2012-07-21 13:40 - 00000000 ____D C:\Users\All Users\Apple Computer
It appeared to work, but after restarting my computer, I keep getting the error, "Windows has encountered a critical problem and will restart automatically in one minute." I open up Microsoft Security Essentials to see what is causing the problem, and the two programs "Win64/Sirefef.Y" and "Win64/Sirefef.B" are labeled as dangerous. MSE cannot scan the computer quickly enough to remove those programs before the computer is restarted.
Details provided by MSE shows that "file:C:\Windows\system32\services"
I have seen other questions about this problem, but I wasn't able to find anything for Vista, only Windows 7. I ran FRST64 and posted the FRST.txt below, but it took multiple posts to get it all.
===================================================
====================== FRST.txt =====================
===================================================
Scan result of Farbar Recovery Scan Tool Version: 15-08-2012
Ran by SYSTEM at 16-08-2012 12:22:34
Running from F:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2215768 2011-09-30] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\Pat Coe\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\PatriciaCoe\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-02-15] (Google Inc.)
HKU\PatriciaCoe\...\Run: [rfwime] rundll32.exe "C:\Users\PatriciaCoe\AppData\Roaming\rfwime.dll",HrVerifyCertEnhKeyUsage [159744 2012-08-15] ()
HKU\PatriciaCoe\...\Run: [asefr] "C:\Users\PatriciaCoe\AppData\Roaming\asefr.dll",MemoryError [466944 2012-08-15] (EFD Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
==================== Services (Whitelisted) ======
3 GameConsoleService; "C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe" [165416 2008-05-05] (WildTangent, Inc.)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [366640 2011-07-06] (Malwarebytes Corporation)
2 McciCMService64; "C:\Program Files\Common Files\Motive\McciCMService.exe" [517632 2009-10-21] (Alcatel-Lucent)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RapportMgmtService; "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" [976728 2012-07-29] (Trusteer Ltd.)
========================== Drivers (Whitelisted) =============
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [25912 2011-07-06] (Malwarebytes Corporation)
3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [43008 2009-09-15] (Printing Communications Assoc., Inc. (PCAUSA))
3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [40960 2009-09-15] (Printing Communications Assoc., Inc. (PCAUSA))
1 RapportCerberus_42020; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys [397720 2012-08-15] ()
1 RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [55096 2012-07-29] (Trusteer Ltd.)
0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [101688 2012-07-29] (Trusteer Ltd.)
1 RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [297240 2012-07-29] (Trusteer Ltd.)
2 {55662437-DA8C-40c0-AADA-2C816A897A49}; \??\C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-10-21] (CyberLink Corp.)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 PCD5SRVC{8AAF211B-043E02A9-05040000}; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC_x64.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-16 12:22 - 2012-08-16 12:22 - 00000000 ____D C:\FRST
2012-08-16 08:06 - 2012-08-16 08:06 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BBAD32CDCD2E5BD
2012-08-15 19:33 - 2012-08-15 19:33 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7A694262B2C0D112
2012-08-15 19:26 - 2012-08-15 19:26 - 00384512 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BA211D3C753A4C1
2012-08-15 19:21 - 2012-08-15 19:21 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-15 19:21 - 2012-08-15 19:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-15 18:23 - 2012-08-15 18:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-15 18:21 - 2012-08-15 19:10 - 00000000 ____D C:\Users\All Users\Application Data\0C1CFB130094D364E329D4D42F3B707C
2012-08-15 18:21 - 2012-08-15 19:10 - 00000000 ____D C:\Users\All Users\0C1CFB130094D364E329D4D42F3B707C
2012-08-15 18:21 - 2012-08-15 18:21 - 00466944 ____A (EFD Software) C:\Users\PatriciaCoe\Application Data\asefr.dll
2012-08-15 18:21 - 2012-08-15 18:21 - 00466944 ____A (EFD Software) C:\Users\PatriciaCoe\AppData\Roaming\asefr.dll
2012-08-15 18:20 - 2012-08-15 18:20 - 00159744 __ASH C:\Users\PatriciaCoe\Application Data\rfwime.dll
2012-08-15 18:20 - 2012-08-15 18:20 - 00159744 __ASH C:\Users\PatriciaCoe\AppData\Roaming\rfwime.dll
2012-08-15 00:05 - 2012-07-04 06:33 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-14 14:33 - 2012-06-29 08:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-14 14:33 - 2012-06-29 08:01 - 00467968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-14 14:33 - 2012-06-28 03:37 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-14 14:33 - 2012-06-28 03:37 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-14 14:33 - 2012-06-28 03:37 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-14 14:33 - 2012-06-28 03:35 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-08-14 14:33 - 2012-06-28 03:33 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 06008320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-08-14 14:33 - 2012-06-28 03:32 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-14 14:33 - 2012-06-28 03:31 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-08-14 14:33 - 2012-06-28 03:31 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-14 14:33 - 2012-06-28 01:59 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-08-14 14:33 - 2012-06-28 00:19 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-08-14 14:33 - 2012-06-28 00:19 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-14 14:33 - 2012-06-28 00:18 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-08-14 14:33 - 2012-06-28 00:17 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-14 14:33 - 2012-06-27 22:53 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-14 14:33 - 2012-06-27 22:53 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-14 14:33 - 2012-06-27 22:53 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-14 14:33 - 2012-06-27 22:51 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-14 14:33 - 2012-06-27 22:49 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-08-14 14:33 - 2012-06-27 22:48 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-14 14:33 - 2012-06-27 22:48 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-08-14 14:33 - 2012-06-27 22:48 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-08-14 14:33 - 2012-06-27 22:47 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-08-14 14:33 - 2012-06-27 21:54 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-08-14 14:33 - 2012-06-27 21:11 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-14 14:33 - 2012-06-27 21:11 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-08-14 14:33 - 2012-06-27 21:10 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-14 14:33 - 2012-06-27 21:10 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-08-14 14:33 - 2012-06-16 03:19 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-08-14 14:33 - 2012-06-16 03:14 - 00727040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-14 14:33 - 2012-06-15 23:02 - 00610816 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-14 14:33 - 2012-06-15 22:58 - 00818176 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-14 14:33 - 2012-05-11 08:34 - 00788480 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-14 14:33 - 2012-05-11 07:57 - 00623616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\localspl.dll
2012-08-12 15:23 - 2012-08-12 15:23 - 00000000 ____A C:\Windows\iPlayer.INI
2012-08-12 15:20 - 2012-08-12 15:20 - 00000877 ____A C:\Users\Public\Desktop\InterActual Player.lnk
2012-08-12 15:20 - 2012-08-12 15:20 - 00000877 ____A C:\Users\All Users\Desktop\InterActual Player.lnk
2012-08-12 15:20 - 2012-08-12 15:20 - 00000000 ____D C:\Program Files\InterActual
2012-08-03 15:35 - 2012-08-03 15:35 - 00038395 ____A C:\Users\PatriciaCoe\My Documents\Senior Discounts... PASS IT ON.htm
2012-08-03 15:35 - 2012-08-03 15:35 - 00038395 ____A C:\Users\PatriciaCoe\Documents\Senior Discounts... PASS IT ON.htm
2012-08-03 15:35 - 2012-08-03 15:35 - 00000000 ____D C:\Users\PatriciaCoe\My Documents\Senior Discounts... PASS IT ON_files
2012-08-03 15:35 - 2012-08-03 15:35 - 00000000 ____D C:\Users\PatriciaCoe\Documents\Senior Discounts... PASS IT ON_files
2012-07-21 13:40 - 2012-07-21 13:41 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-21 13:40 - 2012-07-21 13:40 - 00001758 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-21 13:40 - 2012-07-21 13:40 - 00001758 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk
2012-07-21 13:40 - 2012-07-21 13:40 - 00000000 ____D C:\Users\All Users\Application Data\Apple Computer
2012-07-21 13:40 - 2012-07-21 13:40 - 00000000 ____D C:\Users\All Users\Apple Computer